Index live· 1,284 files · 148 editions
ForensicPost

Search the index

31 results
Try
Results for “Extortion”Newest first
26-0617
File

A Cardiac Monitor Produces a Continuous Record of You

Ambulatory cardiac data is continuous, and continuous physiology is a behavioural record collected for a clinical reason.

Extortion actor, unnamedThird-party applicationHealthcareMedical devices
Sev 3TargetiRhythmActorExtortion actor, unnamed
26-0612
File

DentaQuest Data Published After Extortion Demand Refused

Extortion refused, 234 GB published, 2.6 million addresses verified. The refusal produced a record that payment never does.

ShinyHuntersCredential compromiseHealthcareHealthcare
Sev 4TargetDentaQuestActorShinyHunters
26-0519
File

M&A and Litigation Documents Identified as a Distinct Extortion Target Class

Deal documents are worth a fortune for days and nothing after. There is no ransom note, because publication destroys the value.

MultipleTargeted accessFinanceLegal
Sev 4TargetLegal document estatesActorMultiple
25-1231
File

A Fragmented Extortion Ecosystem Changes What Paying a Ransom Buys

The case for paying depended on a repeat player with a reputation to protect. Seventy-three new entrants in a year removes exactly that.

MultipleVariousMultipleAnalysis
Sev 4TargetExtortion negotiationActorMultiple
25-1226b
File

Half of 2025 Extortion Involved No Encryption, so Containment Metrics Missed It

A containment rate defined against encryption improves partly because encryption is becoming less common.

MultipleMultipleMethod
Sev 3TargetContainment measurementActorMultiple
25-1217b
File

Ransomware Encryption Rate Fell to 50% in 2025 From 70%

A shift from the transaction that sometimes works to the one this corpus has never seen work.

MultipleData extortionMultipleAnalysis
Sev 4TargetRansomware victimsActorMultiple
25-1111b
File

Qilin Branded South Korean Asset Manager Victims as Korean Leaks

An operator optimising for revenue keeps negotiations separate. Branding them together does the reverse.

QilinMSP compromiseFinanceExtortion
Sev 4TargetSouth Korean asset managersActorQilinSouth Korea
25-1110
File

Cl0p Oracle EBS Victim List Spans Schneider Electric, Logitech and Emerson

Automation, mining, peripherals, a newspaper. The vulnerability selected the victims, and the attacker learned afterwards who they were.

Cl0pCVE-2025-61882ManufacturingExtortion
Sev 4TargetOracle EBS customers, multipleActorCl0pUSA
25-1029
File

ShinyHunters Used Stolen CRM Data to Phish the Affected Firms' Own Clients

There is no version of “monitor your accounts” that helps somebody who has already taken the call.

ShinyHuntersTargeted phishingCloudExtortion
Sev 4TargetTenant clients and personnelActorShinyHunters
25-1021
File

Extortion Drove More Than Half of Middle East Cyberattacks in 2025

Geopolitical exposure is additive, not substitutive. It does not displace ordinary criminal risk — it sits on top of it.

MultipleVariousMultipleAnalysis
Sev 3TargetMiddle East organisationsActorMultiple
25-1016
File

Washington Post Named Among Oracle EBS Extortion Victims

Nobody targeted a newsroom. A media organisation cannot scope its security to the systems that obviously hold journalism.

Cl0pCVE-2025-61882MultipleMedia
Sev 3TargetThe Washington PostActorCl0p
25-0930
File

One Zero-Day, Twenty-Nine Named Victims, No Encryption

One ERP zero-day, 29 named victims across unrelated sectors, nothing encrypted. Theft-and-publication at industrial scale.

Cl0pCVE-2025-61882MultipleExtortion
Sev 5TargetOracle EBS deploymentsActorCl0p
25-0926
File

Attackers Published Nursery Children's Details and Images as Extortion Pressure

Extortion works by finding who cannot refuse. This is the endpoint of that logic.

UnattributedEducationExtortion
Sev 5TargetKido InternationalActorUnattributed
25-0923
File

One Technique, One Platform, Several Hundred Companies

What concentrated was not the data but the method. Every tenant presents the same consent screen and the same vocabulary for a caller to use.

ShinyHuntersConsent phishingCloudExtortion
Sev 4TargetSaaS platform tenantsActorShinyHunters
25-0921
File

They Refused, and Recovered Ninety per Cent

The variable that predicts the outcome is not the payment decision. It is whether you could recover without them.

UnattributedRansomwarePublic sectorExtortion
Sev 5TargetNevada state governmentActorUnattributedUSA
25-0815
File

Saint Paul Refused to Pay and 43GB of City Data Was Published

One paid and the data circulated. One refused and the data was published. The difference in outcome is the money.

