Coface Data Breach

Alleged

Ransomware claim involving Coface

Published: Aug 16, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Coface
Industry
Financial Services
Threat Actor
Qilin
Date of Incident
Aug 16, 2026

Executive Summary

Coface, a company operating within the Financial Services sector and based in Italy, has been identified as a victim on the qilin ransomware group’s dark web portal. The listing was published on August 16, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. This incident places Coface among a growing number of entities that qilin has targeted in recent months, indicating the group’s persistent activity across various industries and geographic locations. In the 60 days leading up to this listing, qilin claimed 186 other victims. The group demonstrates a clear preference for targeting the Manufacturing, Professional Services, and Business Services sectors. Geographically, their primary targets are located in the US, Germany, and France. Previous victim listings by qilin, such as Loescher editore Torino, Mulino Padano, FERRARI MANGIMI SRL, and Brembo, show the group’s wide-ranging impact across different industries and regions. The targeting of Coface aligns with qilin’s established pattern of interest in financial services organizations.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry for the domain www.coface.it returned no records within the queried sample. It is important to note that a null result does not definitively confirm that the organization is unaffected. The paginated sample may not have encompassed all relevant logs associated with Coface, and credentials could potentially exist under alternate corporate domains or through personal email aliases used by Coface employees. Therefore, CTI teams should not interpret a null query as an indication of no compromise. For ransomware groups like qilin, the exploitation of infostealer-harvested credentials is a known method for initial access. Threat actors or initial access brokers frequently acquire recent credential logs from underground marketplaces. These validated corporate credentials are then used to access systems such as Microsoft 365, VPNs, or remote-access portals, preceding the deployment of ransomware. The absence of evidence in this specific query does not preclude this scenario; credentials might have appeared in feeds not included in this dataset, been rotated prior to indexing, or been obtained through personal email aliases. CTI teams should prioritize continued monitoring and proactive credential hygiene checks as the appropriate response, rather than relying on a null query as a guarantee of security. This includes reviewing password rotation practices, multi-factor authentication configurations, and activity logs for Microsoft 365, VPNs, and remote-access portals to identify any potential unauthorized access or suspicious behavior.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.