Ransom! FinSoft (Kolibri retail back-office software) (SEP-2026)

Ransom! FinSoft (Kolibri retail back-office software) (SEP-2026)
In Uzbekistan, the N0n ransomware group claims to have compromised FinSoft’s Kolibri retail back-office software, impacting client databases and the platform/API data used by 10+ retail chains (keddo, marc, lancaster, comf_rus, ek, cr, bas_at, bas_juk, bas_nov, bas_zar) including sales, stock, pricing, and financial records. The group alleges it will publish one client database per day after the deadline, starting with keddo, so clients will know exactly whose software failed them. #Uzbekistan

Incident Details

  • Victim: FinSoft (Kolibri retail back-office software)
  • Sector: Retail & E-Commerce
  • Country: UZ
  • Actor: N0n
  • Source: http://nongzecboljwv3yfndkggsybsglfrkffw7bvk2zemuteoxe6etpusnad.onion#v-finsoft
  • Discovered: 2026-09-22T01:51:38.794148+00:00
  • Published: 2026-09-22T01:51:21.337970+00:00

Information

  • Client databases from 10+ retail chains, including sales, stock, pricing, and financial records, as well as back-office platform and API service data
  • One client database will be published per day after the deadline, starting with keddo
  • Their clients will be able to see exactly whose software failed them
  • Deadline: 2026-09-25 01:06 UTC

Disclaimer: This post is based on public claims made by the ransomware group "N0n". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live