LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Popovici Niu Stoica & Asociaii Listed by losttrust Ransomware Group

HIGH severityUnverified claimHow we verify

Popovici Niu Stoica & Asociaii Listed by losttrust Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 26, 2023
Popovici Niu Stoica & Asociaii Listed by losttrust Ransomware Group

Reported September 26, 2023.

HIGH
Severity
September 26, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Popovici Niu Stoica & Asociaii Listed by losttrust Ransomware Group (reported September 26, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 26, 2023, the Romanian law firm Popovici Niu Stoica & Asociaii was listed by the ransomware group losttrust. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.

For clients, counterparties, and others who may have shared information with the firm, the listing raises straightforward questions about what left its systems and what practical steps follow. What is confirmed so far is limited to the group's claim and the description of internal files taken during the incident.

Breaking down the breach

According to the available record, Popovici Niu Stoica & Asociaii appeared on a losttrust listing dated September 26, 2023. The reported summary describes internal files exfiltrated in a ransomware attack. No figure has been given for the volume of data, the number of affected individuals, or the precise window in which the intrusion occurred. Method of initial access, duration of presence in the environment, and any ransom demand are undisclosed.

The listing itself is a claim by the group. Independent confirmation of the full scope has not been supplied in the public facts. In the absence of those details, the incident is best understood as an asserted ransomware event involving exfiltration of internal material, with scale and exact contents still unconfirmed.

The group behind it: losttrust

Losttrust is a ransomware operation that became visible in 2023 and has followed the familiar double-extortion pattern used by many contemporary groups: encrypting systems where possible while also copying data and threatening to publish it on a dedicated leak site if payment is not made. The group typically posts victim names, sometimes with sample files or descriptions, to increase pressure. Its public activity has included listings across multiple sectors and countries rather than a single narrow focus.

As with other actors of this type, losttrust's leak-site entries are claims. They do not by themselves prove every asserted detail about a given victim. In this case, the facts state that the group listed Popovici Niu Stoica & Asociaii and described internal files as having been exfiltrated; no additional specific statements by the group about this firm are recorded in the provided material. Readers should treat the listing as an unverified assertion pending further corroboration.

Who is Popovici Niu Stoica & Asociaii?

Popovici Nițu Stoica & Asociații is described as one of the first incorporated professional partnerships in Romania. The firm acts as outside counsel to a wide spectrum of legal entities, including key players in major industries, financial institutions, public authorities, and investment funds. It has been associated with the creation of essential Romanian market-economy institutions after 1990, including property funds, stock exchanges, numerous regulatory agencies, and judicial bodies. For decades it has been involved in significant investment and acquisition projects on the local market.

Law firms of this profile routinely hold privileged correspondence, transaction documents, corporate records, personal data of clients and employees, and material tied to regulatory or dispute work. A breach affecting such an organisation is consequential because the data often concerns third parties who had no direct relationship with the attack itself, and because legal professional material can carry lasting confidentiality and competitive sensitivity.

What was likely exposed

The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No inventory of file types, client matters, or personal-data categories has been published in the record. Exact contents therefore remain unconfirmed.

Organisations of this kind typically maintain:

Any of the above could have been among the internal files taken; none of them should be treated as verified for this incident until corroborated. The number of people affected is explicitly unknown.

What's at stake

For individuals whose information may have been held by the firm, the practical risks include unwanted contact, attempted fraud that leverages knowledge of real legal or financial matters, and the long-term circulation of personal or professional details. Because law-firm files often contain context about transactions, disputes, or personal circumstances, even partial exposure can be useful to criminals who craft convincing phishing or social-engineering attempts.

For the organisation, the stakes include disruption of client work, potential regulatory and professional-confidentiality obligations, and the need to investigate and remediate without a full public accounting of what left the network. Clients and partners may face secondary exposure if their documents or identifiers were among the internal files. None of these outcomes is asserted as proven fact here; they are the ordinary consequences that follow when a professional-services firm is listed in a ransomware exfiltration claim and the precise data set is unknown.

If your data was in this claimed breach

If you have a past or present relationship with Popovici Niu Stoica & Asociaii and are concerned your information may have been involved, begin with basic precautions. Monitor account statements and credit activity for unfamiliar transactions. Treat unsolicited messages that reference legal matters, investments, or personal details with caution, and verify any such contact through independent channels. Change passwords on important accounts if you reuse credentials, and enable multi-factor authentication where it is available. Consider placing fraud alerts with relevant credit or identity services if you believe sensitive identifiers were held by the firm.

Because the number of people affected and the exact data types remain undisclosed, there is no public list of individuals to check against. You can run a free exposure scan of your email address to see whether it has already appeared in known breach data sets elsewhere. Keep records of any suspicious contact and report clear fraud attempts to the appropriate authorities. Further official statements from the firm, if issued, should be read carefully for concrete guidance on this incident.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPopovici Niu Stoica & Asociaii security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Popovici Niu Stoica & Asociaii’s full breach history →

More recent breaches

SydganCorp Listed by losttrust Ransomware GroupSeptember 26, 2023Leiblein & Kollegen Steuerberatungsgesellschaft Listed by losttrust Ransomware GroupSeptember 26, 2023Gateseven Media Group Listed by losttrust Ransomware GroupSeptember 26, 2023EWBizservice Listed by losttrust Ransomware GroupSeptember 26, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Popovici Niu Stoica & Asociaii Listed by losttrust Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by losttrust — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram