Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

amvinfe

@amvinfe@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Cyber security researcher and blogger

108 Followers
42 Following
24 Posts
Joined November 19, 2022
#InfoSec #DataTheft #Ransomware #DataBreach:
https://www.suspectfile.com
Open post
amvinfe @amvinfe@infosec.exchange
· 3w ago

𝗘𝗫𝗖𝗟𝗨𝗦𝗜𝗩𝗘: 𝗦𝘁𝗼𝗿𝗺 𝗶𝗻𝘁𝗿𝗼𝗱𝘂𝗰𝗲𝘀 𝗮𝘂𝘁𝗼𝗺𝗮𝘁𝗲𝗱 𝗿𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗻𝗲𝗴𝗼𝘁𝗶𝗮𝘁𝗶𝗼𝗻𝘀: 𝗔𝗜 𝗲𝗻𝘁𝗲𝗿𝘀 𝘁𝗵𝗲 𝗽𝗿𝗼𝗰𝗲𝘀𝘀, 𝗯𝘂𝘁 𝗵𝘂𝗺𝗮𝗻𝘀 𝗿𝗲𝗺𝗮𝗶𝗻 𝗯𝗲𝗵𝗶𝗻𝗱 𝘁𝗵𝗲 𝘀𝗰𝗲𝗻𝗲𝘀

Storm has described to SuspectFile a negotiation model that differs from the traditional ransomware scenario, where a victim exchanges messages with a human negotiator who discusses the ransom, answers questions and potentially adjusts the terms of the deal. According to the group, its new system moves most of that process into a standardized online platform.

https://www.suspectfile.com/exclusive-storm-introduces-automated-ransomware-negotiations-ai-enters-the-process-but-humans-remain-behind-the-scenes/

#AI #Artificial_Intelligence #Bitcoin #Ransomware_Negotiation #Storm

suspectfile.com
2
0
1
0
Open post
amvinfe @amvinfe@infosec.exchange
· 3mo ago

𝗡𝗼𝘃𝗮 𝗖𝗹𝗮𝗶𝗺𝘀 𝗔𝗰𝗰𝗲𝘀𝘀 𝘁𝗼 𝗡𝗦𝗪 𝗦𝘆𝘀𝘁𝗲𝗺𝘀: 𝗕𝗲𝘁𝘄𝗲𝗲𝗻 𝟰𝟬𝟬 𝗚𝗕 𝗘𝘅𝗳𝗶𝗹𝘁𝗿𝗮𝘁𝗲𝗱 𝗮𝗻𝗱 𝗗𝗮𝘁𝗮 𝗗𝗶𝘀𝗽𝘂𝘁𝗲𝗱 𝗯𝘆 𝗔𝘂𝘁𝗵𝗼𝗿𝗶𝘁𝗶𝗲𝘀

The story emerged in recent days via the 𝐍𝐨𝐯𝐚 𝐠𝐫𝐨𝐮𝐩’𝐬 𝐝𝐚𝐭𝐚 𝐥𝐞𝐚𝐤 𝐩𝐨𝐫𝐭𝐚𝐥, where the ransomware operators 𝗹𝗶𝘀𝘁𝗲𝗱 𝘁𝗵𝗲 𝗡𝗲𝘄 𝗦𝗼𝘂𝘁𝗵 𝗪𝗮𝗹𝗲𝘀 𝗴𝗼𝘃𝗲𝗿𝗻𝗺𝗲𝗻𝘁 among their alleged victims, claiming to have gained access to a hashtag #Citrix system and exfiltrated a significant amount of data.

https://www.suspectfile.com/nova-claims-access-to-nsw-systems-between-400-gb-exfiltrated-and-data-disputed-by-authorities/

