ransomware Potential Morocco (MA) finance

Shora Advisory listed by the Tengu ransomware group

Shora Advisory (shora.ma)

📅 20 February 2026 👁️ 2 views
CompanyShora Advisory (shora.ma)
CountryMorocco (MA)
Sectorfinance
Breach date2026-02-20
People affected200,000
Ransomware grouptengu
Data typesNot disclosed
<p>On 20 February 2026, the <strong>tengu</strong> ransomware group listed <strong>Shora Advisory (shora.ma)</strong> on its dedicated leak site in Morocco. The group claims to have exfiltrated data from the organisation, a financial services provider, before publishing the victim on its leak site.</p> <h2>What the source reveals</h2> <p>Shora Advisory is a network of accounting, consulting, and auditing firms located in major cities across Morocco, dedicated to providing high value-added services. They offer a range of services including financial management consulting, accounting expertise, legal and tax expertise, and training. The company focuses on proximity to clients, respecting their specific needs and constraints related to their industry. Shora Advisory aims to combine their expertise with that of their clients to foster mutual success</p> <h2>Risks</h2> <ul> <li>Exposure of client financial records, loan agreements, credit assessments, and banking transaction data</li> <li>Regulatory investigation by financial authorities if customer data protection standards were violated</li> <li>Fraudulent transactions and identity theft targeting affected customers using compromised account information</li> <li>Reputational damage affecting depositor confidence and client relationships</li> <li>Permanent loss of data integrity if backups were also compromised or encrypted</li> <li>Regulatory and legal consequences depending on data protection laws in the affected jurisdictions</li> </ul> <h2>What remains unknown</h2> <ul> <li>the volume and specific data types exfiltrated from the organisation</li> <li>the date of the initial intrusion and the attack vector used</li> <li>whether the organisation engaged with the attackers or paid any ransom demand</li> </ul> <h2>Conclusion</h2> <p>Ransomware attacks on financial institutions can expose sensitive client data and trigger regulatory consequences. The affected organisation should conduct a thorough forensic investigation, notify relevant regulatory authorities, and communicate transparently with affected stakeholders. Organisations in Morocco should review their ransomware preparedness, including offline backup verification and incident response testing.</p>