Tag: extortion
130 articles

ShinyHunters Breach Exposes 12.9 Million Carhartt Accounts
A massive data breach at Carhartt has exposed a staggering 12.9 million customer accounts, compromising sensitive information and putting millions of people at risk. The breach, attributed to the ShinyHunters extortion group, included a treasure trove of customer, employee, and corporate data.

Ransomware Affiliate Exploits Trust with Fake Recovery Service
A new scam is targeting ransomware victims, with a fake recovery service called Ransom Busters offering to provide decryption keys and delete stolen data for a hefty fee of $20,000 to $60,000. The impostors are preying on people's trust, contacting them via email and claiming to have access to sensitive information.

Contractor Sentenced for Insider Attack on Brightly Software
A contractor's six-week extortion scheme against Brightly Software ended with a guilty verdict, after he threatened to expose sensitive payroll and personnel records unless he received a whopping $2.5 million - ultimately settling for a significantly smaller sum of $7,540.92. The 27-year-old data analyst had been quietly siphoning off corporate data from the Siemens-owned company's network for months.

Uber Freight Probes Data Breach by Helix Extortion Group
Uber Freight is investigating a data security incident after a hacktivist group claimed to have breached its systems, but fortunately, the issue has been identified, contained, and resolved, with operations now secure and running smoothly. The breach hasn't disrupted daily operations, and the company is working to put customers' minds at ease.

Google Exposes Redact Extortion Group's Ties to BlackFile Rebrand
Google's Threat Intelligence Group uncovered a clever rebranding scheme by the notorious extortion group formerly known as BlackFile, which has now resurfaced under the name Redact, after allegedly being hijacked by a rogue affiliate. The group had claimed retirement, but clearly wasn't done causing trouble, raking in around $10.69 million in Bitcoin transactions.

Canadian Hacker Pleads Guilty to Snowflake Extortion Scheme
A 26-year-old Canadian hacker has pleaded guilty to masterminding a massive Snowflake extortion scheme that compromised over 100 million AT&T customers' sensitive call and text history records. Connor Riley Moucka faces up to 30 years in prison for his role in the cross-border hacking and extortion operation.

Cyberattacks on Hedge Funds Tied to UNC6671 Extortion Group
Meet UNC6671, a notorious extortion group linked to a string of cyberattacks on hedge funds, operating under a web of public brands to deceive and exploit its victims. Using voice-phishing tactics, the group tricks employees into divulging sensitive info, paving the way for a potentially devastating breach.

Ransom Cartel creator gets 16 years for cybercrime scheme
A 40-year-old Belarusian cybercriminal has been sentenced to 16 years in prison for masterminding a massive ransomware scheme that targeted at least 18 companies and attempted to extort a staggering $5.2 million. The defendant, who pleaded guilty to conspiracy and identity theft charges, was a longtime fixture on Russian-speaking cybercrime forums before his arrest and extradition.

Canadian Hacker Pleads Guilty in Snowflake Extortion Scheme
A Canadian hacker has pleaded guilty to masterminding a massive extortion scheme targeting Snowflake customers, compromising at least 165 accounts and swiping billions of sensitive records in a brazen heist that raked in over $2.5m in ransom payments. Connor Riley Moucka, 26, faces up to 32 years in prison for his role in the 2024 cyber attacks.

Ransom Cartel Creator Sentenced to 16 Years for Global Cyberattacks
Meet Maksim Silnikau, the mastermind behind the notorious Ransom Cartel, who's now facing 16 years behind bars for masterminding a global cyberattack spree that targeted at least 18 companies and raked in millions for him. The US Department of Justice brought him to justice, sentencing him for conspiracy, wire fraud, and identity theft.

ShinyHunters Breach Exposes Brinks Home Data
Brinks Home recently disclosed a security breach, with an extortion group claiming to have exposed millions of customer records, prompting the company to activate its incident response procedure and work with leading forensics experts to contain the damage. The breach, identified on July 20, thankfully didn't impact alarm monitoring and system functionality.

