logo

How Black Basta Turned Public Data into a Breach Playbook by Lucie Cardiet

ID: d0cd1d0d-7251-5561-8bd5-f18423ee16c5

STIX ID: report--d0cd1d0d-7251-5561-8bd5-f18423ee16c5

Feed Name: Vectra AI Blog

Threat Score
70/100

Date Published: 2025-06-25

Date Updated: 2026-05-01

...
...

**Executive summary:** Leaked Black Basta chat logs reveal a methodical OSINT-driven process—using services like ZoomInfo, LinkedIn, RocketReach, Shodan and public credential dumps—to map organizations, find exposed infrastructure, harvest credentials, and quietly gain access before executing ransomware; the piece emphasizes the importance of reducing public exposure, improving access controls and monitoring identity/behavioral signals as defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.