Quick Summary
AllegedExecutive Summary
Primeline Logistics, a transportation and logistics company based in Ireland, has been listed as a victim on the Qilin ransomware group’s dark web portal, with the publication date of July 22, 2026. This discovery was made via SOCRadar’s Dark Web Monitoring service. As a logistics operator, the company’s reliance on interconnected distribution networks and Microsoft-based corporate systems inherently broadens its potential attack surface. The listing of Primeline Logistics represents an addition to Qilin’s growing and geographically diverse victim portfolio, including an Irish transportation entity. In the 60 days preceding this listing, Qilin has claimed responsibility for 126 other victims, as documented on its leak portal. The group exhibits a noticeable preference for targeting the business services, manufacturing, and healthcare sectors. Primarily, its victims are located in the United States, Australia, and Spain. Other recent victims in the transportation and logistics sector that align with Primeline’s profile include Bronken’s Dist, Shipping Association of NY and NJ, Associated Theatrical Contractors, and Don Tortaco Mexican Grill. Primeline Logistics aligns with Qilin’s occasional targeting of logistics firms and contributes to the group’s presence in Ireland.
Technical Analysis
Initial access correlation against SOCRadar’s stealer-log telemetry revealed a significant exposure for the primeline.ie domain. The queried data returned five records. Four of these records indicated the same corporate username authenticating to Microsoft identity endpoints, suggesting a direct exposure of employee credentials on the organization’s identity provider. An additional record showed a second corporate username associated with a consumer streaming service, which could imply the existence of other internal credentials on compromised workstations beyond the scope of this sample. The repetition of the same account across multiple timestamps points to either persistent access or unrotated credentials, highlighting a substantial corporate intrusion risk with a freshness window extending from February to mid-July 2026. For ransomware groups such as Qilin, credentials harvested by infostealers serve as a documented initial access vector. Threat actors or initial access brokers commonly source fresh logs from underground marketplaces. They then validate these corporate credentials to gain access to systems such as Microsoft 365, VPNs, or remote-access portals, preceding the deployment of ransomware. While the stealer-log evidence gathered here does not definitively confirm that these specific credentials were used by Qilin, the repeated corporate logins to Microsoft identity endpoints are consistent with the typical kill chain observed for such incidents. This pattern underscores the importance of immediate credential resets, robust Multi-Factor Authentication enforcement, and thorough endpoint triage for organizations identified with this profile.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.