Threat Intelligence Brief
Curated summary with source attribution
Source: claimdepot.com
Threat Risk: High
Victim: Sweetwater Development & Management Company
Incident: Data breach of sensitive PII via a third-party vendor and a concurrent ransomware claim.
Impact: Exposure of Social Security numbers and driver’s license information, creating a high risk of identity theft.
Attacker: CoinbaseCartel and unidentified threat actors
Analysis: The incident underscores the critical risk of third-party vendor dependencies, as the primary leak occurred at Ultimus Funds Solutions rather than within Sweetwater’s internal systems. The simultaneous data claim by the CoinbaseCartel ransomware group suggests a potential coordinated campaign or separate breach targeting the same corporate ecosystem.
Recommendations: Conduct rigorous security audits of third-party vendors handling sensitive PII.; Implement data minimization strategies to limit the amount of sensitive information shared with partners.; Establish a coordinated incident response plan that spans across all related corporate entities.
Source: ClaimDepot
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-08-19 00:06 UTC
Ransomware attack on third-party vendor Ultimus Funds Solutions resulting in data exfiltration. Exposure of sensitive PII, including Social Security numbers and driver’s licenses. The breach originated from a compromise of Ultimus Funds Solutions, a vendor used by Sweetwater, rather than Sweetwater’s own network. This incident underscores the persistent risk of supply chain vulnerabilities where third-party access becomes a primary attack vector. The threat actor utilized ransomware to exfiltrate high-value personally identifiable information.
Corroborating source: claimdepot.com