The Miller Group Data Breach

Alleged

Ransomware claim involving The Miller Group

Published: Aug 5, 2026 Dark Project
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
The Miller Group
Industry
Business Services
Threat Actor
Dark Project
Date of Incident
Aug 5, 2026

Executive Summary

The Miller Group, an organization based in the United Kingdom, has been identified as a victim by the Dark Project ransomware group, with their listing appearing on the group’s dark web portal on August 5, 2026. This information was uncovered through SOCRadar’s Dark Web Monitoring service. While the specific industry of The Miller Group was not detailed, its listing was categorized generically within SOCRadar’s dataset, distinct from single named verticals. This incident marks one of two entries from the United Kingdom found on Dark Project’s recent victim list. In the 60 days preceding this listing, Dark Project claimed a total of 17 victims across its leak site. The group predominantly targets the manufacturing, healthcare, and transportation sectors, with a significant concentration of victims located in the United States, the United Kingdom, and the Philippines. Several recent Dark Project victims share similarities with The Miller Group’s profile, including other UK-based organizations or similarly sized businesses, such as Sutherland Packaging, Mile Bluff Medical Center, Reid Electric Service, Inc, and TSC Logistics. However, the inclusion of The Miller Group is considered part of a secondary geographic focus on the UK rather than an indication of a broader shift in the group’s operational strategy, given the larger number of US-based victims.

Technical Analysis

An analysis of SOCRadar’s stealer-log telemetry for the domain miller-group.com returned no correlating records within the queried data slice. It is crucial to note that a lack of findings in this specific query does not confirm the absence of a compromise. The limitations of the query include coverage of only a paginated sample of data, meaning the complete dataset was not exhaustively searched. Furthermore, credentials may exist under alternate or subsidiary corporate domains that were not included in this particular lookup. In cases where employees use personal email aliases for corporate access, these harvested credentials would not be associated with the primary corporate domain and therefore would not surface in this query. Organizations with complex group structures and multiple trading names are particularly vulnerable to this blind spot, as compromise often occurs on subsidiary domains that go undetected by single-domain monitoring. For ransomware operations like those conducted by the Dark Project group, infostealer-harvested credentials represent a well-documented pathway for initial access. Threat actors or initial access brokers frequently acquire fresh credential logs from underground marketplaces. These validated corporate credentials are then utilized to gain access to systems such as Microsoft 365, VPNs, or remote-access portals, paving the way for ransomware deployment. The absence of evidence in this stealer-log query does not negate this possibility. It is plausible that credentials may have appeared in data feeds not covered by this specific dataset, or they might have been used and subsequently rotated before being indexed. Moreover, as previously stated, credentials associated with personal email aliases would not be captured. Consequently, CTI teams should prioritize continuous monitoring and proactive credential hygiene checks rather than relying on a null query as definitive proof of security.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.