Nova ransomware actors claimed to target La Financi,ère d’Orion (finorion) in France, allegedly exfiltrating around 20GB of client documents and financial information including “ERES.pdf”. The threat actor reportedly provided tree/sample stolen data to the company when contacted, seeking support-driven engagement. #France
Incident Details
- Victim: La Financi,ère d’Orion (finorion)
- Sector: Financial Services
- Country: FR
- Actor: nova
- Source: http://pifk3xu3vad6cuxsjll4qjomyaaaoyvnyqppro75pazadzctrrvpdnyd.onion/la-financiere-d-orion-finorion
- Discovered: 2026-07-21T18:09:05.710193+00:00
- Published: 2026-07-21T18:07:53.434034+00:00
Information
- Since 2009, the organization has been helping to create a privileged relationship between wealth professionals and their clients.
- Its experience allows it to deploy innovative and coherent financial engineering solutions tailored to clients’ aspirations and objectives.
- Nova claims to possess 20 GB of client documents and company financial information.
- Examples of the stolen data include files such as “convestion ERES.pdf” and other confidential materials.
- The attackers state that the stolen data includes sensitive secrets and invite contact for more details.
- They also claim to provide a tree and samples of the stolen data once the company contacts their support department.

Disclaimer: This post is based on public claims made by the ransomware group "nova". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.