SOPEM listed by the hunters ransomware group
SOPEM
Overview
On 10 February 2024, the Hunters International ransomware group listed SOPEM on its leak site. SOPEM, based in Tunisia with the domain sopem.com.tn, was presented as a victim with data exfiltration and encryption confirmed by the group. The incident took place during a period of heightened Hunters International activity.
What was published
The Hunters International listing for SOPEM confirmed that data was exfiltrated and systems encrypted, but provided no record count or data inventory. The group has published archives for other victims, yet no download associated with SOPEM was observed during the analysis window.
Risks for affected individuals
Employees and business partners of SOPEM could be exposed if personnel files, financial records or client contracts were among the stolen data. Such information enables phishing, invoice fraud and impersonation of company representatives.
What remains unknown
The volume and categories of data taken, and whether the group published any files, remain unconfirmed. No official statement from SOPEM about the incident has been identified.
What affected people should do
Staff should reset passwords and enable multi-factor authentication on business accounts. Partners should verify payment instructions through official contacts and report any suspicious communication referencing SOPEM.
Sources
- https://hunters55rdxciehoqzwv7vgyv6nt37tbwax2reroyzxhou7my5ejyid.onion/companies/0302842103