SD Associates Sdn Bhd Data Breach

Alleged

Ransomware claim involving SD Associates Sdn Bhd

Published: Aug 18, 2026 INC Ransom
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
SD Associates Sdn Bhd
Industry
Healthcare
Threat Actor
INC Ransom
Date of Incident
Aug 18, 2026

Executive Summary

INC Ransom has listed SD Associates Sdn Bhd on its leak portal, indicating a potential data breach. The incident, publicly disclosed on August 18, 2026, involves a Malaysia-based firm operating under the domain sda-my[.]com. While INC Ransom typically targets entities in North America within the Professional Services and Healthcare sectors, the exposure of stealer-log data suggests SD Associates Sdn Bhd may have been targeted as an opportunistic victim due to available credentials. Analysis of INC Ransom’s recent activity over the past 60 days reveals 42 other claimed victims, predominantly located in the United States, UAE, and Canada. Listings in the Asia-Pacific region, including SD Associates Sdn Bhd, appear to be sporadic rather than indicative of a strategic focus on Southeast Asia. Previous regional targets mentioned include Foresee Pharmaceuticals, NYK Law Firm, SSF International, and SpearFin Ltd, each representing isolated instances. SD Associates Sdn Bhd’s inclusion aligns with the group’s pattern of exploiting available credentials for access.

Technical Analysis

SOCRadar’s investigation into the domain sda-my[.]com yielded five records from stealer-log data, painting a concerning picture for SD Associates Sdn Bhd. The exposed information includes direct administrative panel access on the target domain, with a masked administrator account identified as ‘adm****1’. Additionally, corporate email credentials for the Ruijie Networks SSO portal (cloud-as.ruijienetworks[.]com) and an employee account (it.****t@sda-my[.]com) were found associated with No-IP and Skrill. The data spans from December 2025 to July 2026, indicating a seven-month period of unrotated access available on underground markets. The presence of these credentials suggests a plausible pathway for intrusion. The compromise of a single workstation exfiltrating browser-stored credentials across multiple platforms could explain the pattern observed. The combination of administrative access and Single Sign-On (SSO) compromise represents a valuable combination for initial access brokers looking to gain entry into corporate networks, potentially facilitating further malicious activities like ransomware deployment. The stealer-log evidence does not definitively confirm that INC Ransom utilized these specific credentials for an attack. However, the existence of seven months of unrotated administrative and SSO credentials represents a significant security vulnerability. It is highly recommended that SD Associates Sdn Bhd immediately rotate all identified compromised credentials, revoke active sessions on the Ruijie Networks SSO portal, and conduct a thorough audit of the sda-my[.]com access logs from December 2025 onwards to identify any unauthorized activity.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.