> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Ransomware: anubis named Prelys Courtage (FR)
- URL: https://f4n6.co.uk/security-feed/ransomware-anubis-named-prelys-courtage-fr/
- Published: 2026-07-28T09:50:07.000Z
- Updated: 2026-07-28T09:50:07.000Z
- Author: Jeff Davies
- Tags: #security-feed, anubis

## 1\. Executive summary

On 28 July 2026, the ransomware group "anubis" publicly claimed a data breach against Prelys Courtage, a major mortgage brokerage franchise in France. The actor alleges theft of client data; no encryption or ransom-demand details are provided in the source. Attribution to "anubis" is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data, and the claim is single-sourced via Ransomware.live. EMEA financial services clients should treat this as a potential data-exfiltration event affecting a French mortgage broker, with possible exposure of sensitive client financial and identity documentation.

## 2\. Regulatory framing

| Article                                                                         | Trigger (the fact in this item)                                                                                                                                                                                                                                                             | Practical impact                                                                                                                                                                                                                         |
| ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | A ransomware group has publicly claimed exfiltration of client data from a French financial-services entity (mortgage brokerage). If a client has a third-party or supply-chain relationship with Prelys Courtage, this may constitute a major ICT-related incident requiring notification. | Clients using Prelys Courtage as an ICT third-party provider must assess whether the claimed breach impacts their own operations or data, and prepare incident classification and reporting under DORA Art. 18–19 if thresholds are met. |
| DORA Art. 28: ICT third-party risk — general principles                         | Prelys Courtage is a mortgage brokerage franchise handling sensitive client financial data; firms that depend on it for mortgage-related services have a third-party exposure.                                                                                                              | Clients should review their third-party risk register for Prelys Courtage dependencies and engage contractual notification clauses (cf. DORA Art. 30).                                                                                   |

No NIS2 or UK NIS articles are specifically engaged beyond generic incident-reporting obligations, which would apply to any incident and are not distinctive to this item.

## 3\. Technical analysis & attack chain

**Attribution caveat:** The actor "anubis" has no MITRE ATT&CK profile in the verified reference data. Attribution rests solely on the Ransomware.live listing. Treat as unconfirmed.

**Source caveat:** All technical detail below is single-sourced (Ransomware.live). No independent corroboration is available. No victim statement, law-enforcement confirmation, or vendor report has been identified at time of writing.

### What is known

1. The ransomware group "anubis" posted a claim on or before 28 July 2026 naming Prelys Courtage (FR) as a victim.
2. The victim is described as "a major mortgage brokerage franchise."
3. The claimed impact is a client data breach.
4. No leak site URL, ransom note text, encryption details, initial-access vector, malware sample, or technical indicators are provided in the source material.
5. A second anubis claim against Nachlass Nord (DE), an inheritance law firm, was published in the same timeframe, suggesting an active campaign — but no shared infrastructure, TTPs, or IOCs link the two beyond actor name.

### What is NOT known

- Initial access vector (no CVE, no infostealer linkage confirmed despite Hudson Rock sponsorship banner on the listing page — this is an advertisement, not an attribution).
- Malware family, payload, or encryption behaviour.
- Data volumes, specific data types, or exfiltration method.
- C2 infrastructure, persistence mechanisms, or lateral movement.
- Whether this is a double-extortion (encrypt + leak) or pure data-theft/extortion event.

The Hudson Rock sponsorship on the Ransomware.live page is an advertisement for infostealer-intelligence tooling. It does not constitute evidence that infostealer malware was used in this specific intrusion. Do not treat it as a confirmed access vector.

## 4\. Mitigation & containment

### P1 — within 24 hours

- Determine whether your organisation has a direct or indirect relationship with Prelys Courtage (vendor, partner, data-sharing, mortgage referral pipeline). If yes, initiate incident-response triage: identify what data was shared, what systems are integrated, and whether credentials or API keys are in use.
- If any SSO, API, or VPN credentials are shared with Prelys Courtage systems, rotate them immediately.
- Notify your DPO and incident-response team; begin documenting for potential DORA Art. 18 classification.

### P2 — within 72 hours

- Contact Prelys Courtage via established third-party channels to confirm or deny the breach and request an incident impact assessment.
- Review data-flow diagrams for any PII or financial data exchanged with Prelys Courtage; prepare a data-impact assessment for affected clients.
- If the breach is confirmed and client data is implicated, prepare DORA Art. 19 major-incident reporting timelines.

### P3 — within 7 days

- Update third-party risk assessments for mortgage brokerage and legal-sector dependencies, incorporating the anubis claim and the parallel Nachlass Nord (DE) claim as threat-intelligence context.
- Review and test callback/verification procedures for mortgage-related transactions in case stolen client data is used for social-engineering or fraud follow-up.
- Monitor the Ransomware.live listing and anubis leak site for publication of stolen data.

## 5\. Indicators of compromise

No indicators of compromise available in the source material.

### Behavioural indicators

| Behaviour                                                       | Where to observe                                          | Confidence                                    |
| --------------------------------------------------------------- | --------------------------------------------------------- | --------------------------------------------- |
| Public claim of breach by "anubis" group naming Prelys Courtage | Ransomware.live listing; anubis leak site (if accessible) | Low — single-sourced, unconfirmed attribution |
| Potential publication of stolen client/mortgage data            | anubis leak site; dark-web monitoring feeds               | Low — claimed but not yet observed            |

## 6\. Detection

Insufficient indicators to author detection rules.

## 7\. Sources

- Ransomware.live, "Ransomware: anubis named Prelys Courtage (FR)", https://www.ransomware.live/id/UHJlbHlzIENvdXJ0YWdlQGFudWJpcw==, published 2026-07-28
- Ransomware.live, "Ransomware: anubis named Nachlass Nord (DE)", https://www.ransomware.live/id/TmFjaGxhc3MgTm9yZEBhbnViaXM=, published 2026-07-28 (context only — separate victim)

## 8\. Adverse Trace position

This is a low-confidence, single-sourced claim of a data breach by an actor ("anubis") with no established MITRE ATT&CK profile and no corroborating technical detail. The victim — a French mortgage brokerage — is financially relevant to EMEA clients with mortgage-referral or data-sharing dependencies. We assess the immediate technical risk as indeterminate: no IOCs, no malware samples, and no confirmed access vector are available. Clients with a direct relationship to Prelys Courtage should execute P1 actions immediately; all others should treat this as threat-intelligence context for third-party risk reviews. Adverse Trace will monitor for corroboration, IOC publication, or leak-site data drops and will re-issue this advisory if technical detail emerges.

---

[Read the original source →](https://www.ransomware.live/id/UHJlbHlzIENvdXJ0YWdlQGFudWJpcw==?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*