FinSoft (Kolibri retail back-office software) Listed by N0n Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
FinSoft, provider of the Kolibri retail back-office software, was listed by the N0n ransomware group on 22 September 2026. Individuals are advised to check whether their information may have been involved and to monitor their accounts for unusual activity.
In the current ransomware landscape, extortion groups routinely post company names on leak sites before any independent verification exists, using countdown timers and partial sample claims to pressure payment. On September 22, 2026, the group that styles itself N0n listed FinSoft, described in the posting as a retail back-office software vendor associated with the Kolibri platform and linked to Uzbekistan, among other IT services activity.
That listing is an accusation published by the group, not a finding confirmed by FinSoft, a regulator, or a breach index. As of writing, FinSoft has not publicly confirmed the claim. What follows treats the leak-site material as claims, explains what such a listing does and does not establish, and outlines conditional steps people and client firms can take if the allegations later prove substantive.
What the listing says
According to N0n’s leak-site entry, FinSoft appears as an active listing with a stated deadline of 2026-09-25 01:06 UTC. The group claims the target is a retail software vendor and IT services provider and asserts access to client databases tied to more than ten named retail chains, including keddo, marc, lancaster, comf_rus, ek, cr, bas_at, bas_juk, bas_nov, and bas_zar. The listing’s own marketing language refers to sales, stock, pricing, and financial records, as well as back-office platform and API service data.
N0n further claims that after the deadline it will publish one client database per day, beginning with keddo, and frames the release as a way for those clients to see “whose software failed them.” The number of people affected is unknown in the available record. Method of intrusion, exact volume of material, and independent verification of the files are undisclosed. Public detail is limited to what the group chose to put on its site.
Who is N0n?
N0n operates in the familiar ransomware-and-extortion pattern: encrypt or exfiltrate data, threaten publication on a dedicated leak site, and use timed deadlines and staged dumps to increase pressure. Groups in this category often name victims, describe supposed data categories in broad terms, and sometimes drip sample files or client lists whether or not outsiders can validate them.
Well-documented public reporting on similar actors shows that leak-site posts can mix new material, recycled older dumps, exaggerated inventories, or false claims. Nothing in the FinSoft listing, as summarized in the available facts, constitutes proof that N0n’s description is accurate. For this victim specifically, only the group’s own claims are on record: the listing, the deadline, the named retail brands in the posting, and the threat of sequential client-database releases. No confirmed negotiation outcome or independent forensic summary is included in the facts provided here.
FinSoft and its sector
FinSoft is presented in the listing as a vendor of retail back-office software (Kolibri) and related IT services, with a geographic association to Uzbekistan. Organisations in this niche typically supply systems that help retail chains manage inventory, pricing, point-of-sale adjacent back office, stock movements, and internal financial or operational reporting. Those systems often sit close to day-to-day commerce data and may connect to APIs used by multiple client stores or brands.
A credible compromise at a shared back-office vendor would matter because one supplier can touch many retailers at once. Even an unverified leak-site claim can unsettle clients, partners, and staff who must decide how much weight to give an extortion narrative. The consequence of the listing itself is reputational and operational uncertainty for FinSoft and for any chain named in the post, separate from whether the underlying theft claim is later substantiated.
What was likely exposed
The facts state that data types named as exposed are not disclosed in a verified inventory sense; the categories above come from N0n’s listing language, which is attacker marketing rather than an audited file list. It is not established what, if anything, left FinSoft’s environment.
If files of the kind the group describes were taken, firms in retail back-office software and their chain clients typically hold material such as:
- Sales and transaction-related operational records
- Stock and inventory figures
- Pricing structures and related commercial data
- Internal financial or accounting extracts used in back-office workflows
- Platform configuration, API-related service data, and client database contents tied to branded retail operations
Exact contents, whether personal data of customers or employees appears, and whether any of the named chains’ live systems were involved remain unconfirmed. People affected are unknown. Readers should treat every category as conditional on the claim being true.
Why it matters
For individuals, risk depends entirely on whether personal or account-related information was actually among any taken files—an open question. If commercial retail databases were involved, exposure could in theory include workplace contacts, loyalty or customer fields sometimes stored alongside operations data, or credentials embedded in integrations; none of that is verified here. Fraudsters often monitor ransomware leak sites and may craft phishing that references FinSoft, Kolibri, or the named chains regardless of whether the dump is real.
For the organisation and its clients, a public extortion listing can disrupt trust, trigger contractual notice obligations, and force parallel investigations even when the post is incomplete or false. Staged “one database per day” threats are designed to maximise client-side pressure. What the listing establishes is only that N0n chose to name FinSoft and those brands on a deadline. What it does not establish is confirmed exfiltration, confirmed file contents, confirmed impact counts, or any verified failure of controls.
Steps worth taking either way
Because the incident is unconfirmed, responses should stay proportionate and conditional. If you are a customer, employee, or partner of FinSoft or of a retail brand named in the listing, useful steps include watching for unexpected password-reset or invoice messages that invoke this story, enabling multi-factor authentication on work and retail-related accounts, and verifying any urgent payment or data requests through known official channels rather than links in unsolicited mail. Client IT teams may wish to review shared credentials, API keys, and vendor access paths with FinSoft through normal support routes, without treating the leak-site text as a technical inventory.
If personal data were later shown to have been published, standard measures—credit or bank alerts where relevant, caution with identity documents, and documenting suspicious contact—would apply; that threshold has not been met in public confirmation as of writing. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in other known breach datasets, which is a separate check from this unverified listing. Stay with primary notices from FinSoft or the retailers you deal with if and when they issue them; until then, N0n’s post remains an allegation on a criminal leak site, not an established breach record.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Fanatics (global sports commerce platform) Listed by N0n Ransomware GroupInter (Venezuela's largest internet provider) Listed by N0n Ransomware GroupArgentem Creek Partners (investment firm) Listed by N0n Ransomware GroupBeLi Teacher / FSC education centers (AWS) Listed by N0n Ransomware GroupLatest breaches
Publicly posted by n0n — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.