#Citrix #Data_Breach #Nova #NSW #Ransomware

infosec.exchange

Infosec Exchange

2
1
1
0
Open post
amvinfe @amvinfe@infosec.exchange
· 2mo ago
Replying to
@PogoWasRight@infosec.exchange I don’t know if it’s all made up, just as I don’t know whether the person behind Hyflock is real or not. Honestly, it’s a story I wanted to tell, even if it is absurd.
1
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 4mo ago

𝐒𝐢𝐧𝐠𝐢𝐧𝐠 𝐑𝐢𝐯𝐞𝐫 𝐇𝐞𝐚𝐥𝐭𝐡 𝐒𝐲𝐬𝐭𝐞𝐦: 𝐁𝐞𝐭𝐰𝐞𝐞𝐧 𝐑𝐚𝐧𝐬𝐨𝐦𝐰𝐚𝐫𝐞, 𝐋𝐞𝐠𝐚𝐥 𝐃𝐢𝐬𝐩𝐮𝐭𝐞𝐬, 𝐚𝐧𝐝 𝐑𝐞𝐜𝐮𝐫𝐫𝐢𝐧𝐠 𝐕𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐢𝐞𝐬

Just over two years after the devastating ransomware attack attributed to the Rhysida group, Singing River Health System (SRHS) has once again fallen victim to cybercrime. This time, the Anubis ransomware group has claimed responsibility for compromising the healthcare organization’s IT systems, stating that it stole sensitive data belonging to patients and employees before encrypting the infrastructure.

https://www.suspectfile.com/singing-river-health-system-between-ransomware-legal-disputes-and-recurring-vulnerabilities/

#Anubis #Data_Breach #HIPAA #PII #PHI #Ransomware #Rhysida #Singing #SRHS

suspectfile.com
2
0
3
0
Open post
amvinfe @amvinfe@infosec.exchange
· 3mo ago

𝗚𝗹𝗼𝗯𝗮𝗹 𝗦𝗰𝗵𝗼𝗼𝗹𝘀 𝗚𝗿𝗼𝘂𝗽 𝗮𝗻𝗱 𝗙𝘂𝗹𝗰𝗿𝘂𝗺𝗦𝗲𝗰: 𝗔 𝗠𝗮𝘀𝘀𝗶𝘃𝗲 𝗗𝗮𝘁𝗮 𝗕𝗿𝗲𝗮𝗰𝗵 𝗮𝗻𝗱 𝘁𝗵𝗲 𝗪𝗼𝗿𝗹𝗱𝘄𝗶𝗱𝗲 𝗣𝘂𝘀𝗵 𝘁𝗼 𝗦𝘂𝗽𝗽𝗿𝗲𝘀𝘀 𝗥𝗲𝗽𝗼𝗿𝘁𝗶𝗻𝗴 𝗼𝗻 𝗜𝘁

Among the statements attributed to FulcrumSec are allegations of particularly poor security practices. The group claims to have identified administrative credentials reused across numerous systems, passwords stored in plaintext, #AWS access keys embedded directly within application code, and databases relying on credentials that had reportedly remained unchanged for years.

https://www.suspectfile.com/global-schools-group-and-fulcrumsec-a-massive-data-breach-and-the-worldwide-push-to-suppress-reporting-on-it/

#Data_Breach #FulcrumSec #Global_Schools_Group #GSG #LedgerWraith #Ransomware

infosec.exchange
1
0
1
0
Open post
amvinfe @amvinfe@infosec.exchange
· 3mo ago

@verisizintisi @PogoWasRight@infosec.exchange @jerry@infosec.exchange @JayeLTee@infosec.exchange

Hi, I read your article on HCRG and I think you may be mistaken about some of your writing.
In one passage, you write, "The entity directly affected by the attack is CRG Medical Services, a subsidiary of HCRG that provides forensic medical services to police forces."
Can I ask where you got this information? Has it been verified by you?
If it has been verified, can you provide evidence?
I think, I'm sure, you're mistaken ;)

