Davroc Data Breach

Alleged

Ransomware claim involving Davroc.

Published: Aug 24, 2026 Booba Project
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Davroc
Industry
Technology
Threat Actor
Booba Project
Date of Incident
Aug 24, 2026

Executive Summary

Davroc, a UK-based technology company operating under davroc[.]co[.]uk, was listed on the Booba Project’s leak site on August 24, 2026. The Booba Project has historically focused its attacks on the Americas and Russia. The listing of a UK technology firm suggests a continued effort by the group to expand its reach into Western European markets. In the 60 days preceding this listing, Booba Project claimed 10 victims across the Business Services, Professional Services, and Technology sectors. Their primary geographic targets have been the United States, Russia, and Mexico. While the current victim’s location in the UK represents a departure from their typical geographic focus, Booba Project’s continued targeting of the technology sector aligns with their established patterns. Previous victims in similar sectors include Incredible Technologies, Federis Abogados, Country-Wide Insurance, and Chernyy & Associates.

Technical Analysis

SOCRadar’s stealer-log telemetry did not return any records associated with davroc[.]co[.]uk in the queried dataset. It is important to note that this telemetry represents a paginated sample of active log feeds and may not encompass all available data. Therefore, the absence of records does not confirm that the organization is unaffected or that no compromise has occurred. The limitations of the dataset mean that alternate corporate domains or credentials harvested under personal email aliases might not be captured. The operators of Booba Project typically acquire infostealer logs from underground markets. They then validate these credentials to gain access to corporate accounts through platforms such as Microsoft 365, VPNs, or remote-access portals before proceeding with ransomware deployment. For UK technology companies, it is common to utilize a combination of corporate and personal cloud accounts for development and client-facing operations. Credentials harvested from developer devices or personal accounts might not be reflected in queries targeting only corporate domains, a critical consideration for any credential hygiene assessment.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.