Quick Summary
AllegedExecutive Summary
Fidelity Services Group, a financial services company operating in the United Kingdom, has been designated as a victim by the ransomhouse ransomware group. This listing was published on their dark web portal on July 15, 2026, and was identified through SOCRadar’s Dark Web Monitoring service. The organization’s industry is reported as financial services. This incident adds Fidelity Services Group to a diverse set of ransomhouse targets observed in recent weeks, indicating a broad operational scope for the threat actor. In the 60 days preceding this listing, ransomhouse claimed at least four other victims. Their recent activity has targeted sectors including financial services, construction, and manufacturing, without a clear preference for any single industry. Geographically, ransomhouse’s victims are spread across the United Kingdom, Italy, and Argentina. While other listed victims include Bonacio, Promepla, Ma Pak Leung Company Limited, and Aegle Aviation, Fidelity Services Group stands out as the group’s first explicit financial services victim within this recent timeframe, differentiating it from potential patterns of continued targeting within established sectors.
Technical Analysis
SOCRadar’s analysis of initial-access correlation against stealer-log telemetry revealed a significant exposure related to the fidelity-services.com domain. The queried dataset contained approximately ten corporate credentials associated with an internal workstation signal, one third-party/external user on an organization-owned URL, and fourteen corporate users noted on third-party services. A key finding was the capture of multiple corporate usernames from the fidelity-services.com domain on the Microsoft identity provider (login.microsoftonline.com), which, if valid, could grant direct access to the organization’s tenant and associated SaaS applications. Additionally, a remote-access gateway on a non-standard port was identified. A recurrent pattern of at least two corporate identities appearing on both the Microsoft identity endpoint and various third-party services suggests compromised employee workstations. The captured credentials show a freshness window from June 17 to July 14, 2026, with near-daily log dates indicating ongoing credential harvesting rather than historical data. These findings are particularly relevant as infostealer-harvested credentials are a well-documented initial access vector for ransomware groups like ransomhouse. Operators or initial access brokers frequently source such logs, validate credentials, and use them to gain access to systems through platforms like Microsoft 365, VPNs, or remote-access portals, ultimately enabling ransomware deployment. While the stealer-log evidence does not definitively confirm that these specific credentials were used by ransomhouse in this incident, the presence of compromised Microsoft 365 identities for the organization is a significant risk factor consistent with this class of intrusion. Threat intelligence teams should treat these exposed identities as potential access paths requiring investigation. Recommended immediate actions include auditing affected accounts, prioritizing credential rotation, revoking active sessions, and enforcing multi-factor authentication for all compromised or potentially targeted accounts. Further monitoring of alternative corporate domains and reviewing recent remote access and Microsoft 365 activities are also advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.