Tag: extortion
-
Clop-linked crims shake down Oracle execs with data theft claims
Extortion emails name-drop Big Red’s E-Business Suite, though Google and Mandiant yet to find proof of any breach First seen on theregister.com Jump to article: www.theregister.com/2025/10/02/clop_oracle_extortion/
-
Oracle customers targeted with emails claiming E-Business Suite breach, data theft
Unknown attackers claiming affiliation with the Cl0p extortion gang are hitting business and IT executives at various companies with emails claiming that they have exfiltrated … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/10/02/oracle-ebs-data-theft-extortion/
-
Oracle customers targeted with emails claiming E-Business Suite breach, data theft
Unknown attackers claiming affiliation with the Cl0p extortion gang are hitting business and IT executives at various companies with emails claiming that they have exfiltrated … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/10/02/oracle-ebs-data-theft-extortion/
-
Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware
Google Mandiant and Google Threat Intelligence Group (GTIG) have disclosed that they are tracking a new cluster of activity possibly linked to a financially motivated threat actor known as Cl0p.The malicious activity involves sending extortion emails to executives at various organizations and claiming to have stolen sensitive data from their Oracle E-Business Suite.”This activity began…
-
Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware
Google Mandiant and Google Threat Intelligence Group (GTIG) have disclosed that they are tracking a new cluster of activity possibly linked to a financially motivated threat actor known as Cl0p.The malicious activity involves sending extortion emails to executives at various organizations and claiming to have stolen sensitive data from their Oracle E-Business Suite.”This activity began…
-
Red Hat confirms security incident after hackers claim GitHub breach
An extortion group calling itself the Crimson Collective claims to have breached Red Hat’s private GitHub repositories, stealing nearly 570GB of compressed data across 28,000 internal projects. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/red-hat-confirms-security-incident-after-hackers-claim-github-breach/
-
Kido nursery hackers say they have deleted stolen data
Experts say attempting to extort children lost Radiant group credibility in hacking world, which made it take actionCybercriminals who stole pictures and the private information of <a href=”https://www.theguardian.com/technology/2025/sep/26/kido-nursery-hackers-radiant-threaten-publish-children-profiles”>thousands of nursery children have deleted the data.A gang calling themselves Radiant have removed details of children at the UK-based Kido nursery chain from a website it had…
-
Clop extortion emails claim theft of Oracle E-Business Suite data
Mandiant and Google are tracking a new extortion campaign where executives at multiple companies received emails claiming that sensitive data was stolen from their Oracle E-Business Suite systems First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clop-extortion-emails-claim-theft-of-oracle-e-business-suite-data/
-
Nach Cyberangriff: IT-Störung in Hoppegarten dauert an
Der Cyberangriff auf die Gemeinde Hoppegarten im August sorgt aktuell noch immer für IT-Probleme.Am 10. August funktionierte in der Gemeinde Hoppegarten (Brandenburg) fast nichts mehr. Aufgrund einer Hackerattacke musste die Verwaltung damals ihre IT-Systeme abschalten. Wie die Kommune nun am Montag (22. September) mitteilte, dauert die Aufarbeitung des Angriffs noch an.Demnach sind zwar zentrale Dienste…
-
Nach Cyberangriff: IT-Störung in Hoppegarten dauert an
Der Cyberangriff auf die Gemeinde Hoppegarten im August sorgt aktuell noch immer für IT-Probleme.Am 10. August funktionierte in der Gemeinde Hoppegarten (Brandenburg) fast nichts mehr. Aufgrund einer Hackerattacke musste die Verwaltung damals ihre IT-Systeme abschalten. Wie die Kommune nun am Montag (22. September) mitteilte, dauert die Aufarbeitung des Angriffs noch an.Demnach sind zwar zentrale Dienste…
-
Nach Cyberangriff: IT-Störung in Hoppegarten dauert an
