Quick Summary
AllegedExecutive Summary
Business Connexion (BCX), identified as South Africa’s largest technology services company, was listed on the dark web leak portal of the INC Ransom group on September 29, 2026. BCX provides ICT infrastructure, cloud, and managed services to enterprise and government clients across Africa. This listing was detected by SOCRadar’s Dark Web Monitoring service. The company’s extensive operations and the critical nature of its services may have made it an attractive target for ransomware and extortion activities. In the 60 days leading up to this listing, INC Ransom claimed 69 other victims, primarily in the United States, Canada, and Malaysia. The group has shown a concentration on the Professional Services, Manufacturing, and Healthcare industries. The listing of Business Connexion marks INC Ransom’s entry into the African market, specifically targeting a South African entity for the first time within this monitoring period. This aligns with the ransomware group’s pattern of expanding its reach beyond its typical North American targets.
Technical Analysis
SOCRadar’s stealer-log telemetry identified a significant exposure related to the domain bcx[.]co.za, with a total of 22 records detected. Among these, 11 higher-priority records were classified as employee credentials on BCX-controlled systems. These compromised credentials pertained to systems such as the ADFS identity provider at logon[.]bcx.co.za, Outlook Web Access at owa[.]bcx.co.za, employee self-service portals at employeezone[.]bcx.co.za and workzone[.]bcx.co.za, and Microsoft 365 (login.microsoftonline.com). An additional 11 records indicated BCX corporate email addresses exposed on third-party enterprise platforms, including SAP, Pluralsight, HPE Partner, and Windows Virtual Desktop. The freshness window for this data spanned from June 2024 through September 2026, with a notable cluster of exposures occurring in September 2026, immediately preceding the INC Ransom claim. The exposure of the ADFS identity provider is considered the most severe finding, as a federated identity provider allows a single compromised account to authenticate across multiple connected BCX systems without individual credential checks. This, combined with the recent exposures on Microsoft 365 and OWA, and the September 2026 credential cluster, presents an exposure profile consistent with the reconnaissance phase preceding a ransomware intrusion. While the stealer-log data does not confirm that INC Ransom utilized these specific credentials, all 22 records should be treated as compromised. Recommended actions include force-rotating ADFS and Microsoft 365 credentials, auditing SSO session logs from June 2024 onward, and reviewing OWA authentication logs for anomalous access patterns.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.