ShellCodeX
Tools • Events • News • Insights
Victim Claim

Desysweb

nova 🇵🇪 Peru Technology desysweb.pe
Claimed by nova
Listed on leak site 08 May 2026
Reported attack date 07 May 2026
Group claims tracked 82
Unverified claim. This entry reproduces a listing published by the nova group on its own extortion site. Attackers routinely exaggerate or fabricate victims. Nothing here confirms that Desysweb suffered a breach, or what data was actually taken.

About the organisation

Desysweb is a comprehensive technology solutions integrator specializing in telecommunications and IT services, including managed services and a Security Operation Center. With over 200 clients and more than 13 years of experience, they offer personalized consulting, high-quality materials, and competitive pricing. The company is ISO 27001:2022 certified, ensuring robust information security and data protection. Desysweb operates nationally with a presence in eight provinces and is committed to delivering tailored projects and 24/7 customer support through a team of certified engineers. - Los sistemas de la empresa están encriptados con más de 60 mil archivos en múltiples servidores. Tienes tiempo de contactarte con nuestro departamento a través de los canales indicados en el archivo de recuperación que está dentro de los sistemas encriptados. Una vez que termine la cuenta regresiva, ya no será posible recuperar la información y tus datos se perderán. Estamos listos para desencriptar cada uno de los archivos. Contáctanos cuanto antes.

What the listing means

Desysweb appeared on the nova leak site on 08 May 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated — the attack itself is dated 07 May 2026, 1 day before the listing. This group has published 21 claims in the last 30 days and remains active.

Recommended actions

  • Treat any unsolicited message referencing Desysweb as suspicious — leaked data gets weaponised for phishing within days.
  • If you hold an account on desysweb.pe, change that password now, update it anywhere you reused it, and enable two-factor authentication.
  • Other Technology organisations should review this group's known TTPs and validate detection coverage against them.
  • Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
  • A leak-site listing is a claim made by the attacker, not a confirmed breach — check the organisation's own disclosures before acting on it.

Leak-site evidence

Listing URL https://www.ransomware.live/id/RGVzeXN3ZWJAbm92YQ==

Show leak-site screenshot

Captured from the group's extortion site. It may contain the victim's data or the attacker's messaging.

Screenshot of the nova leak-site listing for Desysweb