Quick Summary
AllegedExecutive Summary
Liberty Commercial Center, Inc, a professional services firm operating in the Philippines, was listed on the INC Ransom ransomware group’s leak portal on August 4, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. The company is part of a broader commercial group, and its identification as a target by INC Ransom is notable given its geographic location. In the preceding 60 days before this listing, INC Ransom claimed approximately 32 victims, maintaining a consistent activity level. The group’s targeting frequently focuses on the business services, healthcare, and manufacturing sectors, although a significant portion of its claimed victims do not have a confirmed industry. While the United States is the primary target country for INC Ransom, Mexico and Argentina also feature prominently. Liberty Commercial Center, Inc falls into the group’s expanding international victimology, aligning with other non-US entities such as Evangelical Council for Financial Accountability, Oleoductos del Valle, clintonhealthaccess[.]org, and pushidrosal[.]id, rather than its typical US focus.
Technical Analysis
SOCRadar’s analysis of infostealer telemetry revealed a significant exposure related to the domain lccgroup[.]com. Specifically, 25 records were identified: 10 employee credentials directly linked to organization systems and 15 additional credentials with identifier-style usernames that could not be definitively classified. The high-value endpoints targeted included an enterprise resource planning (ERP) login, corporate mail infrastructure, a file-sharing and collaboration platform, and an IT service-desk portal. The combination of ERP and helpdesk access is particularly concerning, as ERP systems often house sensitive business data, while helpdesk portals can be a common entry point for privilege escalation. The detected credentials show a freshness ranging from June 20 to August 2, 2026, with the most recent capture occurring just two days prior to INC Ransom’s public listing. This tight timeframe strongly suggests a potential intrusion path for the ransomware group. While this stealer-log evidence does not definitively confirm that INC Ransom utilized these specific credentials for their attack, the observed pattern aligns precisely with the typical kill chain for ransomware operations that leverage infostealer-harvested credentials. The 15 unclassified records, all associated with organization-owned portals, indicate that the actual extent of internal credential exposure might be higher than initially identified. For threat actors like INC Ransom, infostealer-harvested credentials are a well-established method for initial access. Threat actors or initial access brokers commonly acquire fresh credential logs from underground marketplaces. These credentials are then validated and used to gain access to systems such as Microsoft 365, VPNs, or other remote-access portals, paving the way for ransomware deployment. The six-week capture window for the credentials, closing just before the listing, is a critical detail in understanding the potential timeline of the incident. Given the evidence, continued monitoring of dark web and stealer-log feeds is recommended, alongside proactive credential hygiene checks, password rotations, and a thorough review of multi-factor authentication settings, Microsoft 365, VPN, and remote-access portal activity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.