FulcrumSec is a financially motivated cyber extortion group active since at least late 2025 that focuses on cloud-centric intrusions and data-theft extortion rather than traditional file-encrypting ransomware. The group has been described as specializing in rapid exfiltration of cloud-hosted data and abusing exposed secrets, unrotated API keys, over-permissioned cloud identities, misconfigured cloud storage, and unpatched internet-facing applications. Reported victimology indicates a concentration on cloud-native enterprises in technology, business services, healthcare, financial services, and education, with publicly associated victims including Novo Nordisk, Global Schools Foundation, LexisNexis, youX, Avnet, and Arup Group. FulcrumSec’s operating model is centered on stealing sensitive corporate and personal data and then using that material for extortion, public leaking, or threatened sale. Multiple reports characterize the group as a data-extortion or hack-and-leak actor, and some reporting notes that it generally favors theft and coercion over encryption-based disruption. At the same time, some public incident tracking has labeled certain incidents as ransomware, so the actor is best understood as operating in the ransomware-extortion ecosystem while prominently using data-theft-only extortion. The group has publicly claimed prolonged dwell time in victim environments, including months-long access in at least one major pharmaceutical intrusion. Observed tradecraft includes initial access through exposed credentials and cloud misconfigurations, exploitation of vulnerable public-facing applications, harvesting additional secrets from repositories and cloud services, and movement across SaaS and cloud control planes using valid credentials. Reported techniques include abuse of misconfigured permissions in major cloud environments, compromise of development and source-code ecosystems, access to cloud databases and object stores, and large-scale exfiltration using legitimate tooling. FulcrumSec has also been linked to exploitation of CVE-2025-55182 in one intrusion. Its post-compromise behavior includes extensive data theft, leak-site publication, and technically detailed ransom negotiations. FulcrumSec has also been noted for using large language models to improve extortion operations. Reported uses include analyzing complex exfiltrated databases, correlating identities across datasets, organizing stolen information, and generating persuasive English-language negotiation messages tailored to victim data. This use of AI appears aimed at increasing operational efficiency and negotiation leverage rather than enabling novel intrusion methods. Known targeting includes healthcare and pharmaceuticals in Denmark, education organizations with operations spanning the United States and Singapore, and additional victims in the United States, United Kingdom, Australia, India, and elsewhere. Public reporting consistently portrays FulcrumSec as an extortion-focused criminal actor rather than a state-linked espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Extortion-focused group using AI agents to process stolen data and support extortion operations.
Mentioned as one of several data theft and extortion groups conducting attacks against healthcare-related companies.
A data extortion group highlighted as using large language models to analyze stolen data and generate English-language negotiation messages to strengthen ransom demands.
Data-extortion actor using LLMs to analyze stolen datasets and improve ransom negotiation leverage; part of the trend toward extortion without encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.