Novasport s.r.o. Data Breach

Alleged

Ransomware claim involving Novasport s.r.o.

Published: Jul 21, 2026 Akira
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Novasport s.r.o.
Industry
Consumer Services
Threat Actor
Akira
Date of Incident
Jul 21, 2026

Executive Summary

Akira ransomware has claimed Novasport s.r.o., a consumer services company based in the Czech Republic, as a victim, with the listing appearing on July 21, 2026. This incident marks another entry in the Akira group’s prolific activity, underscoring the challenges in accurately identifying all affected entities and domains within a data breach claim. The nature of Novasport’s business and its potential data holdings may attract ransomware operations seeking value through extortion. The Akira group has been highly active, claiming 56 other victims in the 60 days preceding this listing. Their primary targets are typically found in the business services, manufacturing, and consumer services sectors, with a strong geographical focus on the United States, followed by Canada and the UK. While Novasport aligns with the consumer services vertical, its Central European location is outside Akira’s usual geographic focus. Previous consumer services victims include U.S. companies Finer & Finer and DDC Domus Design Collection, as well as Excalibur Rentals and Australia’s Oaks Park.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed an exposure linked to leki[.]com, a domain identified as an e-commerce property rather than a direct match to Novasport’s corporate domain. This observation indicates that the detected credentials may pertain to associated web properties and do not definitively confirm an initial access path for Akira ransomware against Novasport itself. The stealer-log sample contained approximately two dozen records, predominantly containing customer accounts from consumer email providers interacting with the website and its subdomains. Crucially, no employee credentials were found in this specific dataset. A single credential for an administrative portal on a subdomain was noted, and the recurrence of several usernames across different dates suggests potential credential reuse or ongoing data harvesting. The timeframe of the exposed data extended from late 2025 through mid-July 2026, profiling risks related to customer account takeover and supplier chain vulnerabilities. While this telemetry does not directly implicate Novasport in a compromise by Akira, there remains a possibility that corporate credentials could exist under Novasport’s actual domains, which were not included in this particular query. It is important to note that infostealer logs are a common method for ransomware groups like Akira to gain initial access. However, the disconnect between the queried domain and Novasport’s corporate estate, along with the nature of the exposed records (customer accounts), means this information does not confirm an Akira intrusion route against Novasport. The administrative portal credential found warrants scrutiny on the associated property (leki[.]com) rather than leading to assumptions about Novasport’s main infrastructure. To ensure a comprehensive understanding of potential security risks, it is recommended to broaden the credential search to encompass Novasport’s own domains and continue monitoring for any further related activity.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.