Quick Summary
AllegedExecutive Summary
Radia Inc. PS, a technology company based in the United States, has been identified as a victim by the Chaos ransomware group. The listing, published on July 16, 2026, was detected via SOCRadar’s Dark Web Monitoring service. Operating within the Technology sector, Radia Inc. PS’s inclusion on the group’s leak site suggests it aligns with Chaos’s recent targeting patterns, which span various regions and industries. In the 60 days preceding this listing, the Chaos ransomware group claimed responsibility for seven other victims. The group primarily targets organizations within the Technology, Healthcare, and Business Services sectors. Its most frequent victim locations include the United States, Germany, and Canada. Radia Inc. PS shares a sectoral and geographical overlap with previously identified victims such as Grand Isle Shipyard Inc., AireSpring, Aphena Pharma Solutions, and CorePharma, fitting the group’s typical victim profile.
Technical Analysis
A limited-coverage caveat applies to the analyzed telemetry: the lookup against SOCRadar’s stealer-log data was performed using the domain zoominfo.com, a third-party data platform, rather than Radia Inc. PS’s own corporate domain. This approach narrows the scope of inferences that can be made. Within this specific dataset, all records identified were external user accounts logging into the third-party service, with 18 classified as customer or partner logins. Crucially, none of these records contained a corporate username directly associated with Radia Inc. PS. The predominant pattern observed was customer account takeover or supplier risk, with data freshness limited to a single day. Consequently, the absence of genuine employee credentials from this particular query should be interpreted as a limitation of the coverage, not as definitive evidence that the organization’s estate is unaffected. Infostealer-harvested credentials are a well-established initial access vector for ransomware operators like Chaos. Threat actors or initial access brokers typically source fresh credential logs from underground marketplaces. They then validate these stolen credentials to gain access to systems via platforms such as Microsoft 365, VPNs, or remote-access portals before proceeding with ransomware deployment. While the observed stealer-log evidence does not definitively confirm that these specific credentials were used by Chaos in an intrusion targeting Radia Inc. PS, the pattern is consistent with the typical kill chain observed for such incidents. This situation highlights the exposed accounts and endpoints as immediate priorities for credential rotation and security review.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.