Quick Summary
AllegedExecutive Summary
Seasia Infotech, an India-based software development and IT services company, was listed on TheGentlemen ransomware group’s dark web portal on September 2, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The company serves clients across multiple industries and geographies, and its nature as a software development firm may attract ransomware and extortion activity due to the sensitive data it handles. The listing is claimed and has not been independently confirmed. TheGentlemen ransomware group has been highly active, listing 254 victims in the preceding 60 days. Their core targeting focuses on Manufacturing, Technology, and Professional Services sectors, with a significant concentration in the United States, followed by the United Kingdom and Germany. Recent victims include Nutex Health (United States, Healthcare), CareerSource Palm Beach County (United States, Professional Services), EP Manufacturing Bhd (Malaysia, Manufacturing), and The Sole (United Kingdom, Retail & E-Commerce). The inclusion of Seasia Infotech extends TheGentlemen’s footprint into the Asia-Pacific region, complementing their established victim base in the US and Europe.
Technical Analysis
SOCRadar’s stealer-log telemetry identified a significant exposure for seasiainfotech[.]com, revealing 13 employee credentials on organization-controlled systems. These credentials were found on the victim’s domain controller, an internal web application, and critical SaaS platforms accessed via corporate email accounts. The affected systems include those for IT asset management, application performance monitoring, database infrastructure, source code repositories, and workflow automation services. An additional eight records indicated corporate users on third-party services, suggesting potential workstation compromises across multiple employees. The exposure window for these credentials, particularly those for the domain controller, spans from July 28 to September 1, 2026. Notably, domain controller credentials were found between August 3 and August 19 without any evidence of rotation, indicating an active and unmitigated access window of over two weeks. This critical period of unrotated access is of significant concern. The combination of exposed domain controller credentials, access to source code repositories, and database infrastructure, all remaining unrotated during the identified intrusion window, presents a high-severity exposure profile for a software development firm. This scenario could facilitate both data exfiltration and lateral movement, potentially leading to ransomware deployment. While the stealer-log evidence does not definitively confirm the use of these specific credentials by TheGentlemen, the observed access profile aligns with kill chains seen in high-value technology sector incidents. The unmitigated access during the August window represents the most urgent area for remediation.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.