Compiled from this incident record and the threat intelligence profile for Incransom. Figures and technique mappings are quoted from the source data, not inferred.
Incransom listed SpearFin Ltd on its dark web leak site on 18 August 2026, a Financial Services firm that offers fund administration and corporate services and has assets under administration valued at US$10 billion.
About SpearFin Ltd
SpearFin Ltd
https://spearfin.net
SpearFin offers a wide range of services including fund administration, corporate services, compliance support, and investor relations.
Assets Under Administration US$10 billion.
The leak occurred on June 26, 2026.
Total leak: 416 GB
Leak included: NDA, Correspondence Client, KYC - Passports, Certificates, Investing documents,
Share Registry and Holders, Anti-Money Laundering (AML) audit, Agreements, Application forms, Bank Statements,
Bank Payrolls, Loans Documents, Certificates of GBC (Global Business Company), Register of Directors and many other financial documents.
Clients: YuMee Seven Six, BAMBOO BAY PRIVATE LIMITED, Asio Global Fund, 3B Capital, Abans Group, Amicorp Capital, Apex Fund Services Ltd, Pangaea Fund Limited,
AL Farah Overseas Limited, Zinnia Group, AMG Services Ltd, NEO SEMI SG PTE. LTD, MIC ELECTRONICS LIMITED, Zenbridge Capital Pvt. Ltd., Zinnia Investment Advisers Pvt Ltd,
Onpoint Ventures Limited, Wilson Group, Blue River, Capital Advisors Private Limited, Zenbridge Capital Pvt Ltd,
Topland Group Holdings, Africa Opportunities Fund, Appollo Fund Limited and many other...
Type of information: Confidential
Full publication coming soon...
Source record: ransomware.live
About the Incransom group
INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits. Incransom has listed 893 victims since August 2023.
How Incransom is documented to operate
Valid Accounts
T1078
Stealth
Persistence
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.
Mitigations:
Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication
MITRE ATT&CK reference โ
Exploit Public-Facing Application
T1190
Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.
Mitigations:
Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing
MITRE ATT&CK reference โ
Phishing
T1566
Initial Access
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.
Mitigations:
Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit
MITRE ATT&CK reference โ
Windows Management Instrumentation
T1047
Execution
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.
Mitigations:
Execution Prevention, Behavior Prevention on Endpoint, User Account Management, Privileged Account Management
MITRE ATT&CK reference โ
MITRE ATT&CK techniques attributed to Incransom across its recorded activity, not a finding about how SpearFin Ltd was reached.