#CyberExtortion
the Chinese did a big arrest of a Cambodian-Chinese crimelord/scam compound owner last week and it turns out he made his bones running cyberextortion in South Korean online games in the 2000s, which I find delightful
January 13, 2026 at 3:49 PM
Well, this is just fecking great - potential major data leak at the weekend after the supplier responsible for the data system used by around 200 municipalities and regions in Sweden was subjected to a cyberextortion attack. Any leak may include medical data. Can we go back to paper, please?
August 26, 2025 at 3:25 PM
imo it was either that or a very long time in prison over the whole repeated string of crimes committed. i'm not in a position to argue about the sentencing, but i can take issue with downplaying the crimes [cyberextortion is bad] and blaming rockstar for it [already on the hook by british police]
July 6, 2026 at 8:53 AM
I’d bet $100 that this is yet another way that Trump Admin 2.0 has found to screw over Attorney Client Privilege and break the entire justice system

And some 19 year old scriptkiddie Elon recruited from a cyberextortion ring or w/e botched his Python code and leaked a classified thing
April 9, 2025 at 1:43 AM
High profits stem from business-like structure and resilience.

🔗 read more: www.darkreading.com/cyberattacks...

#ransomNews #ransomwareEconomy #cyberextortion
What Makes Ransomware Groups Successful?
New research revealed successful ransomware groups exhibit three key elements. Spoiler alert: It doesn't all revolve around artificial intelligence.
www.darkreading.com
November 8, 2025 at 8:37 AM
March 27, 2026 at 2:44 PM
Hacker vs. Hacker: ShinyHunters Outsmarts Clop Ransomware Gang #ClopRansomwareGang #CyberAttacks #CyberExtortion
Hacker vs. Hacker: ShinyHunters Outsmarts Clop Ransomware Gang
  The extortion group ShinyHunters hacked the dark web leak site run by Clop, one of the most active ransomware operations in the world, defaced it with their own branding, and is now threatening to put Clop through the same extortion process Clop runs on its corporate victims. The attack happened Friday night, September 19. ShinyHunters found an unauthenticated file upload flaw in Grav CMS, the content management system Clop was running its leak site on, and used it to push a text file directly onto the server. The file read: "THIS SITE HAS BEEN PWN3D BY SHINYHUNTERES #Skids10p - Maybe don't try to threaten us next time." It also linked back to ShinyHunters' own Tor site. The file was confirmed live and downloadable directly from Clop's server. Hours later, ShinyHunters said they had gone further. A visit to Clop's site showed the entire page replaced with ASCII art of Umbreon, the Pokemon ShinyHunters uses as its logo, and the line "rooting your systems since '19 ;)". The same Umbreon artwork had appeared when ShinyHunters defaced HackForums back in August 2020. Clop's defaced page was still live at the time of writing. ShinyHunters claimed full access to the server and said they took source code, Grav CMS plugins, and everything stored in the server's /var/log directory, which typically holds authentication logs, system activity records, and the IP addresses of everyone who connected to it. They also claim to have pulled the private keys for Clop's Tor onion service. Those keys are what tie a .onion address to its server. With them, ShinyHunters could host a copy of Clop's site at the exact same onion URL, on infrastructure they control. "We have their onion keys. So if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL," the group said. The plan is to post an extortion message on their own site and give Clop 72 hours to respond. The defacement and the uploaded file are independently confirmed. The claims about stolen source code, server logs, and Tor private keys come only from ShinyHunters and have not been independently verified. Clop has not commented. The dispute behind this attack goes back about a year. In August 2025, Clop quietly began exploiting a zero-day vulnerability in Oracle E-Business Suite, tracked as CVE-2025-61882, a server-side request forgery flaw that gave attackers remote access to enterprise systems without authentication. Oracle did not patch it until October 2025, after Mandiant confirmed active exploitation. By then, Clop had already sent mass extortion emails to executives at dozens of companies, including Cox Enterprises, The Washington Post, Logitech, Michelin, and Estee Lauder. ShinyHunters says that exploit was originally theirs and that Clop used it without authorization. In October 2025, ShinyHunters, operating under the name "Scattered Lapsus$ Hunters," leaked the proof-of-concept publicly. Oracle confirmed it matched the exploit used in the Clop attacks. ShinyHunters said the leak was deliberate, intended to disrupt Clop's campaign and expose what had been taken from them. What followed, according to ShinyHunters, was a direct threat from a Clop representative. "During the Oracle EBS campaign they ran and stole from me last year, someone from cl0p personally messaged me and said, and I quote (translated from Russian): I have more money than you and all of your people combined, I'll kill you soon," the group said. Those allegations have not been independently verified. This is not the first time criminal groups have turned on each other. In March 2025, DragonForce defaced the leak sites of rival operations BlackLock and Mamona. Later in 2026, two groups called 0APT and KryBit hacked and leaked each other's operational data until both were left severely damaged. The difference in the Clop case is the scale of the target. Clop's leak site is the operational center of its entire extortion model, the platform it uses to name victims and apply public pressure when ransoms go unpaid. Losing control of it, and potentially the keys that anchor its onion address, is not a minor disruption. ShinyHunters' own Tor site went offline shortly after the attack. No connection to Clop has been established.
dlvr.it
September 21, 2026 at 2:43 PM
📰 Trezor Ungkap Kebocoran Data yang Berdampak pada Hampir 14.000 Pelanggan

