Threats Tagged 'data leak'
View all threats tagged with 'data leak'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'data leak'
Click on any threat for detailed analysis and mitigation recommendations
The Kraken ransomware group, originating from the HelloKitty cartel, conducts sophisticated big-game hunting and double extortion attacks targeting Windows, Linux, and VMware ESXi systems. They exploit SMB vulnerabilities for initial access and use tools like Cloudflared and SSHFS for persistence and data exfiltration. Kraken ransomware features advanced capabilities including multi-threaded encryption, encryption benchmarking, anti-analysis techniques, and self-deletion to evade detection. The group operates a public data leak site and has launched an underground forum called 'The Last Haven Board' to facilitate their activities. They target a wide range of file types, including SQL databases and network shares, increasing their impact on enterprise environments. Although no known exploits are currently reported in the wild, the threat is medium severity due to its cross-platform nature and complex attack techniques. European organizations, especially those with VMware ESXi and SMB-exposed systems, face significant risk. Denmark is specifically noted as affected, with other European countries likely at risk based on market penetration and strategic targets. Mitigation requires targeted patching of SMB vulnerabilities, network segmentation, monitoring for Cloudflared and SSHFS usage, and robust incident response plans. Join the discussion | AlienVault OTX General | 11/13/2025, 18:04:27 UTC Added: 11/13/2025, 20:05:17 UTC |
The BlackNevas ransomware group, first appearing in November 2024, has been targeting various industries and critical infrastructure globally, with a focus on the Asia-Pacific region. The group uses AES and RSA encryption, adding the '.-encrypted' extension to affected files. BlackNevas operates independently, threatening to leak data on their own site and through partners. The ransomware supports multiple arguments, excludes certain system paths and file types from encryption, and uses a unique method to check for previous infection. It also creates ransom notes in all accessible folders, demanding negotiation within seven days to prevent data leaks. Join the discussion | AlienVault OTX General | 09/12/2025, 07:41:08 UTC Added: 09/12/2025, 08:11:38 UTC |
A newly emerged ransomware group called Dire Wolf has been observed since May 2025, targeting multiple sectors globally with a focus on manufacturing and technology. The group employs double extortion tactics, encrypting files and threatening to publish stolen data. Analysis of a Dire Wolf ransomware sample revealed it was written in Golang and uses a combination of Curve25519 and ChaCha20 algorithms for encryption. The malware disables event logging, terminates specific processes and services, and deletes backups and recovery options. Victims are given personalized ransom notes with login details for negotiation. As of writing, 16 victims across 11 nations have been listed on the group's leak site, with the US and Thailand being the most affected. Join the discussion | AlienVault OTX General | 07/02/2025, 07:12:53 UTC Added: 07/02/2025, 07:24:34 UTC |
In May 2025, Pakistan-linked hacktivist groups claimed over 100 cyberattacks on Indian government, education, and critical infrastructure websites. However, an investigation reveals most breaches were exaggerated or fake. Alleged data leaks contained primarily public information, website defacements left no real impact, and DDoS attacks caused minimal disruption. The more significant threat came from APT36, which used Crimson RAT malware to target Indian defense networks following the Pahalgam terror attack. The malware, delivered through phishing emails with malicious attachments, allows remote execution of commands and data exfiltration. While hacktivist claims generated alarming headlines, the actual impact was limited, with most targeted websites operating normally. Join the discussion | AlienVault OTX General | 05/11/2025, 18:13:17 UTC Added: 06/10/2025, 18:15:58 UTC |
Showing 1 to 4 of 4 results