COSEF – Consorzio di Sviluppo Economico del Friuli Data Breach

Alleged

Ransomware claim involving COSEF - Consorzio di Sviluppo Economico del Friuli.

Published: Sep 23, 2026 Booba Project
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
COSEF - Consorzio di Sviluppo Economico del Friuli
Industry
Business Services
Threat Actor
Booba Project
Date of Incident
Sep 23, 2026

Executive Summary

COSEF – Consorzio di Sviluppo Economico del Friuli, an Italian public-private economic development consortium, has been targeted by the Booba Project ransomware group. The organization was listed on the group’s dark web portal on September 23, 2026, as identified by SOCRadar’s Dark Web Monitoring service. COSEF operates at the intersection of public administration and business services, making it a potentially attractive target for threat actors seeking to disrupt critical infrastructure or extort public entities. This listing occurred as part of a batch of four victims claimed on the same date, suggesting a coordinated publishing effort by the ransomware group. Booba Project has claimed 14 other victims within a recent 60-day period, with a primary focus on the United States, but also showing a notable secondary interest in European targets. Their most frequently targeted sectors include Professional Services, Government & Defense, and Technology. Previous victims listed by the group include Washington County, Smart Eye Care, The Merrimack County, and GOTTHELF. COSEF’s Italian origin aligns with Booba Project’s documented pattern of targeting entities in Europe, complementing their dominant focus on U.S. victims.

Technical Analysis

A stealer-log query for the domain cosef.fvg[.]it returned zero records. This finding is consistent with the nature of a public consortium, which typically has less digital exposure in commercial infostealer feeds compared to private sector organizations. The absence of data in this specific dataset does not conclusively indicate that the organization is unaffected by credential compromise. Coverage limitations apply to this query. It is possible that credentials may exist under alternate corporate domains or within feeds not captured by this particular search. Therefore, the lack of stealer-log records for cosef.fvg[.]it does not rule out the possibility of credential exposure through other means. Booba Project’s known modus operandi, which involves using infostealer-harvested credentials for initial access, remains a plausible threat vector. The observed lack of stealer-log records for a public consortium like COSEF is not unusual. Such organizations may not consistently appear in the same feeds as private sector entities. This does not diminish the potential threat posed by Booba Project, as they may have gained access through alternative methods or different data sources. Recommended Actions: Review VPN and remote-access authentication logs for anomalous activity. Credential hygiene audit for all staff with external-facing accounts. MFA enforcement on Microsoft 365 and all remote-access portals.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.