<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Extortion on CuraSec</title><link>https://curasec.metacog.co.kr/tags/extortion/</link><description>Recent content in Extortion on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 11:36:35 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/extortion/index.xml" rel="self" type="application/rss+xml"/><item><title>Ransom Busters Charges Victims Up to $60K to Delete Stolen Data</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-ransom-busters-claims-it-hacked-ransomware-servers-asks-vict/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-ransom-busters-claims-it-hacked-ransomware-servers-asks-vict/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No technical vulnerability or patch action here, but engineers involved in ransomware IR should know secondary extortion schemes like this exist and treat unsolicited &amp;lsquo;data deletion&amp;rsquo; offers as suspect.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or detectable TTPs are provided, but IR analysts should add this pattern to their ransomware playbooks — unsolicited emails from third parties claiming server access during an active incident are a red flag to escalate, not engage.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> If the organization is ever a ransomware victim, communications teams should know that secondary fee-based offers to delete stolen data are likely scams; worth a brief mention in IR tabletop exercises and vendor-communications guidance.&lt;/li>
&lt;/ul></description></item><item><title>Data analyst jailed for $2.5M extortion scheme against employer</title><link>https://curasec.metacog.co.kr/insights/2026-08-14-data-analyst-sent-to-prison-for-stealing-data-extorting-empl/</link><pubDate>Fri, 14 Aug 2026 11:54:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-14-data-analyst-sent-to-prison-for-stealing-data-extorting-empl/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> A contractor-turned-extortionist exfiltrated data and leveraged it for a $2.5M scheme; worth reviewing contractor access controls and DLP coverage as a case study for insider threat detection patterns.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A successful insider extortion prosecution illustrates board-level risk from contractor data access; useful for reinforcing third-party access governance and insider threat program justifications.&lt;/li>
&lt;/ul></description></item><item><title>UNC6671/BlackFile extortion group actively targets financial firms</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-ext/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-ext/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Actor profile useful for financial-sector defenders: UNC6671 is tied to BlackFile and is running an active extortion campaign against hedge funds and PE firms, but no IOCs, TTPs, or detection-ready technical details are available in this item yet.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If your organization is in financial services, brief leadership now on the active UNC6671 extortion campaign targeting hedge funds and private-equity firms; verify whether your firm has received any suspicious outreach and confirm IR retainer readiness.&lt;/li>
&lt;/ul></description></item><item><title>ShinyHunters Claims Ernst &amp; Young Breach via Supply-Chain Attack</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-ernst-young-data-breach-claimed-by-shinyhunters-extortion-ga/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-ernst-young-data-breach-claimed-by-shinyhunters-extortion-ga/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Supply-chain credential theft at a major professional services firm is a relevant attack pattern, but no specific compromised component, IOCs, or affected systems have been identified yet — nothing to patch or audit without further detail.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> ShinyHunters remains an active extortion actor using supply-chain pivots; no IOCs or TTPs are published in this disclosure, so no hunt can be launched today — watch for follow-on reporting with technical indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> E&amp;amp;Y provides audit, tax, and advisory services to a large share of enterprises, meaning your firm&amp;rsquo;s confidential data may be in scope; contact your E&amp;amp;Y relationship manager this week to confirm exposure and request a formal incident attestation before customers or auditors ask first.&lt;/li>
&lt;/ul></description></item><item><title>Abbott Laboratories probes two cyber incidents amid extortion claims</title><link>https://curasec.metacog.co.kr/insights/2026-07-18-abbott-probes-two-cyber-incidents-amid-extortion-claims/</link><pubDate>Sat, 18 Jul 2026 11:51:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-18-abbott-probes-two-cyber-incidents-amid-extortion-claims/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Active investigation at a major healthcare vendor with confirmed unauthorized access and extortion claims, but no IOCs, TTPs, or ATT&amp;amp;CK-mappable behaviors have been published yet — nothing actionable to hunt or detect on today.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Abbott confirmed unauthorized access to Exact Sciences legacy systems in its Cancer Diagnostics division and is probing a separate LabCentral portal breach with data-theft claims; if your organization uses Abbott lab or diagnostics services, confirm your exposure this week and request a written attestation of incident scope from your account contact.&lt;/li>
&lt;/ul></description></item></channel></rss>