CPACB Data Breach

Alleged

Ransomware claim involving CPACB

Published: Sep 29, 2026 m3rx
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
CPACB
Industry
Professional Services
Threat Actor
m3rx
Date of Incident
Sep 29, 2026

Executive Summary

The ransomware group m3rx has claimed CPACB, a Canadian professional services firm, as a victim, with the listing appearing on September 29, 2026. This incident was identified through SOCRadar’s Dark Web Monitoring services. The claim is part of a pattern of simultaneous attacks by m3rx against small and mid-sized professional services organizations. This particular incident aligns with m3rx’s ongoing campaign targeting North American entities. In the 60 days preceding this listing, m3rx claimed seven prior victims. The group has primarily targeted the Professional Services, Technology, and Retail & E-Commerce sectors, with victims located in the United States, Brazil, and Canada. CPACB’s profile as a professional services firm in North America fits squarely within m3rx’s typical targeting strategy. Previous victims identified in relation to m3rx include Interconnect Computer Cabling Services Inc., Soma Soluções em T.I., Otero Geeza Law P.A., and Noon Sugar Mills Limited.

Technical Analysis

Seven records related to the domain cpacb[.]com were identified, all categorized as Category A, indicating employee credentials exposed on organization-controlled infrastructure. These records include credentials for the cPanel web hosting admin interface at cpacb[.]com:2083 and the email administration panel at cpacb[.]com:2096. Additionally, general email management panel credentials and one third-party HR and payroll identity platform credential were found. The exposure window for these credentials is noted as July through August 2026, placing the credential compromise in the weeks immediately preceding the September 29 listing date. Access to cPanel provides a comprehensive foothold on a server, granting control over the file system, databases, DNS settings, and mail configurations. The timing of this credential exposure, between July and August 2026, immediately before the m3rx listing, suggests a potential pathway for the ransomware group’s operations. This level of access could facilitate further intrusion and data exfiltration activities. Action Required Rotate all cPanel and email-admin credentials immediately. Audit server access logs for the July–August period for any unauthorized changes, such as new mail forwarding rules or file modifications. Review the HR/payroll platform account for any signs of unauthorized access. If the cPanel version is outdated, ensure it is patched before restoring access.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.