Comet Enterprise Corp Data Breach

Alleged

Ransomware claim involving Comet Enterprise Corp

Published: Jul 16, 2026 The Gentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Comet Enterprise Corp
Industry
Business Services
Threat Actor
The Gentlemen
Date of Incident
Jul 16, 2026

Executive Summary

Comet Enterprise Corp, an organization based in Taiwan, has been identified as a victim on The Gentlemen ransomware group’s dark web portal. The listing, published on July 16, 2026, was detected by SOCRadar’s Dark Web Monitoring service. While the specific industry for Comet Enterprise Corp was not detailed in the leak-site listing, its operational location in Taiwan places it within the broader context of The Gentlemen’s recent extortion activities, which have impacted various regions and industries globally. The company’s listing underscores the expansive reach of the threat actor. In the 60 days leading up to this listing, The Gentlemen claimed 132 other victims. The group predominantly targets organizations within the Business Services, Manufacturing, and Healthcare sectors, with a significant concentration of victims located in the United States, Germany, and France. Comet Enterprise Corp’s inclusion, while not fitting the group’s most common victimology, serves as a key data point illustrating the diverse targeting scope of The Gentlemen ransomware. Previous victims with similar profiles include Excel Cell Electronic, Yao Yuan Technology, Jyharn Electronic, and Terry P Moosmann CPA PC, highlighting the varied nature of their campaigns.

Technical Analysis

An analysis of SOCRadar’s stealer-log telemetry for the domain comet-bearing.com.tw returned no associated records in the queried data slice. However, it is crucial to understand that a null result from this specific query does not conclusively indicate that the organization is unaffected. The telemetry data is gathered from a paginated, partial sample, and credentials may exist under alternative corporate domains. Furthermore, compromised credentials might be associated with personal email aliases or may have been harvested and subsequently rotated prior to their indexing in the queried datasets. The absence of credential exposure within this particular query should not be interpreted as evidence of the organization’s security. Infostealer-harvested credentials are a widely recognized initial access vector for ransomware operations. Threat actors or initial access brokers often source these credentials from underground marketplaces, validate them, and use them to gain unauthorized access to corporate networks via platforms like Microsoft 365, VPNs, or remote-access portals before deploying ransomware. Therefore, the lack of identified credentials does not rule out this potential intrusion path. CTI teams should consider continuing dark web and stealer-log monitoring for Comet Enterprise Corp. Proactive credential hygiene checks, including password rotation and multi-factor authentication reviews, remain essential. It is also advisable to monitor alternate corporate domains and to scrutinize activity logs for Microsoft 365, VPNs, and remote-access portals for any suspicious behavior, as the lack of evidence in one dataset does not mean a compromise has not occurred.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.