106 Followers
42 Following
315 Posts
Cyber security researcher and blogger
#InfoSec #DataTheft #Ransomware #DataBreachhttps://www.suspectfile.com

๐—ก๐—ผ๐˜ƒ๐—ฎ ๐—–๐—น๐—ฎ๐—ถ๐—บ๐˜€ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐˜๐—ผ ๐—ก๐—ฆ๐—ช ๐—ฆ๐˜†๐˜€๐˜๐—ฒ๐—บ๐˜€: ๐—•๐—ฒ๐˜๐˜„๐—ฒ๐—ฒ๐—ป ๐Ÿฐ๐Ÿฌ๐Ÿฌ ๐—š๐—• ๐—˜๐˜…๐—ณ๐—ถ๐—น๐˜๐—ฟ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—ฎ๐—ป๐—ฑ ๐——๐—ฎ๐˜๐—ฎ ๐——๐—ถ๐˜€๐—ฝ๐˜‚๐˜๐—ฒ๐—ฑ ๐—ฏ๐˜† ๐—”๐˜‚๐˜๐—ต๐—ผ๐—ฟ๐—ถ๐˜๐—ถ๐—ฒ๐˜€

The story emerged in recent days via the ๐๐จ๐ฏ๐š ๐ ๐ซ๐จ๐ฎ๐ฉโ€™๐ฌ ๐๐š๐ญ๐š ๐ฅ๐ž๐š๐ค ๐ฉ๐จ๐ซ๐ญ๐š๐ฅ, where the ransomware operators ๐—น๐—ถ๐˜€๐˜๐—ฒ๐—ฑ ๐˜๐—ต๐—ฒ ๐—ก๐—ฒ๐˜„ ๐—ฆ๐—ผ๐˜‚๐˜๐—ต ๐—ช๐—ฎ๐—น๐—ฒ๐˜€ ๐—ด๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐—ป๐—บ๐—ฒ๐—ป๐˜ among their alleged victims, claiming to have gained access to a hashtag #Citrix system and exfiltrated a significant amount of data.

https://www.suspectfile.com/nova-claims-access-to-nsw-systems-between-400-gb-exfiltrated-and-data-disputed-by-authorities/

#Citrix #Data_Breach #Nova #NSW #Ransomware

UK: More than one year later, HCRG is first notifying patients of a ransomware attack:

https://databreaches.net/2026/06/18/uk-more-than-one-year-later-hcrg-is-first-notifying-patients-of-ransomware-attack/

This is the one where they ran to the High Court in the UK to get injunctions that their lawyers sent to @amvinfe and me.

It seems they are first notifying patients now -- 16 months after the attack.

#healthsec #cybersecurity #incidentresponse #HCRG #injunction
#databreach #ransomware

NEW by me:

One threat actor demanded $50 million from Novo Nordisk. Another one demanded $25 million. Neither got paid.

Two different groups tried to extort Novo Nordisk at around the same time. Novo Nordisk strung them both along, and then went dark.

Data leaks followed.

https://databreaches.net/2026/06/16/one-threat-actor-demanded-50-million-from-novo-nordisk-another-one-demanded-25-million-neither-got-paid/

#NovoNordisk #FulcrumSec #TheUSERS007 #hackandleak #extortion #AI #databreach #infosec #cybersecurity

@campuscodi @euroinfosec @jgreig @lorenzofb @ajvicens @amvinfe

๐„๐ฏ๐ž๐ซ๐ž๐ฌ๐ญ: ๐’๐ข๐ฑ ๐˜๐ž๐š๐ซ๐ฌ ๐จ๐Ÿ ๐„๐ฏ๐จ๐ฅ๐ฎ๐ญ๐ข๐จ๐ง ๐Ÿ๐ซ๐จ๐ฆ ๐ƒ๐š๐ญ๐š ๐‹๐ž๐š๐ค ๐ญ๐จ ๐ƒ๐จ๐ฎ๐›๐ฅ๐ž ๐„๐ฑ๐ญ๐จ๐ซ๐ญ๐ข๐จ๐ง โ€“ ๐ญ๐ก๐ž ๐ข๐ง๐ญ๐ž๐ซ๐ฏ๐ข๐ž๐ฐ

