On 3 September 2026, the extortion group Settra added a listing for DiaSorin S.p.A. (DiaSorin) to its dark-web leak site, threatening to publish files it claims to have taken from the company's systems. DiaSorin is an Italian manufacturer of in-vitro diagnostic technologies used by hospitals, laboratories and healthcare providers across dozens of countries. As of publication, DiaSorin has issued no statement confirming that its systems were encrypted, that data was exfiltrated, or that any patient, employee or research record was taken. The leak-site listing is, for now, the only public evidence that anything happened at all.
That gap between claim and confirmation is wide, and it is also the point. Settra is a human-operated extortion group first observed in June 2026 that has already claimed roughly four dozen victims across manufacturing, technology, professional services and healthcare-adjacent sectors in at least eighteen countries. Researchers tracking the group describe its best-documented behaviour as data theft used as leverage rather than the encryption that made earlier ransomware families notorious. Across Settra's confirmed victims, the strongest evidence for how the group gets in points to compromised credentials, many traced back to infostealer malware logs already circulating on criminal marketplaces. Phishing appears far less often in the group's observed pattern.
That mechanism matters because it removes the moment most companies train employees to catch. There is reportedly no help-desk call to hang up on, no urgent request from a fake finance chief, no cloned voice asking someone to approve a reset. A username and password harvested months earlier by unrelated malware, sold or traded in bulk on a criminal forum, is typed into a login page and accepted, because it is, technically, a valid credential. Researchers studying Settra's known intrusions estimate an average of around three weeks between that initial entry and public disclosure, a window the group appears to use for locating and copying data before any extortion demand is made.
If the claim against DiaSorin is confirmed, the exposure sits at an uncomfortable intersection. A diagnostics manufacturer of this size holds assay development data, regulatory submissions, manufacturing records and the operational details of laboratory and hospital partners across international markets, any of which could be valuable well beyond Settra itself. None of that requires a single employee to make a mistake in the moment it happens. It requires only that a credential minted long ago still works when someone, somewhere, types it in.
The defences this exposes are not the ones organisations usually reach for first. Multi-factor authentication stops a large share of credential-stuffing attempts, but credentials harvested by infostealers are frequently captured alongside active session tokens and one-time codes from the same infected device, and a login using a technically valid account does not, on its own, look like an intrusion to most monitoring tools.
This is exactly the layer GoFirm sits on. A valid login only gets an attacker through the door; every high-impact action after that, a bulk data export, a new administrative account, a reach into a connected partner system, still has to clear a separate boundary. Before that action executes, GoFirm sends a real-time push notification to the named authority who owns that access, on the device already registered to them, and requires a biometric confirmation. No confirmation, no export.
An infostealer log has no fingerprint and no face. It cannot answer a push notification on a phone it does not hold, however valid the password sitting behind it. The execution boundary holds regardless of how the credential was obtained.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Roka, F.N. 2026. DiaSorin's ransomware claim exposes a dangerous information vacuum. Opinion Nigeria, 4 September 2026.
2. Montini, H. and Abdelaziz, M. 2026. Settra ransomware: emerging double-extortion threat. Proven Data, 8 July 2026.
3. DeXpose. 2026. Settra ransomware attack on DiaSorin S.p.A. DeXpose, 3 September 2026.
Back to Blog
Case Studies·3 min read
Settra says it breached DiaSorin. It didn't need a phone call to do it.
By GoFirm
