Genesis Ransomware Claims Boyum IT Solutions as Victim

Unverified GENESIS claim names Boyum IT Solutions as victim

Genesis ransomware has reportedly listed Boyum IT Solutions as a victim on its leak site. This alleged incident, surfacing online on 30 July 2026, has raised questions within the cybersecurity community, particularly among organisations relying on SAP Business One add-ons or related services from Boyum. However, the claim remains unverified, with no technical evidence or further details currently available.

Genesis Ransomware Leak: Event Details and Timeline

The report of Boyum IT Solutions being targeted by Genesis ransomware emerged from a post on the group’s dark web leak site. The posting dated 30 July 2026 named Boyum IT Solutions, a Danish technology services provider, as a recent victim. The leak is noteworthy given Boyum’s role in providing software extensions and add-ons for SAP Business One, a widely used enterprise resource planning (ERP) solution among small and medium-sized businesses.

Despite the potential seriousness of the claim, the public post offers no further technical detail. There is no mention of ransom demands, payment instructions, or details regarding data exfiltration, system encryption, or the type of data allegedly compromised. The listing does not include screenshots, downloadable samples, or any evidence to substantiate that the attack occurred or that Boyum IT Solutions has suffered operational disruption.

  • Victim: Boyum IT Solutions (Denmark)
  • Threat actor: Genesis ransomware group
  • Post date: 30 July 2026
  • Affected products/services: Not specified
  • Systems or data targeted: Not specified

The source that surfaced this information, RedPacket Security, has also issued a verification alert. It notes that Genesis ransomware leak listings are currently viewed with suspicion in the threat intelligence community, as several previous posts by this group have been found to contain fabricated or unverified victim claims. The post urges readers to treat the claim as unconfirmed until independent evidence emerges, such as a direct statement from Boyum IT Solutions or corroboration from other reputable cybersecurity sources.

Who Is Affected by the Genesis Ransomware Claim?

Boyum IT Solutions is best known for its suite of software products that extend the functionality of SAP Business One. Its customer base spans across Europe and beyond, with many UK small and medium-sized businesses (SMBs) relying on Boyum’s add-ons for inventory management, production, and business process automation.

Given the lack of technical details, it is not possible to determine whether the incident (if real) has affected Boyum’s internal infrastructure, its customer data, or its commercial operations. SAP Business One users who depend on Boyum’s add-ons should pay close attention to any advisories or updates from the vendor. As of now, there is no evidence of data leaks, downloads, or operational impact affecting Boyum’s customers.

  • Boyum IT Solutions’ direct customers
  • SAP Business One users leveraging Boyum add-ons
  • SMBs in the UK and Europe with supply chain links to Boyum

At present, no official communications from Boyum IT Solutions have confirmed or denied the incident. There are also no public notifications regarding potential data breaches or ransomware payments. The only information available remains the single, unsubstantiated entry on the Genesis leak site, as relayed through RedPacket Security’s automated monitoring.

How Genesis Ransomware Attacks Typically Work

The Genesis ransomware group has gained notoriety for its use of dark web leak sites to publish details about alleged victims, often as part of its extortion strategy. In typical ransomware operations, attackers gain access to an organisation’s network, encrypt critical data, and exfiltrate sensitive information. Victims are then pressured to pay a ransom in exchange for a decryption key or to prevent the publication of stolen data.

However, in this case, the Genesis post does not provide any details about the mode of compromise, the ransomware variant used, or the attack vector. There are no indications whether any systems were encrypted, whether data was exfiltrated, or if any ransom demand was made. The absence of screenshots, file samples, or technical indicators further complicates efforts to validate the claim.

  • Usual Genesis tactics involve extortion through data leaks
  • Leak site postings often list victim names and alleged proof
  • Unsubstantiated claims can be used to create reputational risk or pressure targets

Recent analysis by threat intelligence sources, including BankInfoSecurity, suggests that some Genesis ransomware leak postings are either inflated or entirely fabricated. This tactic may serve to bolster the group’s reputation, sow confusion, or create leverage even in cases where no actual compromise has occurred.

Event Status and Current Exploitation Risks

As of the latest available information, there is no evidence that Boyum IT Solutions has suffered data loss, service disruption, or unauthorised disclosure of customer information. Neither the alleged victim nor independent security researchers have confirmed the Genesis group’s claim.

The lack of technical indicators or leaked data means the situation poses no immediate elevated risk to Boyum’s customers. However, organisations relying on Boyum’s products should remain alert for any official communications or security advisories from the vendor in the coming days and weeks. Monitoring for updates is especially important for UK SMBs that depend on SAP Business One add-ons, as supply chain compromise remains a key concern in the sector.

Why This Matters for the UK SMB Sector

Unverified ransomware claims, even without technical evidence, can affect the reputation and perceived reliability of software vendors. For UK SMBs that operate with limited resources and depend on third-party add-ons like those from Boyum IT Solutions, any suggestion of compromise warrants close monitoring. Supply chain risks are a persistent concern, especially where business-critical functions rely on external software providers.

Recommended Actions for Affected Organisations

  • Monitor official Boyum IT Solutions communications for updates or security advisories
  • Review your organisation’s use of Boyum add-ons and ensure your systems are up to date
  • Remain vigilant for phishing attempts or unusual activity related to SAP Business One accounts
  • Do not take action based solely on unverified leak site claims

Organisations are advised to wait for independent confirmation or vendor guidance before making any operational changes or incident response decisions.

Originally reported by redpacketsecurity.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call