1
1
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 3mo ago

𝐄𝐯𝐞𝐫𝐞𝐬𝐭: 𝐒𝐢𝐱 𝐘𝐞𝐚𝐫𝐬 𝐨𝐟 𝐄𝐯𝐨𝐥𝐮𝐭𝐢𝐨𝐧 𝐟𝐫𝐨𝐦 𝐃𝐚𝐭𝐚 𝐋𝐞𝐚𝐤 𝐭𝐨 𝐃𝐨𝐮𝐛𝐥𝐞 𝐄𝐱𝐭𝐨𝐫𝐭𝐢𝐨𝐧 – 𝐭𝐡𝐞 𝐢𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰

The responses provided to SuspectFile paint a picture of a group that claims to have grown gradually and demonstrated a consistent ability to adapt. One of the most interesting aspects concerns the shift from extortion based solely on stolen data to the adoption of encryption.

https://www.suspectfile.com/everest-six-years-of-evolution-from-data-leak-to-double-extortion-the-interview/

#ALPHV #Black_Basta #Double_Extortion #Everest #Hive #IAB #Interview #Ransomware

suspectfile.com
1
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 2mo ago
𝗡𝗼𝗿𝘁𝗵𝗲𝗮𝘀𝘁 𝗣𝗲𝗱𝗶𝗮𝘁𝗿𝗶𝗰𝘀 𝗲𝗻𝘁𝗲𝗿𝘀 𝗻𝗲𝗴𝗼𝘁𝗶𝗮𝘁𝗶𝗼𝗻𝘀 𝘄𝗶𝘁𝗵 𝗔𝗻𝘂𝗯𝗶𝘀, 𝘁𝗵𝗲𝗻 𝘀𝗶𝗹𝗲𝗻𝗰𝗲. 𝗦𝘂𝘀𝗽𝗲𝗰𝘁𝗙𝗶𝗹𝗲 𝗿𝗲𝗰𝗼𝗻𝘀𝘁𝗿𝘂𝗰𝘁𝘀 𝘁𝗵𝗲 𝗻𝗲𝗴𝗼𝘁𝗶𝗮𝘁𝗶𝗼𝗻 𝘁𝗵𝗮𝘁 𝗽𝗿𝗲𝗰𝗲𝗱𝗲𝗱 𝘁𝗵𝗲 𝗱𝗮𝘁𝗮 𝗽𝘂𝗯𝗹𝗶𝗰𝗮𝘁𝗶𝗼𝗻 For ethical and privacy reasons, SuspectFile has chosen not to analyze or describe documentation relating to minor patients, as Northeast Pediatrics is a healthcare facility specialized in pediatric care. https://www.suspectfile.com/northeast-pediatrics-enters-negotiations-with-anubis-then-silence-suspectfile-reconstructs-the-negotiation-that-preceded-the-data-publication/ #Anubis #Data_Breach #HIPAA #Northeast_Pediatrics #Ransomware #SSN
suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 2mo ago
𝗛𝘆𝗳𝗹𝗼𝗰𝗸 𝗮𝗻𝗱 𝗡𝗼𝘃𝗮: 𝗔 𝗣𝗿𝗶𝘃𝗮𝘁𝗲 𝗖𝗼𝗻𝘃𝗲𝗿𝘀𝗮𝘁𝗶𝗼𝗻 𝗣𝗿𝗼𝘃𝗶𝗱𝗲𝘀 𝗮 𝗚𝗹𝗶𝗺𝗽𝘀𝗲 𝗶𝗻𝘁𝗼 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗚𝗿𝗼𝘂𝗽 𝗗𝘆𝗻𝗮𝗺𝗶𝗰𝘀 The chat, which took place between July 1 and July 6, 2026, concerns a request to join Nova’s affiliate program and contains a series of statements regarding the Hyflock group, the interlocutor’s role, and his alleged technical expertise. https://www.suspectfile.com/hyflock-and-nova-a-private-conversation-provides-a-glimpse-into-ransomware-group-dynamics/ #Hyflock #LockBit #Nova #Qilin #RaaS #Ransomware
suspectfile.com
0
2
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 2mo ago
𝗡𝗮𝘃𝗶𝗴𝗮𝘁𝗲𝟯𝟲𝟬 𝗮𝗻𝗱 𝗣𝟯 𝗚𝗹𝗼𝗯𝗮𝗹 𝗜𝗻𝘁𝗲𝗹: 𝗙𝗿𝗼𝗺 𝘁𝗵𝗲 𝗽𝗿𝗼𝗺𝗶𝘀𝗲 𝗼𝗳 “𝟮𝟬+ 𝘆𝗲𝗮𝗿𝘀 𝗮𝗻𝗱 𝘇𝗲𝗿𝗼 𝘃𝗶𝗼𝗹𝗮𝘁𝗶𝗼𝗻𝘀” 𝘁𝗼 𝘁𝗵𝗿𝗲𝗲 𝗺𝗼𝗻𝘁𝗵𝘀 𝗼𝗳 𝘀𝗶𝗹𝗲𝗻𝗰𝗲 The P3 Global Intel platform was designed to collect reports regarding potentially critical situations within school communities. This means that the information involved could pertain to incidents, behaviors, or circumstances that fall within an extremely private aspect of the lives of students and their families. https://www.suspectfile.com/navigate360-and-p3-global-intel-from-the-promise-of-20-years-and-zero-violations-to-three-months-of-silence/ #Anonymous_Reporting #BlueLeaks_2.0 #Navigate360 #P3_Global_Intel #Privacy #School_Security
suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 2mo ago
𝗘𝘅𝗰𝗹𝘂𝘀𝗶𝘃𝗲: 𝗕𝗮𝘁𝗵 𝗙𝗶𝘁𝘁𝗲𝗿 𝗖𝗹𝗮𝗶𝗺𝗲𝗱 𝗯𝘆 𝗔𝗻𝘂𝗯𝗶𝘀 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲, 𝗔𝗹𝗹𝗲𝗴𝗲𝗱 𝟲𝟬𝟬 𝗚𝗕 𝗗𝗮𝘁𝗮 𝗧𝗵𝗲𝗳𝘁 𝗙𝗼𝗹𝗹𝗼𝘄𝗲𝗱 𝗯𝘆 𝗮 $𝟮.𝟯𝟱 𝗠𝗶𝗹𝗹𝗶𝗼𝗻 𝗘𝘅𝘁𝗼𝗿𝘁𝗶𝗼𝗻 𝗡𝗲𝗴𝗼𝘁𝗶𝗮𝘁𝗶𝗼𝗻 The negotiations, a copy of which was provided by Anubis to SuspectFile, document a familiar pattern increasingly observed in modern double-extortion ransomware operations: technical proof of compromise, demonstrations of data possession, decryptor testing, financial negotiations, and the eventual threat of public disclosure. https://www.suspectfile.com/exclusive-bath-fitter-claimed-by-anubis-ransomware-alleged-600-gb-data-theft-followed-by-a-2-35-million-extortion-negotiation/ #Anubis #Bath_Fitter_Limited #Data_Breach #Ransomware #Negotiation
suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 2mo ago
𝗢𝗩𝗣 𝗛𝗲𝗮𝗹𝘁𝗵 𝘁𝗮𝗿𝗴𝗲𝘁𝗲𝗱 𝗯𝘆 𝗦𝘁𝗼𝗿𝗺: 𝗿𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗴𝗿𝗼𝘂𝗽 𝗰𝗹𝗮𝗶𝗺𝘀 𝘁𝗵𝗲𝗳𝘁 𝗼𝗳 𝟭𝟯𝟬 𝗚𝗕 𝗼𝗳 𝗵𝗲𝗮𝗹𝘁𝗵𝗰𝗮𝗿𝗲 𝗱𝗮𝘁𝗮 One characteristic Storm claims to have adopted concerns the negotiation process. The operators stated that there is no human negotiator involved within the service and that all negotiation stages are automated. Human assistance would reportedly be limited exclusively to technical issues and decryption-related requests. https://www.suspectfile.com/ovp-health-targeted-by-storm-ransomware-group-claims-theft-of-130-gb-of-healthcare-data/ #Data_Breach #HIPAA #Medical_Records #OVPHealth #Ransomware #Storm
suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 2mo ago

𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗶𝗻 𝗜𝘁𝗮𝗹𝘆: 𝗥𝗲𝗱𝗔𝗖𝗧 𝗿𝗲𝗽𝗼𝗿𝘁 𝘀𝗵𝗲𝗱𝘀 𝗹𝗶𝗴𝗵𝘁 𝗼𝗻 𝗮𝗻 𝗲𝘃𝗼𝗹𝘃𝗶𝗻𝗴 𝘁𝗵𝗿𝗲𝗮𝘁 𝗲𝗻𝘃𝗶𝗿𝗼𝗻𝗺𝗲𝗻𝘁

The report highlights how Italy continues to represent a frequent target for numerous ransomware groups. Organizations affected belong to very different sectors, including manufacturing, services, healthcare, technology, and industrial companies.

https://www.suspectfile.com/ransomware-in-italy-redact-report-sheds-light-on-an-evolving-threat-environment/

#Cyber_Threat_Intelligence #Cybercrime #OSINT #ransomNews_online #Ransomware_Italy #RedACT

suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 3mo ago

𝗚𝗹𝗼𝗯𝗮𝗹 𝗦𝗰𝗵𝗼𝗼𝗹𝘀 𝗚𝗿𝗼𝘂𝗽, 𝗿𝗲𝗻𝗲𝘄𝗲𝗱 𝗽𝗿𝗲𝘀𝘀𝘂𝗿𝗲 𝗼𝗻 𝗗𝗮𝘁𝗮𝗕𝗿𝗲𝗮𝗰𝗵𝗲𝘀: 𝘁𝗵𝗲 𝗨𝗦 𝘀𝗶𝘁𝗲 𝗿𝗲𝗷𝗲𝗰𝘁𝘀 𝗮𝘁𝘁𝗲𝗺𝗽𝘁𝘀 𝘁𝗼 𝗰𝗲𝗻𝘀𝗼𝗿 𝗱𝗮𝘁𝗮 𝗯𝗿𝗲𝗮𝗰𝗵 𝗰𝗼𝘃𝗲𝗿𝗮𝗴𝗲

The U.S. site emphasizes that it was not named in either ordinance and has no presence or activity in India or Singapore. For this reason, he had already responded to the law firm on June 23, stating that he did not consider himself subject to the jurisdiction of the courts of the two countries and that she did not intend to take any action as a result of the injunctions.

https://www.suspectfile.com/global-schools-group-renewed-pressure-on-databreaches-the-us-site-rejects-attempts-to-censor-data-breach-coverage/

#cybercrime_investigation #data_breach #legal_injunctions #press_freedom

suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 3mo ago

𝗖𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁𝘀: 𝗪𝗵𝗲𝗻 𝘁𝗵𝗲 𝗣𝗿𝗼𝗯𝗹𝗲𝗺 𝗜𝘀 𝗡𝗼𝘁 𝗢𝗻𝗹𝘆 𝗪𝗵𝗼 𝗔𝘁𝘁𝗮𝗰𝗸𝘀

In this context, attackers’ ability to exploit existing vulnerabilities is intertwined with a less discussed but equally crucial reality: the accumulation of technical and organizational weaknesses that often remains unresolved until data exfiltration occurs.

https://www.suspectfile.com/cybersecurity-incidents-when-the-problem-is-not-only-who-attacks/

