Skip to main content

Threats Tagged 'data leak'

View all threats tagged with 'data leak'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: data leak

Threats Tagged 'data leak'

Click on any threat for detailed analysis and mitigation recommendations

The Kraken ransomware group, originating from the HelloKitty cartel, conducts sophisticated big-game hunting and double extortion attacks targeting Windows, Linux, and VMware ESXi systems. They exploit SMB vulnerabilities for initial access and use tools like Cloudflared and SSHFS for persistence and data exfiltration. Kraken ransomware features advanced capabilities including multi-threaded encryption, encryption benchmarking, anti-analysis techniques, and self-deletion to evade detection. The group operates a public data leak site and has launched an underground forum called 'The Last Haven Board' to facilitate their activities. They target a wide range of file types, including SQL databases and network shares, increasing their impact on enterprise environments. Although no known exploits are currently reported in the wild, the threat is medium severity due to its cross-platform nature and complex attack techniques. European organizations, especially those with VMware ESXi and SMB-exposed systems, face significant risk. Denmark is specifically noted as affected, with other European countries likely at risk based on market penetration and strategic targets. Mitigation requires targeted patching of SMB vulnerabilities, network segmentation, monitoring for Cloudflared and SSHFS usage, and robust incident response plans.

Join the discussion

The BlackNevas ransomware group, first appearing in November 2024, has been targeting various industries and critical infrastructure globally, with a focus on the Asia-Pacific region. The group uses AES and RSA encryption, adding the '.-encrypted' extension to affected files. BlackNevas operates independently, threatening to leak data on their own site and through partners. The ransomware supports multiple arguments, excludes certain system paths and file types from encryption, and uses a unique method to check for previous infection. It also creates ransom notes in all accessible folders, demanding negotiation within seven days to prevent data leaks.

Join the discussion

A newly emerged ransomware group called Dire Wolf has been observed since May 2025, targeting multiple sectors globally with a focus on manufacturing and technology. The group employs double extortion tactics, encrypting files and threatening to publish stolen data. Analysis of a Dire Wolf ransomware sample revealed it was written in Golang and uses a combination of Curve25519 and ChaCha20 algorithms for encryption. The malware disables event logging, terminates specific processes and services, and deletes backups and recovery options. Victims are given personalized ransom notes with login details for negotiation. As of writing, 16 victims across 11 nations have been listed on the group's leak site, with the US and Thailand being the most affected.

Join the discussion

In May 2025, Pakistan-linked hacktivist groups claimed over 100 cyberattacks on Indian government, education, and critical infrastructure websites. However, an investigation reveals most breaches were exaggerated or fake. Alleged data leaks contained primarily public information, website defacements left no real impact, and DDoS attacks caused minimal disruption. The more significant threat came from APT36, which used Crimson RAT malware to target Indian defense networks following the Pahalgam terror attack. The malware, delivered through phishing emails with malicious attachments, allows remote execution of commands and data exfiltration. While hacktivist claims generated alarming headlines, the actual impact was limited, with most targeted websites operating normally.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: data leak
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses