RANSOMWARE VICTIMDUPLICATE CLAIM

Exco

www.exco.com
sinobi📍 United States (US)📅 February 5, 2026
8
same group

Attack Intelligence

Exco was compromised in a ransomware attack attributed to sinobi in February 2026. The organization, operating in an undisclosed sector in United States, was added to the group's data leak site as part of an extortion campaign.

sinobi operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Exco is a network of accounting, consulting, and audit firms that simplifies entrepreneurship across France and internationally. They offer services in accounting, audit, tax, social management, human resources, and legal advice, ensuring tailored support for businesses in various sectors. With a commitment to responsible growth and expertise in complex financial situations, Exco provides guidance in corporate management, financial transactions, and sustainability. Their multidisciplinary teams work closely with clients to foster business development throughout every stage of a company's lifecycle.

Additional Details

Other Victims — sinobi (8)

Quick Facts

CountryUnited States (US)
Attack DateFeb 5, 2026
Domainwww.exco.com
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

sinobi
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.