#Cybersecurity #Data_Breaches #Data_Protection #Digital_Privacy #Ransomware

suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 1w ago

𝗦𝗵𝗶𝗻𝘆𝗛𝘂𝗻𝘁𝗲𝗿𝘀 𝘃𝘀. 𝗖𝗹𝟬𝗽: 𝗧𝗵𝗲 𝗔𝘁𝘁𝗮𝗰𝗸 𝗼𝗻 𝘁𝗵𝗲 𝗦𝗶𝘁𝗲, 𝘁𝗵𝗲 𝗗𝗶𝘀𝗽𝘂𝘁𝗲, 𝗮𝗻𝗱 𝗤𝗶𝗹𝗶𝗻’𝘀 𝗣𝗼𝘀𝗶𝘁𝗶𝗼𝗻

Qilin to SuspectFile: “We’re just watching this, just like you”Qilin’s spokesperson denied any relationship with Cl0p and explained to SuspectFile how the group is viewing the dispute.

https://www.suspectfile.com/shinyhunters-vs-cl0p-the-attack-on-the-site-the-dispute-and-qilins-position/

#Cl0p #DLS #Extortion #Grav #Qilin #Ransomware #ShinyHunters

suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 3w ago

𝟱𝟯𝟬 𝗚𝗕, 𝟯𝟯𝟱,𝟬𝟵𝟯 𝗙𝗶𝗹𝗲𝘀 𝗮𝗻𝗱 𝗘𝗻𝗰𝗿𝘆𝗽𝘁𝗲𝗱 𝗕𝗮𝗰𝗸𝘂𝗽𝘀: 𝗔𝗻𝘂𝗯𝗶𝘀 𝗗𝗲𝘁𝗮𝗶𝗹𝘀 𝗔𝘁𝘁𝗮𝗰𝗸 𝗼𝗻 𝗜𝗻𝘁𝗲𝗿𝗶𝗺 𝗛𝗲𝗮𝗹𝘁𝗵𝗖𝗮𝗿𝗲

One of the first questions SuspectFile asked Anubis concerned the method used to obtain initial access to Interim HealthCare’s network.
The group’s response was specific:
“Initial access was gained by exploiting Citrix Bleed 2 (CVE-2025-5777) on the corporate VPN.”

https://www.suspectfile.com/530-gb-335093-files-and-encrypted-backups-anubis-details-attack-on-interim-healthcare/

#Anubis #Citrix #Data_Breach #Genesis #HIPAA #Interim_HealthCare #Negotiation_Chat #Ransomware

suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 3w ago

𝗠𝗲𝘁𝗮𝗘𝗻𝗰𝗿𝘆𝗽𝘁𝗼𝗿 𝗖𝗹𝗮𝗶𝗺𝘀 𝗔𝘁𝘁𝗮𝗰𝗸 𝗼𝗻 𝗘𝗹𝗹𝗶𝘀𝗗𝗼𝗻: “𝟰𝟬𝟵 𝗚𝗕 𝗼𝗳 𝗗𝗮𝘁𝗮 𝗦𝘁𝗼𝗹𝗲𝗻, 𝗪𝗲 𝗔𝗿𝗲 𝗦𝘁𝗶𝗹𝗹 𝗔𝗰𝗰𝗲𝘀𝘀𝗶𝗻𝗴 𝘁𝗵𝗲 𝗦𝘆𝘀𝘁𝗲𝗺𝘀”

The group claims that it gained access to EllisDon’s systems using an alleged zero-day vulnerability and says that the intrusion took place approximately two months before its response.
According to MetaEncryptor, the access was not simply maintained for a limited period. The group claims that it is still inside the company’s infrastructure and can see what EllisDon is doing.

https://www.suspectfile.com/metaencryptor-claims-attack-on-ellisdon-409-gb-of-data-stolen-we-are-still-accessing-the-systems/

