1. Executive summary
On 2026-06-28, the actor "stormous" publicly claimed a ransomware attack against eogb.co.uk, a UK-registered domain. The claim includes descriptions of deep access to Microsoft Dynamics GP and exfiltration of corporate accounting data, legal documents, and operational spreadsheets. Attribution to "stormous" is unconfirmed — no MITRE ATT&CK profile exists for this actor, and the claim originates from a single source (ransomware.live). No CVE, CVSS score, or CISA-KEV exploitation state is associated with this item. EMEA financial services clients with UK operational links or Microsoft Dynamics GP deployments should treat this as a credible-but-unverified extortion claim and assess potential data exposure.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17: ICT-related incident management process | Public ransomware claim involving exfiltration of corporate financial and legal data from a UK entity | If a client has a relationship with or exposure to eogb.co.uk, the incident management process must be triggered to assess impact and coordinate response. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | Ransomware claim with data exfiltration (Microsoft Dynamics GP, legal documents, financial reports) | The incident must be classified per severity/criticality criteria; data exfiltration of financial systems warrants high classification. |
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | If a client is the victim or a materially affected third party, this constitutes a major ICT-related incident | Reporting to competent authorities may be required within prescribed timelines. |
| NIS2 Art. 23: incident reporting obligations | Ransomware incident with significant operational impact and data exfiltration | NIS2-covered entities must notify their CSIRT/competent authority without undue delay if affected. |
| UK NIS 2018: UK Network and Information Systems Regulations — OES/RDSP duties | Victim is a UK domain (eogb.co.uk); if the victim or an affected party is an OES/RDSP subject, UK NIS duties apply | OES/RDSP operators must manage incidents affecting the availability and integrity of services. |
3. Technical analysis & attack chain
Confirmed facts from the source
- Actor: "stormous" — publicly claimed responsibility via ransomware.live.
- Victim: eogb.co.uk (GB / United Kingdom).
- Published date: 2026-06-28T21:29:58 UTC.
- Claimed access: Deep access to Microsoft Dynamics GP, described as containing "complete corporate accounting, invoices, vendor details, and commercial transactions."
- Claimed data accessed: Internal legal documents, partnership agreements, customer contracts (specifically named: "CBIF OSMO agreements"), operational spreadsheets, financial reports, and executive documents.
- Claimed exfiltration method: Described as "via corporate" — the sentence is truncated in the source, but the exfiltration channel is described as corporate infrastructure (likely corporate network/email, but this is unconfirmed due to truncation).
Technical specifics from the claim
- Target application: Microsoft Dynamics GP (formerly Great Plains) — an ERP system typically accessed via TCP port 80/443 (web client) or via the Dynamics GP desktop client over SQL Server back-end (TCP 1433). Deep access to Dynamics GP implies either direct database access (SQL Server), compromised admin credentials, or access via the Dynamics GP client/server tier.
- Data categories: Financial accounting data, vendor details, invoices, commercial transactions, legal/partnership documents, customer contracts (CBIF OSMO agreements), operational spreadsheets, financial reports, executive documents.
- Exfiltration: Claimed via corporate infrastructure; method truncated in source.
Unconfirmed / single-sourced claims (confidence caveat)
- Attribution to "stormous" is unconfirmed — no MITRE ATT&CK profile exists for this actor. The claim is single-sourced (ransomware.live). Verify before enforcement.
- Ransomware classification: The source categorises this as a ransomware event, but no ransom note, encryption behaviour, malware sample, or extortion demand text is provided. The described activity (access + exfiltration) is consistent with data-theft/extortion but the "ransomware" label cannot be independently corroborated from the source material.
- No CVE, vulnerability, or initial access vector is identified in the source. The mechanism by which the actor gained access to Microsoft Dynamics GP is not described.
- No malware name, C2 infrastructure, persistence mechanism, or privilege escalation technique is provided.
