Twin States News Data Breach

Alleged

Ransomware claim involving Twin States News.

Published: Aug 30, 2026 ThreeAM
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Twin States News
Industry
Media
Threat Actor
ThreeAM
Date of Incident
Aug 30, 2026

Executive Summary

The ransomware group threeam has claimed responsibility for a data breach affecting Twin States News, a media outlet based in Moldova that operates through the domain wmdn[.]net. The claim was posted on threeam’s leak site on August 30, 2026, with the threat actor alleging unauthorized access to the organization’s systems and data. While the claim has not been independently verified, it has been flagged by SOCRadar’s CTI analysis. The targeting of a media organization by threeam is noted as an unusual deviation from their typical operational patterns, which have historically focused on the hospitality sector. Over the past 60 days, threeam has claimed responsibility for three victims, with reported targets in Moldova, Mexico, and the United States. This broader context indicates a degree of geographic diversity in their operations. However, the claim against Twin States News does not align with the group’s predominant targeting of the hospitality industry, suggesting a potentially selective or opportunistic approach in this instance. The low reported victim count and the unusual sector choice might indicate a period of limited or experimental activity for the group.

Technical Analysis

SOCRadar’s investigation into stealer-log datasets for the domain wmdn[.]net yielded no relevant credential records. This null result indicates that no compromised credentials associated with Twin States News were found in the analyzed infostealer logs at the time of reporting. It is crucial to note that the absence of evidence in this specific dataset does not confirm that the organization has not been compromised. The threat actor, threeam, may have gained access through alternative methods not captured by the stealer-log analysis. These methods could include phishing campaigns, exploitation of publicly accessible services, or the use of credentials obtained from other sources outside the scope of the queried datasets. The current dataset has limitations, and it is possible that credentials exist under alternate corporate domains, use personal email aliases, or were used and rotated before their indexing in the analyzed feeds. Given the nature of ransomware operations, where infostealer-harvested credentials can facilitate initial access or lateral movement, the lack of direct telemetry does not rule out a potential intrusion. Continued monitoring of dark web forums and stealer-log feeds for any future mentions or credential exposures related to Twin States News or its associated domains is recommended. Organizations in similar situations should also conduct proactive credential hygiene checks, including password rotation and multi-factor authentication reviews, especially for Microsoft 365, VPNs, and other remote access portals.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.