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/08/14/kebocoran-data-trezor-13689-pelanggan/

#cry
pt#cryptot#cryptocurrencyt#cryptocurrencyWalletr#cyberExtortionr#cyberSecurityr#cybersecurityB#dataBreachI#dataIden
August 14, 2026 at 8:41 AM
🚨 UPDATE Salesforce

Scattered Lapsus$ Hunters claim fresh victims via new leak site.

The merged cybercrime collective (LAPSUS$, ShinyHunters, Scattered Spider) has launched a new website to announce recent breaches and data dumps.

#ransomNews #ScatteredLapsus #CyberExtortion
October 3, 2025 at 12:21 PM
📰 Grafana Ungkap Pencurian Token GitHub Berujung Kebocoran Kode Sumber (Codebase) Perusahaan

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/05/19/token-github-dicuri-hacker-jarah-source-code-grafana/

#ber
it#beritaTeknologib#codebaseLeakb#coinbasecartelr#cyberExtortionr#ehtag/cyberSecurity" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#cyberSecurity
May 19, 2026 at 7:21 AM
🔎 Scattered Lapsus ShinyHunters ramp up extortion chaos

SLSH terrorizes victim firms with harassment, threats, swatting and media manipulation to force payouts, and experts warn that negotiating only fuels more malicious pressure without guaranteed data return.

#ransomNews #SLSH #CyberExtortion
February 12, 2026 at 8:37 AM
One of the largest ransomware payouts that’s become public was reported Tuesday by cloud security firm Zscaler. #Ransomware #Zscaler #DarkAngels #ZeroTrust #CyberExtortion #ITOTConvergence
jpmellojr.blogspot.com/2024/07/75m-...
$75M Ransomware Payment Exposed in New Zscaler Report
One of the largest ransomware payouts that’s become public was reported Tuesday by cloud security firm Zscaler. more
jpmellojr.blogspot.com
July 30, 2024 at 2:34 PM
🚨 Cyber extortion remains a growing threat. Proactive monitoring helps reduce exposure before attackers strike. 🛡️

🌐 threatexposure.io/blog/attack-...

#CyberSecurity #AttackSurfaceMonitoring #ThreatIntelligence #CyberExtortion #RiskManagement #ThreatExposure

