Quick Summary
AllegedExecutive Summary
iah6477 has listed TRC Companies, a US-based professional services firm operating at trccompanies[.]com, as a claimed victim on August 30, 2026. SOCRadar CTI’s investigation identified 24 credential records within stealer-log datasets, comprising 11 employee credentials for M365 and Adobe IdP, and 13 corporate third-party credentials. The observed exposure window for these credentials ranges from February 18, 2024, to August 28, 2026. This extensive two-year period of credential exposure across identity management and third-party access layers presents a significant finding, irrespective of the definitive verification of the threat actor’s claim. In the preceding 60 days before this listing, iah6477 has claimed a total of seven victims, with a predominant focus on the United States. The group’s targeting priorities are concentrated within the Manufacturing, Professional Services, and Technology sectors. TRC Companies, operating within the professional services industry in the United States, aligns precisely with iah6477’s established victimology. The group appears to operate with a curated, smaller victim set, suggesting a strategy of deliberate selection rather than indiscriminate, widespread scanning activities.
Technical Analysis
SOCRadar CTI’s analysis of the domain trccompanies[.]com returned a “severe_exposure_in_sample” status. Specifically, 11 employee credentials found on M365 and Adobe IdP indicate direct access points into TRC Companies’ core identity infrastructure. An additional 13 corporate third-party credentials suggest a broadened exposure that could extend to systems managed by vendors and partners. The timeline for this credential exposure spans over two years, from February 18, 2024, to August 28, 2026. The recency of the most recent exposure, occurring just two days prior to the threat actor’s listing, points to an active and ongoing exposure rather than a historical incident. The observed credential exposure provides a potential pathway for ransomware operations. The 11 credentials linked to M365 and Adobe IdP could grant threat actors access to cloud-based productivity and identity services, potentially allowing for account enumeration, privilege escalation, or the deployment of malicious tools. The 13 third-party credentials further expand the attack surface, possibly enabling lateral movement into interconnected systems or the exploitation of vendor-specific vulnerabilities. The extended two-year exposure period warrants a comprehensive review of historical authentication logs to identify any signs of undetected lateral movement or persistent compromise that may have occurred prior to the current date. Given the extensive two-year credential exposure timeline, it is critical to rotate all identified M365 and Adobe IdP credentials immediately. Furthermore, a thorough audit of authentication logs for anomalous access patterns is essential to detect any unauthorized activity. Organizations should proactively notify affected third-party vendors and request immediate access revocation on their respective systems. The prolonged nature of the exposure suggests the potential for deep-rooted compromise, necessitating a broader investigation into historical access logs for any indications of undetected lateral movement that may predate the current 2026 incident.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.