ctipilot.ch
← Back to the live brief
NOTABLENATOB1incident

BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file

discovered 2026-07-24 04:36 UTCrun 2026-07-24T0409Z-intel4 sourcesmulti-source

The extortion group BravoX — a Ransomware-as-a-Service operation first profiled on the RAMP underground forum in January 2026, which vets affiliates and by convention avoids CIS-based victims (SOCRadar, 2026-01-26) — breached an accounting/fiduciary firm in Yverdon-les-Bains (canton Vaud) around 30 June 2026, and on 18 July published roughly 220 GB (over 100,000 files) on its Tor leak site (Le Temps, 2026-07-22). The firm's own account describes a "connection problem" to its server that led its IT provider to isolate affected systems, revoke compromised access and restore from an external backup; no negotiation took place and no ransom was paid (Le Temps, 2026-07-22). The leaked dataset spans individuals, businesses and institutions, and includes administrative and tax records of some fifteen Nord Vaudois municipalities (Corcelles-près-Concise and Belmont-sur-Yverdon among those named) and the personal tax file of Vaud State Councillor Vassilis Venizelos and his spouse (24 heures, 2026-07-23). The firm filed a criminal complaint and notified both the cantonal data-protection commissioner and the Federal Office for Cybersecurity (BACS/OFCS) — Switzerland's mandatory critical-incident reporting channel (24 heures, 2026-07-23).

Le 18 juillet, quelque 220 Go de données y ont été publiées, soit plus de 100 000 dossiers.

Le Temps 2026-07-22

Aucune rançon n'a été versée. Une plainte pénale a été déposée et le préposé à la protection des données ainsi que l'Office fédéral de la cybersécurité ont été informés.

24 heures 2026-07-23

ATT&CK mapping

2 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Impact TA0040
T1486Data Encrypted for Impact

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

overlap matrix · ATT&CK page ↗

T1657Financial Theft

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.