Quick Summary
AllegedExecutive Summary
Great Bay Bio, a Manufacturing organization based in Hong Kong, has been listed by the ransomware group nightspire on its dark web portal on September 20, 2026. The company operates using the domain greatbay-bio[.]com. As a biotech manufacturing entity, Great Bay Bio’s operations likely involve valuable intellectual property, research and development data, and critical supply chain information, making it an attractive target for cybercriminals seeking to exfiltrate sensitive data for ransom. nightspire has been active recently, claiming 26 victims over the past 60 days. The group has primarily targeted organizations in the United States, Turkey, and Colombia. Its most frequently targeted industries are Manufacturing, Transportation, and a category labeled “Other.” Great Bay Bio’s profile aligns with the typical victimology of nightspire, suggesting a consistent targeting pattern by the ransomware group.
Technical Analysis
SOCRadar’s investigation found no stealer-log records associated with the domain greatbay-bio[.]com. However, this absence of evidence does not definitively rule out a compromise. It is possible that compromised credentials may exist in private stealer markets not covered by the queried sources, or that any records found were under alternate corporate domains, used personal email aliases, or have been rotated and are no longer indexed in the current datasets. The potential for credential exposure, even if not directly observed in the queried stealer logs, remains a significant concern. Infostealer-harvested credentials can provide threat actors with initial access to corporate networks, facilitating ransomware deployment and data exfiltration. Organizations in the Manufacturing sector, particularly those holding valuable intellectual property like Great Bay Bio, are prime targets. It is recommended that Great Bay Bio enhance its security posture by enforcing Multi-Factor Authentication (MFA) on all system access, especially for research and administrative systems. Continuous monitoring of nightspire’s dark web portal for any data publication related to this listing is also advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.