Quick Summary
AllegedExecutive Summary
Dephub, an organization based in Indonesia, has been listed as a victim on the Nova ransomware group’s dark web leak portal, with the entry published on July 19, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The entry places Dephub among the most recent additions to Nova’s victim population. In the 60 days prior to this listing, Nova had claimed 37 other victims across its leak portal. The group has primarily focused on the technology, transportation/logistics, and education sectors, with victims geographically clustered in Indonesia, Australia, and the United States. Other recent Nova listings that overlap with Dephub’s profile include Universitas Nasional, Badan Pangan Nasional, Jota Joias Premium, and meralmanisa. Dephub fits within this broader, opportunistic targeting pattern rather than marking a shift in the group’s focus.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the kemenhub.go.id domain. The returned sample contained 3 records tying employee credentials to organizational systems, and 22 records associated with customer, supplier, or external accounts on org-owned systems. High-value endpoints observed included the corporate mail service, a maritime single-sign-on/identity endpoint, and an internal Lotus Domino application, all on the target domain. The dominant profile is corporate intrusion risk, with sample freshness spanning July 18 to July 19, 2026. For ransomware groups such as Nova, infostealer-harvested credentials are a well-documented initial-access vector. Operators or initial-access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. While the stealer-log evidence here does not confirm that these specific credentials were used by Nova, the pattern is consistent with the kill chain typically observed for this class of incident. CTI teams should prioritize credential rotation, MFA enforcement, and endpoint review for the exposed accounts, and treat the exposure as a live risk rather than a historical artifact.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.