logo

Colt confirms customer data stolen as Warlock ransomware auctions files

ID: ae860ff5-6ae5-55f1-bc3c-ef89bcd55844

STIX ID: report--ae860ff5-6ae5-55f1-bc3c-ef89bcd55844

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-08-21

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Colt Technology Services confirmed an August 12 cyberattack in which the Warlock (aka Storm-2603) ransomware group exfiltrated customer and corporate documents—allegedly up to one million files—now being sold on cybercrime forums; the group has used modified LockBit and Babuk encryptors, includes a Tox ID in ransom notes, and has been observed exploiting a SharePoint vulnerability to breach networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.