logo

Follow-on extortion campaign: confirmation of some findings by Arctic Wolf

ID: ad759a3a-bb37-5e40-8987-2ad5b59cbbf6

STIX ID: report--ad759a3a-bb37-5e40-8987-2ad5b59cbbf6

Feed Name: DataBreaches.Net

Threat Score
64/100

Date Published: 2024-01-10

Date Updated: 2026-04-19

Author: Dissent

...
...

Arctic Wolf and DataBreaches document a follow-on extortion scheme in which a threat actor, including one calling themselves “xanonymoux,” targets victims of Akira and Royal ransomware by offering paid “ethical” services to delete or provide access to stolen data allegedly on the gangs’ servers. Cited interactions include references to Michael Garron Hospital data samples and claims that Akira, Karakurt, TommyLeaks, and SchoolBoys Gang are interlinked, though such affiliations remain unproven. The report underscores the risk of re-extortion and social engineering against organizations already victimized by ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.