ctipilot.ch

BravoX

actor · actor:bravox

Russian-speaking-convention Ransomware-as-a-Service extortion operation first observed on the RAMP underground forum in January 2026; vets affiliates and avoids CIS-based victims (SOCRadar, 2026-01). Breached a Vaud (Switzerland) fiduciary firm around 30 June 2026 and published ~220 GB / 100,000+ files on its leak site on 18 July 2026, exposing ~15 Vaud municipalities' administrative data and a cantonal minister's tax file (Le Temps / 24 heures, 2026-07-22/23).

Coverage timeline
1
first 2026-07-24 → last 2026-07-24
Peak priority
notable
1 notable
Sources cited
4
4 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Related entities below
ATT&CK techniques
2
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-24/bravox-vaud-fiduciary-municipalities-breach · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-07-24/bravox-vaud-fiduciary-municipalities-breach · ATT&CK page ↗

Story timeline

  1. 2026-07-24BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file
    active-threatsA breached Vaud accounting firm spilled 15 municipalities' administrative data — the fiduciary was the pivot, not any government network

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • active-threats1

Source distribution

  • 20min.ch1 (25%)
  • 24heures.ch1 (25%)
  • letemps.ch1 (25%)
  • socradar.io1 (25%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about BravoX (1)

2026-07-24 · view entry permalink →

NOTABLENATOB1

BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file

The extortion group BravoX — a Ransomware-as-a-Service operation first profiled on the RAMP underground forum in January 2026, which vets affiliates and by convention avoids CIS-based victims (SOCRadar, 2026-01-26) — breached an accounting/fiduciary firm in Yverdon-les-Bains (canton Vaud) around 30 June 2026, and on 18 July published roughly 220 GB (over 100,000 files) on its Tor leak site (Le Temps, 2026-07-22). The firm's own account describes a "connection problem" to its server that led its IT provider to isolate affected systems, revoke compromised access and restore from an external backup; no negotiation took place and no ransom was paid (Le Temps, 2026-07-22). The leaked dataset spans individuals, businesses and institutions, and includes administrative and tax records of some fifteen Nord Vaudois municipalities (Corcelles-près-Concise and Belmont-sur-Yverdon among those named) and the personal tax file of Vaud State Councillor Vassilis Venizelos and his spouse (24 heures, 2026-07-23). The firm filed a criminal complaint and notified both the cantonal data-protection commissioner and the Federal Office for Cybersecurity (BACS/OFCS) — Switzerland's mandatory critical-incident reporting channel (24 heures, 2026-07-23).

Le 18 juillet, quelque 220 Go de données y ont été publiées, soit plus de 100 000 dossiers.

Le Temps 2026-07-22

Aucune rançon n'a été versée. Une plainte pénale a été déposée et le préposé à la protection des données ainsi que l'Office fédéral de la cybersécurité ont été informés.

24 heures 2026-07-23
incident24 Jul 04:36Zmulti-sourceOpen finding ↗