Semper Laser Data Breach

Alleged

Ransomware claim involving Semper Laser

Published: Sep 7, 2026 Direwolf
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Semper Laser
Industry
Financial Services
Threat Actor
Direwolf
Date of Incident
Sep 7, 2026

Executive Summary

direwolf ransomware listed Semper Laser, a Swedish medical-aesthetics and laser-technology manufacturer, on its dark web portal on September 7, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring. The telemetry revealed a severe situation with all 25 corporate @semperlaser.com credentials in SOCRadar’s sample. Notably, a single employee account appeared 22 times across various platforms, including identity, ERP, financial, and password manager systems, remaining unrotated over a five-month period. This extensive exposure highlights a significant risk to the company’s data security. In the past 60 days, direwolf has claimed 52 other victims, primarily in Healthcare, Technology, and Financial Services, with a strong concentration in the United States, Sweden, and Brazil. Recent victims from the Scandinavian region and manufacturing sector include PT Intraco Penta Tbk, Allstar Industries, THQ Nordic, and Lifesum. Semper Laser’s profile, being a Swedish manufacturing company with ties to health technology, aligns with direwolf’s documented targeting patterns.

Technical Analysis

SOCRadar’s stealer-log telemetry detected 25 records associated with semperlaser[.]com, covering the period from April 18 to September 7, 2026. A critical finding is that every identified record contains corporate email addresses. Furthermore, one specific employee account was found in 22 of these records, spanning a diverse range of systems including identity providers, ERP and financial operations (via NetSuite), Intuit/QuickBooks for financial management, and a password manager (LastPass). This indicates that credentials for these platforms were exposed. The significant risk stems from the lack of credential rotation for these accounts over a five-month period. The exposure of credentials across critical systems such as ERP, payment processing (Versapay), and a password manager like LastPass presents a substantial threat. Access to the LastPass vault, in particular, could lead to the exposure of additional credentials, amplifying the overall risk. The telemetry returned 25 records for semperlaser[.]com, spanning April 18 through September 7, 2026. Every record carries a corporate email address. One employee account (psa****[email protected]) surfaces across 22 of those records, covering: – Google Workspace and Oracle (identity providers) – NetSuite across three separate tenant URLs (ERP and financial operations) – Intuit/QuickBooks (financial systems) – LastPass (password manager — potential master-key exposure) – Versapay (payment processing) Five months without credential rotation across this breadth of systems is the central risk. Access to the LastPass vault would yield additional credentials; the ERP and payment-system exposure compounds the financial risk. Immediate rotation across all listed platforms is the first-order action. LastPass vault access logs and NetSuite activity should be audited from April 2026 onward for anomalous access patterns.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.