1. Executive summary
On 2026-07-23, the Qilin ransomware group publicly named WellPerf (UK, www.wellperf.com) as a victim on its leak site. Attribution to the Qilin group is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data, and the claim rests solely on the ransomware.live listing. The source material contains no technical detail on initial access, malware payload, or attack chain; it indicates 3 compromised users, 1 third-party employee credential, and 2 external attack-surface entries associated with the victim. EMEA financial services clients should treat this as a low-fidelity claim requiring validation before any enforcement action, and should assess whether WellPerf appears in their supply chain or third-party vendor registers.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 28: ICT third-party risk — general principles | The victim listing references 1 third-party employee credential and 2 external attack-surface entries, indicating potential supply-chain exposure. | If WellPerf is an ICT third-party provider to a DORA-regulated entity, clients must assess whether this incident affects the services received and review contractual incident-notification obligations. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | A named ransomware group has publicly claimed a UK organisation as a victim, constituting a cyber threat event requiring classification. | Clients with any relationship to WellPerf must classify the potential impact under their ICT incident taxonomy and determine whether escalation to a major incident is warranted. |
No NIS2 or UK NIS article is specifically engaged beyond generic incident-management duties, as the source provides no detail on critical-service disruption or cross-border impact.
3. Technical analysis & attack chain
No technical attack-chain detail is available in the source material. The ransomware.live listing for WellPerf contains only victim-identification metadata and high-level compromise indicators. No CVE, initial-access vector, malware sample, persistence mechanism, C2 infrastructure, or lateral-movement detail is provided.
What the source does state
- Actor: Qilin (attribution unconfirmed — no MITRE ATT&CK profile in verified reference data; single-sourced to ransomware.live).
- Victim: WellPerf, UK-based, domain www.wellperf.com.
- Compromised employees: 0
- Compromised users: 3
- Third-party employee credentials: 1
- External attack surface entries: 2
- DNS records: Referenced but not enumerated in the source.
- Leak screenshot: Referenced but not provided.
Context from related Qilin listings (same date window): Qilin has also claimed Sisint (PT), Max Fordham (GB), TQ Financial Services, Eurodefi (MA), Gsma (GB), and Sitmatic (DE) on ransomware.live. This suggests an active campaign, but no shared TTPs, IOCs, or technical commonalities are documented in the source material. All claims are single-sourced to ransomware.live.
Confidence caveat: All claims in this section are single-sourced to ransomware.live. No independent corroboration is available. Verify before enforcement.
4. Mitigation & containment
P1 — Within 24 hours
- Determine whether WellPerf (www.wellperf.com) exists in your organisation's third-party vendor register, supplier database, or ICT service-provider inventory. If found, escalate to the relevant relationship owner and request a formal incident-status statement from WellPerf.
- Search email, DNS, and web-proxy logs for any communication with or traffic to/from www.wellperf.com domains and subdomains. Block at the web proxy if a confirmed supplier relationship exists and the domain is not required for business operations.
- Check identity and access management systems for any user accounts or service principals associated with WellPerf domains. Suspend pending review if anomalous activity is observed.
P2 — Within 72 hours
- If WellPerf is a confirmed third-party provider, initiate a preliminary assessment of ICT concentration risk (DORA Art. 29) if multiple business lines depend on it.
- Review the 3 compromised users and 1 third-party employee credential referenced in the source — if WellPerf is a supplier, request confirmation of whether any shared credentials or integrated accounts are affected. Force credential rotation for any shared/integrated accounts.
- Monitor the ransomware.live listing and Qilin leak site for posted data or additional technical disclosures.
P3 — Within 7 days
- If WellPerf is in the supply chain, document the incident assessment and any actions taken in the ICT incident register per DORA Art. 17.
- Review external attack-surface monitoring for your own organisation to identify analogous exposure (compromised user credentials, third-party credential leaks) using the same categories referenced in this listing.
5. Indicators of compromise
No atomic indicators of compromise (IPs, domains, hashes, file paths, or URLs) are present in the source material beyond the victim domain itself, which is a legitimate corporate domain and not a malicious indicator.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| 3 compromised users associated with victim organisation | Infostealer intelligence platforms (Hudson Rock cited as sponsor) | Low — single-sourced to ransomware.live; no user identities provided |
| 1 third-party employee credential exposed | Infostealer intelligence platforms | Low — single-sourced; no credential details provided |
| 2 external attack-surface entries | Attack-surface management tooling | Low — single-sourced; no specific assets enumerated |
6. Detection
Insufficient indicators to author detection rules. The source material contains no malware strings, file hashes, command-line artefacts, registry keys, mutex names, network indicators, or behavioural log signatures associated with the Qilin payload or this specific incident.
7. Sources
- Ransomware.live, "Ransomware: qilin named WellPerf (GB)", https://www.ransomware.live/id/V2VsbFBlcmZAcWlsaW4=, 2026-07-23
- Ransomware.live, "Ransomware: qilin named Sisint (PT)", https://www.ransomware.live/id/U2lzaW50QHFpbGlu, (context)
- Ransomware.live, "Ransomware: qilin named Max Fordham (GB)", https://www.ransomware.live/id/TWF4IEZvcmRoYW1AcWlsaW4=, (context)
- Ransomware.live, "Ransomware: qilin named TQ Financial Services", https://www.ransomware.live/id/VFEgRmluYW5jaWFsIFNlcnZpY2VzQHFpbGlu, (context)
- Ransomware.live, "Ransomware: qilin named Eurodefi (MA)", https://www.ransomware.live/id/RXVyb2RlZmlAcWlsaW4=, (context)
- Ransomware.live, "Ransomware: qilin named Gsma (GB)", https://www.ransomware.live/id/R3NtYUBxaWxpbg==, (context)
- Ransomware.live, "Ransomware: qilin named Sitmatic (DE)", https://www.ransomware.live/id/U2l0bWF0aWNAcWlsaW4=, (context)
8. Adverse Trace position
This is a low-fidelity ransomware claim. The Qilin attribution is unconfirmed (no MITRE ATT&CK profile; single-sourced to ransomware.live), and the source provides no technical attack-chain detail, IOCs, or malware artefacts. The practical risk to EMEA financial services clients is contingent on whether WellPerf sits in their supply chain — if it does, the third-party credential exposure and compromised-user counts warrant immediate supplier engagement and credential rotation. If it does not, no action beyond situational awareness is required. Adverse Trace will monitor for corroborating technical reporting, leaked data, or additional Qilin campaign disclosures and will update this advisory if substantive IOCs or TTPs emerge. All claims in this advisory are single-sourced; verify before enforcement.
Published via PulseTrace — Adverse Trace threat intelligence.