CuraSec

tag: Extortion · 5 items

2026-08-19 · The Hacker News · source ↗ #ransomware#social-engineering#extortion
  • Engineer — Learn: No technical vulnerability or patch action here, but engineers involved in ransomware IR should know secondary extortion schemes like this exist and treat unsolicited ‘data deletion’ offers as suspect.
  • SOC/IR — Learn: No IOCs or detectable TTPs are provided, but IR analysts should add this pattern to their ransomware playbooks — unsolicited emails from third parties claiming server access during an active incident are a red flag to escalate, not engage.
  • Leader — Learn: If the organization is ever a ransomware victim, communications teams should know that secondary fee-based offers to delete stolen data are likely scams; worth a brief mention in IR tabletop exercises and vendor-communications guidance.
2026-08-14 · BleepingComputer · source ↗ #insider-threat#data-theft#extortion
  • Engineer — Skip
  • SOC/IR — Learn: A contractor-turned-extortionist exfiltrated data and leveraged it for a $2.5M scheme; worth reviewing contractor access controls and DLP coverage as a case study for insider threat detection patterns.
  • Leader — Learn: A successful insider extortion prosecution illustrates board-level risk from contractor data access; useful for reinforcing third-party access governance and insider threat program justifications.
2026-08-07 · BleepingComputer · source ↗ #threat-actors#extortion#financial-sector
  • Engineer — Skip
  • SOC/IR — Learn: Actor profile useful for financial-sector defenders: UNC6671 is tied to BlackFile and is running an active extortion campaign against hedge funds and PE firms, but no IOCs, TTPs, or detection-ready technical details are available in this item yet.
  • Leader — Act: If your organization is in financial services, brief leadership now on the active UNC6671 extortion campaign targeting hedge funds and private-equity firms; verify whether your firm has received any suspicious outreach and confirm IR retainer readiness.
2026-07-28 · BleepingComputer · source ↗ #supply-chain#data-breach#extortion
  • Engineer — Learn: Supply-chain credential theft at a major professional services firm is a relevant attack pattern, but no specific compromised component, IOCs, or affected systems have been identified yet — nothing to patch or audit without further detail.
  • SOC/IR — Learn: ShinyHunters remains an active extortion actor using supply-chain pivots; no IOCs or TTPs are published in this disclosure, so no hunt can be launched today — watch for follow-on reporting with technical indicators.
  • Leader — Act: E&Y provides audit, tax, and advisory services to a large share of enterprises, meaning your firm’s confidential data may be in scope; contact your E&Y relationship manager this week to confirm exposure and request a formal incident attestation before customers or auditors ask first.
2026-07-18 · BleepingComputer · source ↗ #vendor-breach#healthcare#extortion
  • Engineer — Skip
  • SOC/IR — Learn: Active investigation at a major healthcare vendor with confirmed unauthorized access and extortion claims, but no IOCs, TTPs, or ATT&CK-mappable behaviors have been published yet — nothing actionable to hunt or detect on today.
  • Leader — Act: Abbott confirmed unauthorized access to Exact Sciences legacy systems in its Cancer Diagnostics division and is probing a separate LabCentral portal breach with data-theft claims; if your organization uses Abbott lab or diagnostics services, confirm your exposure this week and request a written attestation of incident scope from your account contact.