DisclosureLens
GLOBALMalwareProfessional ServicesProfessional ServicesRansomwareInc RansomRansom DemandedActor NamedData Leak ThreatenedData PublishedHigh

labexpress.com

bd_1acca1b402c0afb6 · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

May 29, 2026

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for labexpress.com

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group INC Ransom on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: Business ServicesDiscovered: 2026-05-30

Source: Ransomware.live

Post text · scraped from the leak site

LABEXPRESS & GARONIT PHARMA: 200 GB OF SHARED INFRASTRUCTURE We have obtained 200 GB of internal data from a US-based group operating under two legal entities: Labexpress and Garonit Pharma. The materials show a single Active Directory domain (LABEXPRESS1.local), a shared file server, and extensive cross‐company records. This data will be made publicly available in the near future. Active Directory Overview - 65 computers, 142 user accounts, 98 groups, 11 organizational units (OUs). - Domain controllers: DC01 (Server 2019), LABXDC01 (Server 2012 R2). - A single AD domain serves both Labexpress and Garonit Pharma. Notable account: cn: Troy Austin sAMAccountName: Taustin memberOf: QuickBooks, LABEXPRESS, LABEXPRESSUSERS The same person appears in Exchange mailboxes as [REDACTED-EMAIL]. Weak Passwords and Brute‐Force Indicators - Administrator account: 3,193 failed logon attempts, last successful logon 2026-04-30. - Computer accounts FRONTDESK$, DEV$, LABEL$ – more than 3,000 failures each. - Cleartext password found on FILE01\passwords.txt: Admin: LabExpress2024! - The Domain Admins group includes: Administrator, labadmin, adminiss, Protect, xtratech, LAE009-CT. - Password for user Protect: Password123! - Outdated password templates in the “SBSUsers” OU are still in use. Mail Servers and Exchange - LABSERVER2 runs Windows Server 2003 SP2 with Exchange 2007. - Full mailbox export performed using the built‐in Export-Mailbox cmdlet – no special exploit required. Contents of the Obtained Data (200 GB) We have data from drive E:\, including: 1. Financial & Accounting - QuickBooks Enterprise 2021 installer and data files (QB2021.DSN, QB2021.ND). - Folder: E:\Garonit Documents\Clients 2022\ – hundreds of invoices, COAs, and COCs (e.g., Amtrade International INV# 50268.pdf for ~21M USD, Estee Lauder Inv# 24.pdf). - Folde

Incident timeline — mostly unverified

? — ?

Breach window unknown

May 29, 2026

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.