Quick Summary
AllegedExecutive Summary
thegentlemen listed SUNSEA, a Thai manufacturing company operating under hisunsea[.]com, as a claimed victim on August 30, 2026. SOCRadar CTI’s investigation uncovered 14 employee credentials within stealer-log datasets. These credentials, active between September 3, 2025, and August 20, 2026, provide access to various systems including Odoo ERP, internal portals, and direct IP-based endpoints. The exposure of Odoo ERP credentials suggests that the threat actors may have gained access to SUNSEA’s core operational business systems, not solely its perimeter infrastructure. In the preceding 60 days, thegentlemen has claimed 248 victims, with a significant concentration in the United States, the United Kingdom, and Germany. The group’s primary sectors of focus are Manufacturing and Technology. SUNSEA, as a manufacturing company based in Thailand, aligns with the group’s established targeting patterns within the manufacturing sector. The inclusion of Thailand represents a geographic expansion for thegentlemen, moving beyond their typical core markets in Western countries.
Technical Analysis
SOCRadar CTI’s analysis returned a “severe_exposure_in_sample” result for hisunsea[.]com. Specifically, fourteen employee credentials were identified across multiple platforms, including Odoo ERP, internal portals, and direct IP-based endpoints. The recorded activity for these credentials spans from September 3, 2025, to August 20, 2026. The discovery of credentials for direct IP-based endpoints is particularly noteworthy, as it indicates that employee devices may have captured credentials for internal systems accessed via raw IP addresses rather than resolvable hostnames. This pattern is consistent with infostealer infections that harvest browser-stored credentials from workstations directly connected to production systems. The exposure of these credentials, particularly those linked to Odoo ERP and direct IP-based endpoints, suggests a potential avenue for further malicious activity. While the stealer-log data does not confirm a direct compromise or active ransomware deployment, it indicates a significant level of credential exposure that could be leveraged by threat actors. The period of credential exposure, nearly a year, raises concerns about the potential for undetected lateral movement and data exfiltration. Immediate credential rotation is required for all 14 identified accounts, with a priority on those associated with Odoo ERP due to its critical role in managing financial, inventory, and operational data. It is essential to investigate whether the direct IP-based endpoints correspond to externally exposed production systems or internal administrative interfaces. A thorough review of Odoo access logs for any unusual data export or bulk query activity within the full timeframe of 2025-09-03 to 2026-08-20 is also recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.