Try it for FREE. 🆓
Supply Chain Cybersecurity | Online Reports - Threatexposure.io
Reduce cyber supply chain risk with full reports for third-party risk management, continuous vendor monitoring, security ratings, and threat intelligence.
threatexposure.io
July 31, 2026 at 7:48 AM
Ransomware activity climbs in Q2 2026 as leading gangs consolidate attacks and AI streamlines extortion efforts #AI #CyberAttacks #CyberExtortion
Ransomware activity climbs in Q2 2026 as leading gangs consolidate attacks and AI streamlines extortion efforts
  Ransomware groups claimed responsibility for 2,279 attacks worldwide during the second quarter of 2026, marking a 7% increase from the previous quarter and a 43% jump compared with the same period last year, according to GuidePoint Security's latest quarterly ransomware report. Researchers also recorded the highest number of active ransomware groups seen in a single quarter, reflecting an ecosystem that continues to attract new threat actors even as attacks remain concentrated among a relatively small number of established operations. Despite the growing number of ransomware groups, a handful of operators continue to dominate victim claims. GuidePoint found that the five most active groups were collectively responsible for more than 40% of all publicly reported ransomware incidents during the quarter, suggesting that while new groups continue to emerge, only a few have achieved sustained operational scale. Qilin remained the most active ransomware operation during Q2, accounting for approximately 13% of all recorded victim claims. It was closely followed by The Gentlemen, a comparatively new group that has expanded rapidly in recent months. Together with Akira and DragonForce, the two groups make up what GuidePoint describes as a "four-headed monster," representing the most prolific ransomware operations currently shaping the threat landscape. Rather than relying on a single dominant ransomware syndicate, today's ransomware ecosystem is distributed across several highly active groups capable of absorbing affiliates from disrupted operations. Researchers noted that this structure could reduce the long-term impact of law enforcement takedowns, as affiliates displaced from one ransomware-as-a-service (RaaS) platform may quickly transition to another established operation without substantially disrupting attack activity. The United States remained the country most frequently targeted by ransomware groups during the quarter, accounting for 40% of publicly claimed victims. Germany ranked second with 32%. However, GuidePoint observed a noticeable shift in targeting patterns, with the U.S. accounting for a smaller proportion of victims than in previous quarters, when roughly half of all reported incidents involved American organizations. Researchers linked this broader geographic distribution to increased activity from groups including Qilin, The Gentlemen and LockBit, each of which claimed a larger share of victims outside the United States during Q2. The findings suggest that ransomware affiliates are expanding their operations across a wider range of regions instead of concentrating primarily on U.S.-based organizations. Alongside changes in victim targeting, the report examined how artificial intelligence is being incorporated into ransomware operations. While concerns have grown around the possibility of AI creating entirely new forms of cyberattacks, GuidePoint found little evidence to support that scenario. Instead, threat actors are primarily using large language models (LLMs) to accelerate tasks that previously required significant manual effort, allowing them to improve efficiency without fundamentally changing their attack methods. One case study highlighted in the report involved the data extortion group FulcrumSec. After obtaining a large volume of stolen information, the group reportedly used an LLM to examine complex databases and identify individuals appearing across multiple datasets. According to researchers, completing this level of analysis manually would have required either extensive knowledge of the victim's database architecture or a substantial investment of time by human operators. The information extracted from the stolen data was then paired with AI-generated negotiation messages written in English. By demonstrating a detailed understanding of the compromised information, FulcrumSec strengthened its position during ransom negotiations, providing victims with evidence of the data in its possession while using those findings to justify its ransom demands. GuidePoint also documented DragonForce's use of large language models during extortion negotiations. Researchers said the group generated convincing messages that sought to increase pressure on victims, including claims that it had legal counsel available to advise its operations. Although the report describes that assertion as almost certainly false, it illustrates how AI can help cybercriminals produce persuasive communications intended to exploit concerns around regulatory obligations, legal consequences and reputational damage. According to the researchers, the effectiveness of these messages does not necessarily depend on their accuracy. Instead, their value lies in presenting information in a manner that appears credible enough to influence decision-making during negotiations. Large language models, which are capable of generating fluent and convincing text within seconds, are increasingly being used to support these psychological tactics. Taken together, the findings indicate that AI is currently serving as an operational force multiplier rather than introducing an entirely new category of ransomware attacks. Tasks such as analyzing stolen data, organizing information, preparing victim communications and drafting negotiation messages can now be completed more quickly, enabling threat actors to devote more time to other stages of their operations. At the same time, the continued concentration of attacks among a small group of highly active ransomware operations suggests that scale, organization and affiliate networks remain key drivers of today's ransomware economy. While new groups continue to enter the ecosystem, a limited number of established operators continue to account for a disproportionate share of publicly claimed attacks, reinforcing their influence across the global ransomware ecosystem.
dlvr.it
July 20, 2026 at 5:20 PM
Crypto extortion scams are getting stranger and smarter. Learn how they work, real tactics criminals use, and how to avoid becoming a target. #cyberextortion
Beware of New Tactics of Digital Extortion in Crypto
hackernoon.com
July 17, 2026 at 12:00 AM
December 31, 2024 at 12:48 AM
📰 Raksasa Ritel 7-Eleven Konfirmasi Kebocoran Data Akibat Serangan Geng Geng Peretas ShinyHunters

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/05/19/raksasa-ritel-7-eleven-konfirmasi-kebocoran-data-salesforce/

#7-e
le#7nDataBreach #berit#beritaTeknologir#cyberExtortionr#cyberSecurity
May 19, 2026 at 2:29 PM
🚨 PowerSchool Hacker Now Targeting Individual School Districts in Ongoing Extortion Campaign 🚨

wiretor.com/%f0%9f%9a%a8...

