FulcrumSec is a financially motivated data-extortion threat actor active since at least late 2025, with reporting placing its emergence around September to October 2025. The group focuses on cloud-native and internet-exposed enterprise environments and is characterized more accurately as a hack-and-leak or data-theft extortion operation than a traditional ransomware operator, because it is repeatedly described as prioritizing theft of sensitive information and extortion over widespread file encryption. FulcrumSec has targeted organizations in sectors including technology, business services, healthcare, financial services, consumer services, and education, with publicly claimed victims spanning multiple countries and a concentration in the United States. Reported victim organizations include Novo Nordisk, Global Schools Foundation, LexisNexis, youX, and Avnet. The group has been associated with especially high-impact incidents involving large-scale theft of corporate, personal, research, and operational data, followed by ransom demands and public leak activity when negotiations fail. The group’s tradecraft is consistently described as cloud-centric. Reported intrusion patterns include exploitation of exposed or unrotated credentials, hardcoded secrets, over-permissioned machine identities, misconfigured cloud storage and permissions, insecure APIs, and unpatched internet-facing applications. Multiple accounts describe FulcrumSec as specializing in rapid exfiltration of cloud-hosted databases and repositories, abusing access across platforms such as AWS, Azure, GitHub, Azure DevOps, Databricks, MongoDB, and other SaaS or cloud services. Some reporting also links the group to exploitation of CVE-2025-55182. FulcrumSec’s operations appear to emphasize lateral movement through identity and permission abuse rather than noisy malware deployment. FulcrumSec has also been cited as an example of threat actors using large language models to improve extortion operations. Reported uses include analyzing complex exfiltrated databases, correlating identities across stolen datasets, organizing stolen information, and generating technically precise or persuasive ransom and negotiation messages in English. This suggests operational use of AI as a force multiplier for data analysis and victim communications rather than as a source of novel intrusion capability. A notable aspect of FulcrumSec’s behavior is its public extortion posture. The group operates leak infrastructure and has used public shaming and staged data releases to pressure victims. In the Novo Nordisk case, FulcrumSec publicly claimed prolonged access, large-scale exfiltration, and a multimillion-dollar ransom demand, then leaked data after negotiations reportedly failed. In the Global Schools Foundation incident, the group was linked to major disruption and theft of sensitive student, parent, and institutional data, followed by threatened publication. Court actions seeking to restrain publication have also been associated with FulcrumSec-related incidents, underscoring the group’s visibility and willingness to weaponize stolen data publicly. FulcrumSec is not credibly identified as a nation-state actor in the available reporting. The available evidence supports classification as a financially motivated cybercriminal extortion group. A reported alternate nickname is “The Threat Thespians,” but FulcrumSec is the name most consistently used in public reporting. No high-confidence sub-groups are established in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A data extortion group highlighted as using large language models to analyze stolen data and generate English-language negotiation messages to strengthen ransom demands.
Data-extortion actor using LLMs to analyze stolen datasets and improve ransom negotiation leverage; part of the trend toward extortion without encryption.
A relatively new ransomware/extortion group that breaches companies using simple intrusion techniques and then uses AI to increase leverage during extortion negotiations with victims.
Conducting ransomware and double-extortion-style intrusions against cloud-hosted organizations, including an international education network, with theft of sensitive data, operational disruption, and threats to leak stolen information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.