Follow-on extortion campaign: confirmation of some findings by Arctic Wolf
ID: ad759a3a-bb37-5e40-8987-2ad5b59cbbf6
STIX ID: report--ad759a3a-bb37-5e40-8987-2ad5b59cbbf6
Feed Name: DataBreaches.Net
Arctic Wolf and DataBreaches document a follow-on extortion scheme in which a threat actor, including one calling themselves “xanonymoux,” targets victims of Akira and Royal ransomware by offering paid “ethical” services to delete or provide access to stolen data allegedly on the gangs’ servers. Cited interactions include references to Michael Garron Hospital data samples and claims that Akira, Karakurt, TommyLeaks, and SchoolBoys Gang are interlinked, though such affiliations remain unproven. The report underscores the risk of re-extortion and social engineering against organizations already victimized by ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
