Commission de la construction du Quebec Data Breach

Alleged

Ransomware claim involving Commission de la construction du Quebec

Published: Sep 1, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Commission de la construction du Quebec
Industry
Government & Defense
Threat Actor
Qilin
Date of Incident
Sep 1, 2026

Executive Summary

Qilin listed the Commission de la construction du Québec (CCQ) on its dark web portal on September 1, 2026. SOCRadar Dark Web Monitoring identified the listing. CCQ is Quebec’s quasi-governmental construction labor board, administering pension, benefits, and wage records for hundreds of thousands of construction workers across the province. This organization’s role in managing sensitive worker data, including pension and benefit information, makes it a potentially attractive target for ransomware operations seeking financial gain through extortion. Qilin has claimed 241 other victims in the prior 60 days, placing it among the most active RaaS operations currently running. The group concentrates on Manufacturing, Professional Services, and mixed geographies — the United States, Germany, and Italy dominate. Recent regulated-body listings include Whitehouse, ATF, PenLink, and the City of Winchester. This high victim count reflects a large affiliate network, making it difficult to attribute specific TTPs to a single affiliate without additional telemetry.

Technical Analysis

Stealer-log query for ccq[.]org returned severe findings. 25 records spanning December 2024 through September 1, 2026 — the most recent dated the same day as the listing. Exposure is concentrated on identity infrastructure: – authentification.ccq[.]org (ADFS / OAuth2 identity provider — 4 records) – portailsel.ccq[.]org/sel (employer and worker portal) – sel.ccq[.]org (primary portal — 12 records) Breakdown: 10 employee credentials, 3 customer, 12 unclear. Profile: Corporate intrusion risk. The ADFS exposure at authentification.ccq[.]org is the headline finding. ADFS provides SSO across on-prem and cloud applications; compromised credentials or service tokens enable domain-wide lateral movement without triggering per-application authentication controls. Records dated September 1, 2026 — concurrent with the dark web listing — suggest these credentials were in active use at time of publication. That matches the pre-ransomware persistence pattern. Rotate ADFS and related SSO credentials immediately. Audit authentication logs for token issuance anomalies from at least December 2024 onward.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.