#Data_Breach #EllisDon #MetaEncryptor #NORAD #Ransomware #RCAF

suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 1mo ago

𝟲𝟮,𝟵𝟮𝟬 𝗙𝗶𝗹𝗲𝘀 𝗶𝗻 𝗢𝗿𝗼𝘃𝗮’𝘀 𝗖𝗿𝗼𝘀𝘀𝗵𝗮𝗶𝗿𝘀: 𝗔𝗹𝗹𝗲𝗴𝗲𝗱 𝗧𝗵𝗲𝗳𝘁 𝗳𝗿𝗼𝗺 𝗗𝗟 𝗛𝗼𝗹𝗱𝗶𝗻𝗴𝘀 𝗛𝗶𝘁𝘀 𝗙𝗶𝗻𝗮𝗻𝗰𝗲, 𝗕𝗶𝘁𝗰𝗼𝗶𝗻 𝗮𝗻𝗱 𝗠𝗼𝗻𝗴𝗼𝗹𝗶𝗮

According to Orova, representatives of DL Holdings Group allegedly entered the negotiation chat on August 17, 2026, and again on August 21, 2026.

https://www.suspectfile.com/62920-files-in-orovas-crosshairs-alleged-theft-from-dl-holdings-hits-finance-bitcoin-and-mongolia/

#BTC #Data_Breach #DLHG #Financial_Data #Mining #Orova #Ransomware

suspectfile.com
0
0
1
0
Open post
amvinfe @amvinfe@infosec.exchange
· 1mo ago

𝗢𝗿𝗼𝘃𝗮’𝘀 𝗖𝗹𝗮𝗶𝗺𝗲𝗱 𝗖𝗔𝗣𝗛 𝗕𝗿𝗲𝗮𝗰𝗵: 𝗗𝗮𝘁𝗮𝗕𝗿𝗲𝗮𝗰𝗵𝗲𝘀 𝗙𝗶𝗻𝗱𝘀 𝟭𝟱𝟬,𝟬𝟬𝟬+ 𝗣𝗮𝘁𝗶𝗲𝗻𝘁 𝗥𝗲𝗰𝗼𝗿𝗱𝘀

Also significant were spreadsheets organized by physician, which collectively contained information relating to more than 30,000 patients, including names, postal addresses, email addresses and telephone numbers. According to Dissent, while these lists did not contain Social Security numbers or diagnostic information, they could potentially be useful for phishing, spam or other targeted fraudulent activity directed at individuals known to be cardiology patients.

https://www.suspectfile.com/orovas-claimed-caph-breach-databreaches-finds-150000-patient-records/

#CAPH #HIPAA #Medical_Records #Orovan #Ransomware

suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 1mo ago

𝟭.𝟰 𝗧𝗕 𝗼𝗳 𝗗𝗮𝘁𝗮 𝗮𝗻𝗱 𝗧𝗵𝗼𝘂𝘀𝗮𝗻𝗱𝘀 𝗼𝗳 𝗣𝗮𝘁𝗶𝗲𝗻𝘁𝘀: 𝗣𝗘𝗔𝗥 𝗖𝗹𝗮𝗶𝗺𝘀 𝗔𝘁𝘁𝗮𝗰𝗸 𝗼𝗻 𝗦𝗼𝘂𝘁𝗵 𝗣𝗹𝗮𝗶𝗻𝘀 𝗥𝘂𝗿𝗮𝗹 𝗛𝗲𝗮𝗹𝘁𝗵 𝗦𝗲𝗿𝘃𝗶𝗰𝗲𝘀 (𝗦𝗣𝗥𝗛𝗦)

PEAR has attributed the attack to an intrusion that began in May 2026.
When contacted by SuspectFile.com, the group stated that it gained access to SPRHS’s IT systems around May 18 or 19, 2026.
Asked how long it remained inside the organization’s infrastructure, PEAR responded:
“About a month”

https://www.suspectfile.com/1-4-tb-of-data-and-thousands-of-patients-pear-claims-attack-on-south-plains-rural-health-services-sprhs/