Der Cyberangriff auf die Gemeinde Hoppegarten im August sorgt aktuell noch immer für IT-Probleme.Am 10. August funktionierte in der Gemeinde Hoppegarten (Brandenburg) fast nichts mehr. Aufgrund einer Hackerattacke musste die Verwaltung damals ihre IT-Systeme abschalten. Wie die Kommune nun am Montag (22. September) mitteilte, dauert die Aufarbeitung des Angriffs noch an.Demnach sind zwar zentrale Dienste…
-
Allianz: Cyberabwehr hilft Hacker suchen leichtere Beute
Eine Analyse von Allianz Commercial zeigt, dass versicherte Großunternehmen zunehmend resilient gegenüber Cyberattacken sind. Kriminelle Hacker machen sich nach Einschätzung der Allianz wegen verbesserter Cybersicherheit großer Unternehmen und Institutionen vermehrt auf die Suche nach leichterer Beute. Die Zahl der Cyberbanden hingegen nimmt nach wie vor zu, wie es im neuen Bericht des Unternehmensversicherers Allianz Commercial…
-
Allianz: Cyberabwehr hilft Hacker suchen leichtere Beute
Eine Analyse von Allianz Commercial zeigt, dass versicherte Großunternehmen zunehmend resilient gegenüber Cyberattacken sind. Kriminelle Hacker machen sich nach Einschätzung der Allianz wegen verbesserter Cybersicherheit großer Unternehmen und Institutionen vermehrt auf die Suche nach leichterer Beute. Die Zahl der Cyberbanden hingegen nimmt nach wie vor zu, wie es im neuen Bericht des Unternehmensversicherers Allianz Commercial…
-
Allianz: Cyberabwehr hilft Hacker suchen leichtere Beute
Eine Analyse von Allianz Commercial zeigt, dass versicherte Großunternehmen zunehmend resilient gegenüber Cyberattacken sind. Kriminelle Hacker machen sich nach Einschätzung der Allianz wegen verbesserter Cybersicherheit großer Unternehmen und Institutionen vermehrt auf die Suche nach leichterer Beute. Die Zahl der Cyberbanden hingegen nimmt nach wie vor zu, wie es im neuen Bericht des Unternehmensversicherers Allianz Commercial…
-
A suspected Scattered Spider member suspect detained for casino network attacks
A suspected Scattered Spider member linked to cyber attacks on Las Vegas casinos was arrested on September 17. The Las Vegas Metropolitan Police Department arrested on September 17 a suspected Scattered Spider member linked to attacks on Las Vegas casinos for computer intrusion, extortion, and identity theft. Between August and October 2023, multiple Las Vegas…
-
(g+) Ransomware 2025: Wie mit KI-gestützten Angriffen Firmen erpresst werden
KI macht Verschlüsselungstrojaner schlauer. Wir zeigen, wie sich Unternehmen 2025 wehren können. First seen on golem.de Jump to article: www.golem.de/news/ransomware-2025-wie-mit-ki-gestuetzten-angriffen-firmen-erpresst-werden-2509-200332.html
-
Alleged Scattered Spider teen cuffed after extortion Bitcoin used to buy games, meals
Feds say gift card splurges tied suspect to multimillion-dollar ransomware crew First seen on theregister.com Jump to article: www.theregister.com/2025/09/19/scattered_spider_teen_cuffed/
-
DOJ: Scattered Spider took $115 million in ransoms, breached a US court system
The Scattered Spider cybercriminal operation was able to extort at least $115 million in a three-year spree that also included the breach of a federal court network, U.S. authorities said in unsealing charges against one suspect. First seen on therecord.media Jump to article: therecord.media/scattered-spider-unsealed-charges-115million-extortion-breached-courts-system
-
Scattered Spider teen cuffed after buying games and meals with extortion bitcoin
Tags: extortionBad opsec First seen on theregister.com Jump to article: www.theregister.com/2025/09/19/scattered_spider_teen_cuffed/
-
Mit Ransomware: Teenager sollen 115 Millionen US-Dollar erbeutet haben
Im Vereinigten Königreich wurden zwei junge Männer verhaftet. Sie sollen als Mitglieder von Scattered Spider unzählige Unternehmen erpresst haben. First seen on golem.de Jump to article: www.golem.de/news/mit-ransomware-teenager-sollen-115-millionen-us-dollar-erbeutet-haben-2509-200260.html
-
Ransomware-Lage verschärft sich drastisch
Zscaler gewährt Einblicke in das globale Ransomware-Ökosystem. JLStockDer jährliche ThreatLabz Ransomware-Report (PDF) von Zscaler hält auch 2025 eher keine guten Nachrichten bereit. Demnach:ist die Zahl der Ransomware-Angriffe im Jahresvergleich um 146 Prozent gestiegen, währendparallel auch die exfiltrierte Datenmenge um 92 Prozent gewachsen ist.Zweitgenannte Entwicklung schreiben die Studienmacher dem Trend zu, dass die Ransomware-Akteure ihren Fokus…
