Quick Summary
AllegedExecutive Summary
ShadowByt3$ added John Engel Team to its leak site on September 10, 2026. John Engel Team is a US-based real estate brokerage and property advisory firm. The listing was identified through SOCRadar’s Dark Web Monitoring service. The professional services sector, which John Engel Team operates within, is a frequent target for ransomware groups due to the valuable and often sensitive data handled. ShadowByt3$ has claimed 6 other victims in the past 60 days. Their primary target sectors are Retail & E-Commerce and Professional Services. The group’s geographic spread includes the United States, United Kingdom, and Indonesia. This actor is considered low-volume, and the targeting of the US service sector aligns with their consistent pattern observed across their listings.
Technical Analysis
A stealer-log query returned two credential records against johnengelteam.realscout[.]com/users/sign_in, captured on September 7, 2026, three days before the leak site listing. These accounts belong to partner real estate firms, not John Engel Team employees. This suggests a potential Customer Account Takeover (ATO) or supplier risk scenario rather than a direct compromise of John Engel Team’s internal systems. It is important to note a coverage caveat: johnengelteam.realscout[.]com is a subdomain of RealScout, a third-party SaaS platform. These credentials reflect shared-platform access, not John Engel Team’s own infrastructure. The organization’s primary corporate domain was not included in the queried sample. Therefore, these records do not directly attribute the exposure to John Engel Team’s internal systems. The identified credential exposure on a third-party platform, even if not directly on John Engel Team’s primary domain, represents a risk. Such shared-platform compromise could potentially be leveraged by threat actors to gain unauthorized access to connected systems or sensitive data if proper segmentation and security controls are not in place. This scenario highlights the importance of managing third-party risk and ensuring robust credential management practices across all connected services.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.