~/f4n6 $ grep -r "Ransomware: anubis named Prelys Courtage (FR)" ./investigations/ --include="*.md"

Ransomware: anubis named Prelys Courtage (FR)

Jeff Davies 28 Jul 2026 4 min read

1. Executive summary

On 28 July 2026, the ransomware group "anubis" publicly claimed a data breach against Prelys Courtage, a major mortgage brokerage franchise in France. The actor alleges theft of client data; no encryption or ransom-demand details are provided in the source. Attribution to "anubis" is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data, and the claim is single-sourced via Ransomware.live. EMEA financial services clients should treat this as a potential data-exfiltration event affecting a French mortgage broker, with possible exposure of sensitive client financial and identity documentation.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 19: reporting of major ICT-related incidents to competent authorities A ransomware group has publicly claimed exfiltration of client data from a French financial-services entity (mortgage brokerage). If a client has a third-party or supply-chain relationship with Prelys Courtage, this may constitute a major ICT-related incident requiring notification. Clients using Prelys Courtage as an ICT third-party provider must assess whether the claimed breach impacts their own operations or data, and prepare incident classification and reporting under DORA Art. 18–19 if thresholds are met.
DORA Art. 28: ICT third-party risk — general principles Prelys Courtage is a mortgage brokerage franchise handling sensitive client financial data; firms that depend on it for mortgage-related services have a third-party exposure. Clients should review their third-party risk register for Prelys Courtage dependencies and engage contractual notification clauses (cf. DORA Art. 30).

No NIS2 or UK NIS articles are specifically engaged beyond generic incident-reporting obligations, which would apply to any incident and are not distinctive to this item.

3. Technical analysis & attack chain

Attribution caveat: The actor "anubis" has no MITRE ATT&CK profile in the verified reference data. Attribution rests solely on the Ransomware.live listing. Treat as unconfirmed.

Source caveat: All technical detail below is single-sourced (Ransomware.live). No independent corroboration is available. No victim statement, law-enforcement confirmation, or vendor report has been identified at time of writing.

What is known

  1. The ransomware group "anubis" posted a claim on or before 28 July 2026 naming Prelys Courtage (FR) as a victim.
  2. The victim is described as "a major mortgage brokerage franchise."
  3. The claimed impact is a client data breach.
  4. No leak site URL, ransom note text, encryption details, initial-access vector, malware sample, or technical indicators are provided in the source material.
  5. A second anubis claim against Nachlass Nord (DE), an inheritance law firm, was published in the same timeframe, suggesting an active campaign — but no shared infrastructure, TTPs, or IOCs link the two beyond actor name.

What is NOT known

  • Initial access vector (no CVE, no infostealer linkage confirmed despite Hudson Rock sponsorship banner on the listing page — this is an advertisement, not an attribution).
  • Malware family, payload, or encryption behaviour.
  • Data volumes, specific data types, or exfiltration method.
  • C2 infrastructure, persistence mechanisms, or lateral movement.
  • Whether this is a double-extortion (encrypt + leak) or pure data-theft/extortion event.

The Hudson Rock sponsorship on the Ransomware.live page is an advertisement for infostealer-intelligence tooling. It does not constitute evidence that infostealer malware was used in this specific intrusion. Do not treat it as a confirmed access vector.

4. Mitigation & containment

P1 — within 24 hours

  • Determine whether your organisation has a direct or indirect relationship with Prelys Courtage (vendor, partner, data-sharing, mortgage referral pipeline). If yes, initiate incident-response triage: identify what data was shared, what systems are integrated, and whether credentials or API keys are in use.
  • If any SSO, API, or VPN credentials are shared with Prelys Courtage systems, rotate them immediately.
  • Notify your DPO and incident-response team; begin documenting for potential DORA Art. 18 classification.

P2 — within 72 hours

  • Contact Prelys Courtage via established third-party channels to confirm or deny the breach and request an incident impact assessment.
  • Review data-flow diagrams for any PII or financial data exchanged with Prelys Courtage; prepare a data-impact assessment for affected clients.
  • If the breach is confirmed and client data is implicated, prepare DORA Art. 19 major-incident reporting timelines.

P3 — within 7 days

  • Update third-party risk assessments for mortgage brokerage and legal-sector dependencies, incorporating the anubis claim and the parallel Nachlass Nord (DE) claim as threat-intelligence context.
  • Review and test callback/verification procedures for mortgage-related transactions in case stolen client data is used for social-engineering or fraud follow-up.
  • Monitor the Ransomware.live listing and anubis leak site for publication of stolen data.

5. Indicators of compromise

No indicators of compromise available in the source material.

Behavioural indicators

Behaviour Where to observe Confidence
Public claim of breach by "anubis" group naming Prelys Courtage Ransomware.live listing; anubis leak site (if accessible) Low — single-sourced, unconfirmed attribution
Potential publication of stolen client/mortgage data anubis leak site; dark-web monitoring feeds Low — claimed but not yet observed

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live, "Ransomware: anubis named Prelys Courtage (FR)", https://www.ransomware.live/id/UHJlbHlzIENvdXJ0YWdlQGFudWJpcw==, published 2026-07-28
  • Ransomware.live, "Ransomware: anubis named Nachlass Nord (DE)", https://www.ransomware.live/id/TmFjaGxhc3MgTm9yZEBhbnViaXM=, published 2026-07-28 (context only — separate victim)

8. Adverse Trace position

This is a low-confidence, single-sourced claim of a data breach by an actor ("anubis") with no established MITRE ATT&CK profile and no corroborating technical detail. The victim — a French mortgage brokerage — is financially relevant to EMEA clients with mortgage-referral or data-sharing dependencies. We assess the immediate technical risk as indeterminate: no IOCs, no malware samples, and no confirmed access vector are available. Clients with a direct relationship to Prelys Courtage should execute P1 actions immediately; all others should treat this as threat-intelligence context for third-party risk reviews. Adverse Trace will monitor for corroboration, IOC publication, or leak-site data drops and will re-issue this advisory if technical detail emerges.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies