Quick Summary
AllegedExecutive Summary
Akira listed COAL (coal.es) on October 3, 2026, claiming a breach of the Spanish organization’s network and exfiltration of corporate data. SOCRadar’s stealer-log intelligence indicates that five employee identities were compromised across three internal platforms, with the records remaining active up to the date of the listing. The affected platforms include COAL’s customer/employee web portal, webmail system, and internal training platform. The combination of compromised credentials across these platforms—operational authentication, email access, and internal documentation—provides an attacker with the necessary tools to impersonate staff, identify internal resources, and move laterally within the network before potentially deploying ransomware. Exposure of the training platform is particularly concerning, as these systems often contain sensitive information such as HR records, compliance materials, and employee directory data, which can significantly accelerate targeted intrusions.
Technical Analysis
Akira is identified as an active ransomware group in Europe, employing a double extortion strategy, though it has also been known to rely solely on data theft for leverage without encryption. Their confirmed initial access methods include compromised VPN credentials and credentials obtained through infostealer malware targeting web applications. The observed multi-platform credential compromise for COAL aligns with patterns associated with infostealer malware affecting multiple employee endpoints. SOCRadar’s stealer-log intelligence detected compromised employee credentials across COAL’s web portal, webmail, and training platform. The exposure extended to five distinct employee identities, with records active up to the date of Akira’s listing. This indicates a significant and ongoing compromise of sensitive information accessible through these systems. The training platform, in particular, may hold HR records and employee directory data, which can be leveraged for further reconnaissance and lateral movement. Immediate actions recommended include forcing a rotation of all five identified employee credentials across affected platforms, auditing webmail and training system access logs for the period between August 25 and October 3, and enabling multi-factor authentication on all portal access points. Organizations should also assess whether client or partner data accessible via the training platform triggers data protection regulations like GDPR. Engaging an incident response firm with expertise in Akira intrusion patterns is also advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.