BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file
The extortion group BravoX — a Ransomware-as-a-Service operation first profiled on the RAMP underground forum in January 2026, which vets affiliates and by convention avoids CIS-based victims (SOCRadar, 2026-01-26) — breached an accounting/fiduciary firm in Yverdon-les-Bains (canton Vaud) around 30 June 2026, and on 18 July published roughly 220 GB (over 100,000 files) on its Tor leak site (Le Temps, 2026-07-22). The firm's own account describes a "connection problem" to its server that led its IT provider to isolate affected systems, revoke compromised access and restore from an external backup; no negotiation took place and no ransom was paid (Le Temps, 2026-07-22). The leaked dataset spans individuals, businesses and institutions, and includes administrative and tax records of some fifteen Nord Vaudois municipalities (Corcelles-près-Concise and Belmont-sur-Yverdon among those named) and the personal tax file of Vaud State Councillor Vassilis Venizelos and his spouse (24 heures, 2026-07-23). The firm filed a criminal complaint and notified both the cantonal data-protection commissioner and the Federal Office for Cybersecurity (BACS/OFCS) — Switzerland's mandatory critical-incident reporting channel (24 heures, 2026-07-23).
ATT&CK mapping
2 techniques mapped from the cited reporting · MITRE ATT&CK v19.1
Impact TA0040
T1486Data Encrypted for Impact
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
T1657Financial Theft
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.