Della Casa Group AG Data Breach

Alleged

INC Ransom Ransomware Claim Regarding Della Casa Group AG

Published: Jul 28, 2026 INC Ransom
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Della Casa Group AG
Industry
Business Services
Threat Actor
INC Ransom
Date of Incident
Jul 28, 2026

Executive Summary

Della Casa Group AG, a Switzerland-based organization operating within the business services sector, has been listed as a victim by the INC Ransom ransomware group. The entry was noted on July 28, 2026, and identified by SOCRadar’s Dark Web Monitoring service. The specific business classification for the company on the threat actor’s portal was general/uncategorized, providing limited insight into the exact nature of the organization’s operations or data that might attract such attention. In the preceding 60 days before this listing, INC Ransom claimed 33 other victims. The ransomware group’s activity has predominantly targeted organizations in business services, manufacturing, and those falling under a general or uncategorized classification. The primary geographic locations for these victims have been the United States, Mexico, and the United Kingdom. Della Casa Group AG’s inclusion marks a rare instance of a Swiss organization being targeted by this group, which otherwise exhibits a strong focus on North American and UK entities. Notable recent victims include The HOP, Foundations to Freedom, Greene County (Georgia), and DUCON, indicating a broad reach and diverse targeting strategy by INC Ransom.

Technical Analysis

A review of stealer-log data for the domain dellacasa[.]group returned zero records within the queried dataset. It is important to note that this query operates on a paginated, partial sample and may not capture all available credentials. Therefore, the absence of observed records does not definitively confirm that the organization is unaffected or that no compromise has occurred. Credentials could potentially exist under alternate corporate domains associated with Della Casa Group AG or utilize personal email aliases of staff members. Furthermore, records might be present in data feeds not included in the queried dataset, or credentials may have been used and subsequently rotated before being indexed. The primary modus operandi for INC Ransom involves leveraging infostealer logs as an initial access vector. Threat actors typically acquire fresh logs from brokers, validate the corporate credentials found within them, and then attempt to gain access to systems via platforms such as Microsoft 365, VPNs, or remote-access portals. This reconnaissance and access phase precedes the deployment of ransomware. While the current stealer-log check for Della Casa Group AG did not yield any findings, this does not preclude the possibility of these credential-harvesting methods being employed. Continued monitoring and proactive credential hygiene measures remain essential. These findings underscore the importance of ongoing dark web and stealer-log monitoring. Organizations should conduct proactive credential-hygiene checks, including regular password rotation and thorough review of multi-factor authentication configurations. Vigilance in monitoring alternate corporate domains and reviewing activity logs for Microsoft 365, VPNs, and remote-access portals are also recommended steps to mitigate potential threats.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.