Ransomware victim disclosure
← All victimsCONEX
Claimed by Nokoyawa · listed 3 years ago
Status timeline
- Listed
May 23, 2023
- Data leaked
At a glance
- Group
- Nokoyawa
- Status
- Data leaked
- Country
- France
- Sector
- Technology
- Listed on leak site
- May 23, 2023
About the victim
AI dossier — public-source company profileCONEX is a French SaaS software company specialising in customs procedure management, with over 30 years of experience. Their modular platform handles all types of customs declarations (Import, Export, NCTS, ICS2, EMCS, GVMS, etc.) and provides EDI interconnection between businesses, customs administrations, suppliers, and customers. The company operates across France, Belgium, the United Kingdom, and Ireland.
- Industry
- Customs Compliance & Trade Declaration Software (SaaS)
- Address
- France (CONEX SAS); Belgium (CONEX SRL); United Kingdom (CONEX SYSTEMS LTD); Ireland (CONEX SYSTEMS LIMITED). French headquarters reachable at Tel. +33(0)3 20 41 43 00, [email protected]
Attack summary
Severity: high — CONEX is a SaaS platform processing sensitive customs and trade compliance data for multiple corporate clients across several countries. A confirmed data publication by Nokoyawa implies exfiltration of significant business data that likely includes client customs records, trade transaction data, and potentially regulated cross-border trade information, representing serious exposure for CONEX and its downstream customers.The Nokoyawa ransomware group claims to have attacked CONEX and has published data ('data_published' status), though the leak post does not specify the volume of data exfiltrated or detail whether encryption of systems also occurred.
Data the group says was taken
AI dossier — extracted from the leak post- Customs declaration data
- EDI exchange records
- Customer business data
- Supplier interconnection data
- Internal business files
What the group claims
CONEX is a customs procedure management software specialist. Our SaaS platform, complete and modular, is dedicated to the treatment of all types of declarations. It’s our core business, and we master all the components of it. We cover all your interconnection needs with customs administrations...
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
