1. Executive summary
On 2026-07-10, the ransomware group "Deadlock" publicly claimed a ransomware attack against EFCA, a Paris-based accounting firm specialising in real estate and property management (domain: www.efca-europe.com), with the victim listed under country code DE. The claim was posted on the Deadlock leak site and indexed by Ransomware.live. Attribution to the "Deadlock" group is unconfirmed — the actor has no MITRE ATT&CK profile in verified reference data, and no technical IOCs, CVEs, or attack-chain details are available in the source material. EMEA financial services clients should treat this as a single-sourced claim requiring verification before enforcement, while noting EFCA's role in real estate accounting could engage third-party risk considerations if the firm is an ICT service provider to regulated entities.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 28: ICT third-party risk — general principles | EFCA provides accounting and property management services; if a regulated financial entity relies on EFCA as an ICT third-party provider, this incident engages third-party risk obligations. | Clients using EFCA for ICT-enabled accounting services must assess whether the incident affects their operational resilience and whether contractual incident-notification clauses apply. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | A ransomware claim against a potential ICT third-party provider constitutes a cyber threat that may require classification if it impacts a regulated entity. | Regulated entities must classify any resulting disruption per their internal ICT incident classification methodology. |
| NIS2 Art. 21(2)(d): supply chain security measures | If EFCA is in the supply chain of an NIS2 in-scope entity, the ransomware claim engages supply-chain security obligations. | NIS2 entities should assess whether EFCA is a supplier whose compromise could affect their own security and take appropriate measures. |
| UK NIS 2018: UK Network and Information Systems Regulations — OES/RDSP duties | If a UK OES or RDSP relies on EFCA as a supplier, the incident may engage supply-chain risk management duties. | UK OES/RDSP operators should evaluate supplier dependency and incident impact on their networks and information systems. |
No specific DORA/NIS2 article is directly engaged by the primary item alone — the triggers above are conditional on EFCA being an ICT third-party provider or supplier to a regulated entity. If no such relationship exists, no specific article is engaged.
3. Technical analysis & attack chain
No confirmed attack chain is available. The source material (Ransomware.live victim listing) contains only the following confirmed facts:
- Actor claim: The group "Deadlock" publicly listed EFCA as a victim on its leak site.
- Victim identity: EFCA, a Paris-based accounting firm specialising in real estate accounting, property management support, trustee/agent accounting, and tax/advisory services. Domain: www.efca-europe.com.
- Country tag: DE (note: EFCA is described as Paris-based; the DE tag may reflect hosting, registration, or operational presence — this discrepancy is unexplained in the source).
- Publication timestamp: 2026-07-10T13:01:37Z.
What is NOT available in the source material
- No initial access vector, exploited CVE, or vulnerability mechanism.
- No malware payload name, sample, or capability description.
- No persistence mechanisms, privilege escalation techniques, or C2 infrastructure.
- No lateral movement, data exfiltration volume, or encryption behaviour details.
- No file paths, registry keys, commands, or network indicators.
- No ransom note text or ransom demand amount.
- No confirmation of data exfiltration versus encryption-only.
Attribution caveat: The actor "Deadlock" has no MITRE ATT&CK profile in verified reference data. Attribution is unconfirmed. The name may refer to a new or rebranded group; no correlation to known ransomware families is possible from the available data.
Campaign context (single-sourced; verify before enforcement): Ransomware.live shows Deadlock claiming multiple victims across Europe in the same timeframe, including IFC Europa (ES/DE), 8.2 Group e.V. (DE), EDISA and INVERTIGE (ES), Picassent City Council (ES), FIRESTA (CZ), and Gerusia S.L. (ES). This suggests an active, broad targeting pattern across EU organisations — primarily in professional services, engineering, construction, and public sectors. All claims are single-sourced from Ransomware.live indexing of the Deadlock leak site.
4. Mitigation & containment
Given the absence of technical indicators, IOCs, or CVE data in the source material, mitigation guidance is necessarily general and conditional.