#PowerSchool #DataBreach #CyberSecurity #RansomwareAttack #StudentDataLeak #SchoolHack #InfoSec #DataPrivacy #TDSB #CyberExtortion #EdTechSecurity
May 8, 2025 at 8:15 PM
GitHub Token Exposure at Grafana Triggered Codebase Theft Incident #APITokenExposure #Cloud #CyberExtortion
GitHub Token Exposure at Grafana Triggered Codebase Theft Incident
  Following the acquisition of a privileged GitHub token tied to Grafana Labs' development environment, a threat actor quickly escalated the initial credential exposure into a significant source code security incident. It was possible for the attacker to gain access to the company's private GitHub infrastructure, extract internal code repositories, and then attempt to extort payment from the organization via unauthorized access. In addition to revoked credentials quickly, Gloria Labs launched an internal forensic investigation to determine the origin of the exposure and limit further risks. In spite of the fact that the breach resulted in access to sensitive development assets, the company announced that investigators found no evidence of data compromise, disruption of operations, or unauthorized access to user environments as a result of the breach.  Grafana’s widespread use in modern observability environments has drawn significant attention across the cybersecurity community due to the platform’s widespread role in monitoring infrastructure, cloud workloads, applications, and telemetry systems through centralized dashboards and analytics. The incident has attracted significant attention across the cybersecurity community. In the course of the investigation, Grafana Labs disclosed that after detecting unauthorized activity, its security team initiated an immediate forensic response, eventually tracing the source of credential exposure and revoking the compromised access token in order to prevent further intrusion. Additionally, additional defensive controls were implemented across the company's development environment as part of its efforts to contain and harden the environment.  Afterwards, the threat actor attempted to extort the organization by requesting payment in exchange for delaying publication of the stolen data, according to the disclosure. Grafana, however, chose not to engage in ransom negotiations, aligning its response with Federal Bureau of Investigation guidance, which has consistently emphasized that paying extortion demands does not ensure data recovery nor prevent future misuse of stolen information.  A number of federal authorities have warned against ransom payments, stating that they rarely ensure suppression of stolen data and often contribute to additional criminal activity targeting technology providers and enterprise platforms.  The exact timeline of the attack or the length of time the attacker was permitted access to Grafana Labs' GitHub environment have not been disclosed, as only that the incident has recently been discovered. It is also noteworthy that the company did not explicitly attribute the intrusion to a specific threat actor.  However, various cyber threat intelligence reports, including Halcyon and Fortinet FortiGuard Labs assessments, have linked claims surrounding the incident with CoinbaseCartel, a collective of data extortionists. It has been noted that the group is an emerging extortion-focused operation that emerged in late 2025 and has operational overlap with criminal ecosystems such as ShinyHunters, Scattered Spider, and LAPSUS$ based on public statements released by Grafana. According to the company's public statements, investigators believe that the intrusion occurred due to the compromise of privileged authentication tokens used in Grafana's development process. As a result, these tokens are frequently used to authenticate automated processes, integrations, and development workflows without requiring repeated manual logins. Although highly beneficial to operational efficiency, exposed tokens can also serve as high-value attack vectors when given broad permissions.  In this case, Grafana Labs' GitHub environment was compromised as a result of a compromised token that allowed the attacker access to private source code repositories within Grafana Labs. Despite the company's assertion that no customer information, user environments, or operational systems were compromised, the exposure of proprietary source code remains a significant security concern within software supply chain environments. Although Grafana stated that customer environments were not affected, unauthorized access to proprietary source codes remains a serious concern, as attackers have the capability of analyzing internal architecture, configurations, or development logic to identify vulnerabilities that may later be used to conduct targeted attacks or other supply chain risks.  Grafana is widely deployed observability technology, and therefore the security of its development infrastructure is of particular importance. Attacks against software vendors may result in downstream risks affecting customers, cloud deployments, as well as broader enterprise environments linked by modern DevOps and observability pipelines. Upon tracking the threat intelligence associated with the incident, it has been determined that the operators behind the claimed attack are primarily engaged in data theft and extortion operations rather than conventional ransomware operations that encrypt files.  Over 170 victims have been linked to the group across sectors such as healthcare, transportation, manufacturing, and technology, reflecting the growing trend toward cyber-attacks that focus on data theft and extortion. There has been no public announcement by Grafana Labs regarding which repositories or internal projects were accessed during the breach, indicating that there is no clear understanding of the scope of the material that was downloaded. Grafana Labs has not disclosed which repositories were accessed during the breach.  