Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationunderground-data-leakoperational-disruptioncybercrime-service-ecosystem

Ransomware and Data-Extortion Groups Expand Pressure Tactics as Some Mass-Theft Campaigns Lose Leverage

Updated 3mo agoFirst seen Feb 10, 20263 sources

Ransomware operations are increasingly industrialized, shifting from simple file encryption to multi-stage extortion that combines encryption, data theft/leak threats, DDoS, and in some cases direct pressure on third parties such as customers, partners, or regulators. This “quadruple extortion” model has been associated with major groups including ALPHV/BlackCat, CL0P, and LockBit, reflecting a broader trend toward scalable, high-tempo campaigns designed to maximize coercion and revenue.

At the same time, incident-response reporting indicates some zero-day-driven, downstream mass data-theft extortion campaigns—popularized by CL0P against widely used file-transfer platforms—are becoming less effective at driving payments, as organizations better understand that paying for “data suppression” does not remove notification obligations or meaningfully reduce litigation and re-extortion risk. Separately, GuidePoint assessed with high confidence that the new “0APT” leak site’s claimed victim list is largely fabricated (or recycled from other groups) and likely intended to enable opportunistic extortion, re-extortion, or affiliate fraud; organizations named by 0APT were advised to validate impact via concrete indicators (e.g., ransom note, encryption, direct communication) before treating the posting as evidence of compromise.

Share:
Ransomware and Data-Extortion Groups Expand Pressure Tactics as Some Mass-Theft Campaigns Lose Leverage
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Feb 9, 20264mo ago

0APT site returns with a shorter victim list

On February 9, 2026, 0APT's site reappeared with a reduced list of more than 15 large multinational companies. The change appeared aimed at making the operation look more credible after earlier allegations of fabrication.

Feb 8, 20264mo ago

0APT site goes offline after public scrutiny

After researchers publicly questioned its claims, 0APT's leak site went offline on February 8, 2026. The outage followed growing scrutiny over whether the group had actually breached the organizations it named.

Feb 5, 20265mo ago

Researchers find signs 0APT is fabricating victim evidence

By early February 2026, researchers and incident responders concluded that 0APT was likely faking many victim claims, including by presenting meaningless streamed data as supposed evidence files. At least two named organizations investigated and found no intrusion, ransom note, or direct contact attributable to the group.

Jan 25, 20265mo ago

0APT leak site appears and rapidly posts 200+ claimed victims

In late January 2026, the data-extortion group 0APT emerged with a leak site and listed more than 200 alleged victims in about a week. Its rapid growth initially resembled a rebrand or splinter operation before researchers identified anomalies.

Feb 1, 20251y ago

CL0P claims 385 attacks within weeks in February 2025

In February 2025, CL0P reportedly took responsibility for 385 attacks within a few weeks, a volume described by TechRadar as a record for a single group in one month. The claim illustrated the industrial scale of modern extortion operations.

Jan 1, 20251y ago

CRM-focused extortion attacks in 2025 are mainly attributed to ShinyHunters

During 2025, another broad extortion campaign targeting CRM-related data was attributed primarily to ShinyHunters. As with earlier mass-theft events, payments by affected downstream victims were reported to remain uncommon.

Jan 1, 20242y ago

Snowflake-related mass data theft campaign hits multiple victims

In 2024, a large-scale extortion wave tied to Snowflake-related breaches affected numerous organizations, but incident responders reported that downstream victims were generally unlikely to pay. The campaign was cited as evidence that mass data-theft extortion was becoming less effective.

Jan 1, 20233y ago

CL0P popularizes zero-day downstream mass data extortion

CL0P established a large-scale extortion model in which zero-day vulnerabilities, often in file transfer software, were exploited to steal data from many downstream victims and pressure them to pay for supposed deletion. This marked a shift from traditional ransomware toward mass data-theft-driven extortion.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Affected products
1 linked
Moveit
Organizations
8 linked
TechRadarDataBreachesCovewareGuidePoint SecurityUnit 221BBankInfoSecurityNeue Zürcher ZeitungDataBreach.com
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.