ShinyHunters Claims Hack of ReliaQuest Without Providing Evidence
Forum user posts screenshots mocking ReliaQuest
What ransomware crews are doing right now — the groups picking up momentum, the breaches they're posting, and the stories tracking their operations. Aggregated from vendor reports, leak sites, researcher analysis, and underground chatter.
Actors ranked by Mallory's mention-velocity model across sources.
Dark Project is a ransomware and data-extortion threat group active in 2026 and publicly associated with multiple victim claims. Reported victims span primarily the United States, with additional activity affecting organizations in the Philippines and Europe. Observed targeting includes manufacturing, transportation and logistics, hospitality, professional services, automotive retail, engineering, and energy-related organizations. Operations attributed to Dark Project consistently involve theft of sensitive corporate and personal data, followed by encryption of victim systems or claims of ransomware-related disruption. Reported stolen information has included financial records, employee and customer personal data, internal business documents, technical schematics, project drawings, and client information, indicating a double-extortion model that combines data exfiltration with encryption pressure. Public victim-claim reporting also indicates the group maintained a notable volume of ransomware disclosures during 2026. Based on observed incidents, Dark Project demonstrates capabilities associated with initial compromise, data exfiltration, post-exploitation activity, and defense-evasive ransomware deployment leading to operational disruption. No high-confidence attribution to a specific state sponsor or country of origin is established from the available facts.
DragonForce is a ransomware and extortion threat actor active by 2026 and commonly referenced as DragonForce ransomware cartel, Dragon Force ransomware group, and Slippery Scorpius. The group operates in the ransomware-as-a-service ecosystem and has been associated with a leak site used to pressure victims after data theft. Reported victimology shows broad, opportunistic targeting across multiple regions and sectors, including financial services, manufacturing, construction, professional services, and organizations supporting energy and defense-related activity. DragonForce has been observed conducting data-theft-backed ransomware intrusions and publicly claiming victims on its leak infrastructure. Reported victims include organizations in the United States, Canada, Brazil, Argentina, and the United Arab Emirates, and broader reporting places the group among the more active ransomware operations in 2026. The actor has been linked to attacks against financial institutions, manufacturers, construction firms, law firms, and industrial organizations. Operationally, DragonForce is associated with post-compromise tooling beyond commodity encryption. In 2026, the group was documented using a Go-based remote access trojan known as Backdoor.Turn to conceal command-and-control traffic through Microsoft Teams TURN relay infrastructure. This demonstrates tradecraft focused on defense evasion, persistent remote access, and post-exploitation while blending malicious traffic with trusted cloud communications. Separate incident-response reporting also tied DragonForce-linked intrusions to reconnaissance activity, data exfiltration, remote-management tooling, and affiliate-driven secondary extortion behavior. DragonForce has also appeared in investigations involving a persona calling itself Ransom Busters, which was assessed with moderate confidence to be a ransomware affiliate attempting to monetize victims separately from the primary ransomware negotiation. In those cases, DragonForce was one of several ransomware brands through which the affiliate allegedly operated. This indicates that at least some DragonForce activity is consistent with an affiliate-based RaaS model rather than a single tightly centralized intrusion set. Overall, DragonForce is best characterized as a financially motivated ransomware actor that combines encryption and stolen-data extortion, broad sector targeting, leak-site pressure, and evolving intrusion tradecraft including covert command-and-control techniques over legitimate enterprise platforms.
Booba Project is a ransomware threat actor active by at least mid-2026. The group has been linked to intrusions against organizations in multiple countries, including the United States, Russia, the United Kingdom, Mexico, and Switzerland. Observed victims span financial services, health care, manufacturing, information technology, and business and professional services, including law firms, architecture, facilities services, and entertainment-related companies. Reported Booba Project incidents consistently involve ransomware accompanied by theft of victim data, indicating extortion operations that rely on both encryption and exfiltrated information. Across observed cases, the group has targeted organizations of varied size and sector rather than a single narrowly defined vertical. High-confidence victimology shows a strong concentration on U.S.-based organizations, with additional activity affecting European and Latin American entities. Based on the available evidence, Booba Project should be characterized as a financially motivated ransomware actor with demonstrated capabilities in initial compromise, data exfiltration, and post-compromise extortion. No high-confidence attribution to a nation state, operating country, or broader cluster of aliases and sub-groups is currently available.