-
Ransomware-Lage verschärft sich drastisch
Zscaler gewährt Einblicke in das globale Ransomware-Ökosystem. JLStockDer jährliche ThreatLabz Ransomware-Report (PDF) von Zscaler hält auch 2025 eher keine guten Nachrichten bereit. Demnach:ist die Zahl der Ransomware-Angriffe im Jahresvergleich um 146 Prozent gestiegen, währendparallel auch die exfiltrierte Datenmenge um 92 Prozent gewachsen ist.Zweitgenannte Entwicklung schreiben die Studienmacher dem Trend zu, dass die Ransomware-Akteure ihren Fokus…
-
ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks
The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/
-
Microsoft and Cloudflare execute ‘rugpull’ on massive phishing empire
Tags: access, ai, attack, blockchain, breach, computer, credentials, crime, crimes, crypto, cybercrime, data, detection, exploit, extortion, finance, fraud, infrastructure, international, law, microsoft, phishing, programming, scam, service, strategy, threat, toolLegal victory with limitations: Microsoft’s investigation identified Joshua Ogundipe, based in Nigeria, as the operation’s leader and primary architect. The company filed a lawsuit against Ogundipe and four associates listed as John Does in late August, then obtained a court order from the US District Court for the Southern District of New York in early…
-
Emerging Yurei Ransomware Claims First Victims
The cybercrime group, named after Japanese ghosts but believed to be from Morocco, uses a modified version of the Prince-Ransomware binary that includes a flaw allowing for partial data recovery. However, an extortion threat remains. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/emerging-yurei-ransomware-claims-first-victims
-
Anthropic Report Shows Bad Actors Abusing Claude in Attacks
A recent report from AI giant Anthropic outlined multiple instances where threat actors abused its Claude LLM in their nefarious activities, including one in which a hacker automated every aspect of a data extortion campaign, from initial reconnaissance to stealing credentials and penetrating networks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/anthropic-report-shows-bad-actors-abusing-claude-in-attacks/
-
Anthropic Report Shows Bad Actors Abusing Claude in Attacks
A recent report from AI giant Anthropic outlined multiple instances where threat actors abused its Claude LLM in their nefarious activities, including one in which a hacker automated every aspect of a data extortion campaign, from initial reconnaissance to stealing credentials and penetrating networks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/09/anthropic-report-shows-bad-actors-abusing-claude-in-attacks/
-
New ransomware Yurei adopts open-source tools for double-extortion campaigns
Tags: access, attack, authentication, backup, breach, ciso, cloud, control, data, edr, extortion, flaw, intelligence, Internet, mfa, network, open-source, phishing, powershell, ransomware, resilience, risk, service, switch, threat, tool, windowsBigger risks beyond downtime: The double-extortion ransomware appears to be an early version, as it has loopholes. Ransomware often targets and deletes shadow copies to block victims from using Windows’ built-in recovery options. But Yurei did not delete the shadow copies, which, if enabled, can allow the victim to restore their files to a previous…
-
US national charged in Finnish psychotherapy center extortion
Tags: extortionFinnish prosecutors allege that a U.S. national, Daniel Lee Newhard, played a role in extorting the psychotherapy center Vastaamo. Until now the case had centered on Aleksanteri Kivimäki. First seen on therecord.media Jump to article: therecord.media/finland-vastaamo-hack-us-national-charged
-
Yurei Ransomware Uses PowerShell to Deploy ChaCha20 File Encryption
A newly discovered ransomware group called Yurei has emerged with sophisticated encryption capabilities, targeting organizations through double-extortion tactics while leveraging open-source code to rapidly scale operations. First observed on September 5, 2025, this Go-based ransomware employs the ChaCha20 encryption algorithm and PowerShell commands to compromise victim systems, marking another evolution in the ransomware-as-a-service ecosystem. Flow…

