Krybit ransomware claims Bulgaria's Eurohold and its Euroins insurer

A low-profile ransomware crew called Krybit has claimed one of Bulgaria's largest financial groups, listing insurance and investment holding Eurohold Bulgaria and its Euroins insurance arm on its dark-web leak site within a single day. The back-to-back postings, dated July 18 and 19, mark the most prominent targets yet for a group that has spent the past two months quietly amassing victims across dozens of countries.

As with all leak-site entries, these are unverified extortion claims posted by the attackers themselves, not confirmed breaches. Neither Eurohold nor Euroins has publicly acknowledged an intrusion, and Krybit has not released proof samples that IntelFusions has been able to review. Treat the listings as allegations until the companies or investigators say otherwise.

Why this one stands out

Eurohold Bulgaria is a publicly listed financial holding whose Euroins Insurance Group operates across South-Eastern Europe, making it a far bigger fish than the small and mid-sized firms that fill most of Krybit's victim list. Seeing a parent company and its insurance subsidiary appear on the same leak site a day apart suggests the attackers may have moved through shared corporate infrastructure rather than breaching two unrelated targets. Insurance and financial records are prized by extortion crews because they are both sensitive and heavily regulated, giving victims extra pressure to pay.

Who is Krybit

Since IntelFusions first tracked the group earlier this month, Krybit has behaved like a high-volume, opportunistic operation rather than a targeted one. Its leak site lists victims scattered across Mexico, Malaysia, Taiwan, Brazil, Germany, Israel and the Czech Republic, spanning business services, technology, healthcare, manufacturing and the public sector. The crew has repeatedly named government bodies, including a national audit court in Senegal and business registries in Bolivia, alongside schools and small manufacturers. The Bulgarian financial listings are a clear step up in profile, and an earlier claim against the Philippines' Liberty Insurance Corporation hints at a recurring interest in insurers.

What defenders should do

No public research yet ties Krybit to a specific initial-access method, so defenses rest on fundamentals. Organisations, especially in financial services, should enforce phishing-resistant multi-factor authentication on all remote access, patch internet-facing systems and VPNs promptly, and segment networks so an intrusion in one subsidiary cannot spread to a parent company. Because Krybit relies on stealing data and threatening to publish it, watching for unusual outbound data transfers and unexpected access to file shares matters as much as blocking the encryptor itself. Keep offline, tested backups so recovery never depends on the attackers' cooperation.

IntelFusions will update this profile if Krybit releases samples or if either company confirms an incident.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions