# Qilin lists Navana Real Estate as victim

Published: 2026-07-10 · Severity: low
Canonical: https://vorant.io/reports/a7efed0e-21a3-5b42-941d-73095b563f4f/qilin-lists-navana-real-estate-as-victim

> Ransomware group Qilin added Navana Real Estate to its leak site, claiming a small data breach.

Ransomware.live tracked a new victim posting by the Qilin ransomware operation targeting Navana Real Estate. The listing indicates a limited compromise, with reported figures of zero compromised employees, one compromised user, 22 third-party employee credentials, and four external attack surface points, suggesting the breach may have stemmed from credential exposure or third-party access rather than a large-scale intrusion.

No technical indicators, exploited vulnerabilities, or detailed attack narrative were provided in the source, limiting further analysis. The entry appears to be a standard leak-site posting used by Qilin to pressure victims into payment, consistent with typical double-extortion ransomware operations.

## Mentioned in this report

- Threat actors: qilin
- Malware: Qilin

Source reporting: https://www.ransomware.live/id/TmF2YW5hIFJlYWwgRXN0YXRlQHFpbGlu

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a7efed0e-21a3-5b42-941d-73095b563f4f/qilin-lists-navana-real-estate-as-victim.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
