1. Executive summary
On 28 July 2026, the ransomware group "anubis" publicly claimed a data breach against Prelys Courtage, a major mortgage brokerage franchise in France. The actor alleges theft of client data; no encryption or ransom-demand details are provided in the source. Attribution to "anubis" is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data, and the claim is single-sourced via Ransomware.live. EMEA financial services clients should treat this as a potential data-exfiltration event affecting a French mortgage broker, with possible exposure of sensitive client financial and identity documentation.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | A ransomware group has publicly claimed exfiltration of client data from a French financial-services entity (mortgage brokerage). If a client has a third-party or supply-chain relationship with Prelys Courtage, this may constitute a major ICT-related incident requiring notification. | Clients using Prelys Courtage as an ICT third-party provider must assess whether the claimed breach impacts their own operations or data, and prepare incident classification and reporting under DORA Art. 18–19 if thresholds are met. |
| DORA Art. 28: ICT third-party risk — general principles | Prelys Courtage is a mortgage brokerage franchise handling sensitive client financial data; firms that depend on it for mortgage-related services have a third-party exposure. | Clients should review their third-party risk register for Prelys Courtage dependencies and engage contractual notification clauses (cf. DORA Art. 30). |
No NIS2 or UK NIS articles are specifically engaged beyond generic incident-reporting obligations, which would apply to any incident and are not distinctive to this item.
3. Technical analysis & attack chain
Attribution caveat: The actor "anubis" has no MITRE ATT&CK profile in the verified reference data. Attribution rests solely on the Ransomware.live listing. Treat as unconfirmed.
Source caveat: All technical detail below is single-sourced (Ransomware.live). No independent corroboration is available. No victim statement, law-enforcement confirmation, or vendor report has been identified at time of writing.
What is known
- The ransomware group "anubis" posted a claim on or before 28 July 2026 naming Prelys Courtage (FR) as a victim.
- The victim is described as "a major mortgage brokerage franchise."
- The claimed impact is a client data breach.
- No leak site URL, ransom note text, encryption details, initial-access vector, malware sample, or technical indicators are provided in the source material.
- A second anubis claim against Nachlass Nord (DE), an inheritance law firm, was published in the same timeframe, suggesting an active campaign — but no shared infrastructure, TTPs, or IOCs link the two beyond actor name.
What is NOT known
- Initial access vector (no CVE, no infostealer linkage confirmed despite Hudson Rock sponsorship banner on the listing page — this is an advertisement, not an attribution).
- Malware family, payload, or encryption behaviour.
- Data volumes, specific data types, or exfiltration method.
- C2 infrastructure, persistence mechanisms, or lateral movement.
- Whether this is a double-extortion (encrypt + leak) or pure data-theft/extortion event.
The Hudson Rock sponsorship on the Ransomware.live page is an advertisement for infostealer-intelligence tooling. It does not constitute evidence that infostealer malware was used in this specific intrusion. Do not treat it as a confirmed access vector.
4. Mitigation & containment
P1 — within 24 hours
- Determine whether your organisation has a direct or indirect relationship with Prelys Courtage (vendor, partner, data-sharing, mortgage referral pipeline). If yes, initiate incident-response triage: identify what data was shared, what systems are integrated, and whether credentials or API keys are in use.
- If any SSO, API, or VPN credentials are shared with Prelys Courtage systems, rotate them immediately.
- Notify your DPO and incident-response team; begin documenting for potential DORA Art. 18 classification.
P2 — within 72 hours
- Contact Prelys Courtage via established third-party channels to confirm or deny the breach and request an incident impact assessment.
- Review data-flow diagrams for any PII or financial data exchanged with Prelys Courtage; prepare a data-impact assessment for affected clients.
- If the breach is confirmed and client data is implicated, prepare DORA Art. 19 major-incident reporting timelines.
P3 — within 7 days
- Update third-party risk assessments for mortgage brokerage and legal-sector dependencies, incorporating the anubis claim and the parallel Nachlass Nord (DE) claim as threat-intelligence context.
- Review and test callback/verification procedures for mortgage-related transactions in case stolen client data is used for social-engineering or fraud follow-up.
- Monitor the Ransomware.live listing and anubis leak site for publication of stolen data.
5. Indicators of compromise
No indicators of compromise available in the source material.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Public claim of breach by "anubis" group naming Prelys Courtage | Ransomware.live listing; anubis leak site (if accessible) | Low — single-sourced, unconfirmed attribution |
| Potential publication of stolen client/mortgage data | anubis leak site; dark-web monitoring feeds | Low — claimed but not yet observed |
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Ransomware.live, "Ransomware: anubis named Prelys Courtage (FR)", https://www.ransomware.live/id/UHJlbHlzIENvdXJ0YWdlQGFudWJpcw==, published 2026-07-28
- Ransomware.live, "Ransomware: anubis named Nachlass Nord (DE)", https://www.ransomware.live/id/TmFjaGxhc3MgTm9yZEBhbnViaXM=, published 2026-07-28 (context only — separate victim)
8. Adverse Trace position
This is a low-confidence, single-sourced claim of a data breach by an actor ("anubis") with no established MITRE ATT&CK profile and no corroborating technical detail. The victim — a French mortgage brokerage — is financially relevant to EMEA clients with mortgage-referral or data-sharing dependencies. We assess the immediate technical risk as indeterminate: no IOCs, no malware samples, and no confirmed access vector are available. Clients with a direct relationship to Prelys Courtage should execute P1 actions immediately; all others should treat this as threat-intelligence context for third-party risk reviews. Adverse Trace will monitor for corroboration, IOC publication, or leak-site data drops and will re-issue this advisory if technical detail emerges.
Published via PulseTrace — Adverse Trace threat intelligence.