Quick Summary
AllegedExecutive Summary
INC Ransom has targeted VantagePoint Management & Autoclear, a financial services company based in the United States. The ransomware group listed the company on its dark web leak portal on July 14, 2026. This listing was detected by SOCRadar’s Dark Web Monitoring service. The financial services sector is a frequent target for cybercriminal groups due to the potential resale value of data and the leverage it provides through regulatory implications.
Technical Analysis
An analysis of SOCRadar’s stealer-log telemetry did not yield any records for VantagePoint’s primary domain, vantagepointcapital[.]com, within the queried segment. However, this absence does not entirely rule out the possibility of compromised credentials, as data could exist under alternate corporate domains or personal email aliases not included in this specific data slice. Ransomware groups like INC Ransom commonly use credentials harvested by infostealers as an initial access vector. Threat actors often purchase these logs from underground markets, validate the credentials for access to corporate systems like Microsoft 365, VPNs, or remote-access portals, and then deploy ransomware. The lack of immediate data in the stealer logs does not exclude this method, as logs can be used and purged before their indexing.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.