Srsly Risky Biz: Data Theft Extortion Is Booming! Hooray!
Google's Threat Intelligence Group reports data theft extortion is surging, with Silent Ransom extracting $10M and $18M from two law firms and BlackFile taking $10M.
Risky Business News, citing Google Threat Intelligence Group (GTIG), reports that cybercriminals are shifting from encrypting ransomware to data theft extortion. Law firms Goodwin Procter and WilmerHale paid Silent Ransom (Luna Moth) ransoms of $10 million and $18 million respectively; GTIG says the group often completes contact-to-extortion in a single day, now sometimes compromising systems in person posing as IT staff. BlackFile, now calling itself Redact, used high-volume vishing to steal credentials and pivot through OneDrive, SharePoint and other SaaS apps, collecting more than $10 million between February and mid-May with an average ransom of $750,000, including attempted attacks on Wall Street hedge funds and private equity firms. The piece argues governments should keep pressure on encrypting ransomware gangs while lower-impact extortion absorbs criminal energy.
McKesson copes with fallout from data theft extortion attack
McKesson discloses a data theft extortion attack by ShinyHunters affecting oncology and medical-surgical customers, with a reported $55 million demand.
McKesson disclosed that attackers gained access to some of its third-party applications and stole data associated with a subset of customers in its oncology, multispecialty, and medical-surgical business units; the intrusion ran for four days from August 21 and was discovered August 25. ShinyHunters claimed responsibility and listed McKesson on its data-leak site, reportedly demanding more than $55 million with a September 1 deadline. Flashpoint analysts say the group typically uses social engineering and identity weaknesses with valid credentials to access cloud-hosted environments, making the intrusion hard to detect. McKesson, which distributes about one-third of pharmaceuticals used in North America with $403.4 billion in annual revenue, says operations continue and it has reasonable assurance of no ongoing unauthorized activity.
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Arctic Wolf tracks PREY-0058, a vishing and AitM token-theft crew targeting Microsoft 365 executives for data theft and extortion.
Arctic Wolf disclosed a widespread data theft and extortion cluster, PREY-0058, which overlaps with Mandiant's UNC6671 and possibly the Pink/Cinder extortion groups. Attackers impersonate IT help desk staff by phone, direct executives to authentication-themed lure domains, and run adversary-in-the-middle Microsoft 365 logins to harvest credentials, MFA approvals, and session tokens replayed via residential proxies such as NodeMaven. After access, they run discovery in SharePoint and Entra ID, then bulk-exfiltrate data from SharePoint, OneDrive, Exchange, and Box before sending extortion demands. Targets are primarily US construction, healthcare, real estate, finance, and professional services organizations.
Hackers Abuse Claude AI Agents to Automate Cyberattacks, Exploitation and Data Theft
Anthropic reports actors including GTG-20006 (Midnight Blizzard-linked) and ShinyHunters clusters abused Claude AI agents to automate phishing, credential harvesting, and data theft against 20+ organizations.
Anthropic's September 2026 threat intelligence report describes threat actors operating multi-agent workflows built on Claude models to automate the cyber kill chain, from reconnaissance and phishing to exfiltration. The group GTG-20006, assessed as consistent with Midnight Blizzard, targeted Ukrainian and European government, diplomatic, defense, and intelligence entities plus the drone supply chain, with more than 20 organizations identified. Clusters tied to ShinyHunters used 10 AWS EC2 instances to decompile 1.8 million Android APKs for hard-coded secrets and, in a separate SaaS supply chain intrusion, dumped over 2,100 Azure AD token sets across 40+ corporate tenants in about 34 hours. Reported malware families include PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc, the GiftDrop Android RAT, and the DarkSword iOS exploit chain.
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic's 154-page report details Generative Threat Groups, including APT29-linked GTG-20006 and ShinyHunters affiliates, using Claude for reconnaissance, exploitation, and data theft.
Anthropic reports that between December 2025 and August 2026 state-sponsored hackers, criminals, spyware vendors, and propaganda operators used its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance. Notable clusters include GTG-50014, a ShinyHunters affiliate that scanned 1.8 million Android APKs for secrets via 10 AWS EC2 workers, GTG-10007, a Chinese-speaking group targeting roughly 50 organizations, and GTG-50029, a lone French-speaking actor exploiting a previously undocumented WordPress re-installation race condition. The report describes multi-agent frameworks autonomously executing reconnaissance, exploitation, and exfiltration against multiple victims, and influence operations that were disrupted before building authentic audiences.
The long tail of Clop’s PTC hack is just beginning to emerge
Clop mass-exploited CVE-2026-12569 in PTC Windchill and FlexPLM in early June, claiming data theft from dozens of large organizations.
Clop began sending extortion emails in mid-July after exploiting CVE-2026-12569 in PTC Windchill and FlexPLM, likely as a zero-day in early June before PTC's June 17 disclosure and patch. Confirmed victims include Toast and Zebra, while GE, Philips and Shell are among claimed victims. CISA added the flaw, which allows unauthenticated remote code execution, to its KEV catalog on June 25. ReliaQuest said the group used a custom Windchill-specific web shell for credential theft and large-scale exfiltration, echoing its past MOVEit and Oracle E-Business Suite mass-exploitation campaigns.
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft links ShinyHunters- and Helix-affiliated actors to passkey-themed vishing and device-code phishing that compromises Microsoft 365 accounts and steals cloud data.
Microsoft attributes passkey- and SSO-themed social engineering activity, observed since May 2026, to Storm-3121 (linked to ShinyHunters and Falcon) and Storm-3032 (tied to BlackFile members now operating as Helix). Attackers impersonate corporate IT help desks by phone or SMS, urging fake passkey, MFA, or SSO updates and directing victims to adversary-in-the-middle phishing pages or device-code authentication flows that yield credentials, session tokens, and OAuth tokens. Post-compromise behavior includes Microsoft Graph enumeration of users, SharePoint, and OAuth grants, plus persistence via attacker-controlled MFA methods. Google Threat Intelligence tracks related activity as UNC6671, linked to the BlackFile, Helix, Falcon, Pink, and Redact extortion gangs.
Spain reports first alleged AI-powered data theft attack
Spain's data protection agency received a report of an AI agent autonomously exploiting flaws, logging in, altering personal data, and reading invoices.
The Spanish Data Protection Agency (AEPD) was notified of an incident in which an AI agent powered by a known LLM reportedly searched for vulnerabilities, gained access to systems, modified personal data, and accessed financial documents. AEPD has not yet investigated or verified the report but says it shows AI-related data breaches are no longer theoretical. The agency urged defenders to revise incident-response procedures, strengthen credential and identity security, and explicitly account for machine-speed AI-assisted attacks.
AI Agent Carries Out Multi-Stage Data Theft Attack
Spain's data protection agency reports the country's first agentic AI-powered breach: an AI agent logged in, found vulnerabilities, and modified personal data.
Spain's Agencia Espanola de Proteccion de Datos (AEPD) disclosed on September 14 what it calls the country's first agentic AI-powered personal data breach. An agent using a known language model scanned generic files to log in, then autonomously searched for application vulnerabilities, modified personal data, and accessed invoices. AEPD said the agent was used as an instrument to chain attack phases, implying deliberate use by a threat actor rather than a rogue model. CybaVerse CTO Simon Phillips suggested the actor likely jailbreaked or bypassed the model's guardrails.
Extortion Group FulcrumSec Claims 86GB Manchester Airports Data Theft
Extortion group FulcrumSec claims stealing 86GB of Manchester Airports Group data, exposing 8.7 million customers' personal and booking details.
Manchester Airports Group disclosed a breach on August 27 affecting parking, lounge, Fast Track and WiFi registrations at Manchester, London Stansted and East Midlands airports, impacting 8.7 million customers, most exposed only email addresses. FulcrumSec claims it stole about 86GB via airport-specific Iterable API credentials exposed in client-side JavaScript, including a 21.5GB Manchester export with booking histories, marketing data and nearly 200,000 records on upcoming 2026 travel. BleepingComputer verified sample records against a real traveler's Fast Track history; MAG declined to address the group's specific claims. Researchers warn the combination of UK postcodes, vehicle registrations and booking details could enable convincing targeted phishing, and MAG says no payment card or banking data was exposed.
McKesson confirms cyber incident after ShinyHunters claims patient-data theft
Healthcare giant McKesson confirmed a cyber incident after ShinyHunters claimed theft of hundreds of millions of patient records.
McKesson acknowledged a data breach following public claims by the threat actor group ShinyHunters that it stole hundreds of millions of records containing patient data. The company confirmed a cyber incident occurred but the full scope of the theft has not yet been independently verified. ShinyHunters is known for large-scale data theft and extortion against major organizations. The healthcare sector remains a frequent target for data-theft extortion groups.