Quick Summary
AllegedExecutive Summary
Harley-Davidson, a prominent manufacturing company based in the United States, was listed as a victim by the Clop ransomware group on September 10, 2026. This listing occurred on the same day that SOCRadar’s analysis identified 14 records associated with the harley-davidson[.]com domain. These records included 10 corporate email credentials used against external platforms such as code-collaboration, financial services, and media portals, and 4 non-corporate accounts that authenticated against Harley-Davidson-owned properties. This discovery points to a potential exposure of sensitive information, which could be attractive to ransomware actors seeking to compromise organizations. Clop has been actively claiming victims, with 87 other organizations listed in the past 60 days. Their primary targets span the Technology, Retail & E-Commerce, and Manufacturing industries. The group frequently targets organizations in the United States, India, and Italy. Recent victims similar to Harley-Davidson include Henry Pratt Company, Zebra Technologies, Largan Precision Co., Ltd., and Atomberg Technologies. The targeting of Harley-Davidson aligns with Clop’s established pattern of focusing on US-based industrial and manufacturing enterprises.
Technical Analysis
SOCRadar’s analysis revealed a mixed credential profile for Harley-Davidson, indicating two distinct types of exposure observed on September 10, 2026. The first type involves 10 corporate email credentials associated with the harley-davidson[.]com domain. These credentials were logged authenticating against external services, suggesting they may have been harvested by infostealer malware operating on employee devices or browsers. The second type of exposure includes 4 non-corporate accounts that authenticated against Harley-Davidson-owned properties, notably including the internal provisioning endpoint at serviceinfo.harley-davidson[.]com. Access to an account-creation infrastructure is a significant indicator, as it could allow unauthorized user provisioning within enterprise directories. The alignment of the log dates with the ransomware group’s listing date is noteworthy. While this evidence does not definitively confirm that Clop utilized these specific credentials for initial access, the combination of fresh corporate email credentials, access to an internal provisioning endpoint, and the contemporaneous logging date is consistent with the typical attack chain observed in such incidents. This correlation suggests a potential pathway for compromise that threat actors could exploit. Continued dark web and stealer-log monitoring is recommended. Proactive credential hygiene checks, including password rotation and multi-factor authentication review, are advised. Monitoring of alternate corporate domains and related Microsoft 365, VPN, and remote-access activity should be considered.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.