~/f4n6 $ grep -r "Ransomware: BrainCipher named hoyletanner.com (GB)" ./investigations/ --include="*.md"

Ransomware: BrainCipher named hoyletanner.com (GB)

Jeff Davies 17 Sep 2026 3 min read

1. Executive summary

On 17 September 2026, the ransomware operator BrainCipher listed the UK engineering consultancy Hoyle Tanner (hoyletanner.com) as a victim on its leak site. The listing is the sole source for this item: no technical detail on intrusion method, malware, or data volume is available, and the claim of a successful breach is unverified. BrainCipher has no MITRE ATT&CK profile in our reference data, so the attribution rests entirely on the operator's own leak-site post. For EMEA financial services the direct risk is low unless a client has a commercial or supply-chain relationship with Hoyle Tanner; the listing's value is as a prompt to check third-party exposure.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The item is an uncorroborated leak-site listing with no confirmed incident at a regulated entity, no verified data compromise, and no identified ICT service dependency. If a client confirms a relationship with the victim and a data or service impact, DORA Art. 18 (classification of ICT-related incidents and cyber threats) and Art. 19 (reporting of major ICT-related incidents to competent authorities) would become relevant at that point, but the trigger facts do not exist yet.

3. Technical analysis & attack chain

No attack chain can be reconstructed from the source material. The ransomware.live entry records only the group name (BrainCipher), the victim domain (hoyletanner.com), the country code (GB), and the existence of a leak-site listing. The page's description fields, DNS records section, and leak screenshot carry no substantive content in the material supplied, and the entry's own summary is marked "N/A". There is no information on initial access, exploited vulnerabilities, malware capabilities, persistence, command-and-control, lateral movement, or exfiltration volume.

Two caveats on this item. First, the attribution to BrainCipher is single-sourced and unconfirmed: the operator has no MITRE ATT&CK profile in our verified reference data, and the only evidence linking the name to this victim is the leak-site post itself. Second, the listing is a claim, not evidence. Ransomware operators list organisations for extortion leverage, occasionally in error, and sometimes without having encrypted anything. Treat the compromise of Hoyle Tanner as alleged until the victim confirms or independent telemetry corroborates it.

4. Mitigation & containment

P1 (within 24h):

  • Check procurement, vendor-management, and payment records for any current or recent relationship with Hoyle Tanner or the hoyletanner.com domain. If a relationship exists, contact the firm through a known-good channel and ask whether your shared data or integrations are affected.
  • Search mail gateway and proxy logs for hoyletanner.com domain resolution and mail flow over the past 90 days to establish whether any operational dependency exists that was not already known.

P2 (within 72h):

  • If a vendor relationship is confirmed, review what data the firm holds on your behalf and whether the listing implies exposure of client-confidential material; escalate to your incident management process under DORA Art. 17 if a data impact is plausible.
  • If no relationship exists, close the item with a record of the checks performed; no further containment applies to your estate.

P3 (within 7 days):

  • Re-check the leak site entry for follow-up posts (sample data, deadlines, or a retraction), since operators frequently update listings in the days after the initial post.
  • Fold the finding into third-party risk reviews: if Hoyle Tanner sits in a supplier tier you monitor, record the listing against that supplier's risk file for the next assessment cycle.

5. Indicators of compromise

No indicators of compromise available in the source material. The entry contains no hashes, network indicators, file paths, or behavioural detail. The victim domain hoyletanner.com is the victim's legitimate domain, not a malicious indicator, and must not be blocked.

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live, "Victim: hoyletanner.com – BrainCipher", https://www.ransomware.live/id/aG95bGV0YW5uZXIuY29tQEJyYWluQ2lwaGVy, 17 September 2026

8. Adverse Trace position

We assess this item as low severity for EMEA financial services clients: it is a single-sourced, uncorroborated leak-site listing against a UK engineering consultancy with no confirmed breach, no technical detail, and no demonstrated link to any financial institution. The BrainCipher attribution is unconfirmed in our reference data and should not be treated as established. We will monitor the listing for corroborating reporting, victim confirmation, or sample data releases, and we will reissue this advisory if any of those appear or if a client identifies an active dependency on the victim.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies