A group of outsourced staff at Ubisoft were bribed by cybercriminals, leading to the compromise and sale of the company's most valuable intellectual property. This incident highlights the growing risk of insider threats, particularly when external contractors are targeted by threat actors seeking privileged access to sensitive assets. The breach underscores the importance of robust vetting and monitoring of third-party personnel, as well as the need for strong internal controls to detect and prevent insider collusion.
In a related trend, cybersecurity professionals themselves have admitted to acting as affiliates for the BlackCat ransomware group, leveraging their technical expertise to facilitate attacks. These revelations demonstrate the increasing willingness of individuals with legitimate access and skills to collaborate with cybercriminal organizations, either for financial gain or under coercion. The convergence of insider threats and professional expertise within cybercrime operations poses a significant challenge for organizations seeking to defend against sophisticated, multi-vector attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Cybersecurity professionals were reported to have admitted moonlighting as affiliates for the BlackCat ransomware group, exposing an insider threat within the cybersecurity industry. The case underscored how trusted individuals with legitimate access and expertise can participate in ransomware operations.
A cybersecurity incident involving Ubisoft was reported in which outsourced personnel were allegedly bribed by cybercriminals and gave access to highly valuable internal assets described as the company's 'crown jewels.' The report highlights a third-party insider threat affecting Ubisoft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.