Quick Summary
AllegedExecutive Summary
PCL Holding, a professional services company based in Canada, has been listed as a victim on the RansomHouse threat group’s dark web portal, published on August 3, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The organization operates in the professional services sector in Canada. RansomHouse maintains a much lower listing cadence than the high-volume operations tracked alongside it, so each addition to its portal represents a proportionally larger share of its recent activity. In the 60 days prior to this listing, RansomHouse has claimed 7 other victims across its leak portal. The group has shown targeting across the Agriculture and Food Production, Professional Services, and Business Services sectors, though with a listing volume this low the sector distribution is close to flat and should not be over-read. Geographically, its recent victims are spread across Canada, Japan, and Brazil, with no single country dominating. Other recent RansomHouse listings that overlap with PCL Holding’s profile — professional and commercial services organizations across multiple regions — include Nichirei, Megawork, Fidelity Services Group, and Bonacio. PCL Holding is the group’s only Canadian listing in this window, and the geographic scatter suggests opportunistic rather than regionally focused selection.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the pclholding.com domain. The queried slice returned eleven records in the employee-credential-on-organizational-systems category, two records placing corporate identities on third-party SaaS platforms, and two further records that could not be classified. The high-value endpoints observed span the organization’s own mail and webmail infrastructure, an enterprise content management platform, and an internal service portal, alongside corporate-domain identities appearing on external cloud storage, project management, and conferencing identity brokers. The freshness window runs from 19 June 2026 to 28 July 2026 with long-tail characteristics, and no evidence of credential rotation is visible across that span. The dominant profile was assessed as mixed — the record set shows both direct corporate system access and workstation-level infection signals. Two records also associate a third-party domain with PCL Holding infrastructure, which raises a shared-credential or supplier-access question worth separate investigation. For threat groups such as RansomHouse, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying their tooling. While the stealer-log evidence here does not confirm that these specific credentials were used by RansomHouse, the pattern is consistent with the kill chain typically observed for this class of incident — the freshness window closes less than a week before the leak-site listing, and the concentration on mail and document-management infrastructure is the access profile most often associated with pre-listing reconnaissance. Correlation against the organization’s own incident timeline would be needed to determine whether the credential activity preceded or followed the intrusion.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.