Tags
Extortionist
Attribution
Incidents
References
Last edited
Jul 24, 2026 1:28 PM
Status
Stub
Cloud-fluent
Data extortion group active since October 2025, specializing in cloud-native credential theft and mass exfiltration without encryption. Operates almost entirely within cloud provider APIs and management planes across AWS, GCP, Azure, Firebase, and MongoDB. Gains initial access through exposed service account keys, IAM credentials, OAuth2 RSA private keys, and API keys. These are frequently harvested from application logs and configuration files. Notable for using LLMs to analyze stolen data, generate negotiation leverage, and produce breach narratives. Operates "Fulcrum Security" data leak site with westernized branding ("The Hardcoded Horror Show," "SLOPOCALYPSE NOW"). Claims to operate as a small team rather than EaaS model.