The ransomware claim targets BCX (Business Connexion) at www.bcx.co.za in South Africa (ZA), attributed to threat actor incransom, and alleges a total leak of 500 GB across 4,224,088 files and 596,613 folders, including source code and confidential technical documentation. The exfiltrated materials include six fully functional business applications and numerous integration libraries/modules, along with claims that multiple vulnerabilities exist in current versions of the affected systems, impacting #SouthAfrica.
Incident Details
Information
- 500 GB of data leaked, including 4,224,088 files and 596,613 folders.
- The leak contains source code, technical documentation, and other confidential information.
- Source code includes 6 fully functional business applications.
- More than 15 integration libraries/modules were exposed.
- More than 10 test and utility projects were included in the leak.
- Exposed business applications include Cemetery Management / Cemres, mSCOA Posting Level Creator, SolarReceipting, PortalSSO / Solution_Menu, StopWatch Reports, and ChangeRequestManager.
- The integration platform includes WfService, SolarMenuStructure, AssemblyConnector, Purchase Requisition Connectors, BcxConnector, XMConnect, HelpRoutine, and Lookup Connectors.
- Numerous vulnerabilities were identified in current versions of the business applications.

Disclaimer: This post is based on public claims made by the ransomware group "incransom". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.