A threat actor named Nova has claimed to have encrypted the entire dataset of Novabio, a medical biology laboratory in France, including sensitive patient, doctor, partner, financial, and testing data totaling 500GB with millions of files such as PDFs, DOCs, XLSx, SQLs, and SSH keys. They assert readiness to provide a decryptor and delete all data, urging the affected organization to contact them immediately. #France
Incident Details
- Victim: Novabio (france laboratories)
- Country: FR
- Actor: nova
- Source: http://novadmrkp4vbk2padk5t6pbxolndceuc7hrcq4mjaoyed6nxsqiuzyyd.onion/#novabio-france-laboratories
- Discovered: 2025-12-10 05:44:00.856273
- Published: 2025-12-10 05:43:28.265786
Information
- Novabio, a medical biology laboratory in France, provides accurate health tests across southwestern regions including Dordogne and Gironde.
- The laboratory employs modern equipment and skilled professionals to conduct comprehensive medical examinations for community health support.
- They handle extensive data, including full information on patients, doctors, partners, financial data, screening results, and various files totaling 500GB, such as PDFs, DOCs, XLSx, SQLs, SSH keys, and more.
- The network has been encrypted by the ransomware actor, Nova.
- The threat actors are prepared to provide a decryptor and delete all compromised data.
- A sample can be provided upon request, and immediate contact is advised.
Disclaimer: This post is based on public claims made by the ransomware group "nova". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.