Ransomware victim disclosure
← All victimsLa Financière d'Orion
listed as La Financière d'Orion (finorion) · Claimed by Nova · listed 8 days ago
Status timeline
- ListedJul 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Nova
- Status
- Data leaked
- Country
- France
- Sector
- Financial Services
- Listed on leak site
- Jul 21, 2026
About the victim
AI dossier — public-source company profileLa Financière d'Orion is a French wealth management and financial advisory firm established in 2009, specializing in creating tailored financial engineering solutions for high-net-worth clients and wealth professionals.
- Industry
- Wealth Management & Financial Advisory
- Founded
- 2009
Attack summary
Severity: critical — Confirmed exfiltration of sensitive financial and client data at scale (20GB) from a wealth management firm; regulated financial sector with likely PII and privileged financial information of high-value clients.Nova claims to have exfiltrated approximately 20GB of client documents and company financial information from La Financière d'Orion. The group states it has sampled stolen data and is offering negotiation contact.
Data the group says was taken
AI dossier — extracted from the leak post- Client documents
- Company financial records
- Financial engineering records
What the group claims
Since 2009, we have been helping to create a privileged relationship between wealth professionals and their clients. The wealth of our experience allows us to deploy innovative, coherent financial engineering levers that are perfectly tailored to your aspirations and objectives - Nova have 20GB of clients documents data and company finance informations, for example convestion ERES.pdf, secrets is here, Contact us for more details, Nova Provide tree and samples from stolen data to the company when its get in touch with support department.
Sources
Source
Indexed 8 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

