Ransomware Group Spacebears Claims Attack on StellarRAD Systems

A criminal group has listed the US telecoms-software firm on its dark-web pressure site, alleging stolen employee data, financial records and client information. The company has not confirmed any incident.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server room with rows of humming rack-mounted servers, cold blue LEDs, tangled ethernet ca
Share

Key points

  • Ransomware group Spacebears listed StellarRAD Systems, a US-based telecoms-software company, on its dark-web extortion site on 2026-07-29.
  • The group claims to have stolen internal documents including employee and client personal information, financial records and engineering files.
  • StellarRAD Systems has not publicly confirmed any breach, and the claim could not be independently verified at the time of publication.
  • Ransomware leak-site listings are sometimes exaggerated or entirely false, and are written by criminals to pressure companies into paying.
  • Monitoring service Ransomware.live first observed the listing on 2026-07-29.

A criminal ransomware gang called Spacebears has named StellarRAD Systems on its dark-web leak site, meaning a site run by the group on a hidden part of the internet where they publicly shame companies they claim to have attacked. The tactic is designed to pressure victims into paying a ransom by threatening to release stolen data.

StellarRAD Systems, which has operated since 1981 and sells software tools to telecommunications providers worldwide, has not issued any public statement about an incident. Threat Vectr could find no public confirmation, and the claim remains unverified.

What is Spacebears actually claiming?

The group claims to have taken several categories of internal data from StellarRAD Systems. According to the group's post, that includes personal information belonging to employees and clients, financial documents and engineering project files. Ransomware.live, a service that tracks these kinds of listings automatically, flagged the entry on 29 July 2026.

That is roughly the shape of what the attackers say they hold. Beyond that, the specifics come entirely from the criminals themselves, whose posts are promotional material written to frighten the target, not verified reporting.

Spacebears is a ransomware group, meaning a criminal organisation that breaks into company networks, steals files, then encrypts or locks the victim's own systems until a payment is made. The stolen-data listing is a second layer of pressure: pay up, or the files go public.

Should StellarRAD customers or staff be worried right now?

Unclear, because no breach has been confirmed. That said, caution costs nothing while the situation is unresolved.

If you work for StellarRAD Systems or use its products, a few sensible steps apply until there is clarity:

  • Watch for phishing emails, where criminals send fake messages pretending to be your employer or a security service, using news of a claimed breach as bait to trick you into clicking a link or handing over a password.
  • Do not reuse passwords across accounts. If your work login matches a password you use elsewhere, change the other accounts now.
  • Be suspicious of any unexpected phone call offering "breach compensation" or asking you to verify personal details. Legitimate companies do not call out of the blue asking for that information.
  • If you receive an email claiming to be from StellarRAD about the incident, verify it through a phone number you already know before clicking anything.

Ransomware leak-site listings appear days or even weeks before any company confirms what happened, and some never lead to a confirmed incident at all. The sensible position is watchful, not panicked.

© 2026 Threat Vectr