UnattributedData extortionPublic sectorExtortion
Sev 4TargetCity of Saint PaulActorUnattributed
25-0519
File

Twenty-five Thousand Dollars, and More Than Half of Them Paid

A $28.7m demand generates a board meeting, a law firm, an insurer and eventually a public record. A $40,000 demand generates a wire transfer.

LockBit affiliatesExtortion pricingMultipleVerification
Sev 4TargetMultiple, unidentifiedActorLockBit affiliates
25-0511
File

LockBit Panel Recorded $2.3 Million of Receipts, Operators Taking a Fifth

A leak-site count is a measure of publication, not of income. This is the first case where both can be looked at side by side.

LockBitExtortionMultipleEconomics
Sev 3TargetNot applicableActorLockBit
25-0507
File

They Paid, and Got a Video of the Deletion

What $2.85 million bought was a recording, made by the counterparty, of an unverifiable claim. The second demand went to districts that had never paid.

UnattributedData re-extortionEducationExtortion
Sev 5TargetSchool districtsActorUnattributed
25-0227
File

Blockchain Analysis Put Black Basta Receipts Above $107 Million

A floor from a public ledger and a ceiling from an interested party are not the same kind of object. This corpus has not always said which it was holding.

Black BastaExtortionMultipleVerification
Sev 4TargetNot applicableActorBlack Basta
25-0216
File

Southern Water Disclosed £4.5 Million of Costs From the Black Basta Attack

Response cost and extortion demand are different quantities. The phrase “the attack cost £4.5m” invites the error of treating them as one.

Black BastaWaterCost
Sev 4TargetSouthern WaterActorBlack BastaUnited Kingdom
25-0215
File

Leaked Chats Show Black Basta Priced Demands off Commercial Revenue Data

If the demand is a function of revenue, the volume figure attached to it is decoration — and the attacker had no incentive to count accurately.

Black BastaExtortion pricingMultipleVerification
Sev 4TargetMultiple, unidentifiedActorBlack Basta
24-1205
File

Termite Claims Blue Yonder Data and Says It Will Reuse the Email Lists

A stated plan costs nothing to announce and cannot be checked, and it raises pressure on the victim at no risk to the group.

TermiteExtortionRetailVerification
Sev 4TargetBlue YonderActorTermiteUSA
24-0711
File

A Billion Dollars, Borne by People Who Were Not Attacked

The party that could have prevented it spent $25m. The parties that could not spent forty times that.

BlackSuitExtortionAutomotiveFunding
Sev 5TargetCDK GlobalActorBlackSuitUSA
24-0624
File

Qilin Published Synnovis Data After the NHS Declined to Pay

One paid and the data circulated anyway. One refused and the data was published. The suppression half delivered in neither case.

QilinExtortionHealthcareExtortion
Sev 5TargetSynnovisActorQilinUnited Kingdom
24-0405
File

They Paid the Operator, and the Affiliate Still Had the Data

A victim negotiating with the brand is negotiating with the party that holds the least. The files sit with the affiliate.

RansomHubRe-extortionHealthcareExtortion
Sev 5TargetChange HealthcareActorRansomHubUSA
24-0301
File

Twenty-two Million Dollars, Paid

A company that pays quietly and says nothing has taken the cheaper path. The sample of known payments is not a sample of payments.

ALPHVExtortionHealthcareExtortion
Sev 5TargetChange HealthcareActorALPHVUSA
24-0221b
File

The Largest Ransom on Record, and a Filing That Mentions No Ransom

Item 1.05 does not ask whether a ransom was paid. So the largest extortion payment on record is compatible with a filing that never mentions one.

Dark AngelsPharmaceutical distributionExtortion
Sev 4TargetCencoraActorDark AngelsUSA
23-1110
File

LockBit Published 43GB From Boeing, Revealing the Citrix Bleed Entry Route

A dump is chosen for extortion value, not evidence. This one disclosed its own method.

LockBitCVE-2023-4966 — Citrix BleedManufacturingAftermath
Sev 4TargetBoeingActorLockBitUSA
22-0322
File

Lapsus$ Took Source Code From Nvidia, Samsung and Microsoft Without Encrypting Anything

The encryption step was always optional. Drop it and you keep the reputational leverage for a fraction of the work.

Lapsus$TechnologyExtortion
Sev 4TargetNvidia, Samsung, MicrosoftActorLapsus$USA
ACT-004
Actor

ShinyHunters

Voice phishing into identity providers, then leak-site extortion. Active since 2020.

VishingSSOLeak siteData theft
Profile
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging