Quick Summary
AllegedExecutive Summary
Basic Grain Products, an agriculture and food production company, was listed on the Akira ransomware group’s dark web portal on August 6, 2026. The listing was identified by SOCRadar’s Dark Web Monitoring service. While the company’s country of registration was not specified in the source, its operations in food production are significant. This sector often involves operational technology and production scheduling systems that are critical to business operations, making it a potential target for ransomware attacks. This marks the second such listing for Akira on the same date. In the 60 days preceding this listing, Akira claimed 41 other victims. The group has frequently targeted the business services, manufacturing, and consumer services sectors, with a notable concentration of victims in the United States, Canada, and the United Kingdom. While food production is not a primary target for Akira, the appearance of a second listing from this sector within a short timeframe suggests that Akira may be incidentally acquiring victims from this industry as part of its broader mid-market outreach. Previous listings related to Basic Grain Products’ profile include Wade’s Dairy, Franz Krause artworksgroup, Nesco Bus Maintenance, and Excalibur Rentals.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry for tastemorr.com, queried against a paginated sample, returned no records indicating credential exposure. It is important to note that a null result does not confirm the absence of a compromise. The query was limited to a specific dataset and a single domain, which may not encompass credentials associated with alternate corporate domains, potential mismatches between brand and legal entity names, or credentials used under personal email aliases on corporate systems. The queried domain, tastemorr.com, is identified as a product brand rather than a corporate namespace, further limiting the scope of a single-domain lookup. The Akira ransomware group commonly leverages infostealer-harvested credentials as an initial access vector. Threat actors or initial access brokers typically source these credentials from underground marketplaces, validate them, and then use them to access systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. The lack of surfaced evidence in this query does not preclude this possibility. Credentials may exist in data feeds not covered by this specific query, may have been rotated before being indexed, or could have been harvested using personal email addresses. Given these findings, CTI teams should prioritize ongoing monitoring of the dark web and stealer-log feeds. Proactive credential hygiene checks, including password rotation and multi-factor authentication reviews for Microsoft 365, VPNs, and remote-access portals, are recommended. Monitoring of alternate corporate domains should also be considered to ensure a comprehensive security posture.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.