NIS2 & DORA in force. EU AI Act next — book a demo
BREACHransomwarelive22 May 2026

Ransomware: nova claims AMACCAO — Not Found

BREACH. Sourced from ransomwarelive, summarised by Matproof.

AI Analysis

What changed and what to do.

A new ransomware group, operating under the name "nova," has claimed responsibility for an attack on the entity identified as "AMACCAO." The claim was published on the ransomware.live leak site on May 22, 2026, under the BREACH framework. At this time, no specific data or proof of exfiltration has been posted, but the listing indicates that the victim has been targeted and may face data exposure if demands are not met. The exact nature of AMACCAO is unclear, but based on naming conventions, it could be a public sector body, a healthcare institution, or a critical infrastructure operator in the EU.

Organizations in the public administration, healthcare, and critical infrastructure sectors should treat this as a high-priority alert. Any entity with similar naming patterns or operating under the AMACCAO acronym should immediately verify whether they have been compromised. The ransomware.live site is a known clearinghouse for threat actor claims, and this incident underscores the ongoing risk of extortion-driven attacks targeting EU-regulated entities.

Compliance teams should immediately conduct a sweep of their incident response logs for any unauthorized access or lateral movement indicators. They should also review their Data Protection Impact Assessments and breach notification procedures under GDPR, as any confirmed data exfiltration would require notification to the relevant supervisory authority within 72 hours. Finally, teams should ensure that their ransomware response playbook is updated and that backups are isolated and tested, as nova may deploy encryption or data theft tactics in the coming days.

View original at ransomwarelive

This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.

More BREACH updates

Latest in BREACH.

ransomwarelive23 May 2026
Ransomware: bravox claims Emek Elektrik (TR) — Energy

On 23 May 2026, a ransomware incident was reported involving the Turkish energy company Emek Elektrik, claimed by the threat actor Bravox. The event was published on the ransomware tracking platform…

← Back to all updates
Live regulatory monitoring

Never miss a compliance update.

Get weekly digests of DORA, NIS2, GDPR, MaRisk, and ISO 27001 changes — straight to your inbox. Free.

No spam. Weekly digest only. Unsubscribe anytime.

DORANIS2GDPRMaRiskISO 27001

Map this to your controls

Connect regulatory changes to your compliance work.

Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.

Book a DemoBrowse all updates