ransomware
Credible
Morocco (MA)
finance
Eurodefi listed by the Qilin ransomware group
Eurodefi
CompanyEurodefi
Domaineurodefis.com
CountryMorocco (MA)
Sectorfinance
Breach date2026-07-10
People affected200,000
Ransomware groupqilin
Data typescustomer data, financial records, internal documents
Overview
The Qilin ransomware group has listed Eurodefi, a Moroccan financial services company, on its leak site. The listing appeared on 10 July 2026.
What was published
The group has listed the company as a victim but has not yet published data details. Financial services firms typically hold customer records, account information and transaction data, which are the likely contents of any exfiltration.
Risks for affected individuals
- Customer financial data may be exposed.
- Phishing using authentic account details becomes more plausible.
- Employees' records may be included.
What remains unknown
- Whether data has been exfiltrated.
- The volume of records involved.
- The timeline of any release.
What affected people should do
Customers should monitor account activity and be cautious of unsolicited messages. The company should notify affected customers and regulators, and review access controls on compromised systems.

Sources
- http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=63fc378c-2a9e-4383-82fd-e8075df9a758