Eurohold Bulgaria AD Data Breach

Alleged

Ransomware claim involving Eurohold Bulgaria AD

Published: Jul 19, 2026 Krybit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Eurohold Bulgaria AD
Industry
Financial Services
Threat Actor
Krybit
Date of Incident
Jul 19, 2026

Executive Summary

Eurohold Bulgaria AD, a financial services organization based in Bulgaria, has been listed on the Krybit ransomware group’s dark web leak portal, with the entry published on July 19, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. The company operates within the financial services sector, and its addition to Krybit’s victim population aligns with the group’s recent targeting activities. The company’s position in the financial services industry and its operating location in Bulgaria make it a potential target for ransomware operations. In the 60 days leading up to this listing, Krybit claimed 30 other victims. The group has primarily targeted the technology, public sector, and business services industries, with a notable concentration of victims in Germany, Taiwan, and Bulgaria. Recent Krybit victims with a similar profile to Eurohold Bulgaria AD include Euroins Insurance Company AD, Liberty Insurance Corporation, Servicio Plurinacional de Registro de Comercio, and Hôpital Catholique Saint Joseph Moscati. Eurohold Bulgaria AD’s targeting appears consistent with the group’s opportunistic strategy of targeting mid-market financial services entities, rather than deviating from its usual pattern.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry revealed a significant exposure for the eurohold.bg domain. The analysis uncovered 3 records indicating employee credentials linked to organizational systems, 2 records showing corporate users on third-party services, and 1 record associated with customer, supplier, or external accounts on company-owned systems. Notable high-value endpoints observed included a corporate credential on IBM’s enterprise platform and an internal HR portal on the corporate domain. The data suggests a prevalent risk of corporate intrusion, with the observed sample freshness spanning May 2025 to February 2026. The long-tail persistence indicates that some credentials may not have been rotated, presenting an ongoing risk. For ransomware groups like Krybit, credentials harvested by infostealers serve as a common initial-access vector. Threat actors or initial-access brokers often source fresh logs from underground marketplaces, validate the corporate credentials, and then use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log evidence presented here does not definitively confirm that these specific credentials were utilized by Krybit, the observed pattern is consistent with the typical kill chain for this type of incident. CTI teams are advised to prioritize credential rotation and enforce multi-factor authentication for the exposed accounts. Furthermore, endpoint reviews for compromised accounts are recommended, and this exposure should be treated as an active risk rather than a past event.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.