~/f4n6 $ grep -r "Ransomware: incransom named www.lichtvision.com (GB)" ./investigations/ --include="*.md"

Ransomware: incransom named www.lichtvision.com (GB)

Jeff Davies 31 Aug 2026 4 min read

1. Executive summary

On 31 August 2026, the ransomware group operating under the name "incransom" listed the UK-registered lighting design firm Lichtvision (www.lichtvision.com) as a victim on its leak site. The listing is a claim of compromise and data theft; no technical detail on initial access, malware, or exfiltrated content is available in the source material, and the claim has not been corroborated by the victim or any second source. Attribution to the "incransom" brand is unconfirmed: the actor has no MITRE ATT&CK profile in our verified reference data, and the listing itself is operator-published. For EMEA financial services clients, the direct risk is low — Lichtvision is a 40-person architectural lighting design practice, not a financial-sector entity — but the listing is relevant to third-party risk screening where Lichtvision or its studios appear in a supply chain.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The item is a single-sourced, uncorroborated leak-site listing with no confirmed incident detail, no financial-sector victim, and no established third-party relationship to a client. A generic "an incident occurred somewhere" trigger does not engage DORA Art. 17–19, Art. 24, Art. 28–30, NIS2 Art. 21(2)(d), Art. 23, or UK NIS 2018 duties. Clients should re-assess only if they hold a contractual relationship with Lichtvision that makes it an ICT third-party provider in scope — at that point DORA Art. 28 (ICT third-party risk — general principles) and, where applicable, DORA Art. 30 (key contractual provisions with ICT third-party providers) would be engaged by that specific relationship, not by this listing alone.

3. Technical analysis & attack chain

No confirmed attack chain can be reconstructed from the source material. The ransomware.live entry contains only the operator-published claim: group name "incransom", victim domain www.lichtvision.com, country code GB, and a victim description drawn from public business information. The page references a leak screenshot and DNS records for the victim domain, but no screenshot content, DNS values, sample names, encrypted file extensions, ransom-note text, or exfiltrated-data samples are present in the material provided.

What is and is not established:

  1. Claimed compromise (single-sourced). The incransom brand claims to have compromised Lichtvision. This is the only source; it is operator-published and self-interested. No victim statement, law-enforcement confirmation, or second-vendor corroboration exists in the provided material.
  2. Data-theft/extortion model (inferred from listing type). Leak-site victim listings of this kind are typically associated with data theft and extortion. The source does not state whether encryption was deployed, what data was taken, or whether a ransom demand was made. Do not characterise this as confirmed ransomware deployment or confirmed exfiltration — only the claim is confirmed.
  3. Attribution (unconfirmed). "incransom" has no MITRE ATT&CK profile in our verified reference data. Treat the group identity as a brand name on a leak site, not a validated threat actor. No TTPs, tooling, or infrastructure for this actor are available to us from the reference data or the source.

Confidence caveat: every substantive claim in this section rests on a single source (the ransomware.live index of the incransom leak site). Verify before enforcement — do not treat the compromise as established fact in client communications or incident-response decisions.

4. Mitigation & containment

There are no technical indicators to drive containment, so actions here are screening and process actions, not host-level response.

P1 — within 24 hours

  • Check the victim domain www.lichtvision.com and the Lichtvision corporate identity (studios in major cities, per the source) against your third-party and client registries. If a relationship exists, open a supplier-incident enquiry with the entity and record the enquiry.
  • If Lichtvision is a contracted ICT third-party provider: request a written incident status statement and assess whether any of your data or interconnections are affected. Do not assume compromise on the basis of the listing alone.

P2 — within 72 hours

  • For any identified relationship, review data shared with Lichtvision (design files, building/facility documentation, staff or site contact data) and determine exposure if the theft claim is true.
  • Add the victim domain to watchlists for monitoring of any follow-on publication of stolen data; do not block the domain — it is the victim's, not the attacker's.

P3 — within 7 days

  • Re-verify the listing status on the leak-site index for evidence of posted data or claim retraction; update the third-party risk file accordingly.
  • If no relationship exists, close the screening with a no-impact record.

5. Indicators of compromise

No indicators of compromise available in the source material. The victim domain www.lichtvision.com is victim infrastructure, not an attacker indicator, and must not be treated as an IOC. The source references DNS records and a leak screenshot for the victim domain but provides no values from either.

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live — "Victim: www.lichtvision.com – incransom" — https://www.ransomware.live/id/d3d3LmxpY2h0dmlzaW9uLmNvbUBpbmNyYW5zb20= — 2026-08-31 (single source; operator-published claim indexed by ransomware.live)

8. Adverse Trace position

Low severity for EMEA financial services clients. This is a single-sourced, uncorroborated leak-site listing against a UK architectural lighting design firm with no established connection to the financial sector in the available material; the "incransom" attribution carries no MITRE ATT&CK profile in our verified reference data and must be treated as unconfirmed. We are not raising a client-wide alert. We will continue to monitor the listing for posted stolen data, claim retraction, or second-source corroboration, and we will re-issue if a client relationship with Lichtvision is identified or if technical detail on the actor emerges. Clients should treat this as a third-party screening input only, not as an established incident.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies