Rodschinson Investment Data Breach

Alleged

Ransomware claim involving Rodschinson Investment.

Published: Aug 5, 2026 Everest
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Rodschinson Investment
Industry
Finance
Threat Actor
Everest
Date of Incident
Aug 5, 2026

Executive Summary

Rodschinson Investment, a financial services company based in Belgium, has been listed as a victim on the Everest ransomware group’s dark web portal, with the listing published on August 5, 2026. This identification was made through SOCRadar’s Dark Web Monitoring service. Operating within the financial services sector, the company is subject to regulatory notification obligations that typically follow such leak-site listings. Notably, Rodschinson Investment is the only Belgian entity and the sole financial services firm among Everest’s recent claimed victims, making it a unique entry for European financial-sector analysts. In the 60 days preceding this listing, Everest claimed 18 other victims. The group predominantly targets the technology, professional services, and energy and utilities sectors, with a significant concentration of victims in the United States, India, and the United Arab Emirates. Other recent victims listed by Everest that share a comparable profile of being outside the US or in professional services include Keysight, Stadler Rail, Mansfield Family Dentistry, and Powerweave. Rodschinson Investment’s inclusion diverges from Everest’s typical targeting patterns in terms of both sector and geography.

Technical Analysis

Initial access correlation against SOCRadar’s stealer-log telemetry revealed a significant exposure for the rodschinson.com domain. The query returned 21 records, all utilizing corporate email addresses. Of these, four records map to identity and single sign-on endpoints across various cloud providers, while 16 records indicate corporate users authenticating to third-party services. This ratio typically suggests infected employee workstations rather than a direct attack against the corporate perimeter. The log activity observed within this dataset dates back to mid-2025, indicating an accumulation of exposure over time rather than recent compromise. While the identity provider records present the most significant practical risk, the overall profile is mixed. For ransomware groups like Everest, credentials harvested by infostealers represent a well-established initial access vector. Threat actors or initial access brokers often source fresh logs from underground marketplaces, validate the corporate credentials, and use them to gain access to platforms such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. Although the stealer-log evidence does not definitively confirm that these specific credentials were used by Everest, a small financial services firm with SSO credentials exposed for over a year aligns with the profile that access brokers commonly target and resell. Consequently, threat intelligence teams monitoring this listing should consider the exposed corporate identities a persistent risk and prioritize credential rotation and session invalidation over a point-in-time assessment.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.