Out of the Crypt: The Evolving Cyber Extortion Economy
ID: 5ffdde4d-a1d4-5a73-936c-21b094d284fb
STIX ID: report--5ffdde4d-a1d4-5a73-936c-21b094d284fb
Feed Name: Palo Alto Networks Unit 42
Unit 42 reports a notable industry trend in 2025–2026 toward data-only extortion and theft—driven by better backups, endpoint maturity, and regulatory pressure—profiling active groups (e.g., TGR-CRI-1135/TeamPCP, Bling Libra, CL-CRI-1116), supply-chain compromises affecting hundreds of software packages, vishing-based SaaS intrusions, data leak sites and RaaS/EaaS collaborations, rapid exfiltration timelines (as fast as 39 seconds and AI-accelerated cases), sector targeting of mid-sized Professional Services, Healthcare and Consumer Services, and recommended controls for DLP, SaaS posture, identity resilience, supply-chain integrity, and AI-threat preparedness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
