Quick Summary
AllegedExecutive Summary
AMBITION Group, a Japanese business services and staffing company, has been identified as a victim of the Settra ransomware group. The threat was revealed on August 19, 2026, through SOCRadar’s Dark Web Monitoring service. The listing on the Settra group’s dark web portal suggests a potential data compromise or extortion attempt against the organization. The Settra ransomware group has recently been active, with AMBITION Group being part of a batch of listings posted on the same day. Other organizations listed include M.A.K. Freight Systems in Malaysia (Transportation), Greco Steel Products in Greece (Manufacturing), ALPHANUMERIC SYSTEMS, INC. in the US, and West Coast Management and Realty. This diverse range of victims, spanning multiple countries and industries with seemingly unrelated geographic origins from Malaysia to Greece to Japan and the US, indicates potential access broker involvement rather than a specific sector or geographic targeting pattern by the ransomware group.
Technical Analysis
A query was performed on the domain ambitiongroup[.]co[.]jp in relation to stealer-log data. The results indicated that no records were found for this specific domain. It is crucial to note that this query covered only a bounded, paginated sample of the available data. The absence of positive findings does not confirm that the organization is unaffected by a compromise. Credentials may still exist in other feeds or databases not included in this query. Furthermore, compromised credentials could be associated with alternate corporate domains, personal email aliases used for corporate access, or may have been used and subsequently rotated before being indexed in the queried dataset. Therefore, the lack of identified records in this specific stealer-log query does not rule out the possibility of a compromise or the exfiltration of data. Continued monitoring of the dark web and stealer-log feeds is recommended. Additionally, proactive credential hygiene checks, including password rotation and multi-factor authentication review for Microsoft 365, VPNs, and other remote-access portals, are advised. Monitoring of alternate corporate domains should also be considered.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.