Tag: extortion
-
Clop Tied to PTC Product Lifecycle Management Software Hits
Signs Point to Cl0p Extortion Group Again Stealing Data and Holding It to Ransom. Digital extortion group Clop, aka Cl0p, has been tied to a fresh spate of supply-chain attacks, this time targeting users of popular Windchill and FlexPLM product lifecycle management software from PTC. Victims appear to at least span the aerospace, automotive, manufacturing…
-
Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
-
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/
-
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Tags: authentication, data, data-breach, endpoint, exploit, extortion, flaw, Internet, login, ransomware, rce, remote-code-execution, threatThreat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.”Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling…
-
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
-
If you pay a hacker’s ransom, chances are that they’ll come back for more
The long-held understanding among security researchers and network defenders is that it’s impossible to negotiate in good faith with an extortion racket because there’s no incentive for the other side to actually walk away. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more/
-
Japanese food logistics giant recovers as extortion group claims cyberattack
Nichirei Logistics Group said warehouse operations and frozen food shipments are returning to normal. A cybercrime gang said it caused the disruption. First seen on therecord.media Jump to article: therecord.media/nichirei-japan-food-logistics-cyberattack-recovery
-
JadePuffer returns with ransomware built to target AI models and infrastructure
JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/jadepuffer-encforge-ransomware/
-
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high”‘value AI and ML artifacts across an entire stack. A missing”‘authentication bug in the /api/v1/validate/code endpoint that enables unauthenticated arbitrary Python execution on the host. That initial operation chained reconnaissance, credential…
-
Hacker löscht europäische Regierungsdatenbank vollständig
Nach einer gescheiterten Erpressung löscht ein Hacker die gesamte Katasterdatenbank Rumäniens. Der Vorfall betrifft zehntausende Immobilientransaktionen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/hacker-regierungsdaten
-
Cryptohack Roundup: Ostium Pauses Trading After $18M Exploit
Also: AscendEX Shuts Down; Ethereum Foundation on AI Bug Hunting. This week, Ostium paused trading, AscendEX shut down, Ethereum said AI hastens bug hunting, not verification, the United States charged an inmate over seized transfer, ex-Sheriff’s deputy jailed for extortion, Tangem card security, Iran-linked wallets sanctions and the U.S. may drop BitClub charges. First seen…
-
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup
The Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests. The attack The attack … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/microsoft-365-fake-passkey-setup-enrollment/
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
The attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment
-
Windows Device ID Helped Authorities Track Scattered Spider Hacking Group Member
Authorities used a persistent Windows Global Device ID, along with VPN telemetry and cloud service records, to connect the infrastructure used in a major extortion attack to a 19-year-old member of the Scattered Spider group, Peter Stokes. In a superseding criminal complaint filed in the Northern District of Illinois, the FBI outlines how Stokes, who…
-
US government agency pays $1 million to data extortion group Kairos
First seen on scworld.com Jump to article: www.scworld.com/brief/us-government-agency-pays-1-million-to-data-extortion-group-kairos
-
Medtronic Notifies 3.8 Million After ShinyHunters Data Breach
Medtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical information. In April 2026, Medtronic confirmed a cyberattack on its corporate IT systems after the hacker group ShinyHunters claimed…
-
Security Affairs newsletter Round 584 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. Government Agency Paid $1M to Data Extortion Group Kairos FBI: TeamPCP Compromised Dev Tools to…
-
U.S. Government Agency Paid $1M to Data Extortion Group Kairos
Tags: blockchain, data, data-breach, extortion, government, group, ransom, ransomware, theft, threatA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked negotiation transcript and blockchain tracing of the ransom payment.…
-
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
Tags: blockchain, breach, data, data-breach, extortion, government, group, ransom, ransomware, theftA U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left.The odd part: the group that took the money calls itself Kairos, but it may not be…
-
FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and security tools to steal credentials from victim environments at scale. The…
-
The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident
Vercel breach happened after an employee used an unvetted AI tool. Attackers exploited it as a trusted link to access systems, steal data, and extort $2M. The Vercel breach of April 2026 did not begin with a classic zero-day exploit, a misconfigured cloud bucket, or a sophisticated nation-state infrastructure implant. Instead, it unfolded when an…
-
Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges
Alleged Scattered Spider member Peter Stokes, 19, was extradited from Finland to the U.S. over hacking, fraud, and extortion charges. Peter Stokes, 19, an alleged Scattered Spider member known online as >>Bouquet,<< has been extradited from Finland to the U.S. to face hacking, fraud, and extortion charges. Prosecutors say he took part in multiple cyberattacks,…
-
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted into a production MySQL/Nacos deployment to carry out a destructive, database-focused extortion playbook without a…

