PT All Cosmos Biotek Data Breach

Alleged

Ransomware claim involving PT All Cosmos Biotek

Published: Aug 5, 2026 Gunra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
PT All Cosmos Biotek
Industry
Biotechnology
Threat Actor
Gunra
Date of Incident
Aug 5, 2026

Executive Summary

PT All Cosmos Biotek, a healthcare and biotechnology company based in Indonesia, has been listed as a victim on the Gunra ransomware group’s dark web portal, published on August 5, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The company operates in the biotechnology segment of the healthcare sector. It is the only Indonesian entry in Gunra’s recent listing population. In the 60 days prior to this listing, Gunra has claimed 10 other victims across its leak portal, placing it among the lower-volume operations tracked in this dataset. The group has shown a targeting pattern weighted toward business services, with healthcare, technology, and manufacturing each represented at low single-digit volumes. Geographically, its victims are scattered rather than clustered — Uruguay, South Korea, and Thailand all appear alongside Indonesia, with no single country dominating. Other recent Gunra listings that share a comparable Asian or mid-market profile include worldtube, Siam Stabilizers and Chemicals Co., Ltd., Weilhotel, and Dissinger and Dissinger Law Firm. The absence of a geographic centre of gravity is itself the notable characteristic here, and PT All Cosmos Biotek fits that pattern of dispersion rather than diverging from it.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for allcosmos.com in the queried slice. A null result is not the same as a clean bill of health: the query covers a paginated sample rather than the complete corpus, alternate or subsidiary domains fall outside the lookup, and credentials harvested under personal email aliases would not surface against the corporate domain at all. Southeast Asian organisations are unevenly represented in commercial stealer-log feeds, which weakens the inference further in this case. For ransomware groups such as Gunra, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. The absence of evidence in this query does not rule that scenario out — credentials may have surfaced in feeds outside this dataset, been used and rotated before indexing, or been harvested under personal email aliases. CTI teams should treat continued monitoring and proactive credential-hygiene checks as the appropriate response rather than reading a null query as exoneration.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.