Quick Summary
AllegedExecutive Summary
Yaomasa, an organisation based in Japan, has been listed as a victim on the AiLock ransomware group’s dark web portal, published on August 13, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. While specific industry details for Yaomasa were not available in the listing data, the organisation operates within Japan’s business sector. AiLock is an emerging ransomware group that has shown a discernible interest in Japanese and East Asian organisations within its recent operational window. In the 60 days prior to this listing, AiLock has claimed 7 other victims across its leak portal. The group has demonstrated a targeting pattern across the Technology, Construction, and Manufacturing sectors. Geographically, its victims are concentrated in Japan, the United States, and Mexico. Other recent AiLock listings that share Yaomasa’s regional profile, specifically Japanese organisations, include Hokua and DAISEN. Organisations like WBF Construction and Pinturas Prisa represent the group’s broader geographic spread. Yaomasa’s listing places it squarely within AiLock’s primary geographic focus area during this period.
Technical Analysis
Initial access correlation against SOCRadar’s stealer-log telemetry surfaced a notable exposure for the yaomasa.com domain. One record was identified in the returned sample: a corporate email address (@yaomasa.com) captured against a Japanese third-party platform (ncw.jp). This is consistent with workstation compromise, indicating that at least one employee endpoint was infected with credential-stealing malware. No credentials directly against Yaomasa’s own infrastructure, such as identity providers, admin portals, or mail systems, were visible in this specific slice of data. The dominant risk profile identified is workstation compromise. The log date for this exposure was February 22, 2026. It is important to note that the absence of direct organizational infrastructure credentials in this sample does not rule out their existence in records outside the queried dataset; this finding represents a floor, not a ceiling, of potential exposure. For ransomware groups like AiLock, infostealer-harvested credentials are a well-documented initial access vector. Operators or initial access brokers commonly source fresh logs from underground marketplaces, validate the corporate credentials, and then use them to log into systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log evidence presented here does not confirm that these specific credentials were used by AiLock, an infected employee workstation is a consistent precursor to the credential validation phase of a ransomware kill chain. CTI teams should treat the identified corporate account as a priority for password rotation and forensic investigation. Continued dark web and stealer-log monitoring is recommended for Yaomasa. Proactive credential hygiene checks, including password rotation and multi-factor authentication review, should be implemented. Furthermore, monitoring of alternate corporate domains, as well as Microsoft 365, VPN, and remote-access activity, is advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.