REXT Holdings Co., Ltd. Data Breach

Alleged

RansomHouse claim involving REXT Holdings Co., Ltd.

Published: Sep 1, 2026 RansomHouse
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
REXT Holdings Co., Ltd.
Industry
Finance
Threat Actor
RansomHouse
Date of Incident
Sep 1, 2026

Executive Summary

RansomHouse has claimed responsibility for a data extortion incident involving REXT Holdings Co., Ltd., a Japanese holding company with diverse business operations. The claim was posted on RansomHouse’s dark web portal on September 1, 2026, and was identified by SOCRadar’s Dark Web Monitoring service. RansomHouse operates as an extortion group, focusing on data theft and subsequent publication to pressure victims into paying ransoms, rather than encrypting files. The nature of REXT Holdings’ multi-vertical operations could potentially make it an attractive target for such groups. In the 60 days preceding this listing, RansomHouse had claimed 10 other victims. Their typical targets are primarily in the Manufacturing, Government and Defense, and Financial Services sectors. Geographically, the group has historically concentrated its attacks in the United States and Japan, with Brazil also being a noted area of activity. REXT Holdings, being based in Japan, aligns with one of the group’s primary target geographies. Other recent victims claimed by RansomHouse include Nichirei, Alya Construtora, and the City of McMinnville, OR.

Technical Analysis

A query of stealer-log data for the domain “rext[.]jp” yielded no records within the analyzed dataset. It is important to note that for groups like RansomHouse, which specialize in direct intrusion and data exfiltration rather than relying on infostealer-generated credentials for initial access, the absence of such records does not definitively indicate that the organization was unaffected. This null result is therefore not particularly indicative either way regarding the compromise status. Given RansomHouse’s operational model, which focuses on data theft and extortion through publication rather than file encryption, the threat-hunting approach should prioritize different indicators than those typically associated with ransomware-as-a-service operations. The absence of stealer-log records is not unexpected for this particular threat actor. Defender actions should therefore concentrate on identifying RansomHouse’s specific intrusion indicators and monitoring for network-based data exfiltration activities. Implementing robust Data Loss Prevention (DLP) measures would also be a key strategy, rather than solely focusing on credential hygiene checks.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.