Quick Summary
AllegedExecutive Summary
MedusaLocker ransomware actors listed Abv, the operator of Bulgaria’s largest free webmail platform, abv[.]bg, on their dark web portal on September 23, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service. Abv’s platform serves millions of Bulgarian users, and a ransomware claim against a consumer webmail provider at this scale carries significant implications for both the organization’s infrastructure and its user base. In the 60 days prior to this listing, MedusaLocker claimed 18 other victims. The group has primarily targeted the Manufacturing, Technology, and general industry sectors, with France, India, and the United States being their dominant victim countries. Bulgaria is not a prominent geography in MedusaLocker’s recent activity, suggesting that Abv’s inclusion might represent a slight deviation from their typical targeting pattern. This listing on the same date as other entities, such as the Czech platform seznam[.]cz and French company Aokkef, indicates a possible batch publication of claims.
Technical Analysis
A query targeting the abv[.]bg domain revealed a severe exposure: 11 credentials classified as INTERNAL_AUTH_EMPLOYEE (Category A). These credentials indicate direct access to Abv’s identity and passport authentication endpoints, as well as Google Accounts sign-in records using @abv.bg corporate usernames. This type of exposure, where employee credentials authenticate to the company’s internal identity infrastructure, is particularly critical as it allows an attacker to authenticate directly as an employee without needing to escalate from a compromised workstation. The association with Google Workspace further expands the potential risk surface by including cloud productivity tools. The exposure of 11 Category-A credentials targeting internal authentication endpoints presents a high-severity precursor to a potential ransomware attack. This level of access suggests that threat actors could potentially gain privileged access within Abv’s network. Given the sensitive nature of the exposed credentials, immediate remediation actions are critical. The severity of this credential exposure necessitates immediate action to mitigate potential impacts. Key actions should include forced password resets across all affected accounts, a comprehensive audit of all identity provider sign-in logs to detect anomalous access patterns, and the enforcement of multi-factor authentication (MFA) on all critical identity endpoints.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.