Quick Summary
AllegedExecutive Summary
On July 5, 2026, SBI Software, a technology company located in the United States, was identified as a victim of the Genesis ransomware group. This intelligence was gathered by SOCRadar through its Dark Web Monitoring service. SBI Software operates within the technology sector, and its targeting aligns with Genesis’s recent pattern of focusing on US-based technology and software providers.
Technical Analysis
SOCRadar’s analysis did not find direct evidence of SBI Software’s domain (sbigrower.com) in their stealer-log telemetry for the period preceding the listing. However, this absence of evidence is not conclusive; it may be due to limitations in the sampled data, the use of alternate corporate domains, or credentials harvested under personal email aliases. The Genesis ransomware group is known to exploit initial access vectors involving credentials sourced from stealer logs. These credentials are used to gain access to systems via platforms like Microsoft 365, VPNs, or remote-access portals, after which ransomware is deployed. CTI teams are advised to maintain continuous monitoring and implement proactive credential hygiene measures, rather than assuming security based on a lack of direct evidence in specific datasets.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.