INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cyber Extortion Economy Evolving

| 2026-05-27 22:00 CRITICAL HIGH
Executive Summary AI-generated
The threat landscape is shifting, with a notable decrease in the use of encryption for extortion-related cases. This trend has been observed by various security organizations, including Google, which reported a gradual rise in data theft and extortion incidents from approximately 2% in 2020 to 15% in 2025. Resilience also increased significantly, with an increase in extortion-only incidents from 49% in the first half of 2023 to 65% in the second half. This shift suggests that threat actors are moving away from using ransomware and towards pure data theft and extortion methods, exploiting vulnerabilities such as software-as-a-service (SaaS) applications and Oracle EBS vulnerabilities.
Technical Mitigations AI-generated
• Implement robust backup and recovery processes to ensure routine re-imaging and restoration. • Enhance endpoint maturity through automated disruption efficacy measures. • Utilize exfiltration speed as a key factor in threat actors' decision-making, prioritizing data-only extortion campaigns.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$ Shai-HuludShai-Hulud
Target & Sectors
NORTH_AMERICA NORTH_AMERICA MIDDLE_EAST MIDDLE_EAST EUROPE EUROPE mediamedia healthcarehealthcare manufacturingmanufacturing defensedefense
Incident Timeline
‎2025/05/27
Threat actors used encryption to target the Global Incident Response Report.
tactic Extortion
organisation Global Incident Response Report
‎at least late 2025
Threat actors used a T1195 supply chain compromise to gain initial access via the exploitation of software vulnerabilities in TGR-CRI-1135.
organisation Initial Access
tactic T1592.002 - Software
tactic T1195 - Supply Chain Compromise
organisation TGR-CRI-1135
‎March 25, 2026
HasanBroker's BreachForums posted a screenshot on March 25, 2026, indicating they had gained access to the system.
organisation HasanBroker’s BreachForums
‎May 11, 2026
The attackers behind CL-CRI-1116 used a Tor-based data leak site to communicate with victims and maintain their communication channel.
tactic Data Leak
threat_actor LAPSUS$
general_metric 7 part
organisation Tor
organisation MFA
organisation Telegram
organisation CL-CRI-1116
organisation BlackFile
‎May 13, 2026
Threat actors used Shai-Hulud to distribute an open source version of the ransomware on BreachForums.
malware Shai-Hulud
‎May 19, 2026
Threat actors used AI models like Mythos to target organizations, exploiting approximately 23,000 potential vulnerabilities across open source software projects in recent weeks.
tactic Data Leak
organisation Frontier AI Defense
organisation Identity and Vishing Resilience
organisation OTP
organisation WebAuthn
organisation Supply Chain Integrity Implement
organisation SCA
organisation Looking Forward In
organisation Palo Alto Networks
organisation CI
organisation Security Posture Management Audit
organisation API
organisation Enforce
organisation Rotate
organisation AI-Accelerated Threat
organisation Deploy
‎May 21, 2026
Threat actors used Initial Access via Vishing to target SaaS tenants.
threat_actor LAPSUS$
organisation Resolute’s BreachForums
organisation Initial Access via Vishing
organisation BreachForums
organisation Vect
organisation the Rostova Organization
‎between 2021-2024
Threat actors used a ransomware attack to extort cryptocurrency from the majority of individuals in the 2021-2024 period.
general_metric 78 %
‎2026/05/27
Threat actors used a software-as-a-service (SaaS) application to target Professional Services firms, exploiting an Oracle EBS vulnerability.
organisation Professional Services
organisation Consumer Services
organisation Construction
organisation Google
organisation ShinyHunters
organisation Differences in Extortion Operations Unit
organisation EaaS
threat_actor LAPSUS$
organisation SEC
organisation GDPR
organisation SSH
organisation Kubernetes
Intelligence Sources