ShopDunk Data Breach

Alleged

Ransomware claim involving ShopDunk

Published: Sep 20, 2026 Qilin
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
ShopDunk
Industry
Retail & E-Commerce
Threat Actor
Qilin
Date of Incident
Sep 20, 2026

Executive Summary

ShopDunk, a Thai organization operating in the Retail & E-Commerce sector, was listed by the qilin ransomware group on their dark web portal on September 20, 2026. This listing brings attention to the threat actor’s targeting patterns and the potential exposure of sensitive information. Organizations in the retail and e-commerce space are often attractive targets for ransomware groups due to the sensitive customer data they handle and the critical nature of their online operations, which can be easily disrupted. The qilin ransomware group has demonstrated a high operational tempo, claiming 243 victims over the past 60 days, placing them among the most prolific ransomware operations currently active. Their primary targets geographically are organizations in the United States, Germany, and the United Kingdom. In terms of industry, Manufacturing and Professional Services have been the most frequently impacted sectors by qilin. ShopDunk’s listing aligns with the group’s broad targeting across various industries, but its specific sector (Retail & E-Commerce) is not as frequently highlighted as their top two.

Technical Analysis

Stealer-log analysis revealed 22 records pertinent to ShopDunk, categorized into three types of credential exposure. This included 9 employee accounts on internal organizational systems, 11 customer or third-party records residing on infrastructure owned by the organization, and 2 corporate accounts accessible via external services. Notably, high-value endpoints compromised include erp[.]shopdunk[.]com, identified as an ERP portal, along with idmsa[.]apple[.]com and amisapp[.]misa[.]vn. The identified credential window spans from August to September 2026, directly overlapping with the date of qilin’s listing of ShopDunk. The exposure of credentials for the ERP portal is considered the most critical finding, as qilin frequently utilizes access to ERP systems and internal portals for lateral movement within a network and for staging exfiltrated data. The proximity between the credential harvesting period and the listing date suggests that the compromise was likely the result of active exploitation by the qilin group, rather than a resale of credentials on the underground market. This temporal correlation indicates a high probability of ongoing or recent malicious activity. Immediate assessment and remediation are strongly advised, beginning with a thorough audit of authentication logs for erp[.]shopdunk[.]com. All affected accounts should be promptly revoked to mitigate further unauthorized access. Continued monitoring of stealer-log feeds and dark web marketplaces for any further mention or sale of ShopDunk’s data is recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.