P1 — Within 24 hours
- Determine whether your organisation has a direct business or ICT relationship with EFCA (www.efca-europe.com). If yes, activate your third-party incident response clause and contact EFCA to confirm/deny the claim.
- If EFCA is an ICT third-party provider: assess whether any of your systems, data, or integrations with EFCA are affected. Check for anomalous traffic to/from EFCA domains or IP ranges.
- Search EDR/SIEM for any communication with www.efca-europe.com over the past 30 days as a precautionary supply-chain measure.
- Block www.efca-europe.com at web proxy/email gateway if EFCA is confirmed compromised and there is no legitimate operational need to reach the domain.
P2 — Within 72 hours
- If EFCA is confirmed as an affected ICT third-party provider, classify the incident per DORA Art. 18 methodology and assess whether major-incident reporting thresholds are met (DORA Art. 19).
- Review data shared with EFCA: identify what sensitive financial, client, or operational data EFCA holds or processes on your behalf. Document for potential regulatory notification.
- Monitor the Deadlock leak site for posted data relating to EFCA; if data appears, assess breach-notification obligations under applicable GDPR/DORA/NIS2 frameworks.
P3 — Within 7 days
- Conduct a third-party risk reassessment of EFCA if the relationship continues. Require written confirmation of remediation status and forensic findings.
- Update vendor risk registers to reflect the incident and any identified control gaps.
- If EFCA provides critical ICT services, evaluate whether concentration risk (DORA Art. 29) is implicated and whether alternative providers should be identified.
5. Indicators of compromise
No indicators of compromise available in the source material.
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Ransomware.live, "Ransomware: Deadlock named EFCA (DE)", https://www.ransomware.live/id/RUZDQUBEZWFkbG9jaw==, 2026-07-10
- Ransomware.live, "Ransomware: Deadlock named IFC Eur (DE)", https://www.ransomware.live/id/SUZDIEV1ckBEZWFkbG9jaw== (context)
- Ransomware.live, "Ransomware: Deadlock named 8.2 Group e.V. (DE)", https://www.ransomware.live/id/OC4yIEdyb3VwIGUuVi5ARGVhZGxvY2s= (context)
- Ransomware.live, "Ransomware: Deadlock named EDISA and INVERTIGE", https://www.ransomware.live/id/RURJU0EgYW5kIElOVkVSVElHRUBEZWFkbG9jaw== (context)
- Ransomware.live, "Ransomware: Deadlock named Picassent (ES)", https://www.ransomware.live/id/UGljYXNzZW50QERlYWRsb2Nr (context)
- Ransomware.live, "Ransomware: Deadlock named FIRESTA (CZ)", https://www.ransomware.live/id/RklSRVNUQUBEZWFkbG9jaw== (context)
- Ransomware.live, "Ransomware: Deadlock named Gerusia S.L. (ES)", https://www.ransomware.live/id/R2VydXNpYSBTLkwuQERlYWRsb2Nr (context)
8. Adverse Trace position
Severity: Low-to-Moderate (conditional). The Deadlock claim against EFCA is unverified and single-sourced from Ransomware.live indexing of the actor's leak site. No CVE, IOC, malware sample, or technical attack-chain detail is available, and the actor "Deadlock" has no MITRE ATT&CK profile — attribution is unconfirmed. The risk to EMEA financial services clients is conditional on whether EFCA is an ICT third-party provider in their supply chain; if so, DORA Art. 28 and NIS2 Art. 21(2)(d) obligations are engaged and clients should execute P1 steps immediately. The broader Deadlock campaign pattern across EU professional services and public-sector targets (6+ victims indexed) suggests an active operator that EMEA clients should monitor. Adverse Trace will continue tracking Deadlock claims and will issue an updated advisory if technical indicators, confirmed attribution, or a verified CVE emerge. Clients with a direct EFCA relationship should verify the claim independently and report back through their Adverse Trace liaison.
Published via PulseTrace — Adverse Trace threat intelligence.