Quick Summary
AllegedExecutive Summary
J&T Bank and Trust, a financial services company based in the United States, has been identified on the Qilin ransomware group’s dark web portal, with the listing published on August 6, 2026. This discovery was made through SOCRadar’s Dark Web Monitoring service. As a banking and trust institution, the organization operates within a sector subject to specific incident notification regulations. This incident marks one of six Qilin entries posted on that particular date. In the 60 days preceding this listing, Qilin claimed responsibility for 135 other victims on its leak portal. The group exhibits a strong propensity for targeting the manufacturing, business services, and professional services sectors. Their victim base is primarily concentrated in the United States, France, and Germany. Recent Qilin claims that align with J&T Bank and Trust’s profile, such as those against financial services companies or other US-based entities, include Bloom Financials, Freedom Claims Management, Affinity Capital, and Triton Trading. While financial services is not Qilin’s primary focus, it is a consistently targeted secondary vertical, indicating that the group’s high volume of attacks leads to frequent targeting across most sectors.
Technical Analysis
An analysis of SOCRadar’s stealer-log telemetry for the domain jtbanktrust.com returned no records within the queried sample. It is crucial to understand that a null result does not definitively confirm the organization’s security. The query was limited to a paginated sample from a single dataset, and any exposure linked to alternative domains, third-party core-banking vendor portals, or personal email addresses used on corporate systems would not be captured. Financial institutions often authenticate staff through external processors and core-banking platforms, whose namespaces are separate from the bank’s own domain, creating a blind spot for single-domain queries. For ransomware groups like Qilin, compromised credentials obtained from infostealers are a well-established method for initial access. Threat actors or initial access brokers acquire fresh credential logs from underground marketplaces, validate them, and subsequently use them to access systems such as Microsoft 365, VPNs, or remote access portals, paving the way for ransomware deployment. The absence of relevant data in this specific query does not preclude this scenario; credentials might exist in data feeds not included in this dataset, they may have been used and subsequently rotated before being indexed, or they could have been harvested using personal email aliases. Security teams should continue monitoring and perform proactive credential hygiene checks rather than relying on a negative query result as proof of security.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.