~/f4n6 $ grep -r "Ransomware: lockbit5 named dupouy-associes.fr (FR)" ./investigations/ --include="*.md"

Ransomware: lockbit5 named dupouy-associes.fr (FR)

Jeff Davies 16 Aug 2026 3 min read

1. Executive summary

On 16 August 2026, the actor "lockbit5" publicly named dupouy-associes.fr — Dupouy et Associes / Crowe Horwath, a French accounting services firm — as a ransomware victim on its leak site. No technical details, initial-access vector, malware sample, data-exfiltration evidence, or negotiation status are available in the source material. Attribution to the "lockbit5" operation is unconfirmed: the actor has no MITRE ATT&CK profile in the verified reference data. EMEA financial services clients should treat this as a single-sourced claim requiring verification before enforcement, and assess any third-party or supply-chain exposure to the named firm.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 28: ICT third-party risk — general principles The named victim is an accounting services firm (Dupouy et Associes / Crowe Horwath) that may act as an ICT or data-handling third party to financial institutions. Clients with vendor or outsourcing relationships involving this firm must assess whether the incident affects the provider's ability to deliver services or exposes client data, and invoke contractual incident-notification clauses.
DORA Art. 19: reporting of major ICT-related incidents to competent authorities If a client confirms the incident impacts its own ICT services or data via this third party, it may constitute a major ICT-related incident requiring authority notification. Clients must evaluate impact severity and timeline against their DORA incident-classification criteria and prepare to report if thresholds are met.

No NIS2 or UK NIS article is specifically engaged beyond generic incident-response obligations, which apply to any incident and are not distinctive to this item.

3. Technical analysis & attack chain

No technical attack-chain detail is available in the source material. The ransomware.live listing provides only the actor name ("lockbit5"), the victim domain (dupouy-associes.fr), the victim's industry (accounting services), and the publication timestamp (2026-08-16T14:52:43Z). No information is provided on:

  • Initial access vector or exploited vulnerability/CVE
  • Malware variant, payload, or capabilities
  • Persistence mechanisms
  • Privilege escalation techniques
  • Command-and-control infrastructure
  • Lateral movement
  • Data exfiltration volume or content
  • Encryption scope or ransom demand

Attribution caveat: The actor "lockbit5" has no MITRE ATT&CK profile in the verified reference data. Attribution is therefore unconfirmed. The relationship between "lockbit5" and the historically known LockBit operation is not established in the source material and should not be assumed.

Source caveat: This advisory is based on a single source (ransomware.live). The listing reflects a public claim by the actor; it does not confirm intrusion, encryption, or data theft. Verify independently before enforcement.

4. Mitigation & containment

P1 — within 24 hours

  • Determine whether your organisation has a current or recent business relationship with Dupouy et Associes / Crowe Horwath (dupouy-associes.fr), including data sharing, outsourced accounting, audit, or advisory engagements.
  • If a relationship exists: identify what data, systems, or credentials have been shared with or accessible to the firm. Assess whether any client confidential data, financial records, or authentication credentials may be exposed.
  • Block and monitor the victim domain (dupouy-associes[.]fr) in DNS and web-proxy logs for any outbound connections from your environment, as a precaution against potential secondary infrastructure abuse.

P2 — within 72 hours

  • Contact the firm through established vendor-management channels to confirm or deny the incident and request an incident notification per contractual terms.
  • If the firm is a registered ICT third-party provider under a DORA-relevant contract, document the inquiry and response for DORA Art. 28 / Art. 30 compliance records.
  • Review email and collaboration logs for any anomalous inbound communications spoofing or originating from dupouy-associes[.]fr domains since 1 August 2026.

P3 — within 7 days

  • If exposure is confirmed, conduct a retrospective review of transactions, data exchanges, and access logs involving the firm for the preceding 90 days.
  • Update third-party risk registers to reflect the incident status and any confirmed impact.
  • Monitor ransomware.live and other threat-intelligence feeds for updates, including leak of exfiltrated data that may contain client information.

5. Indicators of compromise

Type Value Confidence Source
domain dupouy-associes[.]fr High — victim domain confirmed ransomware.live
domain  dupouy-associes[.]fr

Note: The domain above is the victim's legitimate domain, not malicious infrastructure. It is included for monitoring and exposure-assessment purposes only. No attacker-controlled domains, IPs, hashes, file paths, or other atomic indicators are available in the source material.

6. Detection

Insufficient indicators to author detection rules. The source material contains no malware artefacts, command-line strings, registry keys, mutex names, file paths, network indicators, or behavioural patterns attributable to the threat actor. No YARA or Sigma rules can be authored from the available data.

7. Sources

  • Ransomware.live — "Victim: dupouy-associes.fr – lockbit5" — https://www.ransomware.live/id/ZHVwb3V5LWFzc29jaWVzLmZyQGxvY2tiaXQ1 — Published 2026-08-16

8. Adverse Trace position

This is a single-sourced ransomware claim with no technical corroboration. The actor "lockbit5" has no confirmed MITRE ATT&CK profile, and the public listing does not demonstrate intrusion, encryption, or data exfiltration — only that the actor has named the victim. Severity for directly exposed EMEA financial services clients is moderate: an accounting firm with potential access to financial data and client records represents a meaningful third-party risk if the claim is true, but the absence of any technical detail or independent confirmation limits actionable response. We will monitor for corroboration from additional sources, leak-site updates, and any emergence of IOCs or exfiltrated data, and will re-issue this advisory if the threat picture materially changes.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies