Quick Summary
AllegedExecutive Summary
Columbus Informatica, an IT solutions and services company based in Italy, was listed on the Qilin ransomware group’s dark web portal on September 22, 2026. The identification of this listing was made possible through SOCRadar’s Dark Web Monitoring service. IT service companies are often targeted by ransomware groups due to their privileged access to client systems, making a compromise at Columbus Informatica a potential gateway to its downstream clients. The Qilin ransomware group has been highly active, claiming 248 victims in the 60 days preceding this report. Their primary targets are in the Manufacturing, Professional Services, and other sectors, predominantly in the United States, Germany, and the United Kingdom. However, the group is increasingly targeting companies in Southern Europe, including IT firms like Columbus Informatica. The potential for an IT services company to expose its clients’ data makes this listing particularly significant.
Technical Analysis
SOCRadar’s stealer-log telemetry identified one record associated with columbusinformatica[.]it. This record, logged on December 24, 2025, pertained to corporate employee credentials captured through a workstation compromise on a third-party endpoint. It is important to note that a single record does not indicate limited risk; rather, it suggests limited visibility within the queried dataset, as queries are paginated and additional records may exist in unreturned portions of the data. The nature of the workstation compromise indicates that an infostealer likely operated on an employee’s machine, harvesting stored credentials. If these credentials were not subsequently rotated, they would have been available on underground markets since late December 2025, approximately nine months prior to the ransomware group’s listing. This highlights the extended period for which such compromised credentials can be exploited. The exposure of a single, unrotated credential at an IT services company like Columbus Informatica presents a significant risk. Such companies often possess privileged access to their clients’ environments. A successful intrusion into Columbus Informatica’s systems could potentially allow attackers to escalate their access to downstream clients’ networks. Therefore, the primary concern is not solely the ransomware listing, but the broader implications of credential compromise and potential lateral movement. Recommended Actions: Identify the affected employee account and rotate credentials immediately. Investigate the endpoint for infostealer artifacts, such as scheduled tasks, modified startup items, and suspicious outbound connections from the December 2025 timeframe. Determine if the compromised account had access to client systems and notify affected clients if necessary. Monitor Qilin’s leak portal for any data publication.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.