1. Executive summary
On 30 July 2026, the actor "aurora" publicly claimed a ransomware attack against Pyramid Analytics B.V. (NL), a decision-intelligence platform company recently acquired by ServiceNow. The actor claims to have exfiltrated the complete source code of the Pyramid Decision Intelligence Platform — including full Git history — and 22 GB of SQL Server production database backups containing user accounts, credentials, and business data. Attribution to "aurora" is unconfirmed: the named actor has no MITRE ATT&CK profile in the verified reference data, and the claim rests on a single source (ransomware.live). EMEA financial services clients using the Pyramid platform should assess exposure to supply-chain and third-party data-leak risk immediately.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 28: ICT third-party risk — general principles | Pyramid Analytics is an ICT third-party provider (decision-intelligence platform) whose source code and production database backups were allegedly exfiltrated, potentially compromising clients dependent on the platform. | Clients must assess whether their use of Pyramid services introduces ICT third-party risk and review contractual provisions accordingly. |
| DORA Art. 30: key contractual provisions with ICT third-party providers | The alleged exfiltration of source code with full Git history and SQL Server backups from a third-party provider engages the need to verify that key contractual provisions (incident notification, data handling) are in place and being exercised. | Clients should invoke notification clauses with Pyramid/ServiceNow and confirm breach communication timelines. |
| NIS2 Art. 21(2)(d): supply chain security measures | The compromise of a third-party analytics vendor whose platform may be embedded in client environments directly implicates supply-chain security obligations. | Clients must evaluate whether the alleged source-code leak creates exploitable risk in their own supply chain and document mitigations. |
3. Technical analysis & attack chain
Single-source caveat: All technical claims below derive from a single source — the ransomware.live posting attributed to "aurora." No independent corroboration is available. No IOCs, malware samples, or forensic details have been published. Treat all claims as unconfirmed until verified.
What is claimed
- Target: Pyramid Analytics B.V., headquartered in Amsterdam, NL. The company was acquired by ServiceNow (NYSE: NOW) approximately four months prior to the claim.
- Actor: "aurora" — no MITRE ATT&CK profile exists in the verified reference data; attribution is unconfirmed.
- Exfiltrated data claimed: - Complete source code of the Pyramid Decision Intelligence Platform, including 10+ copies with full Git history, described as revealing "every feature, algorithm, security module, and AI integration ever built." - 22 GB of SQL Server production database backups, likely containing user accounts, credentials, and business data. - Customer data from named publicly traded companies: Shufersal (TASE: SAE) retail sales data and ABB (NYSE: ABB) OLAP cube backups.
- Attack vector: Not specified in the source. No CVE, initial-access mechanism, or exploitation chain is described.
- Malware/payload: Not specified. The source describes data exfiltration and extortion but provides no ransomware binary, encryption behaviour, or ransom-note text. The posting is framed as a ransomware claim, but the publicly visible content describes data theft/extortion rather than confirmed encryption.
- Persistence / C2 / lateral movement: No technical detail provided.
What this means for defenders: The primary risk vector for EMEA financial services is not a direct ransomware payload but potential exposure through the Pyramid Decision Intelligence Platform — either as a customer whose data was in the exfiltrated SQL Server backups, or as a user of the platform whose source code is now allegedly in adversary hands, creating risk of future vulnerability discovery or supply-chain compromise.
4. Mitigation & containment
P1 — within 24 hours
- Determine whether your organisation is a Pyramid Decision Intelligence Platform customer or has any data integration with Pyramid Analytics / ServiceNow analytics products. Contact your ServiceNow account manager to confirm whether your environment is affected.
- If you are a Pyramid customer: identify what data was shared with or processed by the platform (user accounts, credentials, business data, OLAP cubes) and assume that data may be compromised. Force password resets for any credentials that were accessible to or managed by the platform.
- Review network egress for connections to Pyramid Analytics infrastructure and assess whether any embedded components in your environment could be affected by source-code disclosure.
P2 — within 72 hours
- Request a formal incident notification from Pyramid Analytics / ServiceNow under your contractual provisions. Document the request and response timeline (engages DORA Art. 30).
- If your organisation had data in the platform, conduct an impact assessment to determine whether the exfiltrated SQL Server backups or OLAP cubes contained regulated financial data, PII, or credentials. Classify the incident per your internal ICT incident classification process (engages DORA Art. 18).
- Audit Git repositories and CI/CD pipelines for any Pyramid platform integrations, API keys, or shared credentials that may now be exposed.
P3 — within 7 days
- Conduct a supply-chain risk assessment of the Pyramid platform dependency (engages DORA Art. 28 and NIS2 Art. 21(2)(d)). Document findings and mitigations.
- If major-incident thresholds are met under DORA Art. 19 or NIS2 Art. 23, prepare regulatory notifications to competent authorities.
- Review and rotate any API keys, service accounts, or integration credentials previously shared with the Pyramid platform.
5. Indicators of compromise
No indicators of compromise available in the source material.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Unauthorised bulk exfiltration of SQL Server database backups from analytics platform infrastructure | Database audit logs, network egress monitoring, DLP | Low — claimed by actor, not independently verified |
| Access to and exfiltration of Git repositories containing platform source code | Git server access logs, SIEM, endpoint telemetry on developer workstations | Low — claimed by actor, not independently verified |
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Ransomware.live, "Ransomware: aurora named Pyramid Analytics B.V. (NL)," https://www.ransomware.live/id/UHlyYW1pZCBBbmFseXRpY3MgQi5WLkBhdXJvcmE=, published 2026-07-30.
8. Adverse Trace position
This is a single-sourced ransomware/extortion claim against a third-party analytics vendor with no independent corroboration, no published IOCs, and no confirmed MITRE attribution for the actor "aurora." The severity for EMEA financial services clients depends entirely on whether they are Pyramid platform customers and what data was exposed through the platform. Clients with no Pyramid dependency face minimal direct risk. Clients who are Pyramid customers should treat this as a credible third-party data-exfiltration event, invoke contractual notification provisions, assess exposed data for regulatory impact, and rotate any credentials or API keys shared with the platform. Adverse Trace will monitor for independent corroboration, IOC publication, and any ServiceNow/Pyramid advisory, and will update this note if the claim is confirmed or if technical indicators emerge.
Published via PulseTrace — Adverse Trace threat intelligence.