Quick Summary
AllegedExecutive Summary
Buzz Trading 104 (Pty) Ltd, a financial services firm operating in South Africa, was identified on Krybit’s leak portal on August 2, 2026. SOCRadar’s Dark Web Monitoring service flagged this listing. The company operates within the financial services sector in South Africa. This incident adds to a consistent, moderate pattern of activity observed from the Krybit ransomware group. In the 60 days preceding this listing, Krybit claimed 29 additional victims. The group’s recent activity shows a concentration in the Technology, Financial Services, and Public sectors, with a focus on victims located in Mexico, South Africa, and India. Notable financial services victims within this timeframe include Eurohold Bulgaria AD, Euroins Insurance Company AD, Liberty Insurance Corporation, and Nile Petroleum Corporation. Buzz Trading’s targeting aligns with Krybit’s established patterns in terms of both industry and geographic focus.
Technical Analysis
Initial access correlation performed against SOCRadar’s stealer-log telemetry did not return any records for the primary corporate domain buzztrading104.co[.]za within the queried dataset. However, this absence of direct correlation does not confirm that the organization is unaffected. The query sampled a specific dataset and focused on the main corporate domain, potentially overlooking credentials exposed under alternate or legacy domains. Furthermore, the telemetry query may not capture credentials harvested using personal email aliases, which could be used for corporate access. Infostealer-harvested credentials are a common entry vector for groups like Krybit. Threat actors or their access broker affiliates often acquire credential logs from underground marketplaces, validate their working status, and then use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. It is important to note that the absence of records in the queried dataset does not rule out compromise. Credentials could have appeared in other data feeds not included in this analysis, may have been used and subsequently rotated before being indexed, or could have been harvested under personal aliases that would not be matched by a domain-specific query. Therefore, continued dark web monitoring, proactive credential hygiene checks, and thorough reviews of password rotation and multi-factor authentication policies remain essential. Monitoring of alternate corporate domains and activity on platforms like Microsoft 365 and VPNs is also recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.