Quick Summary
AllegedExecutive Summary
CreateInfor, an organization based in Portugal operating within the professional services sector, was listed on the M3RX ransomware group’s leak portal on July 26, 2026. This claim was identified by SOCRadar’s Dark Web Monitoring service. The professional services sector, along with business services and manufacturing, represents a significant targeted area for M3RX. Over the preceding 60 days, M3RX claimed nine victims across a geographically diverse range of countries, with no particular hub dominating their activity. The United States accounts for the largest share of victims (four), while Portugal and Germany each have one listed. Similar recent targets include Premier HVAC and Refrigeration, VHS Hydraulics, UB Freight, and WRT World Enterprises. As a Portuguese entity in the professional services sector, CreateInfor aligns with M3RX’s targeting patterns, though it is the sole Portuguese victim noted in this recent activity period, highlighting the group’s scattered approach.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry did not yield any records for the domain createinfor.pt within the queried data sample. It is important to note that a negative result does not conclusively indicate the absence of a compromise. The query was based on a paginated subset of harvested logs, not an exhaustive dataset. Additionally, the organization may operate under alternative corporate domains or regional subsidiaries not included in the current coverage. Credentials associated with personal email addresses used by employees would also not be detected by a corporate-domain specific search. The absence of specific stealer-log records for createinfor.pt during this reporting window reflects a lack of immediate signal rather than a completed comprehensive investigation. The threat actor’s methodology often involves acquiring recent infostealer logs from underground marketplaces. These logs are then used to validate corporate credentials, which can provide access to critical systems like Microsoft 365, VPNs, or remote-access portals. While the current telemetry does not confirm this exact intrusion path for CreateInfor, it highlights a common initial access vector for ransomware groups. Continued monitoring of dark web marketplaces and proactive credential hygiene practices remain essential for organizations.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.