The extortion crew tracked as settra published what it describes as roughly 120GB of internal documents belonging to POWDR Corporation, the US adventure lifestyle operator behind a portfolio of mountain resorts, national park destinations, rafting outfits and heli-adventure brands. The listing surfaced on settra's dark web leak portal in August 2026 and was flagged publicly on August 11, 2026, when ThreatMon's threat intelligence team reported powdr.com added to the group's victim list alongside firstdigital.com. Every account of this incident so far comes from threat intelligence vendors and breach-monitoring outlets. POWDR itself has issued no public statement in any of the available sourcing, and there is no regulator filing, CERT advisory or vendor incident report confirming the intrusion. Treat the scope figures below as the attacker's claims plus third-party analysis of the dump, not as victim-confirmed facts.
What Happened
The sequence, as reconstructed across the sources, is short. Settra listed POWDR on its leak site in August 2026 and, rather than running a countdown, appears to have gone straight to publication of a large archive. Brinztech, which analysed the released files, puts the volume at approximately 120GB and describes the material as spanning nearly two decades of company operations. UndercodeNews reports the leak was staged under deliberately provocative titles including "Point of No Return" and "What the Ski Empire Is Hiding," which is consistent with a pressure play aimed at press pickup rather than a quiet negotiation.
Alongside the data, settra published allegations of corporate misconduct: safety compliance failures, retaliation against employee organising activity, and alteration of internal records affecting thousands of payroll logs. Those are the threat actor's characterisations of documents it stole. Nothing in the available sourcing independently substantiates them, and leak-site narrative framing is a well-established coercion technique. UndercodeNews itself cautions that a leak-site listing does not by itself prove intrusion, exfiltration or an encryption event, and notes that some claims are later withdrawn.
Accounts differ on the intrusion path, and the difference matters. Brinztech attributes the POWDR compromise specifically to an unprotected, unauthenticated internal server repository that the actors discovered and drained. MOXFIVE, drawing on its own Settra casework rather than on POWDR, reports the group gaining initial access through compromised VPN credentials and then moving laterally with those valid accounts. Both are plausible; neither has been confirmed for this victim. The exposed-repository claim rests on a single OTHER-tier source and should be read as a reported finding, not established fact.
What Was Taken
The composition of the dump, per Brinztech's review, is the part defenders should focus on. The archive is reported to contain employee payroll documentation, workers' compensation files, FMLA medical certifications, legal case summaries, internal financial ledgers and guest injury reports. That mix is unusually toxic. FMLA certifications carry medical detail about named employees and their family members. Workers' compensation and guest injury files carry medical and legal detail about incidents the company was already managing. Legal case summaries carry privileged and adverse material. Payroll records carry direct identifiers and compensation data at scale.
On volume, the sources agree only loosely: settra's own claim and Brinztech's analysis both land at approximately 120GB, and no source offers a competing byte count or a record count for POWDR. There is no published figure for how many individuals are affected. Any number circulating without that basis is an estimate.
For scale comparison, settra's July 2026 claim against American Color Imaging in Cedar Falls, Iowa asserted 653GB including financial and payroll records and third-party confidential documents, per DysruptionHub. ACI did not confirm a cyberattack, describing its late-June disruption only as a temporary systems outage. The pattern is the same: large claimed archives, HR and finance material foregrounded, victims declining to characterise the event.
Why It Matters
Settra is young and poorly characterised, and the public numbers on it do not reconcile. Darkfield says it has indexed 28 public victims claimed between June 28 and July 16, 2026, while also stating the group has claimed at least 11 victims. ProvenData reports 31 publicly claimed victims as of August 10, 2026 across 13 countries, with 1 in the trailing 30 days, and separately notes that ransomware-tracking platforms disclose 11 victims. SOCRadar, writing on July 16, says settra claimed 19 additional victims in the preceding 60 days. Sector rankings diverge too: ProvenData weights Technology (19%), Professional Services (19%) and Retail/E-Commerce (16%); Darkfield lists Consumer Services, Manufacturing, Transportation and Logistics, and Agriculture and Food Production; SOCRadar cites Business Services, Technology and Consumer Services. Read the range, not any single figure. The spread reflects different indexing methods and different snapshot dates, and it is a reminder that leak-site counts measure publication activity, not infections.
The sources also disagree on what settra actually does. MOXFIVE describes a full double-extortion operation combining theft with encryption, negotiating over Tox, and states it has direct casework confirming settra as a real and active threat actor. ProvenData characterises researchers as describing settra as a "data broker," with encryption possibly secondary and not confirmed by any public malware analysis. The POWDR incident, as reported, involves no disruption to operations and no encryption claim, which fits the data-broker reading more closely.
