LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Abv Listed by Medusalocker Ransomware Group

HIGH severityUnverified claimHow we verify

Abv Listed by Medusalocker Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 23, 2026
Abv Listed by Medusalocker Ransomware Group

Reported September 23, 2026.

HIGH
Severity
September 23, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Abv was listed by the Medusalocker ransomware group on September 23, 2026, with the group claiming to hold data belonging to an undisclosed number of individuals. Anyone who may have been affected should check official updates from Abv and follow recommended security steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to pressure organisations by posting names on leak sites, often before any independent confirmation exists. On 23 September 2026, the group known as Medusalocker listed Abv, associated with the domain abv.bg and Sofia, Bulgaria, among organisations it claims to have targeted. Public detail is limited: the listing is an accusation from an extortion crew, not a finding by the company, a regulator, or a breach index.

As of writing, Abv has not publicly confirmed the claim. What appears on a leak site may be exaggerated, recycled, incomplete, or false. Readers should treat the episode as an unverified claim and weigh practical precautions only if their own information might be involved.

What the listing says

According to the Medusalocker listing reported on 23 September 2026, Abv appears on the group’s leak site. The reported summary describes an organisation with 583 emails extracted and identifies the domain abv.bg in Sofia, Bulgaria. The number of people affected is unknown. Data types said to have been exposed are not disclosed in the available record.

Timing of any intrusion, technical method, full scale of any file access, and whether any material was actually published beyond the listing itself are undisclosed. The figure of 583 emails is part of the group’s reported summary; it is not an independently verified inventory of what, if anything, left Abv’s systems. Medusalocker has listed Abv; that is the concrete public claim. Nothing in the available facts establishes that a breach has been confirmed.

The group behind it: Medusalocker

Medusalocker is a name associated in public reporting with ransomware and extortion activity. Groups in this category typically encrypt systems or exfiltrate data, then threaten publication on a dedicated leak site to coerce payment. Listings are a form of pressure and marketing for the crew; they are not audited disclosures.

Well-documented patterns for such actors include double-extortion messaging, timed countdowns, and partial samples meant to increase urgency. Those general tactics do not prove what happened in any single case. For this incident, the only specific assertion tied to Abv in the given facts is the leak-site listing and the reported summary about 583 emails and the abv.bg domain. Any broader claim about files, internal systems, or ransoms for this victim is not stated in the record and should not be assumed.

Abv and its sector

Abv is identified in the listing material with the domain abv.bg and a location in Sofia, Bulgaria. Publicly, abv.bg is widely known as a major Bulgarian webmail and online services brand used by a large consumer and business audience. Organisations in email and consumer internet services typically sit at the centre of everyday communication, account recovery, and identity-linked activity.

A credible incident affecting such a provider would matter because email accounts often serve as the hub for password resets, personal correspondence, and links to other services. That consequence is conditional: it follows only if data were actually taken and if those data related to user accounts or mail content. The Medusalocker listing does not, by itself, establish that outcome. It establishes that a named extortion group has chosen to put Abv on a leak site and to circulate a short summary.

The information in question

The facts do not name exposed data types. They are not disclosed. The reported summary refers to 583 emails extracted; it does not itemise message bodies, attachments, password stores, billing records, or other categories, and it does not confirm that full mailbox contents were obtained.

If files or account-related material from a webmail or consumer internet provider were taken, organisations in this sector typically hold items such as account identifiers, email addresses, message metadata or content, contact lists, and authentication-related records. That is a sector-typical profile, not an inventory of this case. Exact contents remain unconfirmed. Readers should not treat the attacker’s marketing language as a catalogue of what is in circulation.

The real-world impact

Impact depends on whether the claim is accurate and on what, if anything, was copied. For individuals, conditional risks if email-related data were involved include targeted phishing that references real contacts or subjects, attempts to reset passwords on other sites using the same address, and social engineering that exploits trust in a familiar provider. For the organisation, a public listing can mean reputational strain, customer concern, and the operational cost of investigation—again only to the extent the underlying claim has substance.

None of these outcomes is proven by a leak-site entry alone. People affected are unknown. No confirmed count of compromised accounts, no verified sample of message content, and no regulator statement appear in the facts provided. The listing’s main established effect is attention and uncertainty, which is why calm verification matters more than assuming the worst.

What to do now

Treat the Medusalocker listing as a claim until Abv or an official authority confirms otherwise. If you use abv.bg or related services, practical steps remain useful whether or not this specific accusation is true:

You can run a free exposure scan of your email to check whether your address has already appeared in known breach datasets from other incidents. That check does not prove or disprove this particular listing, but it can show whether your address is already circulating from past events and help you prioritise password and monitoring hygiene. Stay conditional: act on the possibility that your data could be at risk, without assuming that Medusalocker’s claim about Abv has been verified.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAbv security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Abv’s full breach history →

More recent breaches

Frisby Roofing (Frisby Construction LLC) Listed by Medusalocker Ransomware GroupSeptember 12, 2026Aokkef Listed by Medusalocker Ransomware GroupSeptember 23, 2026Seznam Listed by Medusalocker Ransomware GroupSeptember 23, 2026Praveg Caves Jawai Listed by Medusalocker Ransomware GroupSeptember 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Abv Listed by Medusalocker Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusalocker — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram