Quick Summary
AllegedExecutive Summary
incransom has claimed Oilquip Inc, a US-based company operating in the Energy & Utilities sector, as a victim. The claim was made on August 30, 2026, and identified by SOCRadar CTI. The company’s domain is oilquip[.]com. The identification of a credential linked to a Product Lifecycle Management (PLM) integration platform, plmconnections[.]com, raises concerns about potential access to sensitive product design, engineering, and supply chain data, beyond standard network perimeter systems. In the preceding 60 days, incransom has listed 51 victims, with a significant concentration in North America, including the US, Canada, and Mexico. The group’s primary targeting has focused on the Professional Services and Manufacturing sectors. The targeting of Oilquip Inc, an Energy & Utilities entity, expands the observed footprint of incransom beyond its typical industry focus. This actor is characterized as a mid-volume operator with a consistent presence in North America.
Technical Analysis
SOCRadar CTI’s analysis identified a “severe_exposure_in_sample” for the domain oilquip[.]com. A single credential was found linked to plmconnections[.]com, an integration platform for Product Lifecycle Management (PLM). The activity timestamps for this credential span from March 23, 2024, to August 15, 2026, indicating a two-year window of potential exposure. This prolonged period of activity associated with a single integration point suggests either repeated device reinfection or a persistent infostealer presence on the affected workstation. Notably, the most recent activity date, just 15 days prior to the threat actor’s listing, indicates that the compromised credential was likely still active at the time of the claim. The connection of Oilquip Inc to plmconnections[.]com through this credential implies that the credential holder could potentially access and enumerate product design, engineering, and supply chain data hosted on the PLM platform, in addition to traditional network systems. This type of access can provide attackers with insights into critical operational or proprietary information. The duration of the exposure and its link to a specialized platform like PLM warrants careful investigation. Rotate the plmconnections[.]com credential immediately and notify the PLM platform operator of the potential exposure. It is recommended to audit PLM platform access logs for the entire period of March 23, 2024, to August 15, 2026, to identify any unauthorized data access or unusual query patterns. For an organization in the energy sector, it is crucial to assess whether the PLM data includes sensitive information such as operational technology specifications or critical infrastructure documentation. Such findings may necessitate escalated incident response procedures or regulatory notification.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.