ShinyHunters is a financially motivated cybercriminal extortion group known primarily for large-scale data theft, credential-focused intrusions, and public leak-and-ransom operations. The actor is widely tracked under the name ShinyHunters and has also been associated in some reporting with BLING LIBRA, UNC6040, and UNC6240. Activity attributed to the group in 2026 shows a strong emphasis on social engineering, especially voice phishing against employees and help-desk workflows, to obtain passwords, MFA approvals, and access to identity platforms and SaaS environments. Observed operations show ShinyHunters targeting enterprise identity and cloud application ecosystems rather than relying solely on malware deployment. Reported intrusions include compromise of single sign-on and identity dashboards, abuse of valid accounts, theft of customer and corporate data, and extortion through threats to publish stolen information. In multiple incidents, the group reportedly impersonated internal security, IT, help-desk, or legal personnel, directed victims to lookalike login infrastructure, captured credentials, and leveraged approved MFA prompts or session access to enter downstream environments. Reported follow-on activity includes access to Okta or Microsoft Entra contexts, pivoting into Salesforce environments, and exfiltration of customer records. ShinyHunters has been linked to data-extortion incidents affecting organizations in technology, communications, financial services, health care, education, and cybersecurity. Publicly claimed or attributed victims in the supplied facts include RingCentral, ReliaQuest, BOK Financial, NovoCure, Logitech/Streamlabs, CyrusOne, Harvard University, and Metabase. The group has also been mentioned in connection with attacks involving Salesforce customers, Snowflake-related activity, and claimed exploitation of CVE-2026-35273 for initial access in data-extortion operations. Some claimed affiliations or attributions around specific incidents remain disputed, but the recurring pattern of credential theft, social engineering, SaaS compromise, data exfiltration, and leak-site pressure is consistent across confirmed reporting. The group operates as an extortion actor using stolen-data publication as leverage. Its tradecraft includes initial access via phishing and vishing, credential theft, session abuse, post-compromise movement through trusted enterprise platforms, exfiltration, and defense evasion through use of legitimate identities and approved workflows. In the incidents supported here, the dominant operational model is data-theft extortion rather than destructive encryption-centric ransomware.
Qilin, also tracked as Agenda, is a ransomware-as-a-service operation active since at least 2023 and prominent through 2025–2026. The group is associated with aliases including Agenda, Gold Feather, Water Galura, Qiring, and Qiling. Reporting links the operator name Qilin to the ransomware family name Agenda, and the malware has been observed as a Go-based ransomware family with victim-specific builds and configurable payload options for affiliates. Qilin conducts financially motivated ransomware and data-theft extortion operations against enterprises across multiple regions, with victims documented in North America, Europe, Asia, the Middle East, Africa, and Latin America. Observed targeting includes manufacturing, professional services, technology, healthcare, hospitality, financial services, agriculture and food production, education, and backup infrastructure. The group has been especially active against organizations in the United States and Western Europe, while additional reporting shows attacks against organizations in countries including Italy, Canada, Mexico, India, Chile, Qatar, Indonesia, Saudi Arabia, South Africa, Thailand, and Japan. Operationally, Qilin has demonstrated a mature intrusion lifecycle. Reported initial access methods include use of valid accounts against public-facing remote access infrastructure, credential and session theft likely obtained through fake CAPTCHA lures and information stealers, and abuse of legitimate remote management and remote monitoring tools. Post-compromise activity has included reconnaissance and scanning, lateral movement via RDP and SSH-capable tooling, abuse of Active Directory credentials, creation of Group Policy objects and scheduled tasks for broad deployment, and targeting of backup systems to harvest credentials and impair recovery. The malware and operator tradecraft show strong emphasis on defense evasion and operational flexibility. Observed behaviors include terminating security processes and services, deleting shadow copies, changing local account passwords, enabling automatic logon, rebooting systems into safe mode to facilitate encryption, accessing mapped drives from elevated contexts, and maintaining execution through injected or sideloaded components. Qilin operators have also used bring-your-own-vulnerable-driver techniques, DLL sideloading, SOCKS proxy backdoors, and legitimate administration tools such as ScreenConnect, Splashtop, AnyDesk, Atera, and similar remote access mechanisms. In at least one campaign, the operators deployed a Linux ransomware variant on Windows systems, likely via Windows Subsystem for Linux, underscoring cross-platform adaptability. Qilin’s ransomware encrypts data using hybrid cryptography and has been observed dropping victim-specific ransom notes and using victim-specific identifiers. Samples have contained customized configuration elements such as embedded credentials, unique company identifiers, encryption parameters, and tailored process and service kill lists, indicating per-victim build generation consistent with an affiliate model. Reported ransom demands have varied substantially by victim. The group is also associated with leak-site activity and public victim shaming, consistent with double-extortion operations. Overall, Qilin is a high-tempo financially motivated ransomware actor combining credential-driven intrusion, extensive use of legitimate administrative tooling, strong defense evasion, and affiliate-oriented payload customization to conduct large-scale extortion campaigns.
