logo

Maze Ransomware Attack on Cognizant

ID: 6718eb43-adde-5e0a-bc36-429d5a2ec98d

STIX ID: report--6718eb43-adde-5e0a-bc36-429d5a2ec98d

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-09

Date Updated: 2026-07-16

...
...

Cyble reports a likely Maze ransomware incident targeting IT services firm Cognizant, describing Maze’s "steal, lock and inform" extortion approach, ongoing negotiations, and advising focus on data leakage and detection. The post provides IOCs (mazedecrypt.top and multiple 91.218.114.* IPs), suggests YARA hunting for “DECRYPT-FILES.txt”, and also lists several unrelated, newly observed data breaches the vendor is monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.