Cyber & AI intelligence
Wasteland.
Briefs indexed2406
Issues26
Published Mondays07:30 CT
█ Ransomware DIASORIN-SETTRA-RA 2026-09-04

DiaSorin S.p.A.: Settra Ransomware Extortion Claim

"On September 3, 2026, the ransomware and data extortion group Settra named Italian biotech and diagnostics multinational DiaSorin S.p.A. on its dark web leak infrastructure, threatening to publish sensitive stolen data…"

On September 3, 2026, the ransomware and data extortion group Settra named Italian biotech and diagnostics multinational DiaSorin S.p.A. on its dark web leak infrastructure, threatening to publish sensitive stolen data unless the company opens negotiations. The claim was catalogued the following day by DeXpose, which recorded the target domain as int.diasorin.com and the country as Italy. One caveat frames everything below: as of publication there is no primary confirmation of this incident. No DiaSorin statement, no Italian regulator or Garante filing, and no CERT advisory appears in the available sourcing. Every account of the DiaSorin listing traces back to dark web monitoring vendors reporting what the attackers themselves posted, and attacker claims are marketing. Treat the listing as confirmed; treat the scope of the compromise as unverified.

What Happened

According to DeXpose, Settra published a post on September 3, 2026 claiming responsibility for an attack on DiaSorin, with an accompanying threat that data would be leaked absent negotiation. The fragment of the actor's own statement captured in that report reads: "DIASORIN This article covers only a portion of the data we've chosen to publish. Everything else wil..." That phrasing matters for two reasons. First, it implies Settra has already made some material public rather than merely threatening a future leak, which places the incident past the initial pressure stage. Second, it is written in the narrative, journalistic register Settra has used elsewhere, a style visible in the group's simultaneous Canadian listing for Teletek Structures Inc., which opened with a "PROLOGUE" describing the victim's business.

The DiaSorin post did not arrive alone. September 3, 2026 was a batch publication day for Settra. DeXpose recorded the Teletek Structures listing on the same date, and UNDERCODE NEWS reported two further claims dated September 3 involving Industrias Alegre S.A. in Brazil and Verve Portraits Pty Ltd in Australia, with encryption of documents alleged in those cases. That batching is consistent with what MOXFIVE has documented about the group's operating rhythm.

Notably, none of the sourcing alleges encryption or operational disruption at DiaSorin. The Brazilian and Australian listings reported by UNDERCODE NEWS describe files encrypted alongside data theft; the DiaSorin claim, as recorded, is framed purely as data exposure and extortion. Whether that reflects an exfiltration-only intrusion or simply an incomplete public record is not established by the available sources.

What Was Taken

Honestly: nobody outside DiaSorin and Settra currently knows. No source specifies a data volume, a record count, a file inventory, or a category of affected individuals for this incident. Any figure circulating for DiaSorin at this stage is not supported by the sourcing reviewed here, and readers should be skeptical of one appearing without attribution.

What can be said is what Settra has done to comparable victims. Brinztech reported in August 2026 that the group published roughly 120GB of internal documents belonging to POWDR Corporation, a US ski resort operator, spanning nearly two decades of operations and including payroll documentation, workers' compensation files, FMLA medical certifications, legal case summaries, and internal financial ledgers. Brinztech further reported that Settra weaponised that release by alleging corporate misconduct, including safety compliance failures and retaliation against employee organising. That is a single OTHER-tier account of one incident, not a template, but it establishes the group's demonstrated appetite for high-sensitivity HR and medical records and its willingness to editorialise a leak for maximum reputational damage.

For a diagnostics company, that pattern is the concerning part. DiaSorin's environment plausibly holds clinical assay data, regulatory submissions, distributor and hospital contracts, and employee health records across multiple jurisdictions. If Settra's DiaSorin cache resembles its POWDR cache in character, the exposure is a GDPR special-category problem, not just an IP problem. That remains a hypothesis until DiaSorin or an Italian regulator says otherwise.

