Nova, a ransomware crew that only surfaced in late March, has quietly become the busiest name on the extortion leak sites. Over the past three days the group posted claims against 12 organizations, more than any other gang tracked by IntelFusions, edging out the far better known Qilin (11 claims) and SafePay (9). Its targets span four continents, from an Indonesian university hospital to an Argentine public university and a French finance house.
The tally comes from Nova's own dark web leak site, where it names victims and threatens to publish stolen files unless a ransom is paid. That is an important caveat: these are unverified extortion claims, not confirmed breaches. None of the organizations listed has publicly admitted an intrusion, and leak-site posts exist to pressure victims into paying, so figures and even victim identities can be exaggerated or simply wrong.
Who Nova says it hit
The spree leans heavily on Indonesia and Latin America. In Indonesia the group listed Rumah Sakit Universitas Indonesia, the teaching hospital of the University of Indonesia, alongside a telecoms cooperative tied to Lintasarta and a listing it tagged simply "Dephub", the shorthand commonly used for the country's Ministry of Transportation. In Latin America it named the Universidad Nacional de Mar del Plata and the broadcaster Canal 9 Litoral in Argentina, plus several Brazilian firms. European entries include France's La Financiere d'Orion, a financial services company, and a Portuguese tourism operator.
Healthcare, education, government and finance turning up in the same short window is a familiar ransomware pattern, opportunistic rather than targeted, chasing whichever exposed networks the crew can reach. Nova has now logged roughly 80 claims since it emerged, 17 of them in the last two weeks, a sharp acceleration for a group barely four months old.
Part of a wider crowding
Nova's climb fits a trend IntelFusions has tracked all month, a churn of smaller and newer ransomware brands crowding the leak sites as older cartels fragment and their affiliates shop around. A no-name group topping the charts one week says less about Nova's sophistication than about how low the barrier to running an extortion operation has become.
What defenders should do
Nova's leak posts carry no malware samples or indicators of compromise, so there is nothing to add to a blocklist from these claims alone. The defensive posture is the usual one, and it holds up against most of these crews: enforce phishing-resistant multi-factor authentication on remote access and email, patch internet-facing appliances and VPNs quickly, keep offline and tested backups, and segment networks so a single compromised host cannot reach everything. Organizations in Indonesia and Latin America (see our Indonesia threat profile) should treat the current surge as a prompt to review exposure, not as evidence of one specific technical flaw.
If your organization turns up on a leak site, treat it as a live incident even before you can confirm what was taken: preserve logs, engage counsel, and where required notify regulators.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.