Skip to main content

Threats Tagged 'data extortion'

View all threats tagged with 'data extortion'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: data extortion

Threats Tagged 'data extortion'

Click on any threat for detailed analysis and mitigation recommendations

Helix is a data extortion group conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint data exfiltration. Emerging from the BlackFile and ShinyHunters ecosystem after BlackFile's shutdown in April 2026, Helix uses social engineering to impersonate managers during vishing calls to trigger device code authentication flows. After compromising accounts, the group registers MFA to maintain access, enumerates SharePoint sites with automated tools, and exfiltrates bulk data. Their infrastructure shares hosting with BlackFile and uses geo-matched residential proxies to evade detection. The group varies dwell times to complicate incident response efforts.

Join the discussion

Since April 2026, threat actors operating under O-UNC-066 have deployed a sophisticated vishing campaign targeting Microsoft 365 passkey enrollment. Attackers register domains containing 'passkey' and call victims to convince them to register new passkeys. Victims are directed to operator-controlled phishing kits that mimic Microsoft's enrollment process while attackers simultaneously register their own passkeys in victim accounts. The kit uses real-time polling and adapts to various MFA requirements including TOTP, push notifications, and SMS OTP. Targeted organizations span food and beverage, technology, healthcare, automotive, construction, and aviation industries. The campaign leverages Microsoft's legitimate passkey registration campaigns as a pretext, with primary motivation being data extortion through the Pink data leak site. Infrastructure is hosted on DDoS-Guard and IQWeb FZ-LLC.

Join the discussion

Cyber threats targeting the global aviation and aerospace sector are rapidly evolving, with ransomware, identity-based intrusions, and platform-level disruptions becoming dominant attack vectors. The interconnected nature of this ecosystem, combined with time-sensitive operations and complex third-party dependencies, makes it highly attractive to threat actors. Shared airport IT platforms represent critical single points of failure, as demonstrated by the September 2025 ransomware attack on Collins Aerospace MUSE system that disrupted major European airports including Heathrow, Brussels, Berlin, and Dublin. Major ransomware groups like LockBit and Cl0p maintain heavy focus on aviation suppliers, while advanced persistent threat groups including Refined Kitten, Wicked Panda, and Fancy Bear conduct strategic espionage targeting intellectual property, aircraft design data, and military aviation intelligence. Emerging threats include vulnerabilities in regional airports, aviation SaaS platforms, and satellite ...

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: data extortion
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses