ransomware Credible Côte d'Ivoire (CI)

Codival listed by the spacebears ransomware group

Codival

📅 20 August 2024
CompanyCodival
CountryCôte d'Ivoire (CI)
Sector
Breach date2024-08-20
People affectedNot disclosed
Ransomware groupspacebears
Data typesNot disclosed

Overview

On 20 August 2024, the Space Bears ransomware group listed Codival on its leak site. Codival, created in 1975 and formerly known as Brink's West Africa, is a subsidiary of the SAGAM International group specialising in cash-in-transit, cash processing, ATM management and electronic security in Cote d'Ivoire.

Leak site listing for Codival

What was published

The Space Bears listing for Codival did not include a record count or data inventory. The group has published data for other victims, but no archive linked to Codival was observed during the analysis window. The company profile described its cash management services across the region.

Risks for affected individuals

Codival employees and the financial institutions it serves could be exposed if personnel records, client contracts or operational documentation were stolen. Data related to cash handling operations could inform social engineering attacks against banks and retailers using the service.

What remains unknown

The volume and categories of stolen data, and whether the group published files, are not confirmed. No official statement from Codival about the incident has been identified.

What affected people should do

Client organisations should verify communications referencing cash services through official channels and report suspicious messages. Employees should change passwords, enable multi-factor authentication, and monitor for unusual activity on company systems.

Sources

  • http://5butbkrljkaorg5maepuca25oma7eiwo6a2rlhvkblb4v6mf3ki2ovid.onion/companies/35/codival