Quick Summary
AllegedExecutive Summary
Black X, an extortion group, has claimed a data breach targeting FE CREDIT, a financial services provider based in Vietnam. The claim, made on August 30, 2026, listed the company’s domain fecredit[.]com[.]vn. Infostealer telemetry data captured during the period from December 4, 2024, to August 30, 2026, indicated the presence of two employee credentials associated with OWA, BPM, and SSO portals. Black X asserted unauthorized access to FE CREDIT’s systems and data. As of the report’s writing, no independent verification of these claims has been completed. The targeting of a financial services provider in Vietnam by Black X aligns with the group’s observed operational patterns, suggesting a strategic focus on entities within this sector and region. Over the past 60 days preceding this report, Black X has claimed five victims on its leak site. The group’s geographic focus primarily includes Eastern Europe (YE) and South Korea (KR), with a strong sectorial preference for Financial Services and Manufacturing. FE CREDIT’s profile as a financial services company in Vietnam aligns with both the identified geographic and sectorial targeting tendencies of Black X. This indicates that FE CREDIT fits the typical profile for Black X’s operations, which appear to involve a smaller, yet strategically chosen, set of victims for extortion purposes.
Technical Analysis
SOCRadar CTI’s analysis of stealer-log data has returned a “severe_exposure_in_sample” verdict for FE CREDIT. The telemetry captured two employee credentials, specifically linked to OWA, BPM, and SSO portals. These credentials were recorded with timestamps spanning from December 4, 2024, to August 30, 2026, suggesting a sustained period of potential pre-attack access for approximately 20 months. The presence of credentials across multiple authentication and portal systems is consistent with preparatory activities commonly observed before extortion deployment by threat actors. The observed credential exposure across OWA, BPM, and SSO portals may indicate that the threat actor gained access to sensitive employee login information. This type of access could potentially facilitate lateral movement within the network, the exfiltration of data, or the deployment of ransomware. The longevity of the credential exposure (over 20 months) is particularly concerning, suggesting a prolonged period of undetected compromise or a highly persistent threat actor. It is important to note that while this telemetry indicates credential compromise, it does not definitively confirm that this specific access method was used for a full-scale breach or ransomware deployment against FE CREDIT. The findings suggest the need for immediate security actions. Continuous monitoring of dark web and stealer-log feeds for any further mentions of FE CREDIT is recommended. Organizations should also conduct proactive credential hygiene checks, including immediate password rotation for all affected or potentially affected accounts. A thorough review of multi-factor authentication (MFA) configurations and enforcement across all systems, especially for OWA, BPM, and SSO, is crucial. Furthermore, monitoring activity logs for Microsoft 365, VPNs, and remote-access portals for any anomalous behavior should be prioritized.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.