Dansoft Listed by nova Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Dansoft was listed by the nova ransomware group on July 13, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of individuals may have been affected; anyone connected to Dansoft should verify their exposure and take protective steps.
On July 13, 2025, the ransomware group known as nova listed Dansoft on its leak site, claiming the company had been hit by a ransomware attack that included the exfiltration of internal files. Public detail remains limited: the number of people affected is unknown, and no further confirmation of the incident has been independently verified beyond the group's claim.
For an organisation that develops enterprise software and provides related IT services, any such listing raises immediate questions about the security of internal systems and the potential exposure of business-critical material. What follows is a factual account of what is known so far.
What happened
According to the available record, Dansoft was listed by the nova ransomware group on July 13, 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. No public information has been released about the precise timing of the intrusion, the scale of systems affected, the encryption status of any data, or the method of initial access. The number of individuals whose information may have been involved remains unknown. The listing itself constitutes an unverified claim by the threat actor; no independent confirmation of the breach has been reported in the provided facts.
Inside nova
Nova is a ransomware group that has operated in the public domain using a double-extortion model. In this approach, operators typically encrypt victim systems while also copying data off the network, then threaten to publish the stolen material on a dedicated leak site if a ransom is not paid. The group has previously listed organisations across multiple sectors, using these public postings as pressure tactics. Listings of this kind are claims made by the actors themselves and do not automatically prove that every asserted detail is accurate. In the case of Dansoft, the only specific assertion recorded is that internal files were taken during a ransomware incident; no additional statements by nova about this particular victim appear in the available facts.
About Dansoft
Dansoft was established in 1989. It originally concentrated on defence-related projects before shifting its focus to the development of ERP and enterprise software systems used across various industries. The company also offers IT executive services and cloud hosting. Organisations of this type typically maintain repositories of proprietary source code, customer configuration data, internal operational records, and employee or contractor information necessary to deliver software and hosting services. Because Dansoft works with enterprise clients, a compromise of its systems can have downstream effects on the businesses that rely on its products and infrastructure. The potential sensitivity of both historical defence-related work and current commercial software development makes any confirmed data loss consequential for the company and its partners.
What was likely exposed
The facts state only that internal files were exfiltrated in a ransomware attack. Exact contents have not been disclosed. Organisations that build ERP platforms and provide cloud hosting commonly hold a range of material whose exposure would be significant, yet none of the following can be confirmed as present in this incident:
- Proprietary source code and development documentation
- Customer contracts, configuration files, or operational data
- Employee or contractor records
- Internal administrative and financial documents
- Credentials or access information related to hosted environments
Because the precise inventory remains unconfirmed, any assessment of what was taken must stay provisional.
The real-world impact
For individuals whose details may appear in the exfiltrated files, the primary risks include targeted phishing, identity misuse, or unsolicited contact that leverages knowledge of their relationship with Dansoft or its clients. Employees and contractors could face credential-stuffing attempts if login data was among the material taken. For Dansoft itself, the consequences include potential disruption of software development and hosting services, reputational harm among enterprise customers, and the operational cost of investigating and remediating the intrusion. Clients that depend on Dansoft’s ERP systems or cloud infrastructure may need to reassess their own exposure if any of their data was stored or processed on the affected environment. Until more detail emerges, the full scope of these effects cannot be quantified.
Were you affected?
If you have worked with Dansoft as an employee, contractor, or customer, treat the possibility of exposure seriously even though the number of people affected is unknown. Practical first steps include monitoring financial and email accounts for unusual activity, enabling multi-factor authentication wherever available, and changing passwords that may have been reused across services. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Remain cautious of any unsolicited messages that reference Dansoft or claim knowledge of internal systems; such contacts may themselves be opportunistic fraud attempts. Further public updates will be needed before a definitive picture of this incident can be formed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
CYMA SYSTEMS Listed by nova Ransomware GroupHostingFest Listed by nova Ransomware GroupComputer Ingenuity Associates Listed by nova Ransomware GroupSky devices Listed by nova Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Dansoft Listed by nova Ransomware Group →
Publicly posted by nova — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.