Setic-Pourtier Data Breach

Alleged

Ransomware claim involving Setic-Pourtier.

Published: Aug 3, 2026 LockBit5
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Setic-Pourtier
Threat Actor
LockBit5
Date of Incident
Aug 3, 2026

Executive Summary

Setic-Pourtier, a company based in France, has been listed as a victim on the LockBit5 ransomware group’s dark web portal, published on August 3, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The organization is recorded without a specific sector classification in SOCRadar’s dataset, operating out of France. It is one of several European organizations added to the group’s portal in the same batch. In the 60 days prior to this listing, LockBit5 has claimed 76 other victims across its leak portal. The group has shown a strong targeting pattern in the Manufacturing, Business Services, and Hospitality and Tourism sectors. Geographically, its victims are concentrated in Brazil, the United States, and Germany, with France appearing steadily further down the distribution. Other recent LockBit5 listings that overlap with Setic-Pourtier’s profile — French organizations and neighbouring Western European companies — include Hotel Bourse, groupe-mbm.com, Ravagnan Group, and Media Service Maastricht. France is a recurring but secondary geography for LockBit5 over this window, sitting behind the group’s Brazilian, US, and German clusters.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for setic-pourtier.com in the queried slice. A null result is not the same as a clean bill of health. The query returns a paginated sample rather than a complete inventory, and credentials tied to alternate domains, subsidiary infrastructure, or personal email aliases used by staff would not appear under this lookup. The absence of records here should be treated as an information gap rather than a finding. For ransomware groups such as LockBit5, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. The absence of evidence in this query does not rule that scenario out — credentials may have surfaced in feeds outside this dataset, been used and rotated before indexing, or been harvested under personal email aliases. CTI teams should treat continued monitoring and proactive credential-hygiene checks as the appropriate response rather than reading a null query as exoneration.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.