ZeroHour

fulcrumsec

ransomware group · aka FulcrumSec · unknown (no credible public attribution of operator location, nationality, or ties to other crews) · active since unknown; the group's leak site lists victims predating this dashboard's tracking start (2026-06-16)

Victims · 7d
1▲1 vs prev. week
Victims · 30d
2active targets
Victims · 90d
2
All-time (tracked)
28since 2025-10-20
Last post
09-11 12:40UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

FulcrumSec is an active data-extortion group that publishes stolen files and victim details on a dedicated leak site; public reporting describes it as an extortion operation, and whether it also deploys file-encrypting ransomware is unknown. Its highest-profile claim to date is the Manchester Airports Group breach, with press reporting in 2026 citing exposure of data on roughly 8.8 million people and an 86 GB theft claim. Posting activity is low-volume: this dashboard tracked 2 victims in the past 90 days (2 total since tracking began 2026-06-16), with the most recent post on 2026-09-01, while the leak site lists additional victims predating the tracked window. Claimed victims span aviation, pharmaceuticals, engineering, education, and logistics, indicating broad, likely opportunistic targeting rather than a concentrated sector focus. Operator attribution, origin, and initial-access techniques remain unknown in public reporting.

Tactics & tooling
  • Publishes stolen data on a dedicated leak site to coerce payment (extortion-led, double-extortion model)
  • Claims large-volume exfiltration (e.g., 86 GB claimed in the Manchester Airports Group incident; press reporting, 2026)
  • Emphasizes breach scale affecting millions of individuals' personal data to pressure negotiations
  • Targets large, high-profile organizations across multiple sectors
  • Initial access: unknown; no CVEs or intrusion techniques publicly attributed
  • Ransomware encryption use: unknown/undisclosed in public reporting
Targeted sectors
aviation/airportspharmaceuticals/life sciencesengineering/professional serviceseducationlogistics/recycling and waste managementno clear sector focus (broad, opportunistic targeting)
Notable public victims

Manchester Airports Group (reported breach affecting ~8.8 million people; ~86 GB claimed; press reporting, 2026), Novo Nordisk (leak-site listing), Arup Group (leak-site listing), Global Schools Foundation (leak-site listing), Interzero (leak-site listing)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Dustin Group · 4d ago
Manchester Airports Group · 14d ago
Novo Nordisk · Jun 16, 2026
Global Schools Foundation · Jun 10, 2026
Arup Group · May 10, 2026
Stuf Storage · May 8, 2026
Nordstern Technologies · Apr 29, 2026
ParkEngage · Apr 29, 2026
Saleskido · Apr 29, 2026
Interzero · Apr 29, 2026
IMEVI · Apr 29, 2026
Rotary Club · Apr 29, 2026
JOT · Apr 29, 2026
BookBlock · Apr 29, 2026
Crank Communications · Apr 29, 2026
CrediElite · Apr 29, 2026
Fashinza · Apr 29, 2026
Avnet · Apr 29, 2026
Raptor Supplies · Apr 29, 2026
Lena Health · Apr 29, 2026
Woundtech · Apr 29, 2026
youX / Drive IQ · Apr 29, 2026
LexisNexis · Apr 29, 2026
MCO · Apr 29, 2026
ReFocus AI · Apr 29, 2026
Hatica · Apr 29, 2026
Analog Gold / Prospector · Apr 29, 2026
The Avnet Leaks · Oct 20, 2025We at FulcrumSec completely compromised Avnet's vast infrastructure, with over 1.1 TB of heavily compressed data stolen, mostly as snappy.parquet partitions. The raw data is between 7-12TB uncompressed. The data is global but coverage of their EMEA operations is absolute. To Avnet: You shouldn't have lowballed us repeatedly. You shouldn't have kept stalling. Now it's time for the consequences. This is on you, Gallagher. We'd rather sell it for less than you offered just to inflict damage on you. To Avnet's competitors, corporate intel brokers, and other interested parties: We are selling the entirety of Avnet's EMEA data lake. This is an exclusive, one-time sale to a single buyer. All data will be sold to a single party See our thread in Seller's Place on darkforums.st or contact us directly for private negotiations: Email: [email protected] | [email protected] Telegram: @fulcrumsec https://t.me/fulcrumsec Tox: 6A5E9ED3D7D26CAD5E6CA4E229CC80DA3C13AD002F73D4450078284E6C762F6DBDCF1FE9BF44 We will provide the keys to the cloud servers where the data is stored, delete our local backups, and announce here and our clearnet site that the data is no longer available. Everything -- all Avnet's sales strategies, customer data (including thousands of HIDDEN customers), supplier lists, proprietary AI training data, pricing models, and Databricks infrastructure blueprints -- will be yours, and yours alone. To journalists: Contact us for additional samples or information regarding our motives and the full story of our negotiations with Avnet over the last 3 weeks. Below is a report we generated on the breach with Avnet's own stolen OpenAI API keys as we were exfiltrating the data. This was done before the transfers completed fully, but the below covers about 85% of the total data. You can also find screenshots of the directories, videos of the contents of several of the Azure storage accounts from Avnet's data lake, and a few random sample files. For serious buyers,…

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .