Is KillSec3 Trying to Extort Victims Using Publicly Leaked Data?
ID: 99575b95-18cc-59c6-a388-3b3541f69da7
STIX ID: report--99575b95-18cc-59c6-a388-3b3541f69da7
Feed Name: DataBreaches.Net
This report examines KillSec’s recent ransomware activity and finds that in October–November 2024, 39 of 68 listed victims had the same or nearly identical data already publicly exposed via misconfigured storage, suggesting affiliates may be extorting organizations using previously leaked datasets rather than encrypting systems. Some RansomHub cases show a similar, though smaller, pattern. The authors found little evidence of actual encryption by KillSec in this period and advise potential victims to search for and lock down exposed servers and to avoid paying for data deletion since the information is likely already widely accessible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
