Crowe Data Breach

Alleged

Ransomware claim involving Crowe

Published: Aug 19, 2026 coinbasecartel
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Crowe
Industry
Business Services
Threat Actor
coinbasecartel
Date of Incident
Aug 19, 2026

Executive Summary

Crowe, a prominent professional services firm based in Chicago, has been targeted by the CoinbaseCartel ransomware group, with the group listing Crowe on its dark web portal on August 19, 2026. This listing, identified via SOCRadar’s Dark Web Monitoring service, marks Crowe as a significant victim. As a top-10 US accounting and professional services firm providing audit, tax, advisory, and risk management services, Crowe serves a broad clientele across the financial services, healthcare, government, and private equity sectors. A breach affecting Crowe carries a substantial secondary exposure risk to all its client organizations, particularly those within regulated industries. CoinbaseCartel has demonstrated a concentrated effort against professional services firms in the 60 days preceding this listing, with Advanced Engineering Consultants also named. The targeting of Crowe, an organization with over 4,000 employees and extensive global operations, suggests that CoinbaseCartel has secured access beyond typical mid-market targets, potentially through acquiring or developing advanced intrusion capabilities. This strategic targeting indicates a sophisticated approach rather than opportunistic attacks, aligning with the group’s focus on high-value entities.

Technical Analysis

SOCRadar’s stealer-log telemetry identified 19 records associated with crowe.com, categorized with a “severe” rating. These records comprise 12 employee credentials for organizational systems and 7 corporate credential entries. The critical aspect is the access these credentials provide, including Microsoft’s My Signins portal (mysignins.microsoft.com) for Azure AD identity management, Crowe’s own SSO portal (ilogin.crowe.com), ClearPass network access control (clearpass.crowe.com) for network device authentication, and Microsoft Dynamics 365. The timestamps for these credentials range from June 11 to August 19, 2026, extending to the day of the CoinbaseCartel’s public listing. The combination of exposed credentials is of particular concern. Network Access Control (NAC) credentials alone can offer a pathway to network-level access, potentially bypassing traditional perimeter security measures. When this is coupled with access to cloud identity management, single sign-on (SSO) portals, and critical business applications like Microsoft Dynamics 365, the overall risk profile escalates significantly. This comprehensive set of access points suggests a pre-staging phase for a potential intrusion, rather than a simple reconnaissance effort. Given the identified credential exposure, it is crucial to treat all 19 identified credentials as compromised. Immediate actions should include revoking NAC and Identity Provider (IdP) sessions. Furthermore, an audit of Microsoft Dynamics 365 and SharePoint for any unauthorized data access or exfiltration is recommended. The presence of credentials with timestamps extending up to the publication date indicates an active incident posture, requiring immediate response rather than a retrospective investigation.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.