Intelligence is a forum persona associated with unverified September 2026 listings offering alleged customer datasets from Bulgarian insurance companies, including Generali Insurance Bulgaria and DZI Insurance. The purported records contain sensitive personal, identity, insurance-policy, and vehicle-related information. The persona claimed that the DZI data originated from an insecure customer-portal API, but did not disclose technical details sufficient to verify the assertion. Neither the alleged compromises, data provenance, record counts, nor claimed access methods have been independently verified. The listings’ limited-buyer sales model indicates an apparent financial motive.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed to be selling an unverified dataset allegedly exfiltrated from Generali Insurance Bulgaria's InsurerWeb application. The listing claims the records include sensitive policyholder, identity, contact, and vehicle data and that the data will be sold to three buyers.
An unverified, newly created forum account allegedly offering a dataset containing 3,134,269 DZI Insurance customer records for sale to two buyers. The actor claims to have obtained the data on 21 May 2026 through an inadequately protected customer-portal API.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.