Why It Matters

Settra is young. MOXFIVE dates first identification of the group to June 2026 and began tracking it in late June, when it posted nearly two dozen victims to its leak site in a short span. MOXFIVE explicitly flags that this sharp growth is not fully substantiated, while confirming through direct case work that Settra is a real and active threat actor. SOCRadar's August 11, 2026 report put the count at 25 other victims in the preceding 60 days. The two figures are broadly compatible and both point at the same thing: a group with real capability and an unverified victim board, running at a pace that has not slowed since June.

Volumetric claims aside, the victimology is worth reading closely because the sources do not fully agree. MOXFIVE reports that Settra publicly describes itself as financially rather than ideologically motivated, claiming it does not target specific countries or industries and instead goes after organisations with exploitable weaknesses such as unpatched systems and weak access management. SOCRadar's data describes a concentration in business services, technology, and consumer services, with victims clustered in the United States, Germany, and the United Kingdom, and characterises European listings such as Profinergy BV in the Netherlands as a smaller presence within an otherwise largely American victim set. SOCRadar's own analysis of the August 19, 2026 batch, which included Greco Steel Products in Greece alongside victims in Malaysia, Japan, and the US, reads that geographic spread as evidence the group is buying access from initial access brokers rather than running a targeted campaign.

That reading reconciles the two accounts: opportunistic, broker-fed intake produces a victim list that looks random by sector and geography while still skewing toward wherever the access market is deepest. DiaSorin, an Italian multinational, sits outside Settra's densest cluster but fits comfortably in an IAB-driven model where the deciding factor is available access, not the target's flag or industry.

One sourcing discrepancy should be noted rather than smoothed over. SOCRadar's Profinergy BV page lists the threat actor field as "Royal" in its summary table while the body text identifies Settra throughout and the article itself is filed as a Settra incident. This appears to be a metadata error on that page, but it is a reminder that vendor breach trackers carry data-entry noise, and that a single tracker field is thin ground for actor attribution.

The Attack Technique

There is no public information on how Settra gained access to DiaSorin. The group's broader tradecraft, however, is documented across three sources that describe three different entry paths, which is itself the useful finding.

MOXFIVE, reporting from direct incident response case work, observed Settra obtaining initial access through compromised VPN credentials and then using those valid credentials to move laterally through victim environments. SOCRadar identifies infostealer-harvested credentials as a known and common initial access method for the group, typically acquired and validated by threat actors or access brokers, though its stealer-log queries against both the Profinergy and Greco Steel domains returned no positive matches, and SOCRadar cautions in both cases that the null result reflects a limited paginated sample rather than an absence of compromise. Brinztech, describing the POWDR incident, attributes that breach to an unprotected, unauthenticated internal server repository discovered and exfiltrated by the attackers.

Credential theft and exposed infrastructure are not competing theories; they are two arms of the same opportunistic strategy. Settra appears to take whichever door is open. MOXFIVE also notes operational characteristics that shape victim response: the group negotiates over Tox, posts victims in batches, and often takes several days to respond in chat, a cadence MOXFIVE suggests may indicate a very small crew or even a sole operator rather than a large ransomware-as-a-service organisation. Victims should expect slow, asynchronous communication rather than the structured negotiation desks larger affiliates run.

What Organizations Should Do

Sources: Settra Ransomware Attack on DiaSorin S.p.A. - DeXpose | Settra Ransomware: TTPs, Victims, and Defense Guide | Settra Ransomware Hits Two Australian and Brazilian Targets, Raisin... | Two US Professional Services Firms Hit by Ransomware Attacks as Ins... | Profinergy BV Data Breach Business Services Data Breach Intellige... | Greco Steel Products Data Breach Manufacturing Data Breach Intell... | POWDR Corporation Suffers Massive Data Exposure via Ransomware Grou... | Settra Ransomware Strikes Teletek Structures Inc. - DeXpose