ShinyHunters data leaks fuel sextortion scam targeting breach victims
Beware of sextortion scam emails claiming to be from ShinyHunters, a hacking group that's actually being impersonated by copycats using leaked data to threaten victims. These scammers are sending convincing but fake messages, trying to extort money by claiming they've recorded compromising information about you.

Swiss Train Maker Thwarts Ransomware Demand
A Swiss train maker, Stadler Rail, recently outsmarted a ransomware attack by refusing to give in to a hefty $123 million extortion demand from hackers. By taking a firm stance, the company protected its operational integrity and public reputation.

Stadler Rail Rebuffs $12.3M Ransom Demand by Everest Gang
Stadler Rail is taking a firm stance against ransomware extortion, boldly refusing to pay the $12.3 million demanded by the Everest gang after a mid-July data breach. The company has instead filed a criminal complaint, making it clear that it will never give in to such threats.

Ransomware gangs exploit victims' payments, extort again
Paying ransomware attackers doesn't always guarantee relief, with many victims being extorted again. A recent survey found 54% of organizations globally paid a ransom, yet it often doesn't end the attack.

Abbott Labs Probes Two Cyber Incidents Amid Extortion Claims
Abbott Laboratories is investigating a cyber incident that involved unauthorized access to a limited number of internal systems within its Cancer Diagnostics business, and has activated incident response procedures to address the issue. The company confirms that its operations remain unaffected and that the affected systems are separate from its other businesses and systems.

Armenian National Pleads Guilty to Ryuk Ransomware Conspiracy
Karen Serobovich Vardanyan, an Armenian national, has pleaded guilty to conspiracy charges for his role in a massive Ryuk ransomware scheme that raked in over $15 million in ransom payments from US-based organizations. The guilty plea marks a major win in the fight against cybercrime, as Vardanyan admitted to his part in the global extortion plot.

Ransomware Negotiator Sentenced for Aiding BlackCat Extortions
A ransomware negotiator turned double agent, Angelo Martino, has been sentenced to 70 months in prison for betraying his clients and working with BlackCat to drive up ransoms for personal gain. Martino's shocking deceit involved selling out his clients' confidential negotiating positions to the very cybercriminals he was hired to thwart.

Ransomware Negotiator Sentenced for Duping Clients in $75.3 Million Extortion Scheme
A trusted ransomware negotiator turned double agent, Angelo Martino betrayed his clients, funneling their confidential info to BlackCat affiliates and lining his pockets with a share of their ransoms, leaving a trail of devastated businesses in his wake. His deceit raked in $75.3 million for him and his co-conspirators.

AI-Powered Attacks Rapidly Compromise Cloud Targets
The increasing accessibility of large language models and agentic AI has empowered even less sophisticated threat actors to launch lightning-fast attacks with unprecedented scale, significantly ramping up the challenge for defenders. This alarming trend enables attackers to accelerate their workflows and compromise cloud targets at an unprecedented pace.

ShinyHunters Breach Exposes 2.3M Moody Bible Institute Accounts
A massive data breach at Moody Bible Institute has exposed the sensitive information of over 2.3 million people, including names, addresses, phone numbers, and more, after being targeted by the notorious extortion group ShinyHunters. The stolen data, which was leaked on June 23, puts countless individuals at risk of identity theft and cyber attacks.

US Government Entity Pays $1 Million to Thwart Data Leak
A US government entity was forced to pay a hefty $1 million ransom to prevent a massive data leak, after a group called Kairos threatened to release 1.6 million files unless their demand was met. The payment was the culmination of a month-long negotiation that began with a $3 million opening demand.

Ransomware Groups Adopt Corporate Structure to Extort Victims
Meet Black Basta, a ransomware group that operated like a corporate powerhouse, launching attacks on 520 victims across 39 industries and raking in at least $107 million in bitcoin payments. With a structured team, set schedules, and outsourced tasks, this syndicate's business model was surprisingly sophisticated.

Blackfield Ransomware Targets Nidec with $2 Million Extortion Demand
Nidec Corporation revealed that its Taiwanese subsidiary was hit by a Blackfield ransomware attack, prompting swift emergency measures to contain the breach and prevent further damage. The hackers are now demanding a whopping $2 million in extortion, threatening to leak sensitive data if their demands aren't met.