Desatera Sdn Bhd Data Breach

Alleged

Ransomware claim involving Desatera Sdn Bhd.

Published: Aug 16, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Desatera Sdn Bhd
Industry
Business Services
Threat Actor
Qilin
Date of Incident
Aug 16, 2026

Executive Summary

Desatera Sdn Bhd, a company operating in an undisclosed sector based in Malaysia, has been listed as a victim on the qilin ransomware group’s dark web portal, with the listing published on August 16, 2026. This incident was identified through SOCRadar’s Dark Web Monitoring service. The organization’s inclusion on the list highlights the ongoing threat posed by ransomware groups and their broad targeting strategies. In the 60 days preceding this listing, qilin claimed 186 other victims. The group primarily targets the Manufacturing, Professional Services, and Business Services sectors and has a notable concentration of victims in the US, Germany, and France. Recent victims like Connections, Radiant, Wanted, and 3f demonstrate qilin’s wide reach. While Malaysia is not a primary geographic focus for qilin, this listing indicates the group’s opportunistic approach to targeting organizations across various industries and regions.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry did not return any records for www.desatera.com.my within the queried data slice. It is important to note that a null result does not definitively confirm the absence of compromise. The paginated sample may not have captured all relevant logs, and credentials could exist under alternate corporate domains or personal email aliases used by Desatera Sdn Bhd employees. Therefore, CTI teams should not interpret this null query as an indication that the organization is unaffected. For ransomware groups like qilin, credentials harvested by infostealers are a known method for initial access. Threat actors or initial access brokers often source these credentials from underground marketplaces, validate them, and then use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. The absence of evidence in this specific query does not preclude this possibility, as credentials might have appeared in other data feeds, been rotated before indexing, or been harvested using personal email aliases. Consequently, CTI teams should continue to monitor dark web and stealer-log feeds, conduct proactive credential hygiene checks, and review password rotation and multi-factor authentication configurations. Monitoring alternate corporate domains and reviewing activity on Microsoft 365, VPNs, and remote-access portals remain crucial steps in mitigating the risk of such attacks.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.