nova ransomware reportedly claimed it compromised Centrul de Tehnologii Informaționale în Finanțe (CTIF), offering leaked data samples and a “tree” of stolen files to the victim when contacting their support channel. The actor allegedly targeted CTIF’s automated information systems supporting public finance, accounting, taxation, customs, and public procurement services. #
Incident Details
- Victim: Center Of Information Technologies In Finance Public Institution
- Sector: Financial Services
- Country:
- Actor: nova
- Source: http://pifk3xu3vad6cuxsjll4qjomyaaaoyvnyqppro75pazadzctrrvpdnyd.onion/center-of-information-technologies-in-finance-public-institution
- Discovered: 2026-07-24T22:57:47.407993+00:00
- Published: 2026-07-24T22:56:57.864195+00:00
Information
- Offers services and products for public authorities, budget institutions, economic agents, and individuals interested in financial information technology
- Focuses on managing, developing, and operating automated information systems for public finance, accounting, taxation, customs, and public procurement
- Provides training courses for professionals in public procurement
- Emphasizes transparency and communication with clients
- Claims to have data officially taken from the Minister Private Information Cloud
- States that Nova can provide a directory tree and samples of stolen data upon contact with the support department

Disclaimer: This post is based on public claims made by the ransomware group "nova". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.