POEMA S.r.l. Data Breach

Alleged

Ransomware claim involving POEMA S.r.l.

Published: Aug 20, 2026 Titan
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
POEMA S.r.l.
Industry
Business Services
Threat Actor
Titan
Date of Incident
Aug 20, 2026

Executive Summary

POEMA S.r.l., an Italian company operating within the commercial services sector, has been identified as a victim on the dark web portal of the Titan ransomware group. The listing, published on August 20, 2026, was detected by SOCRadar’s Dark Web Monitoring service. POEMA S.r.l. manages its operations through custom application infrastructure, and this incident places the company within Titan’s recent targeting activities, specifically noting an Italian targeting cluster for August 2026. In the 60 days preceding this listing, Titan had claimed 10 other victims. The group’s recent activity shows a consistent pattern of targeting the Manufacturing, Technology, and Other sectors, with a geographical focus on Italy and India. Previous victims in Italy, such as TECNOLOGICA S.r.l., Elbor S.p.A., CONDOR SPA, and Tedesco & Partners STP srl, indicate that POEMA S.r.l.’s situation aligns with Titan’s ongoing campaign to target Italian commercial organizations.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure for the poemasrl.it domain. The queried dataset returned 17 records, all identified as INTERNAL_AUTH_EMPLOYEE credentials. These corporate-format credentials were used to access the organization’s internal application infrastructure, including SAP UI5 endpoints and an internally hosted application portal (app.poemasrl.it). The logged credentials date from March to May 2026, indicating a prolonged period where employee credentials were available on infostealer feeds prior to the ransomware group’s public listing. The data suggests that the exposed credentials were for internal accounts on business-critical systems. For ransomware operations like those conducted by Titan, harvested credentials from infostealers represent a common initial access vector. Threat actors or initial access brokers frequently obtain these logs from underground marketplaces, validate the corporate credentials, and then leverage them for access to platforms such as Microsoft 365, VPNs, or remote-access portals before proceeding with ransomware deployment. While the stealer-log data does not definitively confirm that these specific compromised credentials were used by Titan, the finding of 17 exposed corporate employee credentials across critical systems over several months presents a clear pre-breach indicator. This extensive credential exposure across internal systems over a multi-month period warrants immediate security actions. These include proactive credential hygiene checks, such as immediate password rotation for affected accounts and a thorough review of access privileges. Continuous monitoring of the dark web and stealer-log feeds is also recommended to detect any further exposure or related activity. Reviewing access logs for Microsoft 365, VPNs, and remote-access portals could provide additional context on potential unauthorized access attempts.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.