Quick Summary
AllegedExecutive Summary
Codinter, a technology company operating in the United States and involved in providing IT products, technology solutions, and procurement services to enterprise and government clients, was listed as a victim by the Insomnia ransomware group on August 17, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. Codinter’s operations span North American and Latin American markets, and its role as an intermediary for technology vendors and procurement services exposes a broad client base to potential supply-chain risks. Insomnia ransomware has claimed five other victims in the 60 days preceding Codinter’s listing. The group’s typical targets include the Technology, Healthcare, and unspecified sectors, with a concentration of victims in the United States and Panama. Recent organizations claimed by Insomnia include Park Place Behavioral Health Care, Laempe Reich, and Merritt Construction. Codinter represents the most significant technology-sector victim claimed by Insomnia in this recent activity cycle, aligning with the group’s focus on the technology industry.
Technical Analysis
SOCRadar telemetry identified 25 records associated with the domain codinter[.]com. Sixteen of these records were classified as employee credentials on organizational systems. Specifically, eight credentials targeted Microsoft identity infrastructure (login.microsoftonline[.]com) using @codinter.com email addresses, one was found on login.live[.]com, three were associated with SAP Ariba procurement (service.ariba[.]com), and four were linked to a third-party supplier portal (portalproveedores.elcondor[.]com), with a total of seven records found for this endpoint. Additionally, six other @codinter.com credentials appeared on third-party Software as a Service (SaaS) platforms, including LinkedIn and cambridgeone[.]org. A notable finding was a single account, ven****[email protected], appearing in 11 records over a period from January to August 15, 2026. This indicates a credential reuse and lack of rotation for over seven months. Given Codinter’s position as a technology vendor serving enterprise and government clients, this extended period of credential exposure, especially on a supplier portal, presents a significant supply-chain risk that could extend beyond Codinter’s own network perimeter. The exposure of eight Microsoft identity infrastructure credentials, three SAP Ariba procurement credentials, and the single persistent account across seven months is consistent with common credential-harvesting and lateral movement tactics observed in technology sector ransomware incidents. The compromise of procurement systems, such as service.ariba[.]com and portalproveedores.elcondor[.]com, poses an elevated risk due to Codinter’s intermediary role, potentially exposing their downstream clients who share access to these supplier portals. Immediate revocation of Microsoft 365 credentials and enforcement of multi-factor authentication for all observed @codinter.com accounts are recommended, starting with the identified persistent account. Auditing access logs for service.ariba[.]com and portalproveedores.elcondor[.]com from January 2026 onward is also advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.