ransomware Credible Morocco (MA) finance

Eurodefi listed by the Qilin ransomware group

Eurodefi

📅 10 July 2026
CompanyEurodefi
CountryMorocco (MA)
Sectorfinance
Breach date2026-07-10
People affected200,000
Ransomware groupqilin
Data typescustomer data, financial records, internal documents

Overview

The Qilin ransomware group has listed Eurodefi, a Moroccan financial services company, on its leak site. The listing appeared on 10 July 2026.

What was published

The group has listed the company as a victim but has not yet published data details. Financial services firms typically hold customer records, account information and transaction data, which are the likely contents of any exfiltration.

Risks for affected individuals

  • Customer financial data may be exposed.
  • Phishing using authentic account details becomes more plausible.
  • Employees' records may be included.

What remains unknown

  • Whether data has been exfiltrated.
  • The volume of records involved.
  • The timeline of any release.

What affected people should do

Customers should monitor account activity and be cautious of unsolicited messages. The company should notify affected customers and regulators, and review access controls on compromised systems.

Eurodefi leak listing

Sources

  • http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=63fc378c-2a9e-4383-82fd-e8075df9a758