Quick Summary
AllegedExecutive Summary
ShadowByt3$, a ransomware group, has claimed Ben Leeds Properties as a victim, with the incident identified on September 7, 2026, via SOCRadar’s Dark Web Monitoring. Ben Leeds Properties, a residential property management and lettings agency based in the United Kingdom, was added to the group’s dark web portal. The nature of the victim’s business, dealing with property management and potentially sensitive tenant and financial data, makes it an attractive target for ransomware and extortion activities. In the preceding 60 days, ShadowByt3$ has claimed five other victims, impacting the Retail & E-Commerce, Other, and Education sectors. Notable past victims include Knottingham Trent University, A-Plus Software Limited, and BayView Real Estate. The consistent targeting of real estate and property-adjacent organizations suggests a deliberate strategy by the group to focus on entities within the property sector. Ben Leeds Properties aligns directly with this observed pattern of targeting.
Technical Analysis
SOCRadar’s stealer-log telemetry identified four records associated with the domain benleedsproperties[.]com. While the count is low, the composition of these records is significant. All four records utilize the same corporate email address, @benleedsproperties.com. One credential specifically targets benleedsproperties.appfolio[.]com/users/sign_in, which is the victim’s tenant-specific AppFolio property management platform. This indicates a potential direct pathway into core business systems. The remaining three records show the same credential appearing on Pixlr, a third-party SaaS platform, across various dates from November 2025 through September 3, 2026. The persistence of the same unrotated corporate credential across multiple platforms over a ten-month period suggests either a persistent stealer activity or a compromise at the workstation level. The most immediate risk identified is the potential for corporate intrusion through the AppFolio platform, given the direct credential exposure on its login page. The persistent exposure of this credential on platforms like Pixlr, in addition to the sensitive AppFolio platform, raises concerns about the breadth of potential compromise. Reviewing access logs for the AppFolio platform from at least November 2025 onwards is crucial. Additionally, continued dark web monitoring for any further listings or evidence of data exfiltration by ShadowByt3$ is recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.