Ransomware group "threeam" claims attack on German insurtech firm BSynchro Holding
By
Monitorman
A bagel you'd recommend to a friend without hedging.
Summary
A ransomware group called "threeam" has allegedly targeted bsynchro.com in Germany, disrupting BSynchro Holding's insurtech software operations. The attack impacted the company's CORA product configuration tools, which are used by insurance companies, brokers, and reinsurance brokers. The claim was made publicly by the threat actor, but the accuracy of the information cannot be independently confirmed.
Key quotes
· 2 pulledIn an alleged ransomware claim targeting bsynchro.com in Germany, the threat actor threeam disrupted BSynchro Holding's insurtech software operations, including its CORA product configuration tools used by insurance companies, brokers, and reinsurance brokers.
Disclaimer: This post is based on public claims made by the ransomware group 'threeam'. I cannot confirm the accuracy of the information.
You might also wanna read
Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
Investigating the Identity Behind the Ransomware Group 'The Gentlemen'
A cybercrime group called The Gentlemen has become the second most active ransomware gang by victim count, using an aggressive recruitment s

Allianz Life Confirms Data Breach Affecting Majority of 1.4 Million Customers
Allianz Life, a major U.S. insurance company, has confirmed that hackers stole personal data of the 'majority' of its 1.4 million customers,
Kaspersky Researchers Document New Infection Chains and IoCs in Notepad++ Supply Chain Attack
Kaspersky GReAT experts discovered previously undocumented infection chains used in the Notepad++ supply chain attack that occurred from Jun
Bitwarden CLI 2026.4.0 Compromised in Checkmarx Supply Chain Attack via GitHub Action
Socket researchers discovered that Bitwarden CLI version 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign. Th
Trivy Vulnerability Scanner Compromised in Supply Chain Attack That Harvested CI/CD Credentials
The article details a sophisticated supply chain attack on Aqua Security's Trivy vulnerability scanner in March 2026, where attackers inject
