Moscord Data Breach

Alleged

Ransomware claim involving Moscord

Published: Aug 16, 2026 Eclipse
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Moscord
Industry
undisclosed
Threat Actor
Eclipse
Date of Incident
Aug 16, 2026

Executive Summary

Moscord, a company operating in an undisclosed sector and based in Singapore, has been identified as a victim on the Eclipse ransomware group’s dark web portal. The listing was published on August 16, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. This incident places Moscord among an increasing number of entities targeted by the Eclipse group in recent months, highlighting the group’s consistent activity across various industries and geographical locations. The specific sector of Moscord was not disclosed in the listing, but its presence in Singapore aligns with other recent targets of the Eclipse ransomware operation. In the 60 days preceding this listing, Eclipse claimed one additional victim. The group exhibits a tendency to target diverse sectors and has primarily focused its attacks on victims located in Singapore. The broad reach of Eclipse, as evidenced by recent listings against organizations similar to Moscord, demonstrates its opportunistic approach to targeting, even if Singapore is not its most frequent geographical focus. This pattern suggests a flexible and adaptive targeting strategy by the Eclipse ransomware group.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry related to initial access for moscord.com returned no records within the queried data sample. It is crucial to note that a null result does not confirm the absence of compromise. The paginated nature of the query might not encompass all associated logs, and credentials could exist under alternative corporate domains or personal email aliases utilized by Moscord employees. Therefore, cybersecurity teams should not interpret this absence of evidence as definitive proof of security. Ransomware groups like Eclipse frequently leverage credentials harvested by infostealers as a primary method for initial access. Threat actors or initial access brokers commonly source current credentials from underground marketplaces, validate them, and then use them to infiltrate systems, such as Microsoft 365, VPNs, or remote access portals, before deploying ransomware. The lack of found records in this specific query does not preclude this attack vector; credentials might have appeared in data feeds outside the scope of this analysis, been rotated prior to indexing, or been exfiltrated using personal email addresses. Given these factors, continued monitoring of dark web sources and stealer-log data is recommended. Proactive credential hygiene checks, including regular password rotation and a thorough review of multi-factor authentication status, are essential. Additionally, monitoring activity across Microsoft 365, VPNs, and other remote access solutions for suspicious behavior should be a priority. These measures are critical for mitigating risks associated with potential credential exposure and subsequent ransomware deployment, rather than relying on the absence of evidence in a single query.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.