Quick Summary
AllegedExecutive Summary
On July 14, 2026, the construction firm Arkın Group, based in Turkey, was identified on the dark web leak portal of the BlackNevas ransomware group. SOCRadar’s Dark Web Monitoring service detected this listing, indicating Arkın Group as a claimed victim. The construction industry is particularly vulnerable to ransomware attacks due to the significant financial impact of project delays and operational downtime. BlackNevas is identified as a low-frequency operator, with few claimed victims in the period preceding Arkın Group’s listing. The victims were located in Turkey, Saudi Arabia, and Sri Lanka, spanning the construction and consumer services sectors.
Technical Analysis
Correlating Arkın Group’s listing with SOCRadar’s stealer-log telemetry revealed activity related to the domain arkingroup[.]com. The collected data included employee credentials for the company’s webmail (webmail.arkingroup[.]com) and numerous corporate usernames (@arkingroup[.]com) across various third-party services such as TeamViewer, Oracle SSO, and Auth0. A notable observation was the repeated use of a single corporate account across multiple services, suggesting a compromised employee workstation. The exposed credentials for remote access and enterprise SSO are critical for threat actors to facilitate lateral movement within a network. The observed credential exposure window spans from January 2024 to early July 2026. While direct confirmation of BlackNevas’s use of these specific credentials is not provided, the pattern of exposed webmail, TeamViewer, and SSO logins aligns with the typical modus operandi for ransomware attacks. Recommended response actions include resetting passwords, revoking active sessions and tokens on affected services, and conducting endpoint forensics on compromised user accounts.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.