- No IOCs (hashes, IPs, domains, mutexes, filenames) are present in the source material.
4. Mitigation & containment
P1 — Within 24 hours
- If your organisation has any relationship with eogb.co.uk (vendor, customer, partnership, data-sharing), initiate an incident assessment immediately. Focus on whether any shared data, credentials, or integrated systems are exposed.
- Audit Microsoft Dynamics GP access logs for anomalous sessions, unusual SQL queries, or bulk data export activity — particularly against tables containing vendor details (PM00200, PM0000200), invoices (PM20000, PM30300), and GL data (GL00100, GL30000).
- Review and rotate credentials for any accounts with Dynamics GP admin or SQL Server access, especially service accounts.
- Check for unauthorised SQL Server logins: review
sys.server_principals,sys.sql_logins, and the SQL Server error log for suspicious authentication events.
P2 — Within 72 hours
- If eogb.co.uk is a third-party supplier, assess contractual exposure: review data-sharing agreements, identify what data was shared, and determine whether notification obligations to your regulators are triggered (DORA Art. 19, NIS2 Art. 23).
- Conduct a credential sweep: check whether any corporate credentials appear in infostealer-derived datasets (the source is sponsored by Hudson Rock, which links infostealer infections to ransomware — treat this as contextual, not as evidence of infostealer compromise in this specific case).
- Review perimeter logs for connections to/from eogb.co.uk domains and assess whether any data exchange channels could have been leveraged for lateral movement.
P3 — Within 7 days
- If Microsoft Dynamics GP is deployed in your environment, conduct a full access-control review: verify least-privilege on SQL Server roles, review Dynamics GP security roles, and audit any integrations (eConnect, Web Services for Microsoft Dynamics GP) for exposed endpoints.
- Validate backup integrity for Dynamics GP databases (DYNAMICS, company databases, system databases) — ensure offline/immutable backups exist.
- If this incident is confirmed to affect your organisation, complete the DORA Art. 17 incident management process and file the DORA Art. 19 report if classified as a major ICT-related incident.
5. Indicators of compromise
No indicators of compromise available in the source material.
6. Detection
Insufficient indicators to author detection rules.
The source material contains no file hashes, IP addresses, domains (beyond the victim domain), mutex names, filenames, registry keys, ransom-note text, or hard-coded values attributable to the actor or malware. The victim domain (eogb.co.uk) is not an IOC — it is the victim's own domain.
7. Sources
- ransomware.live — "Ransomware: stormous named eogb.co.uk (GB)" — https://www.ransomware.live/id/ZW9nYi5jby51a0BBzdG9ybW91cw== — Published 2026-06-28T21:29:58 UTC
- ransomware.live — Victim page for eogb.co.uk (sponsored by Hudson Rock) — https://www.ransomware.live/id/ZW9nYi5jby51a0BBzdG9ybW91cw== — Accessed 2026-06-29
8. Adverse Trace position
This is a single-sourced, unconfirmed ransomware claim with no technical artefacts, no CVE association, and no MITRE-validated actor profile. The "stormous" attribution cannot be corroborated. The described activity — deep access to Microsoft Dynamics GP and exfiltration of financial, legal, and operational data — is consistent with a targeted data-theft/extortion operation, but the source provides no evidence of encryption or ransom demand, so the "ransomware" classification rests solely on the ransomware.live categorisation. For EMEA financial services clients: (1) if you have a direct relationship with eogb.co.uk, treat this as a potential third-party data breach and trigger your DORA Art. 17 incident management process; (2) if you operate Microsoft Dynamics GP, use this as a prompt to audit access controls and SQL Server security; (3) do not treat the attribution as confirmed for threat-hunting purposes — single-sourced; verify before enforcement. Adverse Trace will monitor for corroborating sources, additional claims by "stormous," and any emerging IOCs or technical details.
Published via PulseTrace — Adverse Trace threat intelligence.