logo

ALPHV Ransomware Expands Extortion Techniques

ID: ca3ec731-9ade-5a5e-8f1b-0a4505a408b3

STIX ID: report--ca3ec731-9ade-5a5e-8f1b-0a4505a408b3

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

ALPHV (aka BlackCat) ransomware has added a new extortion capability: a searchable web-based portal called "ALPHV Collections" that lets adversaries query exfiltrated victim data (file contents, filenames, wildcard searches). The report shows examples of exposed PII and credentials, warns that such searchable leaks increase the risk of secondary attacks and supply-chain compromise, and provides actionable defensive recommendations (monitoring for third-party breaches, DLP, EDR, IAM, backups, and regular testing).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.