Moores Data Breach

Alleged

Bravox ransomware claim involving Moores

Published: Aug 17, 2026 Bravox
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Moores
Industry
Retail & E-Commerce
Threat Actor
Bravox
Date of Incident
Aug 17, 2026

Executive Summary

Bravox ransomware claimed Moores as a victim on August 17, 2026, as identified through SOCRadar’s Dark Web Monitoring service. Moores is a UK-based retailer specializing in fitted kitchen and bedroom furniture, with a significant presence across the British market through showrooms and an online platform. This claim aligns with observed active stealer-log exposure, which is often indicative of credential-staging activities preceding a ransomware deployment. The nature of Moores’ business, serving consumers with home furnishings, can attract such attacks due to the potential for sensitive customer data and the perceived ability to disrupt operations impacting a broad customer base. In the 60 days preceding this listing, Bravox claimed six other victims. The group has predominantly targeted entities in Italy, Switzerland, and the United Kingdom, showing a sector preference for “Other,” “Retail & E-Commerce,” and “Not Found” categories. Recent comparable victims include Verona 83, Elettrica System, MEDICOS, and MITC AG. These examples highlight Bravox’s pattern of targeting European retailers and providers of light industrial services. Moores fits squarely within this established targeting profile, indicating a consistent approach by the ransomware group.

Technical Analysis

SOCRadar telemetry data revealed 25 records associated with the domain moores[.]co[.]uk. Among these, three credentials were classified as “employee-on-org-systems,” specifically targeting the internal authentication platform at miview.moores[.]co[.]uk, affecting login, submit, and registration endpoints. Additionally, three corporate email credentials from the @moores.co.uk domain were found associated with missing-host[.]com. This domain is known to be controlled by attackers and is consistent with compromised employee workstations exfiltrating credentials to external infrastructure. Ten external-user credentials were also identified on the miview authentication system, suggesting a possible compromise of supplier or contractor accounts. The observed stealer-log data spans from August 2025 to August 10, 2026. A notable observation is the persistence of one account cluster, identified as “geo****i,” which appeared 11 times across multiple email domains over a six-month period without any evidence of credential rotation. This pattern, combining direct access to internal authentication systems by employees and signals of workstation-based credential exfiltration, strongly suggests credential staging facilitated by initial access brokers (IABs) rather than incidental commodity infections. This method is frequently employed to gather the necessary credentials for subsequent ransomware deployment. Immediate actions should include revoking the three identified @moores.co.uk credentials. It is also recommended to audit the access logs for miview.moores[.]co[.]uk and review employee endpoints associated with the compromised accounts. Furthermore, the presence of missing-host[.]com as an exfiltration indicator warrants the implementation of an IOC block at the network level to prevent further communication with this malicious infrastructure.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.