Quick Summary
AllegedExecutive Summary
Qilin listed the Commission de la construction du Québec (CCQ) on its dark web portal on September 1, 2026. SOCRadar Dark Web Monitoring identified the listing. CCQ is Quebec’s quasi-governmental construction labor board, administering pension, benefits, and wage records for hundreds of thousands of construction workers across the province. This organization’s role in managing sensitive worker data, including pension and benefit information, makes it a potentially attractive target for ransomware operations seeking financial gain through extortion. Qilin has claimed 241 other victims in the prior 60 days, placing it among the most active RaaS operations currently running. The group concentrates on Manufacturing, Professional Services, and mixed geographies — the United States, Germany, and Italy dominate. Recent regulated-body listings include Whitehouse, ATF, PenLink, and the City of Winchester. This high victim count reflects a large affiliate network, making it difficult to attribute specific TTPs to a single affiliate without additional telemetry.
Technical Analysis
Stealer-log query for ccq[.]org returned severe findings. 25 records spanning December 2024 through September 1, 2026 — the most recent dated the same day as the listing. Exposure is concentrated on identity infrastructure: – authentification.ccq[.]org (ADFS / OAuth2 identity provider — 4 records) – portailsel.ccq[.]org/sel (employer and worker portal) – sel.ccq[.]org (primary portal — 12 records) Breakdown: 10 employee credentials, 3 customer, 12 unclear. Profile: Corporate intrusion risk. The ADFS exposure at authentification.ccq[.]org is the headline finding. ADFS provides SSO across on-prem and cloud applications; compromised credentials or service tokens enable domain-wide lateral movement without triggering per-application authentication controls. Records dated September 1, 2026 — concurrent with the dark web listing — suggest these credentials were in active use at time of publication. That matches the pre-ransomware persistence pattern. Rotate ADFS and related SSO credentials immediately. Audit authentication logs for token issuance anomalies from at least December 2024 onward.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.