Codival listed by the spacebears ransomware group
Codival
Overview
On 20 August 2024, the Space Bears ransomware group listed Codival on its leak site. Codival, created in 1975 and formerly known as Brink's West Africa, is a subsidiary of the SAGAM International group specialising in cash-in-transit, cash processing, ATM management and electronic security in Cote d'Ivoire.

What was published
The Space Bears listing for Codival did not include a record count or data inventory. The group has published data for other victims, but no archive linked to Codival was observed during the analysis window. The company profile described its cash management services across the region.
Risks for affected individuals
Codival employees and the financial institutions it serves could be exposed if personnel records, client contracts or operational documentation were stolen. Data related to cash handling operations could inform social engineering attacks against banks and retailers using the service.
What remains unknown
The volume and categories of stolen data, and whether the group published files, are not confirmed. No official statement from Codival about the incident has been identified.
What affected people should do
Client organisations should verify communications referencing cash services through official channels and report suspicious messages. Employees should change passwords, enable multi-factor authentication, and monitor for unusual activity on company systems.
Sources
- http://5butbkrljkaorg5maepuca25oma7eiwo6a2rlhvkblb4v6mf3ki2ovid.onion/companies/35/codival