#SPRHS #PEAR #Ransomware #PHI #HIPAA

suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 1mo ago

𝗦𝘁𝗼𝗿𝗺 𝗖𝗹𝗮𝗶𝗺𝘀 𝗔𝘁𝘁𝗮𝗰𝗸 𝗼𝗻 𝗔𝗺𝗲𝗿𝗶𝗰𝗮𝗻 𝗖𝗼𝗻𝘁𝗿𝗮𝗰𝘁𝗼𝗿𝘀 𝗜𝗻𝘀𝘂𝗿𝗮𝗻𝗰𝗲 𝗚𝗿𝗼𝘂𝗽 (𝗔𝗖𝗜𝗚) 𝗮𝗻𝗱 𝗣𝘂𝗯𝗹𝗶𝘀𝗵𝗲𝘀 𝗦𝘁𝗼𝗹𝗲𝗻 𝗗𝗮𝘁𝗮

The Storm ransomware group published on August 20, on its blog accessible through the Tor network, the data it claims to have stolen during an attack against American Contractors Insurance Group (ACIG), a U.S.-based insurance group specializing primarily in insurance and risk management services for the construction sector.

https://www.suspectfile.com/storm-claims-attack-on-american-contractors-insurance-group-acig-and-publishes-stolen-data/

#ACIG #Data_Breach #Insurance #Ransomware #Storm

suspectfile.com
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 1mo ago

𝗙𝗮𝗸𝗲 𝗡𝗬𝗣𝗗 𝗢𝗳𝗳𝗶𝗰𝗲𝗿𝘀 𝗼𝗻 𝗩𝗶𝗱𝗲𝗼 𝗖𝗮𝗹𝗹𝘀: 𝗛𝗼𝘄 𝗦𝗰𝗮𝗺𝗺𝗲𝗿𝘀 𝗕𝘂𝗶𝗹𝗱 𝗮 𝗖𝗼𝗻𝘃𝗶𝗻𝗰𝗶𝗻𝗴 𝗧𝗿𝗮𝗽

The case described by #Dissent therefore illustrates how modern scams are no longer limited to generic messages, spoofed emails, or poorly convincing phone calls. Criminals can construct complex scenarios in which multiple individuals, identities, and communication tools are used together to make the fraud more convincing.

https://www.suspectfile.com/fake-nypd-officers-on-video-calls-how-scammers-build-a-convincing-trap/

#Fake #NYPD #Scam

infosec.exchange
0
0
0
0
Open post
amvinfe @amvinfe@infosec.exchange
· 1mo ago

𝗘𝘅𝗰𝗹𝘂𝘀𝗶𝘃𝗲: 𝟱𝟬𝟬 𝗛𝗼𝘀𝘁𝘀, 𝟭 𝗧𝗕 𝗮𝗻𝗱 𝗡𝗼 𝗡𝗲𝗴𝗼𝘁𝗶𝗮𝘁𝗶𝗼𝗻: 𝗔𝗻𝘂𝗯𝗶𝘀 𝗥𝗲𝘃𝗲𝗮𝗹𝘀 𝗜𝘁𝘀 𝗙𝗮𝗶𝗿𝗹𝗶𝗳𝗲 𝗔𝘁𝘁𝗮𝗰𝗸

A vulnerable VPN, weak passwords, one week to reach the highest privileges, and approximately 500 compromised hosts. Anubis tells SuspectFile how it allegedly attacked Fairlife, a wholly owned subsidiary of The Coca-Cola Company. The group claims to have exfiltrated approximately 1 TB of data, 546,573 files, and demanded $15 million. But above all, it claims that this time there was never a real negotiation.

https://www.suspectfile.com/exclusive-500-hosts-1-tb-and-no-negotiation-anubis-reveals-its-fairlife-attack/

#Anubis #Coca_Cola #Data_Breach #Fairlife #Milk #Ransomware

suspectfile.com
0
0
1
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:42:28 UTC