FulcrumSec is a financially motivated data-extortion group active since 2025. Also known as SeesawSec, it steals corporate data and uses threatened or actual public disclosure to pressure victims, rather than relying on encryption of victim systems. The group has claimed data-extortion attacks against Manchester Airports Group, Novo Nordisk, LexisNexis, Avnet, and Global Schools Group. Its public victim activity includes publication of allegedly stolen datasets through a leak site following unsuccessful ransom negotiations. In the Manchester Airports Group incident, the company confirmed theft of customer data associated with airport parking, lounge, Fast Track, and Wi-Fi services; FulcrumSec claimed responsibility and subsequently published data. FulcrumSec has reportedly used large language models to analyze stolen databases, identify high-value leverage for negotiations, and produce persuasive English-language extortion communications. The group has been associated with the Cybercats Matrix ecosystem used by TeamPCP-linked cybercriminal entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Extortion-focused intrusion against Manchester Airports Group involving theft and publication of customer data after alleged ransom demands were not met.
Conducted a data-extortion attack against Manchester Airports Group, allegedly using administrator keys exposed in frontend JavaScript on airport websites, exfiltrating customer and platform-configuration data, demanding a ransom, and publishing approximately 550 GB after MAG declined to pay.
Claimed responsibility for an attack against Manchester Airports Group that compromised and publicly released personal data belonging to 8.7 million customers after MAG reportedly declined to negotiate a ransom.
Claimed responsibility for breaching Manchester Airports Group, allegedly using exposed Iterable administrative keys embedded in the airports' frontend JavaScript. The group claims it exfiltrated and leaked approximately 549 GB of customer PII, booking, marketing, SMS, vehicle-registration, and future-travel data, and stated that MAG declined its extortion demand.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.