Quick Summary
AllegedExecutive Summary
VNSO, an organization based in Vietnam, has been listed as a victim on the Nova ransomware group’s dark web portal, published on July 22, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The organization’s specific sector was not recorded in the source data beyond its Vietnamese location. Its appearance adds a Vietnamese entry to a Nova victim population that has leaned toward Southeast Asia and technology-adjacent targets. In the 60 days prior to this listing, Nova has claimed 37 other victims across its leak portal. The group has shown a targeting pattern weighted toward technology, transportation and logistics, and the public sector. Geographically, its victims are concentrated in Indonesia, Australia, and the United States. Other recent Nova listings that overlap with VNSO’s profile — Southeast Asian and nearby recent listings — include La Financière d’Orion, Koplarla, Jota Joias Premium, and Dephub. VNSO fits the group’s regional Southeast Asian focus rather than any single sector concentration.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the vnso.vn domain. The queried slice returned around twenty-five records spanning the organization’s own identity/SSO endpoint, corporate mail infrastructure, and several back-office subdomains, alongside external users on the identity portal. One corporate account recurs across roughly half a dozen third-party consumer and Vietnamese web services, a strong workstation-compromise signal, and another corporate account was seen on the corporate mail host. The same weak password recurs across multiple corporate records, pointing to poor password hygiene. The dominant profile is Mixed, with a long-tailed freshness window running from August 2024 to mid-July 2026, indicating credentials that appear not to have been rotated. For ransomware groups such as Nova, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. While the stealer-log evidence here does not confirm that these specific credentials were used by Nova, the exposure of corporate identity and mail systems alongside reused passwords is consistent with the kill chain typically observed for this class of incident, and it makes credential resets, MFA enforcement, and workstation triage a priority for organizations fitting this profile.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.