Phi
bd_4a2295e093240b17 · schema v1 · pii pii-v1
Full breach record for Phi →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Nova on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
PHI Studio focuses its activities on the presentation and curation of immersive works in virtual reality (VR), augmented reality (AR) and extended reality (XR). Recognized locally and internationally for its innovative production approach, technical expertise and achievements in new forms of storytelling, PHI Studio collaborates with major global industry players and has worked on many award-winning projects, with international presentations in New York, Tokyo, Venice, Frankfurt, Luxembourg and Salt Lake City, among others. As a pioneer in interactive experiences, PHI Studio pushes the boundaries of immersive projects, with a focus on enhancing the visitor experience through a keen sense of detail and the elaboration of high-quality scenography. With a reputation for close collaborations with artists, creators, directors and producers from different backgrounds, PHI Studio aspires to be a catalyst of innovation, supporting the development of present and future talent - Nova Provide tree and samples from stolen data to the company when its get in touch with support department.
Source provenance
- Source URL
- https://www.ransomware.live/id/UGhpQG5vdmE=
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 17, 2026
- Raw hash
- 7d784044b71d41a6bfaa926d76bb7ce1a56c30d14fb11d03249411ba8a8b72e5
Reporting entity
- Name
- nova
Victim entity
- Name
- Phinorm: phi
- Domain
- phi.ca
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· nova
- Threat actor
- NovaExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.