The responses provided to SuspectFile paint a picture of a group that claims to have grown gradually and demonstrated a consistent ability to adapt. One of the most interesting aspects concerns the shift from extortion based solely on stolen data to the adoption of encryption.

https://www.suspectfile.com/everest-six-years-of-evolution-from-data-leak-to-double-extortion-the-interview/

#ALPHV #Black_Basta #Double_Extortion #Everest #Hive #IAB #Interview #Ransomware

๐’๐ข๐ง๐ ๐ข๐ง๐  ๐‘๐ข๐ฏ๐ž๐ซ ๐‡๐ž๐š๐ฅ๐ญ๐ก ๐’๐ฒ๐ฌ๐ญ๐ž๐ฆ: ๐๐ž๐ญ๐ฐ๐ž๐ž๐ง ๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž, ๐‹๐ž๐ ๐š๐ฅ ๐ƒ๐ข๐ฌ๐ฉ๐ฎ๐ญ๐ž๐ฌ, ๐š๐ง๐ ๐‘๐ž๐œ๐ฎ๐ซ๐ซ๐ข๐ง๐  ๐•๐ฎ๐ฅ๐ง๐ž๐ซ๐š๐›๐ข๐ฅ๐ข๐ญ๐ข๐ž๐ฌ

Just over two years after the devastating ransomware attack attributed to the Rhysida group, Singing River Health System (SRHS) has once again fallen victim to cybercrime. This time, the Anubis ransomware group has claimed responsibility for compromising the healthcare organizationโ€™s IT systems, stating that it stole sensitive data belonging to patients and employees before encrypting the infrastructure.

https://www.suspectfile.com/singing-river-health-system-between-ransomware-legal-disputes-and-recurring-vulnerabilities/

#Anubis #Data_Breach #HIPAA #PII #PHI #Ransomware #Rhysida #Singing #SRHS

๐€๐ซ๐ฆ๐ž๐ง๐ข๐š: ๐๐š๐ฌ๐ก๐ž ๐‚๐ฅ๐š๐ข๐ฆ๐ฌ ๐ญ๐จ ๐‡๐š๐ฏ๐ž ๐๐ฎ๐ซ๐œ๐ก๐š๐ฌ๐ž๐ ๐š ๐ƒ๐š๐ญ๐š๐›๐š๐ฌ๐ž ๐จ๐Ÿ ๐Œ๐จ๐ซ๐ž ๐“๐ก๐š๐ง ๐Ÿ‘๐ŸŽ,๐ŸŽ๐ŸŽ๐ŸŽ ๐•๐จ๐ญ๐ž๐ซ๐ฌ ๐Ÿ๐ซ๐จ๐ฆ ๐š ๐๐ซ๐จ-๐“๐ฎ๐ซ๐ค๐ข๐ฌ๐ก ๐†๐ซ๐จ๐ฎ๐ฉ

Just a few days before the Armenian parliamentary elections on June 7, 2026, the Bashe ransomware group, formerly known as APT73, published an announcement on its blog claiming to have obtained a database containing information on 30,074 Armenian citizens eligible to vote.

According to the group, the database was purchased from โ€œWolves of Turanโ€, a pro-Turkish hacktivist group that, according to the actors involved, has long been targeting Armenian entities.

https://www.suspectfile.com/armenia-bashe-claims-to-have-purchased-a-database-of-more-than-30000-voters-from-a-pro-turkish-group/

#Armenia_elections #Armenian_Ministry_of_Internal_Affairs #Bashe #Wolves_of_Turan

