Tag: extortion
-
Ransomware attackers are zeroing in on mid-market companies
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/black-kite-mid-market-ransomware-risk-report/
-
ShinyHunters Leaks 7.1 Million Baxter International Records
Gang Claims It Stole Medical Device Maker’s Salesforce Info Including Personal Data. Extortion gang ShinyHunters has struck the healthcare sector again. The notorious cybercriminal gang claims on its darkweb site of leaking 7.1 million Salesforce records stolen from medical device maker Baxter International, including personally identifiable information. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/shinyhunters-leaks-71-million-baxter-international-records-a-32630
-
US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank to meet an undisclosed extortion demand. As of now, the details of the alleged attack have not been independently verified,…
-
ShinyHunters: Erpressungsversuch bei Logitech-Tochter
Hacker drohen Streamlabs mit Erpressung: Die Gruppe ShinyHunters fordert Kontakt bis 21. August. Millionen Daten sind bedroht. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/logitech-tochter-erpressung
-
The long tail of Clop’s PTC hack is just beginning to emerge
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. First seen on cyberscoop.com Jump to article: cyberscoop.com/clop-zero-day-attacks-ptc-windchill-flexplm/
-
Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments…
-
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest.The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault…
-
Prison for data analyst who tried to extort $2.5 million from his employer
When Cameron Curry discovered that his contract as a data analyst wasn’t going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/prison-data-analyst-extort-employer
-
Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion
Tags: advisory, attack, cisa, cyber, extortion, infrastructure, intelligence, ransomware, service, updateMedusa ransomware operators have compromised over 500 organizations across critical infrastructure sectors, according to a joint advisory issued by the FBI, CISA, and the U.S. Department of Health and Human Services (HHS) as part of their #StopRansomware initiative. An update released on August 18, 2026, provides expanded intelligence based on FBI investigations conducted as recently…
-
Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data
Tags: credentials, cve, cvss, cyber, data, exploit, extortion, hacker, ransomware, remote-code-execution, vulnerabilityThe Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can harvest credentials, map engineering data vaults, and exfiltrate files without requiring additional attacker tooling. Tracked as CVE-2026-12569, the vulnerability is a CVSS 9.3 remote code execution issue affecting PTC Windchill PDMlink and…
-
Details emerge on BlackFile’s recent attacks on financial companies
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google. First seen on cyberscoop.com Jump to article: cyberscoop.com/blackfile-cyberattacks-financial-sector/
-
Multiple organisations investigating fresh wave of Cl0p breaches
Multinational giants such as Philips and Shell may have been affected after the Cl0p cyber extortion gang hacked a popular piece of PLM software. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366648757/Multiple-organisations-investigating-fresh-wave-of-Cl0p-breaches
-
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
Tags: blockchain, communications, data, extortion, group, infrastructure, leak, microsoft, network, ransomware, service, threatThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.”Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat First seen on thehackernews.com Jump…
-
Former BlackFile affiliates linked to extortion campaign targeting private equity
Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/former-blackfile-extortion-campaign-private-equity/827574/
-
DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July 2025, the operation uses double extortion: encrypting enterprise data while threatening publication of stolen material. The encryptor’s pre-encryption routine is built to degrade both prevention and recovery. After XOR-decoding an embedded configuration,…
-
Financial Services Under Fire From Rebranded Extortionists
What’s in a Name? Vishing-Savvy BlackFile Rebrands as Redact, Pink, Helix, Falcon. Data theft extortion group BlackFile claimed retire in May. Threat researchers at Google said telemetry and attack infrastructure shows that the group has carried on using a variety of new brand names and shifted its focus to targeting financial services. First seen on…
-
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671.”UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their…
-
Google Links Redact Extortion Group to BlackFile Rebrand
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/
-
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/
-
Google says hackers are calling financial firm employees to hack and extort victims
Groups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/06/google-says-hackers-are-calling-financial-firm-employees-to-hack-and-extort-victims/
-
Canadian Pleads Guilty to Snowflake Customer Data Extortion
Extortionist Connor Moucka, 26, Helped Breach Over 150 Customers’ Accounts. Canadian national Connor Riley Moucka, 26, pleaded guilty in Seattle federal court holding to ransom data he helped steal from over 150 customers of cloud-based data warehousing platform Snowflake, leading to victims paying millions in cryptocurrency ransoms and incident response costs. First seen on govinfosecurity.com…
-
Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign
A Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victims First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/canadian-hacker-guilty-snowflake/
-
Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers
Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to charges related to a large-scale cloud data theft and extortion operation that affected at least 165 organizations. This campaign resulted in the theft of billions of sensitive records, impacting an estimated 100 million individuals worldwide. Canadian Hacker Pleads Guilty According to…
-
Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/
-
INC Ransomware is Calling Victims Pressure Tactics Post SonicWall Zero-Day Exploit
INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since…
-
CRPx0 Ransomware Claims Hyundai Turkey Breach, Steals 1.5GB of Assessment Data
The double-extortion ransomware group CRPx0 has listed Hyundai’s Turkish operations on its dark web leak site, claiming to have exfiltrated 1.5 GB of sensitive personnel and recruitment data from the automaker’s assessment systems. According to CyberWatch, first flagged on its data-leak portal, the target is described as a >>Korean automotive manufacturer (Turkish operations)<< with the…
-
DentaQuest Data Theft Hack Affects 15M Patients
Number of Victims Is 5 Times Higher Than Claims by ShinyHunters Ransomware Gang. Dental and vision benefits administrator DentaQuest is notifying 15 million patients that their information was compromised in a May hack. The reported victim total is significantly higher than the number claimed by extortion gang ShinyHunters, which took credit for the data theft…
-
Medical Billing Vendor Hack Affects 1.3M Patients
Extortion Gang PEAR Claims Theft of 3.3TB of MCBS LLC’s Client and Patient Data. A Georgia-based medical billing firm is notifying nearly 1.3 million patients of seven healthcare practices of a 2025 hack, ranking the incident among the largest health data breaches reported so far this year. Extortion gang PEAR claimed it stole 3.3 terabytes…
-
ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Tax Data
ShinyHunters has claimed responsibility for the data breach at Ernst & Young (EY) and is threatening to publish allegedly stolen client tax information unless the professional services firm engages in negotiations before July 31, 2026. The extortion group posted about EY on its dark web leak site, describing the deadline as a “final warning” and…

