Prelys Courtage Data Breach

Alleged

Ransomware claim involving Prelys Courtage

Published: Jul 28, 2026 Anubis
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Prelys Courtage
Industry
Business Services
Threat Actor
Anubis
Date of Incident
Jul 28, 2026

Executive Summary

Anubis ransomware has targeted Prelys Courtage, a financial services firm based in France. The listing appeared on the group’s dark web portal on July 28, 2026, and was identified by SOCRadar’s Dark Web Monitoring service. While Anubis currently has a modest victim count, its targeting patterns often include the financial sector and French entities. This specific victim fits both of these identified trends, making the incident noteworthy. In the 60 days preceding this listing, Anubis claimed seven other victims. These victims were primarily in the healthcare, financial services, and business services sectors. The geographic distribution of these previous victims included the United States, France, and the United Kingdom. Prelys Courtage’s listing aligns with Anubis’s preference for the financial sector and its established targeting of French organizations. Other recent victims of Anubis include KTR Real Estate Advisors, Quest Healthcare Solutions, Boston Orthotics & Prosthetics, and ESMS Global Limited, highlighting a consistent pattern in the group’s operations.

Technical Analysis

A check of stealer-log data for the domain prelyscourtage[.]com returned no relevant records within the queried dataset. It is important to note that this query covered only a limited, paginated sample of available data. As such, the absence of visible records does not definitively confirm that the organization is unaffected. Compromised credentials may exist under alternate corporate domains, or through alternative data sources not included in this specific query, potentially utilizing personal email aliases or having been used and rotated before indexing. The existence of infostealer-harvested credentials is a frequent initial access vector for ransomware groups like Anubis. Such credentials are often sold by initial access brokers on underground marketplaces. Threat actors then validate these credentials to gain access to corporate accounts, including those for Microsoft 365, VPNs, or remote-access portals. This access is subsequently leveraged to deploy ransomware. Therefore, the lack of observable data in this specific query, while noted, does not rule out the possibility of credential compromise supporting a potential intrusion path. The findings underscore the importance of continued monitoring and proactive security measures. Organizations should maintain ongoing vigilance for any credential exposure on the dark web and conduct regular credential hygiene checks, including comprehensive password rotation and multi-factor authentication reviews. Monitoring alternate corporate domains and scrutinizing activity logs for Microsoft 365, VPNs, and remote-access portals remain critical steps in mitigating potential risks associated with this threat.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.