Quick Summary
AllegedExecutive Summary
Orova listed Sc Regional Housing Authority, a US public-sector body, as a victim on its dark web portal on August 4, 2026, as flagged by SOCRadar’s Dark Web Monitoring service. Classified under government and defense, this regional housing authority places a resident-facing service portal at the core of its digital footprint. Notably, it is the sole public-sector entity among the Orova listings within this specific reporting batch. Orova’s recent activity includes 23 other victims from the preceding 60 days, all posted in the same August 4 batch, suggesting this may represent the group’s initial tracked wave rather than a consistent targeting pattern. Their campaigns typically cluster around healthcare, manufacturing, and financial services, with many unlabelled victim entries. While victims primarily concentrate in the United States, Hong Kong, and Taiwan, the Sc Regional Housing Authority’s inclusion, as the only public-sector entity, highlights a geographic overlap with other US-based organizations. Related victims from the United States mentioned in this batch include Global Friction Products, Inc, Conceptual Designs, Inc., Integrated Site Management, and Yost Home Improvements.
Technical Analysis
The stealer-log correlation for scrha[.]net returned a significant number of records, unlike most other entries in this batch. All twenty-five records within the queried sample targeted an application subdomain belonging to the authority. These records were distributed across the application root, an account-provisioning endpoint, and a mobile authentication path. The data primarily indicates customer account takeover and supplier risk, rather than corporate intrusion. The masked sample did not contain corporate-domain usernames, suggesting these credentials belong to resident and external portal accounts rather than employee credentials. However, the masking limits a definitive call on the exact nature of the compromised accounts. The captured credentials range in freshness from August 2025 to July 16, 2026. The recurrence of several usernames three to five times across this period suggests either unrotated credentials or repeat infection of the same users, rather than isolated harvesting events. Infostealer-harvested credentials commonly serve as an initial access vector for ransomware groups like Orova. Threat actors or access brokers often purchase fresh logs, validate corporate credentials, and then use them to access systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While this evidence does not confirm that these specific credentials were directly used by Orova for an intrusion, the year’s worth of harvested logins for the authority’s resident portal represents a substantial access surface. In smaller public-sector organizations, portal passwords are often reused for staff accounts. Therefore, the volume and persistence observed in this sample should be treated as a signal of access readiness, even though the visible records do not exclusively consist of employee credentials. Continued monitoring of dark web stealer logs, proactive credential hygiene checks, password rotation, and multi-factor authentication review are recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.