Quick Summary
AllegedExecutive Summary
Orova ransomware has listed Bai-chi CPA Firm, a certified public accounting firm based in Taiwan, as a victim on its dark web portal. The listing was observed on August 25, 2026, and was detected through SOCRadar’s Dark Web Monitoring. Bai-chi CPA Firm specializes in accounting, auditing, tax, and financial advisory services. This incident poses a significant risk of exposure for client financial, tax, and audit records. In the preceding 60 days, Orova has claimed 41 other victims. The primary sectors targeted by the group are listed as “Other,” Healthcare, and Professional Services, with the United States, Taiwan, and Hong Kong being the leading victim geographies. Recent listings that share a connection with Taiwan or professional services include Central Florida Civil LLC, David King Architect, Hilliard’s Air Conditioning & Heating Inc, and Integrated Site Management. This particular listing aligns with Orova’s established pattern of targeting Taiwanese professional services organizations, a consistent segment within their Asia-Pacific victim portfolio.
Technical Analysis
A query into stealer-log telemetry data targeting the domain baichi[.]com[.]tw returned no records. It is important to note that the datasets used for these queries are often paginated and sampled. Therefore, credentials may still exist within unqueried feeds, could have been rotated by the victim organization before indexing, or might have been harvested using personal email aliases that fall outside the scope of a domain-filtered search. Infostealer-harvested credentials represent a common initial access vector for the Orova ransomware group. Threat actors typically source fresh credential logs from underground markets, validate them against corporate accounts, and subsequently use these credentials to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. The absence of observed telemetry in this specific query does not definitively rule out such an attack scenario. Cybersecurity and threat intelligence teams should maintain continuous monitoring for further indicators and conduct proactive credential hygiene checks, rather than interpreting a null result as confirmation of no compromise.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.