Quick Summary
AllegedExecutive Summary
Penfold, a UK-based digital pension and savings platform, has been listed as a victim by the Storm ransomware group. The listing appeared on August 18, 2026, and was identified by SOCRadar’s Dark Web Monitoring service. Penfold operates the website getpenfold[.]com, providing workplace pension management for individuals and employers. The incident involves a significant exposure of 25 customer authentication records, with data stretching back to February 2024, primarily affecting customer email accounts associated with common providers like Gmail, Hotmail, and Outlook. These records were identified across customer-facing authentication endpoints, including the platform’s Azure B2C sign-in/sign-up API. In the 60 days preceding this listing, Storm claimed 24 other victims, with a notable concentration in the United States, Australia, and Canada. Penfold represents a geographic and sectoral outlier, as Storm’s typical targets are predominantly North American industrial entities. This pattern suggests that the listing may stem from access acquired through an Initial Access Broker (IAB) rather than a targeted campaign specifically against UK FinTech companies. The broad timeframe of the exposed data, spanning multiple years, indicates a potential accumulation of credentials over time through various stealer-log incidents.
Technical Analysis
SOCRadar’s analysis of getpenfold[.]com, utilizing stealer-log data, revealed 25 records associated with the domain. These records originate from various stealer-log batches, suggesting a prolonged period of credential compromise rather than a single event. The compromised credentials primarily consist of consumer email accounts (Gmail, Hotmail, Outlook) belonging to Penfold’s pension account holders, indicating a focus on customer data. The exposed logs cover a date range from July 2026 to August 10, 2026, with some isolated instances dating back to February 2024. The targeted endpoints included getpenfold[.]com and login.getpenfold[.]com, specifically noting the platform’s Azure B2C sign-in/sign-up API. Notably, no employee credentials associated with the @getpenfold[.]com domain were found in this particular query sample. The multi-year spread of the compromised data, coupled with the targeting of the Azure B2C endpoint, suggests that credentials may have been harvested and accumulated over an extended period through various infostealer campaigns. While this specific query did not reveal any corporate credentials, the scope of the analysis was bounded, meaning that additional compromised employee credentials might exist within unsampled portions of the stealer-log data. The presence of customer account data, especially linked to authentication endpoints, poses a risk of unauthorized access and potential follow-on activities, including ransomware deployment. Given the findings, it is recommended that Penfold treat all 25 identified customer accounts as potentially compromised. Affected customers should be notified in accordance with UK GDPR regulations. Furthermore, an audit of authentication logs for login.getpenfold[.]com should be conducted, focusing on anomalous session activity from July 2026 onwards. A broader sweep of stealer-log data is also advisable to determine if any corporate credentials exist in unsampled data segments.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.