> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Ransomware: stormous named eogb.co.uk (GB)
- URL: https://f4n6.co.uk/security-feed/ransomware-stormous-named-eogb-co-uk-gb/
- Published: 2026-06-29T15:41:59.000Z
- Updated: 2026-06-29T15:41:59.000Z
- Author: Jeff Davies
- Tags: #security-feed, stormous

## 1\. Executive summary

On 2026-06-28, the actor "stormous" publicly claimed a ransomware attack against eogb.co.uk, a UK-registered domain. The claim includes descriptions of deep access to Microsoft Dynamics GP and exfiltration of corporate accounting data, legal documents, and operational spreadsheets. Attribution to "stormous" is **unconfirmed** — no MITRE ATT&CK profile exists for this actor, and the claim originates from a single source (ransomware.live). No CVE, CVSS score, or CISA-KEV exploitation state is associated with this item. EMEA financial services clients with UK operational links or Microsoft Dynamics GP deployments should treat this as a credible-but-unverified extortion claim and assess potential data exposure.

## 2\. Regulatory framing

| Article                                                                         | Trigger (the fact in this item)                                                                                    | Practical impact                                                                                                                                           |
| ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DORA Art. 17: ICT-related incident management process                           | Public ransomware claim involving exfiltration of corporate financial and legal data from a UK entity              | If a client has a relationship with or exposure to eogb.co.uk, the incident management process must be triggered to assess impact and coordinate response. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats         | Ransomware claim with data exfiltration (Microsoft Dynamics GP, legal documents, financial reports)                | The incident must be classified per severity/criticality criteria; data exfiltration of financial systems warrants high classification.                    |
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | If a client is the victim or a materially affected third party, this constitutes a major ICT-related incident      | Reporting to competent authorities may be required within prescribed timelines.                                                                            |
| NIS2 Art. 23: incident reporting obligations                                    | Ransomware incident with significant operational impact and data exfiltration                                      | NIS2-covered entities must notify their CSIRT/competent authority without undue delay if affected.                                                         |
| UK NIS 2018: UK Network and Information Systems Regulations — OES/RDSP duties   | Victim is a UK domain (eogb.co.uk); if the victim or an affected party is an OES/RDSP subject, UK NIS duties apply | OES/RDSP operators must manage incidents affecting the availability and integrity of services.                                                             |

## 3\. Technical analysis & attack chain

### Confirmed facts from the source

1. **Actor:** "stormous" — publicly claimed responsibility via ransomware.live.
2. **Victim:** eogb.co.uk (GB / United Kingdom).
3. **Published date:** 2026-06-28T21:29:58 UTC.
4. **Claimed access:** Deep access to Microsoft Dynamics GP, described as containing "complete corporate accounting, invoices, vendor details, and commercial transactions."
5. **Claimed data accessed:** Internal legal documents, partnership agreements, customer contracts (specifically named: "CBIF OSMO agreements"), operational spreadsheets, financial reports, and executive documents.
6. **Claimed exfiltration method:** Described as "via corporate" — the sentence is truncated in the source, but the exfiltration channel is described as corporate infrastructure (likely corporate network/email, but this is unconfirmed due to truncation).

### Technical specifics from the claim

- **Target application:** Microsoft Dynamics GP (formerly Great Plains) — an ERP system typically accessed via TCP port 80/443 (web client) or via the Dynamics GP desktop client over SQL Server back-end (TCP 1433). Deep access to Dynamics GP implies either direct database access (SQL Server), compromised admin credentials, or access via the Dynamics GP client/server tier.
- **Data categories:** Financial accounting data, vendor details, invoices, commercial transactions, legal/partnership documents, customer contracts (CBIF OSMO agreements), operational spreadsheets, financial reports, executive documents.
- **Exfiltration:** Claimed via corporate infrastructure; method truncated in source.

### Unconfirmed / single-sourced claims (confidence caveat)

- **Attribution to "stormous"** is **unconfirmed** — no MITRE ATT&CK profile exists for this actor. The claim is single-sourced (ransomware.live). Verify before enforcement.
- **Ransomware classification:** The source categorises this as a ransomware event, but no ransom note, encryption behaviour, malware sample, or extortion demand text is provided. The described activity (access + exfiltration) is consistent with data-theft/extortion but the "ransomware" label cannot be independently corroborated from the source material.
- **No CVE, vulnerability, or initial access vector** is identified in the source. The mechanism by which the actor gained access to Microsoft Dynamics GP is not described.
- **No malware name, C2 infrastructure, persistence mechanism, or privilege escalation technique** is provided.
- **No IOCs (hashes, IPs, domains, mutexes, filenames)** are present in the source material.

