Corsica-Ferries Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Corsica-Ferries Listed by alphv Ransomware Group (reported October 27, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 27 October 2023, the Franco-Italian ferry operator Corsica-Ferries was listed by the ransomware group alphv. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.
The listing itself is a claim published on the group’s leak site. What is confirmed in available reporting is limited: the organisation’s name, the reported date, and the description of internal files taken during a ransomware incident. For passengers, staff and partners who rely on the company, even an unverified claim of this kind raises practical questions about what may have been exposed and what steps to take next.
What happened
According to the reported summary, Corsica-Ferries appeared on alphv’s listings on 27 October 2023. The available account describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. No public figure has been given for the volume of data, the precise systems involved, or the initial access method. The number of individuals potentially affected is listed as unknown. Timing beyond the reporting date, any ransom demand, and confirmation of whether data were later published are not detailed in the facts provided. The group’s leak-site entry should be treated as an unverified claim unless independently confirmed.
Inside alphv
Alphv, also widely known in public reporting as BlackCat, is a ransomware operation that emerged in late 2021 and has been documented as operating a ransomware-as-a-service model. Affiliates typically gain access to victim networks, move laterally, exfiltrate data, and deploy encryption, after which the group pressures victims by threatening to publish stolen material on a dedicated leak site. The group has been associated with attacks across multiple sectors and geographies; its tooling and negotiation style have been described in numerous independent security analyses. Those established patterns supply context for how such listings usually appear. They do not, however, prove the specific technical details of any single claimed intrusion. In this case, the only attribution tied directly to Corsica-Ferries is the group’s own listing and the accompanying description of internal-file exfiltration.
Who is Corsica-Ferries?
Corsica-Ferries, also operating as Corsica Sardinia Ferries, is a Franco-Italian ferry company that runs passenger and vehicle services to and from the islands of Corsica, Sardinia and Elba. Public descriptions characterise it as a leading operator on the Western Mediterranean, carrying more than 2.8 million passengers a year on routes linking France and Italy with those islands. Organisations of this type routinely manage booking systems, passenger manifests, payment records, crew and employee data, operational schedules, and commercial contracts with ports and suppliers. A ransomware incident affecting such an operator therefore touches both the travelling public and the internal workings of a transport business that moves large numbers of people across international routes.
The information in question
The facts name the exposed material only as “internal files exfiltrated in a ransomware attack.” No inventory of specific data categories—such as names, contact details, payment card numbers, passport or identity documents, employee records, or operational documents—has been published in the material supplied. Exact contents therefore remain unconfirmed. Ferry operators commonly hold passenger reservation data, loyalty or account information, crew personal records, and business documents. Whether any of those categories were among the files taken in this incident has not been established in the available reporting. Readers should treat claims about precise data types as unverified until corroborated by the company or by independent analysis of published samples.
Why it matters
When internal files leave an organisation during a ransomware event, the practical risks depend on what those files contain. If passenger or staff personal data were included, affected individuals could face phishing, identity misuse, or unwanted contact. If commercial or operational documents were taken, the company could confront competitive harm, regulatory scrutiny, or disruption to booking and sailing operations. Because the scale and exact contents are undisclosed, the concrete exposure for any given person cannot yet be measured. The incident still matters because transport operators sit at the intersection of consumer trust, cross-border travel, and critical scheduling; even limited confirmation of exfiltration is enough to justify caution and basic protective steps by anyone who has booked travel or worked with the company.
Were you affected?
If you have travelled with Corsica-Ferries, held an account, or worked with the company, treat the situation as a prompt for ordinary hygiene rather than panic. Monitor bank and card statements for unfamiliar charges, be wary of unexpected emails or messages that reference a ferry booking or refund, and consider changing passwords on any accounts that reused credentials tied to the company. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Official confirmation of what was taken, if any, will come from the company or from regulators; until then, the prudent course is to remain alert without assuming the worst.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
royaleinternational.com Listed by alphv Ransomware GroupUPDATE! FEAM Maintenance Listed by alphv Ransomware GroupFEAM Maintenance Listed by alphv Ransomware Grouppenanshin Listed by alphv Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Corsica-Ferries Listed by alphv Ransomware Group →
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.