1. Executive summary
On 2026-09-16 the ransomware leak-site aggregator ransomware.live indexed a listing in which the group "qilin" names Thema Foundries, a French manufacturer (www.thema-foundries.com), as a victim. The listing contains no technical detail: no initial-access vector, no malware family, no exfiltration volume, no proof-of-data sample, and no indicators. The same aggregator shows qilin naming several EMEA financial-sector entities in the same corpus — Philippe Hottinguer Finance (FR), TQ Financial Services, DAB Investments (GB) — alongside German and UK victims, which is the only reason this item is relevant to our client base. There is no CVE, no CVSS score, no EPSS value and no CISA KEV entry associated with this item in the verified reference data, and no exploitation state can be asserted. Bottom line for EMEA financial services: no actionable technical exposure today; treat this as a low-confidence sector-targeting signal and a prompt to verify leak-site monitoring coverage, not as an incident affecting your estate.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 18: classification of ICT-related incidents and cyber threats | The same actor's leak-site listings in the supplied corpus name identifiable EMEA financial-sector entities (Philippe Hottinguer Finance FR, TQ Financial Services, DAB Investments GB), not only industrial victims | If your entity is subsequently named by this actor, you must run the Art. 18 classification process — including whether the event qualifies as a significant cyber threat — rather than treating a leak-site post as unactionable noise |
No other article in the regulatory reference is engaged by the facts of this item. The victim named in the primary listing is a French industrial manufacturer, not a financial entity, and the source states no client impact, no third-party provider involvement, and no incident at any regulated entity. DORA Art. 17, 19, 24, 28, 29 and 30 and NIS2 Art. 21(2)(d) and Art. 23 would only be triggered by facts (a confirmed incident at your entity, a named ICT third-party dependency, a major-incident threshold breach) that this item does not contain.
3. Technical analysis & attack chain
Confirmed steps (all that the source supports)
- The actor "qilin" posted a victim entry naming Thema Foundries (FR) to its leak site.
- ransomware.live indexed that entry on 2026-09-16T15:05:26Z, recording group, victim name, country (FR) and website (www.thema-foundries.com).
- The aggregator page renders placeholder sections for DNS records and a leak screenshot; in the supplied content both are empty.
That is the entirety of the confirmed chain. No initial-access vector, exploited component, CVE, payload, malware capability, persistence mechanism, privilege-escalation path, command-and-control channel, lateral-movement technique, exfiltration method or impact statement is present in the source material. Any such detail would have to be imported from general knowledge of this actor and is deliberately omitted here.
What the listing does and does not establish. A leak-site entry is an unverified claim by the operator. The source does not confirm that encryption occurred, that data was exfiltrated, what volume or category of data is claimed, or whether the victim has engaged with the actor. The item title classifies the event as "Ransomware"; the underlying listing content does not independently substantiate encryption or data theft, and this advisory does not assert either.
Corpus pattern (single-sourced, low confidence). The related sources are all ransomware.live victim entries for the same group, spanning FR, DE and GB, and include financial-services names. This establishes only that the aggregator has indexed multiple qilin listings across EMEA in the same window — it does not establish a coordinated campaign against financial services, a common intrusion vector, or any link between the victims. All of it rests on one aggregator; verify before treating the pattern as targeting intelligence.
Not evidence. The aggregator page carries a sponsor banner for Hudson Rock referencing infostealer infections as a precursor to ransomware. This is advertising inventory on the page, not a finding about Thema Foundries or any other victim, and must not be read as an infostealer link in this case.
4. Mitigation & containment
No technical containment is possible against this item — there is no artefact to block, no version to patch, and no vendor fix to apply. The actions below are monitoring and readiness controls proportionate to a low-confidence sector-targeting signal.
P1 — within 24 hours
- Confirm your leak-site monitoring covers the qilin actor feed and that alerts route to the incident-management function, not only to threat intel. A leak-site post naming your entity is the first trigger for the DORA Art. 18 classification process.
- Verify that your incident-management runbook has a defined path for "named on a ransomware leak site" as an event type, including who validates the claim before it is escalated.
P2 — within 72 hours
- Re-validate that your external attack-surface inventory includes all public-facing domains and subsidiaries, so that a future listing can be matched to a real asset within minutes rather than hours.
