Cosef Listed by Booba Team Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Cosef was listed by the Booba Team ransomware group on 23 September 2026. The group claims to hold data belonging to an undisclosed number of people, but no breach date or data types have been established; anyone connected to Cosef should verify their status and take protective steps.
A ransomware group known as Booba Team has listed Cosef on its leak site, asserting that it holds a large volume of material tied to the organisation's facilities-services website. As of writing, Cosef has not publicly confirmed the claim. For anyone who has dealt with Cosef—employees, contractors, suppliers, or people whose details may appear in facilities or service records—the practical question is simple: if the claim is accurate, what might be exposed and what steps reduce the risk of misuse.
Public detail is limited. The listing names a claimed data volume and a website domain, but does not establish how many people are involved, which files exist, or whether any material has been released. Treating the post as an unverified accusation, rather than settled fact, is the only responsible way to read it until Cosef, a regulator, or another independent source confirms otherwise.
What the listing says
According to the listing associated with Booba Team, Cosef appears on the group's leak site. The reported summary describes a facilities services website at cosef.fvg.it and claims “stolen data” amounting to 200 GB. The listing was reported on September 23, 2026. The number of people potentially affected is unknown. Specific data types named as exposed are not disclosed in the material provided.
Method of access, timing of any intrusion, whether encryption or extortion demands were used against Cosef systems, and whether any files have actually been published are undisclosed. Booba Team's listing is a claim by the group; it is not independent verification. Cosef has not publicly confirmed the claim as of writing.
Inside Booba Team
Booba Team is known in public reporting as a ransomware and extortion-style actor that pressures organisations by threatening to publish material on a dedicated leak site. Groups of this type typically advertise victims, assert large data volumes, and set deadlines meant to force payment or attention. Their posts function as marketing for the crew as much as as evidence; volumes, file inventories, and timelines on such sites are often unverifiable without the victim's or a forensic third party's confirmation.
Well-documented patterns among similar crews include double-extortion rhetoric—claiming both system disruption and data theft—and the use of leak portals to name organisations in facilities, industrial, or services sectors. For this specific listing, only what appears in the reported summary can be repeated: the group claims association with Cosef, a facilities-services website domain, and roughly 200 GB of material. No further statements attributed to Booba Team about Cosef beyond that summary are included in the available facts.
Cosef and its sector
Cosef is presented in the listing context as tied to facilities services, with a public-facing website under the cosef.fvg.it domain. Organisations in facilities and building-services work commonly manage contracts, site access, maintenance schedules, supplier relationships, and operational contacts for properties or public-sector clients. That kind of work often sits at the intersection of physical sites and administrative systems: work orders, vendor lists, and correspondence that can identify people who enter buildings or manage services.
A leak-site claim against a facilities-services operator matters because the sector routinely handles identity and contact data for staff and partners, and sometimes details that map to real locations and schedules. Even when a listing does not prove theft, the allegation alone can worry people who interact with the organisation. What the listing does establish is only that Booba Team chose to name Cosef; what it does not establish is confirmation of intrusion, the accuracy of the 200 GB figure, or any inventory of files.
What data was at risk
The facts do not name exposed data types; those details are not disclosed. The group's summary asserts a volume of about 200 GB linked to the facilities-services website, but that description is the attacker's claim, not a verified catalogue.
If files were taken from an organisation of this kind, firms in facilities services typically hold items such as employee and contractor contact details, customer or client service records, invoices and procurement data, building or site reference information, and internal documents used to coordinate maintenance and access. None of that inventory is confirmed here. Exact contents remain unconfirmed, and no public source in the given facts lists personal identifiers, financial account numbers, or other specific fields as having been taken.
What's at stake
For individuals, the conditional risk is misuse of personal or workplace information if material related to them were ever published or traded. That can include targeted phishing that references real employers or sites, attempts to reset accounts using known email addresses, or social engineering against colleagues and suppliers. For the organisation, a public extortion listing can disrupt trust with clients and partners even before any confirmation, and can create pressure to investigate systems, notify stakeholders, and coordinate with counsel or authorities under applicable rules.
Because people affected are unknown and data types are undisclosed, no one reading this should assume their own records are included. The stakes are real only if the claim proves accurate and if particular files match a person's relationship with Cosef. Conversely, dismissing every leak-site post without checking one's own exposure habits leaves people unprepared if fragments later appear in criminal markets.
What to do now
Remain calm and treat Booba Team's listing as an unverified claim until Cosef or an official source says otherwise. Practical steps stay conditional: act if you have reason to believe your information could be involved, not because a headline alone proves it.
- If you work with or for Cosef, watch for unexpected password resets, invoice changes, or messages that cite facilities jobs or internal names; verify requests through known channels.
- If you reuse passwords on work-related email, change them on important accounts and enable multi-factor authentication where available.
- Be sceptical of urgent calls or emails that reference a “Cosef breach” and ask for credentials, payments, or personal documents.
- Keep records of any suspicious contact and report fraud attempts to your bank or local authorities if money or identity theft is involved.
- Readers can run a free exposure scan of their email to check whether their information has surfaced in known breach data.
Public confirmation from Cosef would clarify scope; until then, the listing shows only what Booba Team chose to publish on its site, not a verified account of what, if anything, left Cosef's control.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
Washington County Listed by Booba Team Ransomware GroupSmart Eye Care Listed by Booba Team Ransomware GroupThe Merrimack County Listed by Booba Team Ransomware GroupTulare Western High School Listed by Booba Team Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Cosef Listed by Booba Team Ransomware Group →
Publicly posted by boobateam — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.