In addition to Grafana Cloud, Grafana's managed cloud monitoring platform is widely used across enterprise environments for observing observability. In addition to the disclosure, cyber attacks aimed at extortionating software vendors and cloud service providers are also becoming increasingly aggressive. Following threats of leaking large volumes of data supposedly associated with schools and universities across the United States, Instructure reportedly agreed to negotiate with threat actors connected to ShinyHunters following an alleged agreement to negotiate.  Grafana Labs' decision to reject the extortion demand reflects a growing industry debate concerning ransomware economics, incident response strategies, and the long-term consequences of compensating cybercriminals. A company statement in accordance with advice issued by the Federal Bureau of Investigation stated that paying attackers would not guarantee the suppression of the stolen material nor eliminate the possibility of future abuse, resale, or repeated extortion attempts.  The company notes that organizations have no assurance that the stolen information will actually be removed after payment, which makes ransom negotiations risky and uncertain from an operational perspective. The incident emphasizes the high value of authentication tokens, API credentials, and machine-level secrets within enterprise environments, in addition to the breach itself. In order to reduce the risk of token-based intrusions and software supply chain attacks, security teams are increasingly recommending implementing measures such as short-lived credentials, least privilege access, credential rotation, and multi-factor authentication. They also recommend continuous monitoring of repositories and continuous delivery pipelines.  The enterprise attack surface has been increasingly centered around GitHub repositories, package distribution systems, internal build pipelines, and cloud-based engineering environments, which require security controls comparable to those protecting production infrastructure. Grafana Labs has gained attention for its relatively transparent disclosure approach despite the seriousness of the intrusion.  A statement from the company outlined the compromise, clarified what investigators believe remains unaffected, disclosed the attempted extortion component, and indicated that further details may become apparent as the forensic investigation proceeds. At present, the known impact appears to be limited to unauthorised access and download of internal source code repositories, with no evidence suggesting that customer environments, operational systems, or personal information has been compromised. Grafana remains closely monitored across the cybersecurity community, as it is widely used throughout production observability stacks and cloud-native enterprise environments around the world. Despite Grafana Labs' assurance that customer systems and personal data were not affected, the incident highlights the increasing importance of securing development infrastructure, access credentials, and cloud-connected engineering environments against increasing sophistication in extortion-focused threats.
dlvr.it
May 19, 2026 at 12:35 PM
Rival Ransomware Gangs 0APT And Krybit Clash In Unusual Cyber Extortion Battle #CyberAttacks #Cybercrimes #CyberExtortion
Rival Ransomware Gangs 0APT And Krybit Clash In Unusual Cyber Extortion Battle
 A clash almost unseen among digital outlaws has begun - 0APT, a hacking collective, now warns it will unmask operatives from enemy faction Krybit. This shift came to light through surveillance of hidden online forums. Tension simmers beneath the surface of these underground circles. Rival gangs once operating in parallel seem to fracture under pressure. Trust, usually scarce, is vanishing faster than usual. Evidence points toward escalating friction inside ransomware communities.  What began as covert threats may reshape alliances unexpectedly. Reports indicate 0APT sent a threat to Krybit, insisting on payment under risk of exposing private records - names, positions, operational files - if ignored. A limited set of claimed stolen materials was published shortly after, serving as evidence - a move mirroring classic dual-pressure methods seen in attacks on businesses. Yet using such an approach toward another illicit network stirs doubt around its real impact, given that public image matters little within hidden communities.  Even so, the danger remains somewhat real. Because cybercrime networks depend on staying hidden, revealed identities might invite legal trouble or revenge attacks. From the exposed information, security analysts pulled login details tied to Krybit members - alongside digital currency wallets - hinting at weak points in how the group functions. Yet the full impact stays unclear. Now showing a blank page, Krybit's site now displays only a standard upkeep notice, hinting at disruptions tied to recent events. Little is known about the collective so far, mainly because big security analysts have published almost nothing on them - possibly a sign they are just beginning operations.  On the opposite end, 0APT emerged around spring 2026 and gained attention fast, marked by complex tools and methods, even though some doubt surrounds how truthful their early reports of breaches really were. Odd as it seems, infighting among hackers has happened before. Earlier clashes included DragonForce going after opponents - BlackLock, then Mamona - by altering web pages and exposing private messages.  In much the same way, activity aimed at RansomHub tied back to DragonForce, revealing ongoing friction between ransomware crews. This conflict taking shape between 0APT and Krybit signals changes in how cybercriminals operate - motives like money, dominance, and competition now spark open clashes. With ransomware networks evolving fast, these kinds of face-offs might happen more often, making it harder for security experts to follow the players involved.
dlvr.it
April 27, 2026 at 3:32 PM