PanasonicAero Data Breach

Alleged

Ransomware claim involving PanasonicAero

Published: Jul 15, 2026 coinbasecartel
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
PanasonicAero
Industry
Business Services
Threat Actor
coinbasecartel
Date of Incident
Jul 15, 2026

Executive Summary

PanasonicAero, a manufacturing company based in Japan, has been listed as a victim on the coinbasecartel threat group’s dark web portal, with the listing published on July 15, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service. The organization operates in the manufacturing sector and is part of a recent trend of coinbasecartel targets that has predominantly included technology and manufacturing organizations. In the 60 days preceding this listing, coinbasecartel claimed five other victims, with a notable targeting pattern favoring the technology, manufacturing, and business services sectors. Geographically, their victims are primarily located in the United States, France, and Japan. Recent listings of technology and manufacturing organizations, such as Cambridge Mobile Telematics, Demand.io, Siveco, and Pragmatic Solutions, show an overlap with PanasonicAero’s profile. PanasonicAero’s inclusion fits the group’s strategy of listing a mix of manufacturing and technology entities on their relatively low-volume portal.

Technical Analysis

SOCRadar’s stealer-log telemetry revealed a significant exposure for the panasonic.aero domain. The query identified one corporate credential associated with an internal system, flagged as a workstation. Additionally, approximately nineteen records were found for customers, suppliers, or other third-party users utilizing organization-owned URLs. Three corporate users were also observed accessing third-party services with corporate email addresses. Key high-value endpoints included the organization’s identity/SSO portal, where a credential was captured, and a third-party payroll/HR service accessed using a corporate email address. A recurring corporate username across the internal payroll service and multiple third-party sites suggests an employee workstation was likely infected by an information stealer. This pattern indicates a blend of endpoint compromise and broad external account exposure, with a recent timeframe observed between July 13 and July 15, 2026. For ransomware groups like coinbasecartel, credentials harvested by infostealers are a known initial access vector. Threat actors or initial access brokers often acquire fresh logs from underground marketplaces, validate the corporate credentials, and use them to authenticate to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log evidence does not definitively confirm that these specific credentials were used by coinbasecartel in this incident, the observed pattern of a compromised employee endpoint alongside credentials reaching the corporate identity fabric is consistent with the typical intrusion kill chain for such attacks. CTI teams should consider the exposed identity-provider and workstation-linked accounts as potential access paths that warrant auditing. Prioritizing credential rotation and session revocation for affected identities is recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.