Doimo Cucine Data Breach

Alleged

Ransomware claim involving Doimo Cucine.

Published: Aug 17, 2026 Panzer
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Doimo Cucine
Industry
Government & Defense
Threat Actor
Panzer
Date of Incident
Aug 17, 2026

Executive Summary

Panzer ransomware listed Doimo Cucine on its dark web portal on August 17, 2026, identified through SOCRadar’s Dark Web Monitoring service. Doimo Cucine is a mid-sized Italian manufacturer of kitchen cabinetry and home furnishings, distributing products through dealer networks across Europe. The claim correlates with credentials on an internal cloud endpoint that went unrotated for 2.5 years, with the most recent log dated August 10, 2026, just days before publication. The company’s operational scope and focus on physical goods manufacturing could attract ransomware operations seeking significant financial leverage. Panzer claimed 11 other victims in the 60 days prior to this listing. The ransomware group’s sector preferences primarily include Manufacturing, Technology, and Government & Defense. Their geographic concentration has historically been in Thailand, Spain, and South Korea. Recent victims claimed by Panzer include DL E&C, Alpine Electronics Europe, and Castilla La Mancha. Doimo Cucine’s Italian origin represents a geographic expansion from Panzer’s typical concentration on Asian and European countries like South Korea and Spain, though Italy falls within the broader European scope.

Technical Analysis

Six records were recovered against doimocucine[.]it, all specifically targeting cloud.doimocucine[.]it, which is the organization’s internal cloud infrastructure. The usernames found in these records appear as numeric or short masked identifiers, consistent with employee or system accounts. The log dates for these records span from February 2024 up to August 10, 2026. Notably, the insertion dates for these records lag the log dates by months to years across multiple entries, strongly indicating that the credentials were never rotated during this extended period. All six recovered records are conservatively classified as external-user credentials due to the masking of usernames. The exclusive focus on a single internal cloud endpoint, combined with a persistence window of 2.5 years and the context of a ransomware victim listing, strongly suggests systematic access to Doimo Cucine’s hosted file-sharing or internal collaboration infrastructure. The limited observation windows for these logs do not provide an alternative explanation for this pattern of prolonged credential exposure. This credential exposure could have facilitated initial access or lateral movement for the threat actor. Response Priorities Force password resets for all four identified account identifiers on cloud.doimocucine[.]it. Pull file-access logs from that platform and look for anomalous download or exfiltration activity from February 2024 onward.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.