Quick Summary
AllegedExecutive Summary
Hitachi High-Tech, a manufacturing company based in Japan, has been listed as a victim on the Coinbasecartel ransomware group’s dark web portal, published on August 13, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. Hitachi High-Tech is a global supplier of high-technology equipment and materials, operating across semiconductor, life science, and industrial measurement sectors. The organisation’s position in high-value industrial supply chains elevates the potential systemic impact of a confirmed compromise. In the 60 days prior to this listing, Coinbasecartel has claimed 7 other victims across its leak portal. The group has shown a strong targeting pattern in the Manufacturing, Technology, and Healthcare sectors. Geographically, its victims are concentrated in Japan, the United Kingdom, and the United States. Other recent Coinbasecartel listings that overlap with Hitachi High-Tech’s profile — Japanese organisations or manufacturing companies — include PanasonicAero, M. B. Kahn Construction Co., Xs Cad, and MIM Fertility. Hitachi High-Tech represents the most prominent industrial name in Coinbasecartel’s recent victim set, consistent with the group’s apparent interest in technology-adjacent manufacturing firms.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the hitachi-hightech.com domain. The queried sample returned 16 records spanning corporate credentials across internal and external platforms: 6 employee credentials on organisation-controlled systems, 5 records tied to customer or supplier accounts on those systems, and 5 records of corporate usernames appearing on third-party services. High-value endpoints observed include Siemens SSO (login.siemens.com), SAP/ondemand tenant instances accessed repeatedly by the same corporate username, and internal Hitachi High-Tech portals including hha.hitachi-hightech.com and extranet.hha.hitachi-hightech.com, where both corporate and external usernames from supplier domains appear — a pattern consistent with either supplier credential compromise or lateral movement into customer-facing systems. The dominant profile is Mixed, with indicators of both workstation-level infection and direct corporate account access. Log dates span May 2025 through July 2026, indicating a long-tail persistence window and no apparent credential rotation during that period. For ransomware groups such as Coinbasecartel, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. While the stealer-log evidence here does not confirm that these specific credentials were used by Coinbasecartel, the pattern is consistent with the kill chain typically observed for this class of incident — particularly where high-value SaaS and internal portal credentials are captured across a multi-month window without rotation. CTI teams should prioritise credential hygiene for all affected accounts and treat the supplier-domain access on internal portals as a separate lateral-movement indicator warranting investigation.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.