Quick Summary
AllegedExecutive Summary
Country-Wide Insurance, a US-based insurance company operating under cwico[.]com, was listed on the Booba Project’s leak site on August 24, 2026. Insurance providers are frequently targeted by ransomware operators due to the sensitive policyholder data they hold and the significant operational downtime costs they face if compromised, creating substantial leverage for extortion. In the 60 days preceding this listing, Booba Project claimed 10 victims, primarily targeting the Business Services, Professional Services, and Technology sectors. The group’s main geographic focuses are the United States, Russia, and Mexico. Their activity within the US has encompassed a variety of sectors, including legal firms, insurers, and technology providers, indicating a diverse but geographically concentrated targeting strategy. Previous victims attributed to Booba Project include Betz Industries, Incredible Technologies, Oklahoma Manufacturing Alliance, and Pelli Clarke Pelli Architects.
Technical Analysis
SOCRadar’s stealer-log telemetry query for cwico[.]com returned no records for the analyzed dataset. It is important to note that this dataset represents a paginated sample and does not encompass all active log feeds, alternative corporate domains, or credentials harvested using personal email aliases. Therefore, a negative result does not confirm that the organization has no credential exposure or is unaffected by compromise. Booba Project operators are known to acquire infostealer logs from underground marketplaces. They then validate corporate credentials found within these logs to gain access to systems such as Microsoft 365, VPN gateways, or remote-access portals, prior to deploying ransomware. Insurance companies often utilize agent portals and integrate with third-party systems, which can present separate credential exposure points beyond the primary corporate domain. Consequently, the current stealer-log coverage for cwico[.]com should be extended to include any affiliated agent or claims portals to ascertain the full scope of potential credential exposure.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.