Ransom! La Financi,ère d’Orion (finorion) (JUL-2026)

Ransom! La Financi,ère d’Orion (finorion) (JUL-2026)
Nova ransomware actors claimed to target La Financi,ère d’Orion (finorion) in France, allegedly exfiltrating around 20GB of client documents and financial information including “ERES.pdf”. The threat actor reportedly provided tree/sample stolen data to the company when contacted, seeking support-driven engagement. #France

Incident Details

  • Victim: La Financi,ère d’Orion (finorion)
  • Sector: Financial Services
  • Country: FR
  • Actor: nova
  • Source: http://pifk3xu3vad6cuxsjll4qjomyaaaoyvnyqppro75pazadzctrrvpdnyd.onion/la-financiere-d-orion-finorion
  • Discovered: 2026-07-21T18:09:05.710193+00:00
  • Published: 2026-07-21T18:07:53.434034+00:00

Information

  • Since 2009, the organization has been helping to create a privileged relationship between wealth professionals and their clients.
  • Its experience allows it to deploy innovative and coherent financial engineering solutions tailored to clients’ aspirations and objectives.
  • Nova claims to possess 20 GB of client documents and company financial information.
  • Examples of the stolen data include files such as “convestion ERES.pdf” and other confidential materials.
  • The attackers state that the stolen data includes sensitive secrets and invite contact for more details.
  • They also claim to provide a tree and samples of the stolen data once the company contacts their support department.

Disclaimer: This post is based on public claims made by the ransomware group "nova". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live