BlackNevas claims Mefa Group ransomware breach
Ransomware group BlackNevas has listed Turkish industrial conglomerate Mefa Group and its subsidiaries as a data-leak victim.
A leak-site posting attributed to the ransomware/extortion group BlackNevas claims compromise of Mefa Group, a Turkish industrial conglomerate headquartered in Ankara with operations in plastics, rubber processing, automotive components, and logistics across Turkey, Romania, and Poland. The posting names several group subsidiaries as affected, including MEFA Endüstri (manufacturing), Efachem (plastic/rubber compounds), Ecopolymer (recycled raw materials processing), and Milkrun Lojistik (logistics division), describing them as an integrated production-to-logistics ecosystem.
The post includes a link to an exfiltration/file-hosting service (send.exploit.in) purportedly containing a stolen file listing, along with a Telegram channel and an email contact for 'cooperation' — typical extortion-negotiation tradecraft for ransomware leak sites. No technical details of the intrusion vector, malware used, or exploited vulnerabilities are provided in this listing; the posting functions primarily as a victim-shaming/extortion notice rather than a technical disclosure.
Defenders in the manufacturing and logistics sectors, particularly organizations with Turkish, Romanian, or Polish operations tied to automotive and industrial supply chains, should treat this as a reminder to review third-party/supply-chain exposure and ensure standard ransomware defenses (segmentation, backup integrity, EDR coverage) are in place. No confirmation of the claim's veracity or scope is available beyond the leak-site posting itself.
Mentioned in this report
Detection guidance
1 detection artefacts for this report are available to subscribers.
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free