LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Center Of Information Technologies In Finance Public Institution Listed by nova Ransomware Group

HIGH severityUnverified claimHow we verify

Center Of Information Technologies In Finance Public Institution Listed by nova Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 24, 2026
Center Of Information Technologies In Finance Public Institution Listed by nova Ransomware Group

Reported July 24, 2026.

HIGH
Severity
1
Data types exposed
July 24, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Center Of Information Technologies In Finance Public Institution was listed by the nova ransomware group on July 24, 2026, after internal files were exfiltrated in a ransomware attack. Individuals connected to the institution should verify whether their data was exposed and follow recommended steps to protect themselves.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Center Of Information Technologies In Finance Public Institution Listed by nova Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

Ransomware groups continue to target public-sector technology providers that sit at the center of government finance systems, treating those organisations as high-value pressure points. In that landscape, a listing that appeared on 24 July 2026 drew attention to the Center Of Information Technologies In Finance Public Institution, also known as Centrul de Tehnologii Informaționale în Finanțe or CTIF.

The nova ransomware group has claimed responsibility for an incident involving the organisation and has stated that internal files were taken. Public detail remains limited: the number of people affected is unknown, and independent confirmation of the full scope has not been released. Even so, any compromise at a body that supports public finance, taxation, customs and procurement systems carries clear consequences for institutions and individuals who rely on those services.

Inside the incident

According to the available record, the Center Of Information Technologies In Finance Public Institution was listed by the nova ransomware group on 24 July 2026. The group’s claim describes a ransomware attack in which internal files were exfiltrated. No public figure has been given for the volume of data, the number of systems involved, or the precise method of initial access. The number of people affected is recorded as unknown.

Beyond the listing itself and the statement that internal files were taken, further operational detail has not been disclosed in the material provided. There is no confirmed timeline of when the intrusion began, how long it lasted, or whether encryption of production systems accompanied the alleged exfiltration. Readers should treat the group’s assertion as a claim pending fuller verification by the organisation or independent investigators.

The group behind it: nova

Nova is a ransomware operation that has appeared in public reporting as a group that combines data theft with encryption pressure. Like other actors in this category, it typically seeks to obtain internal material, then leverages the threat of publication or sale to compel payment. Listings on dedicated leak sites are a standard part of that model: the appearance of a victim name is presented by the group as proof of access, though such listings remain unverified claims until corroborated.

Public knowledge of nova’s broader activity indicates a focus on organisations whose data carries regulatory, financial or operational sensitivity. The group has not, in the facts available for this case, released detailed technical indicators or a full file inventory specific to CTIF beyond the assertion that internal files were exfiltrated. Any statements about motive, ransom demands or subsequent data dumps tied exclusively to this victim are therefore outside what can be stated from the record.

Center Of Information Technologies In Finance Public Institution and its sector

CTIF provides technology services and products aimed at public authorities, budget institutions, economic agents and individuals who need financial information systems. Its work centres on the management, development and operation of automated information systems used in public finance, accounting, taxation, customs and public procurement. It also offers training for professionals in public procurement and emphasises transparency and communication in its public posture.

Organisations of this type occupy a critical layer between government policy and day-to-day administration. They often hold or process configuration data, system documentation, operational records and interfaces that connect multiple agencies. A breach affecting such a centre is consequential because disruption or exposure can ripple outward to the authorities and economic actors that depend on those shared platforms, even when the precise contents of any stolen material remain unconfirmed.

What data was at risk

The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No further breakdown—such as databases, credentials, personal records, contracts or source code—has been disclosed. The number of individuals whose information might be involved is unknown.

Institutions that run public-finance and procurement systems typically maintain technical documentation, administrative correspondence, system logs, user or role data tied to institutional accounts, and records related to taxation, customs or budgeting workflows. Those categories are characteristic of the sector; they are not confirmed as present in this incident. Exact contents remain unconfirmed, and no inventory has been published in the available record.

The real-world impact

For people and organisations that interact with CTIF-supported systems, the practical risks centre on misuse of any internal material that may have left the environment. If administrative or technical files were among those taken, adversaries could attempt social engineering, secondary intrusion against connected agencies, or fraud that exploits knowledge of procurement and finance processes. Because the scale and composition of the data are undisclosed, the concrete exposure for any single individual or entity cannot be quantified from public information alone.

For the institution itself, a claimed ransomware event raises operational, reputational and continuity concerns. Restoring confidence among public authorities and economic agents that rely on its platforms requires clear communication and verified containment. Until fuller detail emerges, affected parties are left to manage uncertainty rather than a defined list of compromised records.

What to do if you're exposed

If you work with or rely on CTIF services, treat unsolicited requests for credentials, payment changes or urgent document transfers with heightened caution. Monitor official channels from the organisation for any notices about password resets, system outages or confirmed data categories. Where you hold accounts tied to public-finance or procurement platforms, enable strong unique passwords and multi-factor authentication where available, and review recent account activity for anomalies.

Individuals who want a practical next step can run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. That check does not confirm or rule out involvement in this specific incident, but it can highlight credentials that warrant immediate rotation and closer monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCenter Of Information Technologies In Finance Public Institution security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Center Of Information Technologies In Finance Public Institution’s full breach history →

More recent breaches

Koperasi Karyawan PT Aplikanusa Lintasarta Listed by nova Ransomware GroupJuly 21, 2026La Financière d'Orion (finorion) Listed by nova Ransomware GroupJuly 21, 2026SistNet Listed by nova Ransomware GroupJuly 25, 2026Digital Edge Listed by nova Ransomware GroupJuly 24, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Center Of Information Technologies In Finance Public Institution Listed by nova Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by nova — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram