A&E + SMA Design Data Breach

Alleged

Qilin ransomware claim involving A&E + SMA Design

Published: Aug 24, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
A&E + SMA Design
Industry
Professional Services
Threat Actor
Qilin
Date of Incident
Aug 24, 2026

Executive Summary

A&E + SMA Design, a professional services firm based in the United Arab Emirates and operating under the domain ae[.]design, was identified on Qilin’s leak site on August 24, 2026. This event signifies Qilin’s ongoing expansion into Middle Eastern markets, adding a UAE-based firm to its list of victims which previously included entities across Europe and the Americas. The targeting of a professional services firm in the UAE aligns with Qilin’s broader strategy of diversifying its victim base geographically and across various industry sectors. In the 60 days preceding this listing, Qilin claimed 213 victims. Its primary targets have been in the Manufacturing, Professional Services, and unclassified industry sectors. The ransomware group has shown a preference for victims in the United States, Germany, and Italy, but has consistently pursued targets across Europe, the Americas, and the Middle East. A&E + SMA Design’s inclusion in Qilin’s victimology is consistent with the group’s pattern of targeting professional services firms, with other notable victims in this sector including Clear Align, Studio BOLDRIN PAOLO, The Pendas Law Firm, and White-Daters & Associates Inc.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry yielded no records associated with the domain ae[.]design within the queried dataset. It is important to note that the .design Top-Level Domain (TLD) is not commonly covered in standard stealer-log monitoring. Consequently, queries limited to this specific domain may not capture credential exposures that could be present under alternate corporate domains, such as those using the .ae country-code TLD or other regional UAE domains that A&E + SMA Design might utilize. The absence of observed records in this specific query should not be interpreted as confirmation of a clean security posture. The operational methodology of Qilin typically involves obtaining infostealer logs from illicit markets, validating acquired corporate credentials, and then leveraging these for access to platforms like Microsoft 365, VPNs, or remote-access portals, prior to deploying ransomware. For a professional services firm such as A&E + SMA Design operating in the UAE, the attack surface for credential compromise likely encompasses both its primary public-facing domain, ae[.]design, and any other regional or client-facing platforms hosted within the UAE. Considering Qilin’s aggressive pace of victim acquisition, averaging over three victims per day within the last 60 days, and its demonstrated interest in expanding into the Middle Eastern market, a thorough review of credential hygiene across all domains associated with A&E + SMA Design’s operations is a critical and time-sensitive security imperative.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.