Panzer is an emerging ransomware-as-a-service operation active by August 2026. It has been advertised on a Russian-speaking cybercriminal forum and presents itself as an affiliate program with an 80/20 revenue split, automated affiliate management, victim negotiation portals, and a leak site used to pressure victims. Panzer claims support for ransomware builds targeting Windows, Linux, ESXi, and FreeBSD, along with configurable locker functionality, execution monitoring, and anti-detection features. Reported affiliate rules prohibit targeting CIS countries and certain categories of victims, and access to malware samples is reportedly restricted to approved affiliates. Panzer has been associated with publicly claimed ransomware incidents affecting organizations across multiple countries and sectors, including government, technology, manufacturing, energy, communications and media, food production, and education. Reported victims include public-sector entities in Serbia and Spain; private-sector organizations in Thailand, Indonesia, Germany, Italy, South Korea, Switzerland, Nigeria, the Czech Republic, and the United States; and incidents described as both ransomware attacks and data breaches. The operation’s extortion model includes leak-site functionality and publication of stolen data samples, indicating use of data theft as leverage in addition to encryption claims. High-confidence reporting indicates Panzer is a financially motivated cybercriminal actor rather than a state-sponsored intrusion set. However, some early claims about the operation and its attacks were described as preliminary and not independently verified at the time, so technical details beyond the advertised RaaS model should be treated cautiously unless corroborated by confirmed incident reporting.
Arcus Media is a ransomware group that emerged in May 2024 and is described as a technically advanced ransomware-as-a-service operation. It has been associated with victim claims across multiple countries and sectors, including technology, professional services, transportation and logistics, tourism, public-sector organizations, and industrial or critical infrastructure environments. Reported activity indicates a broad, opportunistic targeting pattern rather than a narrow vertical focus, although the group has also been noted as focusing on industrial and critical infrastructure targets. Arcus Media operates as an extortion-oriented ransomware actor and has publicly claimed multiple victims. Reported incidents include both ransomware deployment and associated data-breach claims, with victim postings accompanied by deadlines consistent with double-extortion workflows. The group has been linked to credential harvesting, including collection of browser-stored credentials, and is assessed as part of the broader trend of modern ransomware crews consolidating tooling for intrusion, theft, and monetization. Aliases include arcusmedia and arcus_media. Available information supports classification as a financially motivated cybercriminal actor. No high-confidence attribution to a nation state or a specific country of origin is currently available.
