Threats Tagged 'data extortion'
View all threats tagged with 'data extortion'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'data extortion'
Click on any threat for detailed analysis and mitigation recommendations
Helix is a data extortion group conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint data exfiltration. Emerging from the BlackFile and ShinyHunters ecosystem after BlackFile's shutdown in April 2026, Helix uses social engineering to impersonate managers during vishing calls to trigger device code authentication flows. After compromising accounts, the group registers MFA to maintain access, enumerates SharePoint sites with automated tools, and exfiltrates bulk data. Their infrastructure shares hosting with BlackFile and uses geo-matched residential proxies to evade detection. The group varies dwell times to complicate incident response efforts. Join the discussion | AlienVault OTX General | 07/23/2026, 15:25:38 UTC Added: 07/23/2026, 15:37:23 UTC |
Since April 2026, threat actors operating under O-UNC-066 have deployed a sophisticated vishing campaign targeting Microsoft 365 passkey enrollment. Attackers register domains containing 'passkey' and call victims to convince them to register new passkeys. Victims are directed to operator-controlled phishing kits that mimic Microsoft's enrollment process while attackers simultaneously register their own passkeys in victim accounts. The kit uses real-time polling and adapts to various MFA requirements including TOTP, push notifications, and SMS OTP. Targeted organizations span food and beverage, technology, healthcare, automotive, construction, and aviation industries. The campaign leverages Microsoft's legitimate passkey registration campaigns as a pretext, with primary motivation being data extortion through the Pink data leak site. Infrastructure is hosted on DDoS-Guard and IQWeb FZ-LLC. Join the discussion | AlienVault OTX General | 07/10/2026, 08:15:24 UTC Added: 07/20/2026, 11:11:45 UTC |
Cyber threats targeting the global aviation and aerospace sector are rapidly evolving, with ransomware, identity-based intrusions, and platform-level disruptions becoming dominant attack vectors. The interconnected nature of this ecosystem, combined with time-sensitive operations and complex third-party dependencies, makes it highly attractive to threat actors. Shared airport IT platforms represent critical single points of failure, as demonstrated by the September 2025 ransomware attack on Collins Aerospace MUSE system that disrupted major European airports including Heathrow, Brussels, Berlin, and Dublin. Major ransomware groups like LockBit and Cl0p maintain heavy focus on aviation suppliers, while advanced persistent threat groups including Refined Kitten, Wicked Panda, and Fancy Bear conduct strategic espionage targeting intellectual property, aircraft design data, and military aviation intelligence. Emerging threats include vulnerabilities in regional airports, aviation SaaS platforms, and satellite ... Join the discussion | AlienVault OTX General | 05/06/2026, 10:26:02 UTC Added: 05/07/2026, 08:36:22 UTC |
Showing 1 to 3 of 3 results