Borrer Executive Search Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Borrer Executive Search Listed by apt73 Ransomware Group (reported June 13, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target professional services firms across Europe, using data theft and public leak-site listings as leverage. In this environment, even smaller specialist consultancies can appear on threat-actor sites, raising questions for clients, candidates and staff about what may have been taken.
On 13 June 2024, Borrer Executive Search, an AESC-accredited boutique search and selection firm based in Lausanne, Switzerland, was listed by the ransomware group apt73. The group claims to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the precise scale and method is limited. The listing itself is an unverified claim by the group.
Inside the incident
According to the available record, Borrer Executive Search was listed by apt73 on or around 13 June 2024. The group asserts that internal files were exfiltrated during a ransomware attack. Named material includes internal documents and agreements. No confirmed figure for the volume of data, the number of systems involved, or the exact date of initial access has been published. The number of people whose information may have been involved is listed as unknown. Whether encryption was deployed alongside exfiltration, and whether any ransom demand was made or paid, is not disclosed in the public facts. The incident is therefore known primarily through the group’s leak-site claim rather than through a detailed official disclosure.
The group behind it: apt73
apt73 is a ransomware operation that follows a pattern common among modern double-extortion groups: it claims to steal data before or during encryption, then lists the victim on a dedicated leak site to pressure payment. Such groups typically advertise stolen material in stages, sometimes releasing samples to demonstrate authenticity. Public reporting on apt73 has associated it with opportunistic targeting of mid-sized organisations rather than highly selective nation-state campaigns. Its tactics generally include initial access via phishing, compromised credentials or exposed remote services, followed by lateral movement, data staging and exfiltration. The group’s listing of Borrer Executive Search should be treated as a claim; independent confirmation of the full contents or the success of any attack has not been provided in the facts available here. Like other ransomware actors, apt73 relies on the reputational and regulatory risk of data exposure to extract payment, and its leak sites serve both as a pressure tool and as a public record of claimed victims.
About Borrer Executive Search
Borrer Executive Search is described as an AESC-accredited boutique search and selection firm headquartered in Lausanne, Switzerland. AESC accreditation indicates membership in a recognised professional body for executive search. Firms of this type specialise in identifying and placing senior executives and specialised talent for corporate clients. They routinely handle confidential candidate profiles, client engagement letters, contractual agreements, and internal working documents. Because the work sits at the intersection of human resources, corporate strategy and personal career data, a breach at such an organisation can affect both the firm’s clients and the individuals whose professional histories are held on file. The Swiss base places the firm under Swiss data-protection rules as well as, for many cross-border placements, the broader European regulatory framework.
What data was at risk
The facts state that internal files were exfiltrated and specifically mention internal documents and agreements. Beyond that description, the exact contents of the stolen material have not been publicly itemised. Executive-search firms typically hold curricula vitae, contact details, employment histories, compensation information, client contracts, non-disclosure agreements and internal correspondence. Whether any of those categories were present in the files claimed by apt73 remains unconfirmed. No inventory of personal data fields, no count of records, and no confirmation of financial or authentication credentials have been released. Readers should therefore treat the exposed set as “internal documents and agreements” as claimed, while recognising that the full scope is undisclosed.
What's at stake
For individuals whose information may have been among the internal files, the practical risks include unwanted contact, social-engineering attempts that reference genuine professional details, and longer-term exposure of career or compensation data. For corporate clients, the leakage of agreements or search mandates could reveal strategic hiring plans or commercial terms. For Borrer Executive Search itself, the incident carries reputational, contractual and regulatory consequences: Swiss and European data-protection authorities may expect notification and remediation if personal data were involved, and clients may reassess the firm’s handling of confidential material. Because the number of affected people is unknown and the precise data types beyond “internal documents and agreements” are unconfirmed, the concrete impact cannot yet be quantified. The absence of public detail does not eliminate the risk; it simply means affected parties must proceed on the basis of the limited information available.
If your data was in this claimed breach
If you have been a candidate, client or employee of Borrer Executive Search, treat the possibility of exposure seriously even though the full contents remain unconfirmed. Monitor professional email accounts and LinkedIn or similar profiles for unusual approaches that reference your background. Consider placing fraud alerts with credit bureaus if financial or identity data could have been present, and review any non-disclosure or engagement agreements for notification clauses. Change passwords on accounts that may have shared credentials with work systems, and enable multi-factor authentication where available. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. Keep records of any suspicious contact and report it to the appropriate authorities if it escalates. Public detail on this incident is limited; further official statements from the firm or regulators, if they appear, will provide the most reliable next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
n4telecom.com.br Listed by apt73 Ransomware Groupmelhorcompraclube.com.br Listed by apt73 Ransomware Groupwww.sella.eng.br Listed by apt73 Ransomware Groupwww.protectasecurity.pe Listed by apt73 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Borrer Executive Search Listed by apt73 Ransomware Group →
Publicly posted by apt73 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.