Integraduanas Data Breach

Alleged

Ransomware claim involving Integraduanas.

Published: Aug 19, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Integraduanas
Industry
Manufacturing
Threat Actor
Qilin
Date of Incident
Aug 19, 2026

Executive Summary

On August 19, 2026, the Qilin ransomware group listed Integraduanas, an organization based in Uruguay, as a victim on their leak site. The specific nature of Integraduanas’ operations and its potential for attracting ransomware attacks is not detailed in the provided information, beyond its geographical location and industry. SOCRadar’s intelligence identified this listing on the ransomware group’s platform, indicating a potential data exposure or extortion attempt. Qilin has demonstrated significant activity in recent times, claiming 196 victims over the past 60 days. The group’s primary targets are predominantly located in the United States, Germany, and France. While Latin American entities are less frequently targeted, Qilin has recently claimed victims in this region, such as AGUNSA in Chile (Transportation) and Movitecnica in Peru (Manufacturing). The targeting of Integraduanas in Uruguay represents an isolated incident, as Uruguay does not appear to be a primary cluster for the group’s operations.

Technical Analysis

SOCRadar’s investigation uncovered two records from November 2025 linking a corporate email identity associated with the domain integraduanas[.]com[.]uy to PayPal’s authentication endpoint. These records, dated between November 12 and 25, 2025, suggest a potential compromise of a workstation approximately nine months prior to Integraduanas being listed by the Qilin ransomware group. While the identified PayPal authentication logs indicate potential credential exposure, this alone does not confirm an enterprise-level breach. The true extent of the compromise depends on what other information was harvested from the compromised workstation, such as VPN credentials, email logins, or access to remote-access portals, which fall outside the scope of this domain-specific query. Further investigation of adjacent log data is recommended to identify such credential classes.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.