logo

Ransomware victims targeted by fake hack-back offers

ID: 9c142460-8a54-516c-9aab-eca3461f5bfe

STIX ID: report--9c142460-8a54-516c-9aab-eca3461f5bfe

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-01-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Arctic Wolf investigated cases in Oct–Nov 2023 where organizations hit by Royal and Akira ransomware were approached by a scammer posing as a security researcher offering to delete stolen data for a fee (up to ~5 BTC); consistent messaging across cases suggests a coordinated follow-on extortion campaign that increases financial and operational risk for ransomware victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.