~/f4n6 $ grep -r "Ransomware: direwolf named Reviso Cloud Accounting Limited (DK)" ./investigations/ --include="*.md"

Ransomware: direwolf named Reviso Cloud Accounting Limited (DK)

Jeff Davies 21 Aug 2026 4 min read

1. Executive summary

On 21 August 2026, the ransomware actor "direwolf" publicly listed Reviso Cloud Accounting Limited (DK; domain reviso.com) as a victim on its leak site. Reviso provides cloud-based bookkeeping, invoicing, financial reporting, and VAT management to SMBs. Attribution to "direwolf" is unconfirmed: the actor has no MITRE ATT&CK profile in the verified reference data, and the claim rests solely on the ransomware.live listing. The listing reports 286 compromised users and 23 external attack-surface assets but zero compromised employees, suggesting the initial access vector is not yet established. EMEA financial services clients using Reviso should treat the platform as potentially compromised and assess exposure of financial and VAT data.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 19: reporting of major ICT-related incidents to competent authorities Reviso is a cloud accounting platform processing financial/VAT data for financial-services clients; a ransomware claim against the provider is a potential major ICT-related incident at client entities. Clients of Reviso that are in-scope of DORA must assess whether this constitutes a major incident requiring authority notification under their classification criteria.
DORA Art. 28: ICT third-party risk — general principles Reviso is an ICT third-party provider delivering cloud accounting services to financial entities. Clients must review their third-party risk exposure to Reviso, including contractual provisions for incident notification and data breach response.
NIS2 Art. 21(2)(d): supply chain security measures The ransomware listing targets a SaaS provider in the supply chain of potentially in-scope NIS2 entities. NIS2 in-scope organisations using Reviso should evaluate whether supply-chain security measures were adequate and whether supplier-side incident reporting obligations are triggered.

3. Technical analysis & attack chain

Source caveat: The sole source for this advisory is the ransomware.live public listing (single-sourced; verify before enforcement). No technical forensic detail, malware sample, CVE, or attack-chain description has been published. The following is limited to what the listing states.

What is confirmed from the listing

  1. The actor "direwolf" posted Reviso Cloud Accounting Limited as a victim on its leak site on 2026-08-21.
  2. Victim domain: reviso.com.
  3. Victim country code: DK (the listing notes the company is UK-based and serves UK businesses; the DK tag may reflect registration or operational jurisdiction).
  4. Hudson Rock data referenced in the listing reports: 286 compromised users, 0 compromised employees, 0 third-party employee credentials, 23 external attack-surface assets.
  5. A leak screenshot is referenced but its contents are not described in the source material.

What is NOT confirmed

  • Attribution: "direwolf" has no MITRE ATT&CK profile in the verified reference data. Treat the actor name as unconfirmed.
  • Initial access vector: The 0 compromised employees / 286 compromised users split may suggest infostealer-driven access via user credentials rather than employee endpoint compromise, but this is speculative — the source does not state a vector.
  • Malware, payload, C2, persistence, lateral movement, exfiltration method: None described in the source.
  • Data actually exfiltrated or encrypted: The listing implies data theft (ransomware leak-site convention) but no file list, data sample, or encryption detail is available.

Related direwolf activity (single-sourced via ransomware.live): The same actor has recently listed Eva AI Limited (GB) and PayUp (financial software, payup.com), suggesting a pattern of targeting SaaS/FinTech platforms. This pattern is unconfirmed and based solely on ransomware.live indexing.

4. Mitigation & containment

P1 — within 24 hours

  • Identify all Reviso accounts in use across the organisation; enumerate which business units process financial data, invoicing, or VAT reporting through the platform.
  • Force password resets and re-authentication for all Reviso user accounts; enable or verify MFA is enforced on every account.
  • Review Reviso audit logs for anomalous logins, data exports, bulk report generation, or API access from unfamiliar IPs since 2026-08-01 (allowing lead time before the public listing).
  • If Reviso API keys or OAuth tokens are used for integrations (e.g., ERP, banking feeds), rotate all credentials and tokens immediately.

P2 — within 72 hours

  • Contact Reviso (reviso.com) directly to request an incident confirmation, scope of data affected, and their incident response timeline. Do not rely solely on the ransomware leak site.
  • Assess what financial data, VAT records, customer invoicing data, or bank-account details may have been accessible to the platform and prepare a data-impact assessment.
  • Notify internal DPO and compliance teams; evaluate whether a personal data breach notification to the relevant supervisory authority (DK Datatilsynet or UK ICO, depending on jurisdiction) is required.
  • Block Reviso platform access from non-essential users pending confirmation of the incident scope.

P3 — within 7 days

  • Review the DORA Art. 28 third-party risk assessment for Reviso; verify contractual incident-notification clauses were met.
  • If Reviso confirms a breach, execute the contractual right to audit or request a forensic summary.
  • Evaluate whether to invoke contingency arrangements (alternative accounting/invoicing workflow) if the platform remains unavailable or untrusted.
  • Update vendor risk register to reflect the incident and reassess Reviso's risk tier.

5. Indicators of compromise

No indicators of compromise available in the source material.

Behavioural indicators

Behaviour Where to observe Confidence
Anomalous logins to Reviso accounts from unfamiliar IPs or geographies Reviso audit logs; SSO/IdP logs Low — inferred from incident type, not source-confirmed
Bulk data export or report generation from Reviso platform Reviso admin/audit console Low — inferred from incident type, not source-confirmed
Unauthorised API access using valid Reviso credentials API gateway logs; Reviso integration logs Low — inferred from 286 compromised users figure

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Ransomware.live, "Ransomware: direwolf named Reviso Cloud Accounting Limited (DK)", https://www.ransomware.live/id/UmV2aXNvIENsb3VkIEFjY291bnRpbmcgTGltaXRlZEBkaXJld29sZg==, 2026-08-21
  • Ransomware.live, "Ransomware: direwolf named Eva AI Limited (GB)", https://www.ransomware.live/id/RXZhIEFJIExpbWl0ZWRAZGlyZXdvbGY= (context)
  • Ransomware.live, "Ransomware: direwolf named PayUp", https://www.ransomware.live/id/UGF5VXBAZGlyZXdvbGY= (context)

8. Adverse Trace position

This is a single-sourced ransomware leak-site claim with no technical forensic detail and an unconfirmed actor attribution (direwolf has no MITRE ATT&CK profile). The severity for EMEA financial services clients depends entirely on whether they use Reviso as an ICT third-party provider: those with active engagements face potential exposure of financial, invoicing, and VAT data and should execute P1 actions immediately. Clients without Reviso exposure face no direct technical risk from this item. We will monitor for a Reviso incident confirmation, additional direwolf technical reporting, and any emergence of IOCs or malware samples. This advisory will be updated if attribution is confirmed or technical artefacts become available.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies