#DataExtortion
⚠️ Salesforce rejects ransom demand after data extortion

#Salesforce says it will not negotiate with or pay extortionists claiming they stole data from its customers.

ScatteredLapsus$Hunters target client systems, not the core Salesforce platform.

#ransomNews #dataextortion #cloudsecurity
October 8, 2025 at 12:37 PM
Ransomware attack timelines plummet to 17 hours, demanding faster incident response. #Cybersecurity #Ransomware #DataExtortion
Ransomware Gangs Accelerate Encryption Timelines
Ransomware attack timelines plummet to 17 hours, demanding faster incident response. #Cybersecurity #Ransomware #DataExtortion
www.csoonline.com
February 18, 2025 at 10:13 PM
Grafana reports GitHub token breach leading to codebase access and extortion attempt; no customer data compromised. #Grafana #GitHub #SecurityBreach #DataExtortion #Cybersecurity #FBI thedailytechfeed.com/grafana-suff...
May 17, 2026 at 7:48 AM
Cybercrime's new powerhouse: Scattered Spider, LAPSUS$, and ShinyHunters unite as Scattered LAPSUS$ Hunters, intensifying data extortion and targeting Salesforce users. #CyberSecurity #DataExtortion #Salesforce Link: thedailytechfeed.com/cybercrime-g...
November 5, 2025 at 3:06 PM
🚨 Hackers extort Salesforce after mass customer data theft

SSLSH breached #Salesforce by exploiting permissions flaws, stole customer data from dozens of clients, and is now extorting both Salesforce and affected customers.

#ransomNews #SalesforceHack #DataExtortion
October 6, 2025 at 12:37 PM
ShinyHunters is expanding SaaS extortion — shifting from breaches to pressure campaigns across cloud apps. When data is everywhere, leverage is too. ☁️💣 #DataExtortion #SaaSSecurity
ShinyHunters Expands Scope of SaaS Extortion Attacks
Following its Salesforce attacks last year, the cybercrime group has broadened its targeting and gotten more aggressive with extortion tactics.
buff.ly
February 3, 2026 at 2:05 PM
Marshall Dennehey, a Philadelphia-based law firm founded in 1962, was targeted by SilentRansomGroup, which allegedly demanded $100,000 to stop stolen data from being published. #UnitedStates #DataExtortion #LawFirm
Ransom! Marshall Dennehey (MAY-2026)
Marshall Dennehey, a US-based legal firm founded in 1962 and headquartered in Philadelphia, was targeted by SilentRansomGroup after they were offered $100,000 to prevent data from being published. The impacted country(s): #UnitedStates
www.hendryadrian.com
May 13, 2026 at 2:45 AM
Wanted to check the article but I won’t consent to such practices of economic duress that the @theguardian.com uses that forces users to give up their online privacy, pay up or get out.

The ads don’t need to be personalized.

#DigitalCoercion #DataExtortion #UnconscionableDigitalTax #PrivacyRights
September 10, 2026 at 8:02 PM
Discover how the PREY-0058 extortion campaign uses Microsoft 365 vishing attacks and AiTM tactics to bypass MFA, steal cloud data, and demand high ransoms.

#Microsoft365 #Vishing #Cybersecurity #DataExtortion #PREY0058
PREY-0058: Microsoft 365 Vishing Attacks Extort Firms
Threat actors are actively compromising executive accounts using highly targeted Microsoft 365 vishing attacks. The PREY-0058 extortion campaign bypasses traditional multi-factor authentication to steal sensitive cloud data. At a Glance
securityonline.info
September 9, 2026 at 5:17 PM
New threat PREY-0058 uses fake IT calls & token-theft-AitM to extort Microsoft 365 execs. #CyberSecurity #Microsoft365 #IdentitySecurity #DataExtortion #Phishing #PREY0058 thedailytechfeed.com/microsoft-36...
September 7, 2026 at 7:06 PM
Ransomware group lists U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives on leak site; DOJ designates incident as major under federal guidelines

#Atf #Cyberattack #DataExtortion #FederalAgency #LawEnforcement #Qilin #Ransomware
ATF Confirms Cyber Incident After Qilin Ransomware Claim
Ransomware group lists U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives on leak site; DOJ designates incident as major under federal guidelines
pulseofnations.lol
August 30, 2026 at 12:26 AM
Clop built a custom web shell for Windchill data theft - extortion groups are evolving from opportunistic attacks to tailored intrusion tooling. 🎯⚠️ #DataExtortion #Ransomware
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file…
buff.ly
August 19, 2026 at 8:05 AM
📰 Wesco Konfirmasi Insiden Keamanan Setelah ExfilSquad Klaim Curi Data

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/08/12/wesco-data-breach-exfilsquad/

#clo
ud#cloudSecurity##crmr#cyberAttackr#cybersecurityB#dataBreachE#dataExtortionS#dataSecurityT#dataTheftl#exfilsquada#keamananSiber
August 12, 2026 at 8:20 AM
Data extortion is overtaking classic ransomware. The Kairos case shows attackers can force a 7-figure payment with stolen files alone - no encryption needed. New Hexon post: https://www.hexon.bot/blog/data-extortion-kairos-no-encryption #Cybersecurity #Ransomware #DataExtortion
July 4, 2026 at 5:30 PM
Hunters International ransomware group now focuses on data extortion. #DataExtortion #Cybersecurity #Ransomware
Hunters International Shifts to Data Extortion
Hunters International ransomware group now focuses on data extortion. #DataExtortion #Cybersecurity #Ransomware
www.bleepingcomputer.com
April 5, 2025 at 1:46 PM
FBI warns of fake BianLian ransomware extortion letters sent via mail; don't fall victim. #Cybersecurity #DataExtortion #FBIWarning
FBI Warns of Fake BianLian Extortion Letters
FBI warns of fake BianLian ransomware extortion letters sent via mail; don't fall victim. #Cybersecurity #DataExtortion #FBIWarning
arcticwolf.com
March 7, 2025 at 7:52 AM
Same attacker. Same week. Grafana refused to pay. Instructure settled. CoinbaseCartel stole 275M education records — no encryption, pure extortion. 170 victims since Sept 2025. Does your org have a data extortion policy?

#CyberSecurity #DataExtortion #Ransomware
May 20, 2026 at 11:00 AM
The FBI & DOJ are warning that North Korean IT workers are infiltrating U.S. companies using false identities to commit fraud and extort data. Indictments have been issued. Learn how to protect your company: bit.ly/4jwnRnV
#CyberSecurity #FBIWarning #DOJ #DataExtortion #RemoteWorkRisks #ITSecurity
January 24, 2025 at 9:01 PM
MyPillow Hit by Ransomware Attack as Cyber Threats Intensify #CybersecurityIncident #DarkWebLeak #DataExtortion
MyPillow Hit by Ransomware Attack as Cyber Threats Intensify
  MyPillow, a Minnesota-based bedding manufacturer founded by Mike Lindell, has been targeted by a ransomware group. This adds the company to a growing list of organizations that are currently under cyber extortion threats. As a result of the unauthorized access to a broad range of sensitive corporate and personal records, identified as Play, the threat actor claims that payroll data, financial information, tax information, identification information, and internal business files have been exfiltrated.  The claims have attracted attention due to the sensitive nature of the alleged exposed data, even though Lindell has denied the allegations and described them as politically motivated. As a result of this incident, the risks associated with modern ransomware campaigns are evolving, resulting from increased data theft and public exposure, which often accompany or replace traditional file encryption methods.  MyPillow has become increasingly aware that its network has been compromised and its company data has been stolen as further details emerge from the alleged intrusion. It was reported that CEO Mike Lindell dismissed the claims when they first emerged in May 2025, however, the threat actors later released approximately 9.8 gigabytes of data via a dark-web leak portal, a tactic commonly used to pressure organizations unwilling to negotiate ransom.  There are 11,456 files reported in the dataset dating from 2011 through 2026, indicating that historical records of the company have been preserved alongside more recent information about the company. This exposure indicates that the attackers obtained sensitive operational data, including payroll records and financial transactions, indicating the potential depth of the compromise, as well as raising further concerns about how long unauthorised access will remain within the company's network.  Play's dark-web leak portal revealed the allegations of MyPillow, listing the company among its claimed victims and setting a deadline for public release of purportedly stolen information if ransom negotiations failed. The allegations gained further visibility when MyPillow appeared there. Ransomware operations are evolving in a broader sense, with attackers increasingly stealing data and threatening to publish it, as opposed to relying solely on file encryption to threaten victims. In the ransomware ecosystem, data-centric extortion tactics are becoming increasingly popular. Modern threat groups increasingly prioritize stealing sensitive information over system encryption as a means of disrupting business operations. By leveraging the threat of public disclosure, they are exerting pressure on victims by leveraging the theft of sensitive information. By adopting this approach, organisations become more vulnerable to reputational damage, regulatory scrutiny, legal liabilities, and heightened concerns about employee and customer privacy as a result of an incident.  The lack of verification can lead to unverified claims of data compromise quickly escalating to a broader business risk, prompting questions about the security posture of the organization and the integrity of data that has been entrusted to it from stakeholders, partners, insurers, and regulators. In addition to the nature of the alleged cyber intrusion, the incident has gained heightened public attention as a result of the company's and its leadership's high profile.  During Mike Lindell's tenure, MyPillow has grown beyond its flagship bedding products to include mattresses, linens, bath products, nutritional supplements, coffee, and snacks. Since Lindell is a political activist and continues to promote disputed claims regarding the 2020 U.S. presidential election, MyPillow's public profile extends beyond retail. These claims have resulted in multiple legal challenges, making any major development involving the company likely to be of interest to individuals outside the cybersecurity community as well.  The consequences of such an unverified claim of data compromise are that it quickly escalates into a broader business risk, causing stakeholders, partners, insurers, and regulators to inquire about the organization's security posture and the integrity of data entrusted to it. Due to the nature of the alleged cyber intrusion as well as the profile of the company and its management, the incident has heightened public attention.  Since Mike Lindell has become President of MyPillow, it has expanded its product line beyond its bedding offerings to encompass mattresses, linens, bath products, nutritional supplements, coffee, and snack items. Due to Lindell's political activism and ongoing promotion of disputed claims surrounding the 2020 United States presidential election, MyPillow's public profile has extended beyond retail.  A number of legal challenges have been brought against the company for these claims, making any major development involving the company likely to draw attention from outside the cybersecurity community as well.  According to Lindell, political controversy has negatively impacted MyPillow's business, indicating that independent assessments have estimated an estimated $400 million in losses to the company and brand. Additionally, Lindell indicated that he plans to seek compensation through President Donald Trump's recently instituted $1.8 billion Anti-Weaponization Fund, an initiative that has become the subject of political debate and controversy.  Since several years, MyPillow has had financial difficulties, particularly after major retailers, including Walmart, Kohl's, J.C. Penney, Wayfair, and Bed Bath & Beyond, removed its products from their shelves as a result of the events surrounding January 6. While Lindell has maintained that these decisions were politically motivated, several retailers have indicated that declining consumer demand played a significant role in these decisions. Due to this, the ransomware claims are coming at a time when the company is already confronting legal disputes, reputational pressure, and broader political controversy.  The ten candidates who seek the Republican nomination to run for Minnesota’s gubernatorial office include Lindell, who will face Senator Amy Klobuchar as the Democratic frontrunner after Governor Tim Walz has decided not to seek another term.  Based on the information reportedly exposed through the leak, it appears as though access has been gained to some of the company's most important financial and personnel records. It is believed that the breach resulted in the theft of Social Security numbers, tax documentation including W-9 and 1099 forms, payroll records containing employee contact information, bank statements, wire transfer documentation, American Express account statements, vendor billing records, advertising expenditure reports, internal audit documents, budgeting materials from the corporation, and even aviation-related expense logs associated with private aircraft operations.  From a data security and compliance perspective, the breadth of the dataset indicates that the attackers may have accessed systems that contained both administrative and operational information, thus increasing the severity of the incident.  From a data security and compliance perspective, MyPillow has not disclosed how many people were potentially affected, whether external incident-resolution specialists were consulted, or whether identity theft protection services were offered to the affected. It remains unclear, therefore, how the breach was disclosed, how notifications were carried out, and how the company is conducting remediation efforts. In addition to the immediate allegations, this incident illustrates an important aspect of cybercrime: access to sensitive information has become just as valuable to threat actors as access to systems. In this case, it is likely that the outcome will be determined not only by what was accessed, but also by what was disclosed.
dlvr.it
June 6, 2026 at 6:22 PM
Why Backups Alone Can No Longer Protect Against Modern Ransomware #Backups #CyberSecurity #DataExtortion
Why Backups Alone Can No Longer Protect Against Modern Ransomware
For a long time, ransomware incidents have followed a predictable pattern. An organization’s systems are locked, critical files become inaccessible, operations slow down or stop entirely, and leadership must decide whether to recover data from backups or pay a ransom. That pattern still exists today, but recent findings show that the threat has evolved into multiple forms. A recent industry report based on hundreds of real-world incident response cases reveals that attackers are increasingly moving toward a different strategy. Instead of encrypting data, many are now stealing it and using it for extortion. These “data-only” attacks have increased sharply, rising from just 2 percent of cases to 22 percent within a year, representing an elevenfold jump. This trend is also reflected in broader industry data. The Verizon 2025 Data Breach Investigations Report treats both encrypted and non-encrypted ransomware incidents as part of a single extortion category. According to its findings, ransomware was involved in 44 percent of the breaches it studied. Why resilience needs to be redefined These developments highlight a critical issue. Many organizations still treat ransomware mainly as a problem of restoring operations. Their focus is often on how quickly systems can be brought back online, whether backups are secure, and how much downtime can be managed. While these factors remain relevant, they are no longer enough to address the full scope of risk. When attackers shift their focus from disabling systems to stealing sensitive information, the situation changes completely. The priority is no longer just restoring access to systems. Instead, organizations must immediately understand what data has been taken, who owns it, and how sensitive it is. This includes identifying whether the exposed information involves customer records, regulated datasets, intellectual property, or internal communications. It also requires knowing where that data was stored, whether in primary systems, cloud services, third-party platforms, or legacy storage that may have been retained unnecessarily. If leadership teams cannot quickly answer these questions, restoring systems will not prevent further damage, including regulatory consequences, reputational harm, or legal exposure. Data theft is becoming the main objective Additional reporting reinforces this shift. Data from Coveware shows that in the second quarter of 2025, data exfiltration occurred in 74 percent of ransomware incidents. The company noted that in many cases, stealing data has become the central objective rather than just a step before encryption. Attackers are no longer focused only on disruption. Instead, they are aiming to maximize pressure by using stolen data as leverage. Encryption still exists, but its role is changing This does not mean that encryption-based attacks have disappeared. Many ransomware operations still use a “double extortion” approach, where they both lock systems and steal data. However, the key change is that data theft alone can now be enough to force payment. This reduces the effectiveness of relying solely on backups as a defense strategy. Organizations such as the Cybersecurity and Infrastructure Security Agency continue to stress the importance of maintaining secure and offline backups that are regularly tested. At the same time, they warn that cloud-based backups can fail if compromised data is synchronized back into the system and overwrites clean versions. This underlines a broader reality: restoring systems is only one part of true resilience. Moving beyond a recovery-focused mindset The cybersecurity industry is gradually adjusting to these changes. There is a growing emphasis on protecting and understanding data, rather than focusing only on system recovery. This reflects a more dynamic turn of events. Resilience is no longer just about recovering from an attack. It is about reducing uncertainty about data exposure before an incident occurs. However, many organizations still measure their preparedness using disaster recovery metrics such as recovery time objectives and backup testing. Even service providers often frame ransomware readiness in these terms. In a data-driven threat environment, a more meaningful measure of security maturity is whether an organization truly understands its data. This includes knowing where sensitive information is stored, how it moves across systems, who has access to it, and whether it needs to be retained. Guidance from the National Institute of Standards and Technology supports this approach. Its Cybersecurity Framework 2.0 recommends maintaining detailed inventories of data, including its type, ownership, origin, and location. It also emphasizes lifecycle management, such as securely deleting unnecessary data and reducing redundant systems that increase exposure. NIST’s incident response guidance further highlights that organizations with clear data inventories are better equipped to determine what information may have been affected during a breach. The hidden risk of data sprawl A major challenge for many organizations is uncontrolled data growth. Sensitive information is often copied across multiple platforms, including cloud storage, collaboration tools, shared drives, employee devices, and third-party services. At the same time, outdated data is rarely deleted, often because responsibility for doing so is unclear. Access permissions also tend to expand over time without proper review. As a result, organizations may appear prepared due to strong backup systems, while actually carrying significant hidden risk due to poorly managed data. The bigger strategic lesson The key takeaway is not that backups are unimportant. They remain a critical part of cybersecurity. However, they solve a different problem. Backups help restore systems after disruption. They do not protect against the consequences of stolen data, such as loss of confidentiality, reputational damage, or reduced negotiating power during an extortion attempt. To address modern threats, resilience must become more focused on data. This includes better classification of sensitive information, stronger access controls, improved visibility across cloud and third-party systems, and stricter data retention practices to reduce unnecessary exposure. Organizations also need to communicate more clearly with leadership and stakeholders about the difference between operational recovery and true resilience. Ultimately, the organizations best prepared for modern ransomware are not just those that can recover quickly, but those that already understand their data well enough to respond immediately. In today’s environment, the gap between having backups and truly understanding data is where attackers gain their advantage.
dlvr.it
April 17, 2026 at 4:28 AM
RansomHouse Develops More Complex Encryption for Recent Attacks #CyberCrime #DataExtortion #Encryption
RansomHouse Develops More Complex Encryption for Recent Attacks
  The ransomware group known as RansomHouse has recently enhanced the encryption mechanism used in its attacks, moving away from a basic, single-step process to a more advanced, multi-layered approach. This change reflects a deliberate effort to strengthen the effectiveness of its ransomware operations. Earlier versions of the encryptor relied on a linear method, where data was transformed in one continuous pass. The updated version introduces multiple stages of processing, which results in stronger encryption, improved execution speed, and greater stability across modern systems. These improvements increase the pressure on victims by making encrypted data harder to recover and negotiations more favorable for attackers after systems are locked. RansomHouse first appeared in late 2021 as a cybercrime group focused on data extortion, where stolen information was used as leverage rather than encryption alone. Over time, the group expanded its tactics and began deploying ransomware encryptors during attacks. It also developed an automated tool, known as MrAgent, designed to simultaneously encrypt multiple VMware ESXi hypervisors, a technique that allows attackers to disrupt large virtualized environments efficiently. In more recent activity, security analysts observed RansomHouse using more than one ransomware strain during attacks on a major Japanese e-commerce company. This suggests a flexible operational strategy rather than reliance on a single malware family. Further insight into the group’s evolving capabilities comes from a new analysis by cybersecurity researchers, who examined RansomHouse’s latest encryptor, internally referred to as “Mario.” This version introduces a two-stage data transformation process that relies on two different encryption keys: one substantially longer than the other. Using multiple keys increases the randomness of the encrypted output, making partial file recovery or reconstruction far more challenging. The updated encryptor also changes how files are handled during the encryption process. Instead of treating all files the same way, it adjusts its behavior based on file size. Large files are processed in dynamically sized chunks, with encryption applied intermittently rather than continuously. This irregular pattern makes the malware harder to analyze because it avoids predictable processing behavior. Researchers also noted improvements in how the encryptor manages memory. The newer version separates tasks across multiple buffers, with each buffer assigned a specific role during encryption. This design increases operational complexity and reduces inefficiencies found in earlier variants. Another visible change is the amount of internal information displayed during file processing. Unlike older versions, which only indicated when encryption was complete, the new encryptor provides more detailed status output as it operates. Despite these changes, the ransomware continues to focus on virtual machine-related files, renaming encrypted data with a new extension and placing ransom instructions across affected directories. Security researchers caution that these upgrades indicate a troubling direction in ransomware development. While RansomHouse does not carry out attacks at the scale of larger ransomware groups, its continued investment in advanced encryption techniques points to a strategy centered on precision, resilience, and evasion rather than volume.
dlvr.it
December 21, 2025 at 3:12 PM