Quick Summary
AllegedExecutive Summary
The Servicio Plurinacional de Registro de Comercio, Bolivia’s national commercial registry, was identified as a victim of the Krybit ransomware group. The listing appeared on Krybit’s dark web portal on July 7, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. This incident marks a Latin American government entity as a target for Krybit, aligning with the group’s historical focus on public sector organizations.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure related to the seprec.gob.bo domain. This exposure included one corporate credential within the organizational mail infrastructure, two on a related third-party domain, and 22 external-user accounts on target portals. This suggests a mixed risk profile involving direct corporate access and extensive external/customer account exposure. The presence of a corporate mail credential is a key indicator of potential initial access and warrants immediate attention such as credential rotation and session invalidation. The use of stealer-log harvested credentials is a common vector for threat groups like Krybit, enabling them to gain access to corporate systems and deploy ransomware.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.