ThreatBrief AI
Listed Pakistan · Financial Services

EFU Life Assurance

Qilin ransomware group added Pakistan-based EFU Life Assurance to its dark web leak site on July 22, 2026, claiming stolen internal data and threatening public release.

Country

Pakistan (PK)

Actor

Qilin

First seen

2026-07-22

Last checked

2026-07-23

Snapshot

EFU Life Assurance is tracked here because the Qilin ransomware group listed efulife.com on their dark web leak site on July 22, 2026. The record is country-labeled as Pakistan, sector-labeled as Financial Services, and tied to the victim domain efulife.com.

Current status

The current status is listed. Qilin has claimed the breach and threatened data publication, but as of July 23, 2026, no stolen data has appeared on the group’s leak site. The incident remains in negotiation phase.

Threat actor background

Qilin (also tracked as Agenda) is a ransomware-as-a-service operation known for double-extortion tactics: encrypting victims and exfiltrating data simultaneously, then threatening to publish stolen files if ransoms go unpaid. The group has a track record of actually publishing stolen data from non-paying victims, including NHS Synnovis (400 GB of patient data, June 2024) and Conpet (nearly 1 TB, February 2026). Qilin primarily targets manufacturing, financial services, healthcare, and construction sectors across North America and Europe, with an expanding footprint into Asia.

Source picture

Five independent sources corroborate the Qilin listing. DeXpose and GalaxyWarden provide the earliest verified reports dated July 22, 2026. HackerFeeds carries the Qilin leak site onion URL. SOCRadar’s ransomware intelligence dashboard tracks the victim in real time. Undercode News reported Qilin’s parallel expansion into EFU Life and P & A Construction on the same day.

The available sources do not establish the volume, sensitivity, or authenticity of any allegedly exfiltrated data. This record should be read as an exposure tracker entry, not as a confirmed breach notice.

What to watch

The primary watch item is whether Qilin moves from listing to public data release — typically within 7–14 days under their standard playbook. If data is published, this record should move to data-published status. EFU Life customers and partners should monitor for targeted phishing leveraging stolen policy or personal data, and review logs for account compromise or infostealer signals.