XP95 is an emerging cybercrime extortion actor first observed in March 2026. Available reporting characterizes the group as a pure data-theft-and-extortion operation rather than a conventional ransomware crew that encrypts victim systems. XP95 has claimed intrusions against government and healthcare-related organizations and has used stolen sensitive personal and medical data as leverage for ransom demands. The group’s known tradecraft centers on unauthorized access, data exfiltration, and extortion. XP95 has publicly claimed theft of large datasets from victim environments, published proof-of-compromise samples on a Tor-hosted leak site, cross-posted victim data samples to BreachForums, imposed payment deadlines, and threatened to release or sell stolen information if victims do not pay. In at least one reported case, the group claimed it leaked victim data after ransom negotiations failed. Public reporting cited in these incidents does not confirm use of file-encrypting malware, and threat intelligence assessments have specifically described XP95 as operating an exfiltration-and-extortion model without encryption. Victims attributed to XP95 include Healthdaq, a recruitment platform used by Northern Ireland health trusts; Statistics South Africa; Gauteng Province in South Africa; and Eholo Health, a Spanish mental-health software provider serving psychologists in Spain and Andorra. The data XP95 has claimed to steal includes identity documents, employment-related records, contact information, criminal background information, vaccine records, and highly sensitive health and clinical data. This victimology indicates a focus on organizations holding large volumes of personally identifiable information and regulated or high-impact records, especially in government-adjacent and healthcare contexts. No high-confidence attribution to a nation state or to a known larger intrusion set is currently available. Reporting has noted no prior threat intelligence references linking XP95 to an established organized group or earlier campaigns. The actor’s dominant observed motivation is financial gain through extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A relatively new extortion-focused threat actor claiming responsibility for attacks against Healthdaq and previously Eholo Health. The group reportedly steals sensitive data and extorts victims without deploying file-encrypting ransomware.
Claimed responsibility for a ransomware-style extortion incident against Healthdaq, alleging theft of nearly half a million sensitive files and demanding a ransom.
Emerging cybercrime group conducting ransomware-associated data theft and extortion operations. The group claims breaches against South African government entities and healthcare-related organizations, steals large volumes of sensitive data, posts victims on a leak site, demands ransom payments, and threatens or carries out public data leaks when victims do not pay.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.