fulcrumsec
ransomware group · aka FulcrumSec · unknown (no credible public attribution of operator location, nationality, or ties to other crews) · active since unknown; the group's leak site lists victims predating this dashboard's tracking start (2026-06-16)
FulcrumSec is an active data-extortion group that publishes stolen files and victim details on a dedicated leak site; public reporting describes it as an extortion operation, and whether it also deploys file-encrypting ransomware is unknown. Its highest-profile claim to date is the Manchester Airports Group breach, with press reporting in 2026 citing exposure of data on roughly 8.8 million people and an 86 GB theft claim. Posting activity is low-volume: this dashboard tracked 2 victims in the past 90 days (2 total since tracking began 2026-06-16), with the most recent post on 2026-09-01, while the leak site lists additional victims predating the tracked window. Claimed victims span aviation, pharmaceuticals, engineering, education, and logistics, indicating broad, likely opportunistic targeting rather than a concentrated sector focus. Operator attribution, origin, and initial-access techniques remain unknown in public reporting.
- Publishes stolen data on a dedicated leak site to coerce payment (extortion-led, double-extortion model)
- Claims large-volume exfiltration (e.g., 86 GB claimed in the Manchester Airports Group incident; press reporting, 2026)
- Emphasizes breach scale affecting millions of individuals' personal data to pressure negotiations
- Targets large, high-profile organizations across multiple sectors
- Initial access: unknown; no CVEs or intrusion techniques publicly attributed
- Ransomware encryption use: unknown/undisclosed in public reporting
Manchester Airports Group (reported breach affecting ~8.8 million people; ~86 GB claimed; press reporting, 2026), Novo Nordisk (leak-site listing), Arup Group (leak-site listing), Global Schools Foundation (leak-site listing), Interzero (leak-site listing)
No public figure.
Leak-site victims28 posts · newest first
| Victim | Discovered | Details |
|---|---|---|
| Dustin Group | · 4d ago | — |
| Manchester Airports Group | · 14d ago | — |
| Novo Nordisk | · Jun 16, 2026 | — |
| Global Schools Foundation | · Jun 10, 2026 | — |
| Arup Group | · May 10, 2026 | — |
| Stuf Storage | · May 8, 2026 | — |
| Nordstern Technologies | · Apr 29, 2026 | — |
| ParkEngage | · Apr 29, 2026 | — |
| Saleskido | · Apr 29, 2026 | — |
| Interzero | · Apr 29, 2026 | — |
| IMEVI | · Apr 29, 2026 | — |
| Rotary Club | · Apr 29, 2026 | — |
| JOT | · Apr 29, 2026 | — |
| BookBlock | · Apr 29, 2026 | — |
| Crank Communications | · Apr 29, 2026 | — |
| CrediElite | · Apr 29, 2026 | — |
| Fashinza | · Apr 29, 2026 | — |
| Avnet | · Apr 29, 2026 | — |
| Raptor Supplies | · Apr 29, 2026 | — |
| Lena Health | · Apr 29, 2026 | — |
| Woundtech | · Apr 29, 2026 | — |
| youX / Drive IQ | · Apr 29, 2026 | — |
| LexisNexis | · Apr 29, 2026 | — |
| MCO | · Apr 29, 2026 | — |
| ReFocus AI | · Apr 29, 2026 | — |
| Hatica | · Apr 29, 2026 | — |
| Analog Gold / Prospector | · Apr 29, 2026 | — |
| The Avnet Leaks | · Oct 20, 2025 | We at FulcrumSec completely compromised Avnet's vast infrastructure, with over 1.1 TB of heavily compressed data stolen, mostly as snappy.parquet partitions. The raw data is between 7-12TB uncompressed. The data is global but coverage of their EMEA operations is absolute. To Avnet: You shouldn't have lowballed us repeatedly. You shouldn't have kept stalling. Now it's time for the consequences. This is on you, Gallagher. We'd rather sell it for less than you offered just to inflict damage on you. To Avnet's competitors, corporate intel brokers, and other interested parties: We are selling the entirety of Avnet's EMEA data lake. This is an exclusive, one-time sale to a single buyer. All data will be sold to a single party See our thread in Seller's Place on darkforums.st or contact us directly for private negotiations: Email: [email protected] | [email protected] Telegram: @fulcrumsec https://t.me/fulcrumsec Tox: 6A5E9ED3D7D26CAD5E6CA4E229CC80DA3C13AD002F73D4450078284E6C762F6DBDCF1FE9BF44 We will provide the keys to the cloud servers where the data is stored, delete our local backups, and announce here and our clearnet site that the data is no longer available. Everything -- all Avnet's sales strategies, customer data (including thousands of HIDDEN customers), supplier lists, proprietary AI training data, pricing models, and Databricks infrastructure blueprints -- will be yours, and yours alone. To journalists: Contact us for additional samples or information regarding our motives and the full story of our negotiations with Avnet over the last 3 weeks. Below is a report we generated on the breach with Avnet's own stolen OpenAI API keys as we were exfiltrating the data. This was done before the transfers completed fully, but the below covers about 85% of the total data. You can also find screenshots of the directories, videos of the contents of several of the Azure storage accounts from Avnet's data lake, and a few random sample files. For serious buyers,… |