๐”๐ง๐ข๐ฏ๐ž๐ซ๐ฌ๐ข๐ญ๐š๐ญ ๐๐ž ๐•๐š๐ฅ๐žฬ€๐ง๐œ๐ข๐š ๐“๐š๐ซ๐ ๐ž๐ญ๐ž๐ ๐›๐ฒ ๐๐จ๐ฏ๐š ๐†๐ซ๐จ๐ฎ๐ฉ: ๐Ÿ‘๐ŸŽ๐ŸŽ๐†๐ ๐ƒ๐š๐ญ๐š ๐„๐ฑ๐Ÿ๐ข๐ฅ๐ญ๐ซ๐š๐ญ๐ข๐จ๐ง ๐‚๐ฅ๐š๐ข๐ฆ๐ž๐, ๐ˆ๐ง๐ข๐ญ๐ข๐š๐ฅ $๐Ÿ“๐ŸŽ๐ŸŽ,๐ŸŽ๐ŸŽ๐ŸŽ ๐‘๐š๐ง๐ฌ๐จ๐ฆ ๐ƒ๐ž๐ฆ๐š๐ง๐ ๐‘๐ž๐ฏ๐ž๐š๐ฅ๐ž๐

News of the attack was initially reported by the online newspaper Escudo Digital in an article by journalist Alberto Payo, which included statements attributed to a member of the universityโ€™s IT team. These details are now complemented by statements provided exclusively to SuspectFile.com directly by the Nova group, introducing additional information that had not previously emerged publicly, including an alleged initial ransom demand of $500,000.

https://www.suspectfile.com/universitat-de-valencia-targeted-by-nova-group-300gb-data-exfiltration-claimed-initial-500000-ransom-demand-revealed/

#Data_Breach #Data_Exfiltration #Nova #Ransomoware #Universitat_de_Valรจncia

๐’๐ข๐ง๐œ๐ž ๐–๐ก๐ž๐ง ๐ƒ๐ข๐ ๐€๐ฌ๐ค๐ข๐ง๐  ๐Ÿ๐จ๐ซ ๐„๐ฏ๐ข๐๐ž๐ง๐œ๐ž ๐๐ž๐œ๐จ๐ฆ๐ž โ€œ๐ƒ๐ž๐Ÿ๐ž๐ง๐๐ข๐ง๐  ๐‚๐ซ๐ข๐ฆ๐ข๐ง๐š๐ฅ๐ฌโ€?

Dissent responded harshly to these accusations, firmly rejecting any insinuation of collusion with criminal groups. The journalist pointed out that every time she asks for evidence to support certain claims, she is labeled โ€œcriminal-friendlyโ€ or accused of being a mouthpiece for cybercriminals, simply for refusing to uncritically accept statements lacking public verification.

https://www.suspectfile.com/since-when-did-asking-for-evidence-become-defending-criminals/

#Canvas #Data_Breach #Instructure #Navigate360 #Ransom #ShinyHunters

๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž, ๐“๐ซ๐š๐ง๐ฌ๐ฉ๐š๐ซ๐ž๐ง๐œ๐ฒ, ๐š๐ง๐ ๐ˆ๐ง๐ฏ๐ข๐ฌ๐ข๐›๐ฅ๐ž ๐•๐ข๐œ๐ญ๐ข๐ฆ๐ฌ: ๐ƒ๐ข๐ฌ๐ฌ๐ž๐ง๐ญ ๐‘๐ž๐ฌ๐ฉ๐จ๐ง๐๐ฌ ๐ญ๐จ ๐ญ๐ก๐ž ๐ˆ๐ง๐ฌ๐ญ๐ซ๐ฎ๐œ๐ญ๐ฎ๐ซ๐ž ๐‚๐š๐ฌ๐ž

A recent article published by DataBreaches.net by journalist Dissent addresses one of the most controversial issues in modern cybersecurity: the payment of ransoms following a cyberattack and the consequences such decisions can have not only on the companies involved, but also on the individuals whose data has been compromised.

https://www.suspectfile.com/ransomware-transparency-and-invisible-victims-dissent-responds-to-the-instructure-case/

#Canvas #Data_Breach #Instructure #Navigate360 #Ransom #Ransomware #ShinyHunters