CyberLeek is a self-identified leaker or hacktivist-style actor associated with the unauthorized release of alleged Grand Theft Auto VI gameplay footage and map material in August 2026. The actor publicly framed the leaks as a protest against perceived anti-consumer practices in the video game industry, especially digital preorders, digital-only distribution, paid unlocking of single-player content, and server-dependent ownership models. Based on the available reporting, CyberLeek threatened to continue releasing additional material unless Rockstar Games issued a public apology and changed its practices. The actor’s activity is centered on information disclosure and coercive public pressure rather than financially motivated ransomware operations. Reported behavior includes publishing leaked gameplay clips, map imagery, and manifesto-style statements through its own web presence, while leveraging the publicity generated by rapid redistribution across social and content-sharing platforms. Rockstar Games and Take-Two reportedly responded with copyright takedowns, but there is no high-confidence evidence that CyberLeek deployed malware, conducted credential theft, or operated broader intrusion tooling as part of this campaign. CyberLeek’s known targeting is tightly associated with Rockstar Games and the Grand Theft Auto VI ecosystem, placing its activity in the video game and broader interactive entertainment segment of the information technology sector. Claims that the actor possessed a complete unreleased build of the game, or additional sensitive internal material, remain unverified. Likewise, the method by which CyberLeek obtained the leaked content is not established with high confidence. No reliable attribution to a nation state or specific country of origin is currently available.
Storm is a ransomware threat actor observed conducting attacks against organizations in multiple countries, with publicly claimed victims spanning the United States, Australia, Canada, and the United Kingdom. Reported targeting indicates a broad, opportunistic victimology rather than a narrowly specialized sector focus. Observed victims include local government, defense-related contractors, healthcare providers, financial and insurance organizations, manufacturing firms, legal and professional services, technology companies, automotive and machinery businesses, and construction- or project-related organizations. Storm has been associated with ransomware incidents that were also described as data breaches, indicating theft of victim data in addition to disruptive intrusion activity. The group has appeared in weekly ransomware claim rankings and was noted among more active extortion actors during multiple weeks in 2026. Available reporting supports attribution of multiple victim claims to Storm, but does not provide high-confidence technical detail on its malware lineage, initial access tradecraft, or operational links to a known nation-state sponsor. The name should be distinguished from the historical Storm botnet, a separate criminal botnet operation previously described as a predecessor to Kelihos and associated with a Russian cybercriminal suspect. That botnet reference does not establish that the contemporary ransomware actor using the name Storm is the same entity. Based on observed activity, Storm is best characterized as a financially motivated ransomware and data-extortion actor with broad cross-sector targeting and recurring public victim claims.
Mabna Institute is an Iran-based hacking-for-hire organization, reportedly founded in Tehran around 2013, that has been publicly linked to a large-scale cyber espionage and intellectual-property theft campaign conducted on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian government and university clients. The organization is associated with a long-running operation targeting higher education, private-sector companies, government agencies, and international organizations in the United States and abroad. Mabna Institute is best known for a global university intrusion campaign that used spearphishing and other credential-focused tradecraft to target more than 100,000 professor accounts and compromise roughly 8,000 of them. Operators used stolen credentials to gain unauthorized access to university email accounts, library systems, journals, dissertations, theses, electronic books, and other restricted academic resources. Stolen material included research and intellectual property across scientific, engineering, medical, technology, and social-science fields. The operation also targeted at least 144 U.S. universities and 178 foreign universities, alongside dozens of private companies, multiple U.S. federal and state agencies, nongovernmental organizations, and international bodies including the United Nations and UNICEF. The group’s tradecraft has included spearphishing, credential theft, reconnaissance, password spraying, unauthorized access, data exfiltration, and broader post-compromise activity against victim networks and accounts. In addition to espionage collection, the organization monetized stolen academic access and content by reselling research materials and access to compromised university resources to customers in Iran. Some members tied to Mabna Institute were also linked to intrusions outside academia, including attacks on private-sector and government targets and participation in the HBO intrusion and attempted Bitcoin extortion case involving Behzad Mesri and several co-defendants. Known associated individuals include founders Gholamreza Rafatnejad and Ehsan Mohammadi, as well as Behzad Mesri, Keyvan Fayaz, Mojtaba Galekuhi, Arman Kahzadian, Saber Shahbazi Ballojeh, Saeid Houshyar, Manouchehr Hashemloo, Abdollah Karima, Mostafa Sadeghi, Seyed Ali Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Abuzar Gohari Moqadam, Sajjad Tahmasebi, and Amir Barati. Behzad Mesri has been associated with the alias Skote Vahshat, and Keyvan Fayaz with Achilles, The Joker, and bc.monster. Mabna Institute is widely characterized as an Iranian state-aligned contractor supporting espionage-driven collection and theft of foreign research and sensitive information.
Lazarus Group is a North Korean state-sponsored threat actor widely assessed to operate on behalf of the Democratic People’s Republic of Korea, including elements linked to the Reconnaissance General Bureau and Bureau 121. It is tracked under numerous aliases including Hidden Cobra, Labyrinth Chollima, Diamond Sleet, Zinc, TA404, UNC2970, Nickel Academy, Selective Pisces, TempHermit, Black Artemis, APT-C-26, and Lazarus APT. Subgroups and closely associated clusters commonly discussed alongside Lazarus include APT38, Famous Chollima, and operations such as Dream Job. The actor conducts both espionage and financially motivated operations. Lazarus has repeatedly targeted cryptocurrency exchanges, brokers, wallets, software supply chains, technology companies, research and healthcare organizations, government entities, communications and telecommunications providers, logistics and cargo organizations, manufacturing firms, and energy-related targets. Reported victim geography spans the United States, South Korea, Japan, Italy, Belgium, China, and many other countries. Lazarus is known for combining social engineering with technically sophisticated intrusion tradecraft. Documented activity includes recruiter-themed lures and fraudulent employment schemes, phishing, compromise of software maintainers and package ecosystems, exploitation of public-facing vulnerabilities and zero-days, SSH brute force, use of commodity malware as well as bespoke implants, and abuse of trusted third-party contractors or pre-compromised infrastructure. The group has also been linked to supply-chain compromises affecting enterprise software and open-source package repositories. Observed capabilities include credential theft, session and account abuse through compromised identities, reconnaissance, initial access, persistence, privilege escalation, defense evasion, process injection, post-exploitation remote control, and data exfiltration. Malware and tooling associated with Lazarus-linked reporting include remote access trojans and cross-platform implants such as WAVESHAPER and other loaders or backdoors used to collect host information, execute commands, inject into processes, and deliver follow-on payloads. The actor has also been associated with Android spyware, phishing infrastructure, and domain hijacking or reuse of aged legitimate sites for command-and-control and malware delivery. A defining feature of Lazarus is its sustained focus on cryptocurrency theft and sanctions-evasion revenue generation. North Korean operators linked to Lazarus have been described coordinating crypto theft and laundering activity through encrypted messaging platforms and financial intermediaries, with proceeds widely assessed to support the DPRK’s strategic programs. At the same time, Lazarus continues to pursue classic intelligence collection and strategic access objectives against government, defense-adjacent, research, and critical-sector organizations.
SafePay is a ransomware and cyber-extortion group active in 2026 and tracked under aliases including SafePay, safepay_ransomware_actors, safepay_ransomware_gang, safepay_ransomware_group, and safepay_team. It has been observed publicly claiming numerous victims and appearing repeatedly in ransomware activity rankings, including counts that place it among the more active extortion brands during 2026. Publicly disclosed victim claims indicate broad opportunistic targeting across multiple countries, with repeated activity against organizations in the United States, Germany, Italy, Spain, the United Kingdom, and Israel. Observed victimology shows SafePay targeting a diverse set of sectors, including manufacturing, information technology, retail, education, professional services, and agriculture- and food-related businesses. Reporting on ransomware trends in Italy also links SafePay to a spike in claims during June 2026, consistent with a campaign tempo focused on volume. SafePay is associated with ransomware incidents described as data breaches, indicating theft of victim data as part of its operations. The available evidence supports extortion activity and data exfiltration, but does not provide high-confidence detail on whether SafePay consistently encrypts systems, operates a ransomware-as-a-service model, or uses specific intrusion tradecraft such as particular initial-access vectors, persistence mechanisms, or lateral movement techniques. No high-confidence attribution to a nation state or specific country of origin is currently available.
Breaches attributed to ransomware activity, most recently reported first.
Forum user posts screenshots mocking ReliaQuest
Gunra claims 40 TB data theft from Dubai hospital
US Bancorp linked LockBit claim to a fourth-party incident