Quick Summary
AllegedExecutive Summary
INC Ransom has listed SpearFin Ltd, a financial services firm based in Mauritius, on its data leak portal. The company operates under the domain spearfin[.]net and is involved in international capital management and investment fund activities. SOCRadar’s threat intelligence analysis indicates that SpearFin Ltd’s location in Mauritius is a geographical outlier compared to the ransomware group’s typical targets. This suggests that the targeting may have been driven by the availability of credentials rather than a specific regional campaign. In the preceding 60 days, INC Ransom has claimed 42 other victims, primarily located in the United States, UAE, and Canada. The group’s typical targeting spans Professional Services, Healthcare, and Business Services. Notable recent victims within the financial sector and comparable geographies include Third Coast Bancshares, VantagePoint Management & Autoclear, and Foresee Pharmaceuticals. SpearFin Ltd’s inclusion in this list, despite its location, highlights the opportunistic nature of credential-driven attacks, where the ransomware group may exploit available access irrespective of broader geographic or sector patterns.
Technical Analysis
SOCRadar’s investigation using stealer-log telemetry returned no specific records associated with spearfin[.]net within the queried dataset. It is important to note that this null result does not confirm that the organization is unaffected by credential compromise. The paginated nature of the dataset and potential use of alternative corporate domains or staff personal email aliases mean that credentials may still exist but were not captured in this specific query. The absence of direct evidence in the queried data does not rule out the possibility of compromised credentials. It is recommended that the stealer-log query be expanded to include staff personal email domains. Furthermore, continued monitoring for spearfin[.]net records in subsequent scans is advised to gain a more comprehensive understanding of any potential credential exposure.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.