Two further points. First, settra's cadence is bursty, with victims posted in batches and multi-day gaps in Tox responses, which MOXFIVE reads as a very small crew or possibly a single operator. A small operator is not a small threat when the technique is scanning for exposed data stores. Second, ProvenData's timeline analysis suggests roughly a twenty-day gap between estimated compromise and public listing, meaning a POWDR-style victim would have had a staging window in which detection was still possible.
Attribution remains open. No source links settra to a prior ransomware family, identifies a country of origin, or documents a RaaS affiliation, and Darkfield notes an absence of published analysis from CISA, the FBI or Mandiant. No law enforcement action against the group has been reported.
The Attack Technique
For POWDR specifically: Brinztech reports the entry point as an unauthenticated internal file repository reachable without credentials, exfiltrated wholesale. If accurate, this is not an intrusion in the traditional sense so much as a collection operation against data that was already reachable. Groups running this play scan continuously for misconfigured cloud storage buckets, exposed file shares and internal servers published to the internet without access control, then pull whatever they find. It requires no malware, no phishing, and generates no encryption event, which is why it frequently leaves no operational symptom for the victim to notice.
For settra generally: MOXFIVE's casework points to compromised VPN credentials used as valid accounts for lateral movement, and settra has publicly stated it does not target specific countries or industries but instead goes after organisations with unpatched systems and weak access management. SOCRadar's stealer-log telemetry work on another settra victim, the Brazilian technology firm Acilab, found 25 exposed records tied to the victim domain, none using corporate email addresses, which it reads as customer-side account-takeover exposure rather than corporate credential compromise in that particular telemetry slice. Infostealer-harvested credentials remain a documented initial access route for operators of this type.
One item to keep separate: UndercodeNews raises Microsoft's August 2026 Patch Tuesday in the same article as POWDR, including the actively exploited Windows AFD driver flaw CVE-2026-68820 (privilege escalation to SYSTEM) among a community-tracked 421 Microsoft CVEs. No source connects that vulnerability to the POWDR incident. It is contextual, not causal.
What Organizations Should Do
- Inventory and authenticate every internal file repository. Run external attack surface discovery against your own ranges and cloud tenancies specifically looking for unauthenticated SMB shares, HTTP file indexes, object storage buckets and legacy document servers. The reported POWDR entry point is the cheapest breach in the catalogue to prevent and the easiest to miss.
- Enforce phishing-resistant MFA on all VPN and remote access. MOXFIVE observed settra entering through compromised VPN credentials and then operating as a valid user. Password-only or SMS-backed remote access is the difference between a blocked login and a twenty-day dwell.
- Apply retention limits to HR, medical and legal records. An archive spanning nearly two decades is a retention failure as much as a security one. FMLA certifications, workers' compensation files and injury reports should have defined destruction schedules and should not sit on general-purpose file servers.
- Instrument for bulk egress, not just for encryption. If the extortion model is theft-only, ransomware detection will never fire. Alert on anomalous volume leaving via cloud sync, file transfer services and unusual outbound sessions from file servers.
- Monitor infostealer logs for your domains. SOCRadar's Acilab analysis shows the value of distinguishing corporate credential exposure from customer-side exposure. Both need response, but only one puts an attacker inside your VPN.
- Prepare a communications and legal track before you need it. Where a dump contains medical certifications, injury reports and employee PII, multi-agency regulatory attention follows, and leak-site posts that allege misconduct are designed to create a second crisis. Decide in advance who owns the response to allegations embedded in a leak, separate from the technical investigation.
- Treat leak-site claims as unverified until you verify them. Both POWDR and American Color Imaging have declined to confirm settra's claims. If your organisation is listed, validate against your own logs before conceding or disputing anything publicly.
Sources: POWDR Corporation Suffers Massive Data Exposure via Ransomware Grou... | Settra Ransomware Group Claims Two New Victims: POWDR and First Dig... | POWDR Targeted by Settra Ransomware as a Massive Microsoft Patch Tu... | settra ransomware group — victims, leak site & IOCs · Darkfield | Settra Ransomware: TTPs, Victims, and Defense Guide | SETTRA Ransomware: Emerging Double-Extortion Threat | Settra claims American Color Imaging after Iowa outage | Acilab Data Breach Technology Data Breach Intelligence SOCRadar®...