Quick Summary
AllegedExecutive Summary
EFU Life Assurance, a financial services company based in Pakistan, has been listed as a victim on the Qilin ransomware group’s dark web portal, with the listing published on July 22, 2026. This incident was identified through SOCRadar’s Dark Web Monitoring service. As a life-assurance provider, the company handles customer-facing policy and health-claims portals alongside internal corporate systems, which increases its potential exposure. The listing of EFU Life Assurance is notable as it represents a relatively rare instance of a financial services and Pakistan-based entity being targeted by Qilin, whose recent victim base has been largely centered in the United States. In the 60 days leading up to this listing, Qilin claimed 126 other victims on its leak portal. The group has consistently targeted the business services, manufacturing, and healthcare sectors. Geographically, its victims are primarily located in the United States, Australia, and Spain. Other recent victims of Qilin that share similarities with EFU Life Assurance include Century Equities, TQ Financial Services, Cash Canada, and Infina Health (in the healthcare/insurance space). While EFU Life Assurance aligns with the group’s focus on financial services and insurance-adjacent entities, it represents one of the ransomware group’s fewer targets within the insurance sector, diverging from its dominant pattern of targeting business services and manufacturing organizations.
Technical Analysis
Initial access correlation conducted through SOCRadar’s stealer-log telemetry revealed a significant exposure for the efulife.com domain. The queried data set returned approximately twenty-five records. These included two records with corporate usernames associated with the internal webmail host, indicating a potential for direct employee credential compromise and email account takeover. The majority of the records, however, were customer-facing accounts on the company’s client and health-claims portals, identified through generic handles, consumer emails, or numeric policy IDs. The telemetry did not uncover any corporate credentials on third-party services, suggesting that evidence of workstation compromise outside the target environment is currently limited, with the dominant profile being mixed. Critically, the data’s freshness window is narrow, clustering between July 17 and July 21, 2026, which points to a recent and concentrated harvesting event occurring around the time of the Qilin listing. For ransomware groups like Qilin, credentials harvested by infostealers serve as a well-documented initial access vector. Threat actors or initial access brokers acquire recent logs from underground marketplaces, validate corporate credentials, and subsequently leverage them to gain unauthorized access to systems such as Microsoft 365, VPNs, or remote-access portals, ultimately enabling ransomware deployment. While the stealer-log evidence presented here does not definitively confirm that these specific compromised credentials were used by Qilin in an attack against EFU Life Assurance, the presence of compromised corporate mail credentials, coupled with a surge in exposed customer portal credentials, is consistent with the observed kill chain patterns for such incidents. This makes immediate mailbox credential resets, session revocation, and customer-account rotation critical priorities for the affected entity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.