Jbc Data Breach

Alleged

Ransomware claim involving Jbc

Published: Sep 7, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Jbc
Industry
E-Commerce
Threat Actor
Qilin
Date of Incident
Sep 7, 2026

Executive Summary

qilin listed Jbc on its dark web portal on September 7, 2026, identified through SOCRadar’s Dark Web Monitoring. Jbc operates via jbctools[.]com, a customer-facing e-commerce platform selling tools and related products to a predominantly European customer base. qilin is a high-volume group, claiming 242 other victims in the past 60 days. Their operations are concentrated in Manufacturing and Professional Services, primarily in the United States, Germany, and Italy. While recent Spanish and European listings include Acosol, Feliubadaló, AFSARD, and BLISS 1041, Jbc’s e-commerce/retail profile diverges somewhat from qilin’s typical manufacturing and professional-services focus. Retail is less common within the group’s recent victim set, though such a high volume of activity suggests a broad sector spread is expected.

Technical Analysis

SOCRadar’s stealer-log telemetry returned 25 records for jbctools[.]com, spanning August 20 through September 7, 2026. Twenty-four of these records are consumer-facing e-commerce checkout and cart credentials. The remaining record is a corporate email address from an external organization (@tametgroup[.]com), logged on September 7, 2026. The affiliation of this domain—whether employee, supplier, or other third party—is unconfirmed and warrants verification. No internal-system or identity-provider endpoints were found in this specific data slice. The dominant profile identified is customer account takeover and supplier access risk, consistent with the customer-facing nature of the Jbc platform. The single non-consumer corporate email found is an anomaly that requires further explanation. If @tametgroup[.]com represents a supplier or partner, that relationship warrants scrutiny. The volume of customer credentials, while secondary, is significant enough to indicate active harvesting from the platform in the weeks leading up to its listing.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.