## 4\. Mitigation & containment

### P1 — Within 24 hours

- If your organisation has any relationship with eogb.co.uk (vendor, customer, partnership, data-sharing), initiate an incident assessment immediately. Focus on whether any shared data, credentials, or integrated systems are exposed.
- Audit Microsoft Dynamics GP access logs for anomalous sessions, unusual SQL queries, or bulk data export activity — particularly against tables containing vendor details (PM00200, PM0000200), invoices (PM20000, PM30300), and GL data (GL00100, GL30000).
- Review and rotate credentials for any accounts with Dynamics GP admin or SQL Server access, especially service accounts.
- Check for unauthorised SQL Server logins: review `sys.server_principals`, `sys.sql_logins`, and the SQL Server error log for suspicious authentication events.

### P2 — Within 72 hours

- If eogb.co.uk is a third-party supplier, assess contractual exposure: review data-sharing agreements, identify what data was shared, and determine whether notification obligations to your regulators are triggered (DORA Art. 19, NIS2 Art. 23).
- Conduct a credential sweep: check whether any corporate credentials appear in infostealer-derived datasets (the source is sponsored by Hudson Rock, which links infostealer infections to ransomware — treat this as contextual, not as evidence of infostealer compromise in this specific case).
- Review perimeter logs for connections to/from eogb.co.uk domains and assess whether any data exchange channels could have been leveraged for lateral movement.

### P3 — Within 7 days

- If Microsoft Dynamics GP is deployed in your environment, conduct a full access-control review: verify least-privilege on SQL Server roles, review Dynamics GP security roles, and audit any integrations (eConnect, Web Services for Microsoft Dynamics GP) for exposed endpoints.
- Validate backup integrity for Dynamics GP databases (DYNAMICS, company databases, system databases) — ensure offline/immutable backups exist.
- If this incident is confirmed to affect your organisation, complete the DORA Art. 17 incident management process and file the DORA Art. 19 report if classified as a major ICT-related incident.

## 5\. Indicators of compromise

No indicators of compromise available in the source material.

## 6\. Detection

Insufficient indicators to author detection rules.

The source material contains no file hashes, IP addresses, domains (beyond the victim domain), mutex names, filenames, registry keys, ransom-note text, or hard-coded values attributable to the actor or malware. The victim domain (eogb.co.uk) is not an IOC — it is the victim's own domain.

## 7\. Sources

- **ransomware.live** — "Ransomware: stormous named eogb.co.uk (GB)" — https://www.ransomware.live/id/ZW9nYi5jby51a0BBzdG9ybW91cw== — Published 2026-06-28T21:29:58 UTC
- **ransomware.live** — Victim page for eogb.co.uk (sponsored by Hudson Rock) — https://www.ransomware.live/id/ZW9nYi5jby51a0BBzdG9ybW91cw== — Accessed 2026-06-29

## 8\. Adverse Trace position

This is a **single-sourced, unconfirmed** ransomware claim with no technical artefacts, no CVE association, and no MITRE-validated actor profile. The "stormous" attribution cannot be corroborated. The described activity — deep access to Microsoft Dynamics GP and exfiltration of financial, legal, and operational data — is consistent with a targeted data-theft/extortion operation, but the source provides no evidence of encryption or ransom demand, so the "ransomware" classification rests solely on the ransomware.live categorisation. For EMEA financial services clients: (1) if you have a direct relationship with eogb.co.uk, treat this as a potential third-party data breach and trigger your DORA Art. 17 incident management process; (2) if you operate Microsoft Dynamics GP, use this as a prompt to audit access controls and SQL Server security; (3) do not treat the attribution as confirmed for threat-hunting purposes — single-sourced; verify before enforcement. Adverse Trace will monitor for corroborating sources, additional claims by "stormous," and any emerging IOCs or technical details.

---

[Read the original source →](https://www.ransomware.live/id/ZW9nYi5jby51a0BzdG9ybW91cw==?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*