Ransomware Group Spacebears Claims Attack on StellarRAD Systems
A criminal group has listed the US telecoms-software firm on its dark-web pressure site, alleging stolen employee data and financial records. The company has not confirmed any incident.

Key points
- Ransomware group Spacebears listed StellarRAD Systems, a US-based telecoms-software company, on its dark-web extortion site on 29 July 2026.
- The group claims to have stolen internal documents including employee and client personal information and financial records.
- StellarRAD Systems has not publicly confirmed any breach, and the claim could not be independently verified at the time of publication.
- Ransomware leak-site listings are sometimes exaggerated or entirely false, written by criminals to pressure companies into paying.
- Monitoring service Ransomware.live first observed the listing on 29 July 2026.
A criminal ransomware gang called Spacebears has named StellarRAD Systems on its dark-web leak site, meaning a site run by the group on a hidden part of the internet where they publicly shame companies they claim to have attacked. The tactic is designed to pressure victims into paying a ransom by threatening to release stolen data.
StellarRAD Systems, which has operated since 1981 and sells software tools to telecommunications providers worldwide, has issued no public statement about any incident. No public confirmation exists, and the claim remains unverified. Spacebears isn't a name we've tracked long: this is the first time Threat Vectr has covered the group, and it sits alongside sixteen ransomware listings we've reported in the past 30 days.
What is Spacebears actually claiming?
The group claims to have taken categories of internal data from StellarRAD Systems. According to its post, that includes personal information belonging to employees and clients, along with financial documents. Ransomware.live, a service that tracks these listings automatically, flagged the entry on 29 July 2026.
The specifics come entirely from the criminals themselves. Their posts are promotional material written to frighten the target, not verified reporting. Spacebears is a ransomware group, meaning a criminal organisation that breaks into company networks, steals data and then encrypts the victim's own systems until a payment is made. The stolen-data listing adds a second layer of pressure: pay up, or the files go public.
Should StellarRAD customers or staff be worried right now?
No breach has been confirmed, so panic isn't warranted. Caution costs nothing, though, and the situation is unresolved.
If you work for StellarRAD Systems or use its products, a few steps apply until there's clarity:
- Watch for phishing emails, where criminals send fake messages pretending to be your employer or a security service, using news of a claimed breach as bait to steal a password.
- Don't reuse passwords across accounts. If your work login matches one you use elsewhere, change the other accounts now.
- Be suspicious of any unexpected phone call offering "breach compensation" or asking you to verify personal details. Legitimate companies don't call out of the blue requesting that.
- If you receive an email claiming to be from StellarRAD about the incident, verify it through a phone number you already hold before clicking anything.
Leak-site listings appear days or weeks before any company confirms what happened, and some never lead to a confirmed incident at all. Watchful, not panicked, is the right posture here.