- Confirm offline, immutable backup integrity for at least one restore point per critical system, and test a restore. This is the control that determines whether a future extortion event is survivable; it is not a response to this listing.
P3 — within 7 days
- Review third-party and supplier exposure: if any supplier in your register is named in a qilin listing, treat it as a trigger for your third-party risk process rather than a standalone alert.
- Brief finance and treasury staff on callback verification for any payment-instruction change request, since extortion actors frequently follow a leak-site post with secondary fraud approaches. This is a process control, not a technical one.
5. Indicators of compromise
No indicators of compromise available in the source material. The source contains no hashes, domains, IP addresses, file paths, registry keys, mutexes, or command-line artefacts.
The only observable in the source is the publication event itself, captured below as a behavioural indicator.
Behavioural indicators
| behaviour | where to observe | confidence |
|---|---|---|
| Victim name "Thema Foundries" published on the qilin leak site, indexed by ransomware.live on 2026-09-16T15:05:26Z | Ransomware leak-site monitoring / dark web monitoring feed | High — directly observed in the source |
| Repeated qilin victim listings naming EMEA entities across FR, DE and GB, including financial-sector names, within the same corpus window | Ransomware leak-site monitoring, aggregated over time | Low — single-sourced to one aggregator; pattern not corroborated |
No copyable indicator block is provided: the source yields no machine-pivotable atomic indicators.
6. Detection
Insufficient indicators to author detection rules.
The source provides no distinctive strings, command-line flags, mutex names, scheduled-task or service names, file names or paths, registry keys, ransom-note text, or hard-coded values. A rule built on the actor name, the victim name, or the aggregator URL would detect reporting about the event rather than the threat itself, and is not emitted.
7. Sources
- ransomware.live — Ransomware: qilin named Thema Foundries (FR) — https://www.ransomware.live/id/VGhlbWEgRm91bmRyaWVzQHFpbGlu — published 2026-09-16
- ransomware.live — Ransomware: qilin named Philippe Hottinguer Finance (FR) — https://www.ransomware.live/id/UGhpbGlwcGUgSG90dGluZ3VlciBGaW5hbmNlQHFpbGlu — undated (retrieved 2026-09-16)
- ransomware.live — Ransomware: qilin named INVENSITY (DE) — https://www.ransomware.live/id/SU5WRU5TSVRZQHFpbGlu — undated (retrieved 2026-09-16)
- ransomware.live — Ransomware: qilin named TQ Financial Services — https://www.ransomware.live/id/VFEgRmluYW5jaWFsIFNlcnZpY2VzQHFpbGlu — undated (retrieved 2026-09-16)
- ransomware.live — Ransomware: qilin named InVentry (GB) — https://www.ransomware.live/id/SW5WZW50cnlAcWlsaW4= — undated (retrieved 2026-09-16)
- ransomware.live — Ransomware: qilin named DAB Investments (GB) — https://www.ransomware.live/id/REFCIEludmVzdG1lbnRzQHFpbGlu — undated (retrieved 2026-09-16)
- ransomware.live — Ransomware: qilin named Savills France (FR) — https://www.ransomware.live/id/U2F2aWxscyBGcmFuY2VAcWlsaW4= — undated (retrieved 2026-09-16)
8. Adverse Trace position
We assess no direct technical risk to EMEA financial services clients from this item. The verified reference data contains no CVE, no CVSS score, no EPSS value and no CISA KEV entry for it, so no severity rating can be assigned and none is asserted; the victim is a French industrial manufacturer with no stated connection to any regulated entity. Attribution to "qilin" is unconfirmed: the actor has no MITRE ATT&CK profile in our verified reference data, and the only source is a single leak-site aggregator whose entries are operator claims, not validated findings — treat the entire item as single-sourced and verify before any enforcement or escalation decision. The one element worth retaining is the corpus pattern of the same actor naming EMEA financial-sector entities, which is likewise single-sourced and low confidence, but is sufficient to justify confirming leak-site monitoring coverage and the Art. 18 classification path. We will continue to monitor the qilin feed for listings naming our clients or their critical suppliers, and will re-issue with technical detail only if a corroborating source provides intrusion artefacts.
Published via PulseTrace — Adverse Trace threat intelligence.