Quick Summary
AllegedExecutive Summary
Torsion Group, a business services company based in the United Kingdom, was listed on the Settra threat group’s dark web portal on July 16, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service, placing the organization within the broader context of Settra’s recent leak-site activity. Torsion Group operates within the Business Services sector, an industry frequently targeted by ransomware operations. In the 60 days preceding this listing, Settra had claimed 19 other victims. The group predominantly targets the Business Services, Technology, and Consumer Services sectors, with a notable concentration of victims in the United States, United Kingdom, and Germany. Torsion Group’s profile as a UK-based business services organization aligns with Settra’s typical targeting patterns, similar to other recent victims such as Green Valley Financial Services Inc., WT Law LLP, R.C. Fields & Associates, and Wilfley.
Technical Analysis
SOCRadar’s analysis of infostealer-log telemetry for torsiongroup.co.uk yielded no records within the queried scope. It is crucial to note that a null result does not confirm the absence of a compromise. The queries are based on partial, paginated samples and can omit credentials exposed through alternate corporate domains, personal email aliases, or logs that have been harvested and subsequently rotated before indexing. Therefore, the absence of findings in this specific query does not guarantee that no compromise has occurred. Ransomware operators, including groups like Settra, commonly utilize infostealer-harvested credentials as an initial access vector. Threat actors often source these credentials from underground marketplaces, validate them, and then use them to gain access to corporate systems via platforms such as Microsoft 365, VPNs, or remote-access portals, ultimately leading to ransomware deployment. The lack of identifiable credentials in this particular telemetry pull does not preclude this scenario, as exposed credentials may exist in other data feeds not included in the query, or may have been remediated prior to data indexing. Given these limitations, CTI teams should consider continued monitoring of dark web and stealer-log feeds, alongside proactive credential hygiene checks and regular password rotation. Reviewing multi-factor authentication configurations and scrutinizing activity logs for Microsoft 365, VPNs, and remote access solutions are also recommended to fortify the organization’s security posture against potential intrusions.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.