Quick Summary
AllegedExecutive Summary
Eva AI Limited, a United Kingdom-based company specializing in AI-driven recruitment and talent management platforms, was listed by the Direwolf ransomware group on August 17, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The company’s operations involve hosting infrastructure for international development partners, including the UN Development Programme, which presents a complex data exposure scenario. This targeting aligns with Direwolf’s typical profile of engaging with entities in English-speaking markets within the technology sector, particularly those with significant third-party data dependencies. In the 60 days leading up to this listing, Direwolf claimed approximately 20 other victims, with a primary focus on the Technology, Healthcare, and Professional Services sectors. The ransomware group has shown a geographical concentration in the United States, the United Kingdom, and Brazil. Previous UK-based or technology-sector victims attributed to Direwolf include Mighty Kingdom, Wishfully Studios, DXS International, and TOTVS. The targeting of Eva AI Limited fits within this pattern, highlighting the group’s continued focus on these industries and regions.
Technical Analysis
SOCRadar’s analysis of Eva AI’s domain (eva[.]ai) revealed 25 records in stealer-log data. Of these, 22 records indicated access by external users through various Eva AI subdomains. These subdomains included undp.eva[.]ai, undp-globalcall.eva[.]ai, and undp-ieo.eva[.]ai, which are associated with UNDP partnership portals, as well as semester.eva[.]ai and apply.eva[.]ai, used for candidate management. Critically, no credentials belonging to Eva AI employees with the @eva[.]ai email domain were found within this specific sample. The stealer-log data spanned from June 2026 to August 10, 2026. Some of the exposed records indicated credentials that had been active for up to two years, suggesting either unrotated credentials or repeated harvesting of the same account information over an extended period. This exposure specifically points to compromised external user accounts accessing Eva AI’s hosted infrastructure, rather than a direct compromise of employee workstations. To assess potential employee credential exposure, further queries against different dataset slices would be necessary. The sustained pattern of compromised external user access, particularly concerning the UNDP-linked subdomains, represents a significant indicator of potential compromise, irrespective of the absence of direct employee credentials in the initial query. The exposure of partner data associated with these subdomains carries additional implications, potentially triggering notification obligations for Eva AI, the UNDP, and other affiliated international development partners whose users accessed these portals. This situation warrants a thorough review of credential hygiene for Eva AI’s primary identity infrastructure, with the UNDP subdomain exposure adding a layer of secondary concern. Recommended actions include continued monitoring of dark web and stealer-log feeds, proactive credential hygiene checks, including password rotation and multi-factor authentication reviews for all user accounts accessing Eva AI and associated partner systems. Monitoring of alternate corporate domains and reviewing access logs for Microsoft 365, VPNs, and remote-access portals should also be prioritized.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.