Quick Summary
AllegedExecutive Summary
Qilin ransomware has claimed Prenisac as a victim, with the listing appearing on the group’s dark web portal on July 30, 2026. SOCRadar’s Dark Web Monitoring service identified this listing. While Prenisac is identified as a U.S.-based organization, the specific sector of operations was not classified in the provided data, leaving this aspect of the incident without confirmation. In the 60 days preceding this listing, Qilin claimed 122 other victims, making it one of the most active ransomware operations. The group’s targeting has primarily focused on the Business Services, Manufacturing, and Technology sectors, with a significant number of victims located in the United States, France, and Germany. Prenisac aligns with the dominant concentration of U.S. victims, though its specific industry does not match the group’s typical targets. Recent U.S. victims listed by Qilin include Affinity Capital, Byonyks, TenSparrows, and Wilbert’s.
Technical Analysis
SOCRadar’s telemetry identified eight stealer-log records associated with prenisac[.]com. These records indicate the same corporate @prenisac[.]com account authenticating to Microsoft identity endpoints, with one instance occurring via an OAuth authorization flow. These attestations span from December 2025 through June 2026, revealing a six-month period with no credential rotation, a significant red flag for potential undetected compromise. The persistence of Microsoft 365 tenant access through a single, unrotated credential is among the highest severity patterns detected by this telemetry. The evidence, while not confirming that this specific account was used by Qilin for a ransomware deployment, points to a concerning pattern. A persistent Microsoft 365 credential, particularly one coupled with an OAuth flow and a prolonged lack of rotation, is characteristic of the initial access methods exploited by this class of threat actor. This scenario presents a clear pathway for intrusion, as infostealer-harvested credentials are a standard initial access vector for Qilin and similar ransomware groups. Such credentials are often purchased by brokers, validated, and used to gain access to Microsoft 365, VPNs, or remote-access portals, ultimately leading to ransomware deployment. Given the findings, immediate actions are recommended to mitigate potential risks. These include resetting the compromised password, revoking all active sessions and tokens associated with the account, auditing all OAuth application grants, and thoroughly reviewing Azure AD sign-in logs for any anomalies. Continued dark web monitoring and proactive credential hygiene checks are also advised to detect any further related activity or potential secondary compromises.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.