www.labexpress.com
bd_1acca1b402c0afb6 · schema v1 · pii pii-v1
Full breach record for www.labexpress.com →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group INC Ransom on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
LABEXPRESS & GARONIT PHARMA: 200 GB OF SHARED INFRASTRUCTURE We have obtained 200 GB of internal data from a US-based group operating under two legal entities: Labexpress and Garonit Pharma. The materials show a single Active Directory domain (LABEXPRESS1.local), a shared file server, and extensive cross‐company records. This data will be made publicly available in the near future. Active Directory Overview - 65 computers, 142 user accounts, 98 groups, 11 organizational units (OUs). - Domain controllers: DC01 (Server 2019), LABXDC01 (Server 2012 R2). - A single AD domain serves both Labexpress and Garonit Pharma. Notable account: cn: Troy Austin sAMAccountName: Taustin memberOf: QuickBooks, LABEXPRESS, LABEXPRESSUSERS The same person appears in Exchange mailboxes as taustin@garonitpharma.com. Weak Passwords and Brute‐Force Indicators - Administrator account: 3,193 failed logon attempts, last successful logon 2026-04-30. - Computer accounts FRONTDESK$, DEV$, LABEL$ – more than 3,000 failures each. - Cleartext password found on FILE01\passwords.txt: Admin: LabExpress2024! - The Domain Admins group includes: Administrator, labadmin, adminiss, Protect, xtratech, LAE009-CT. - Password for user Protect: Password123! - Outdated password templates in the “SBSUsers” OU are still in use. Mail Servers and Exchange - LABSERVER2 runs Windows Server 2003 SP2 with Exchange 2007. - Full mailbox export performed using the built‐in Export-Mailbox cmdlet – no special exploit required. Contents of the Obtained Data (200 GB) We have data from drive E:\, including: 1. Financial & Accounting - QuickBooks Enterprise 2021 installer and data files (QB2021.DSN, QB2021.ND). - Folder: E:\Garonit Documents\Clients 2022\ – hundreds of invoices, COAs, and COCs (e.g., Amtrade International INV# 50268.pdf for ~21M USD, Estee Lauder Inv# 24.pdf). - Folde
Source provenance
- Source URL
- https://www.ransomware.live/id/d3d3LmxhYmV4cHJlc3MuY29tQGluY3JhbnNvbQ==
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2026
- Raw hash
- f5c345d68d5865e0fd47c9d21ce9bab36c58bb3291e65a43d18271b2ec6735ec
Reporting entity
- Name
- incransomnorm: inc_ransom
Victim entity
- Name
- www.labexpress.comnorm: wwwlabexpresscom
- Domain
- labexpress.com
- Industry
- Professional Servicesllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· inc_ransom
- Threat actor
- Inc RansomExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.