logo

Out of the Crypt: The Evolving Cyber Extortion Economy

ID: 5ffdde4d-a1d4-5a73-936c-21b094d284fb

STIX ID: report--5ffdde4d-a1d4-5a73-936c-21b094d284fb

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: Matt Brady and Justin Moore

...
...

Unit 42 reports a notable industry trend in 2025–2026 toward data-only extortion and theft—driven by better backups, endpoint maturity, and regulatory pressure—profiling active groups (e.g., TGR-CRI-1135/TeamPCP, Bling Libra, CL-CRI-1116), supply-chain compromises affecting hundreds of software packages, vishing-based SaaS intrusions, data leak sites and RaaS/EaaS collaborations, rapid exfiltration timelines (as fast as 39 seconds and AI-accelerated cases), sector targeting of mid-sized Professional Services, Healthcare and Consumer Services, and recommended controls for DLP, SaaS posture, identity resilience, supply-chain integrity, and AI-threat preparedness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.