Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationdata-exfiltration-methodmass-credential-exposureoperational-disruption

Ransomware and data-extortion activity escalates, highlighted by Conduent’s expanded breach impact and new tooling by World Leaks

Updated 3mo agoFirst seen Feb 13, 20264 sources

Reporting and research indicate ransomware/data-extortion activity remained elevated through 2025 into early 2026, with threat actors increasingly emphasizing data theft, public pressure, and supply-chain leverage rather than encryption alone. Cyble’s threat landscape findings cited by TechRepublic put 2025 at 6,604 recorded ransomware attacks (up 52% YoY), with 731 attacks in December and 2,000+ claims in the last three months of 2025; the same reporting also notes supply-chain attacks nearly doubled, increasing the potential blast radius when service providers are hit.

A major example is Conduent, where the January 2025 ransomware attack is now assessed to have impacted ~25 million Americans (up from an initial 10 million), with reporting describing ~8TB of data stolen including Social Security numbers and medical data, alongside days of operational disruption. Separately, Accenture-linked research reported that the World Leaks extortion operation added a custom Rust-based tool, RustyRocket, described as a stealthy data-exfiltration and proxy capability using obfuscated, multi-layer encrypted tunnels and a runtime “guardrail” requiring a pre-encrypted configuration—features intended to make detection and monitoring difficult. Broader ecosystem reporting also highlights how data leak sites (DLSs) and “naming-and-shaming” tactics have become central to double-extortion pressure, while a weekly incident roundup underscores continued real-world disruption from ransomware (e.g., impacts to public services) and ongoing regulatory consequences for inadequate security controls following breaches.

Share:
Ransomware and data-extortion activity escalates, highlighted by Conduent’s expanded breach impact and new tooling by World Leaks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
Feb 12, 20264mo ago

Accenture reports World Leaks using custom RustyRocket malware

Accenture Cybersecurity reported that World Leaks had added a previously unseen malware tool called RustyRocket to its operations. The tool provides stealthy data exfiltration, proxying, persistence, and encrypted tunneling designed to blend malicious traffic into legitimate network activity.

Feb 11, 20264mo ago

Conduent says no stolen data has appeared on dark web forums

As part of its response, Conduent said it implemented data protection and dark web monitoring measures. The company reported that it had not observed the stolen data appearing on dark web forums so far.

Conduent sets aside $25 million for breach response and notifications

Conduent reserved $25 million for notification and related response activities, had already spent $9 million, and expected to complete payments by early 2026. The company also said cyber insurance could cover costs above that amount within policy limits.

Oregon says 10.5 million residents were affected by Conduent breach

Oregon's attorney reportedly stated that 10.5 million residents were affected by the Conduent breach. Combined with other state disclosures, this helped push the estimated total impact to roughly 25 million individuals.

Texas breach figures for Conduent rise from 4 million to 15.4 million

Updated Texas breach reporting increased the estimated number of affected individuals tied to the Conduent incident from 4 million to 15.4 million. This was one of the major revisions that expanded the known scale of the breach.

Dec 31, 20256mo ago

Ransomware groups claim over 2,000 attacks in late 2025

In the final three months of 2025, ransomware groups claimed more than 2,000 attacks, including 731 in December alone. Elevated activity continued into early 2026, underscoring sustained momentum in the threat landscape.

Qilin identified as the most active ransomware group of 2025

Cyble identified the Russia-linked Qilin group as the most active ransomware operation in 2025, claiming 1,138 successful breaches. The group remained highly active into December 2025 and January 2026.

Cyble records sharp rise in ransomware activity during 2025

Cyble's annual threat report found ransomware activity surged throughout 2025, reaching 6,604 recorded attacks for the year, a 52% increase over 2024. Monthly attack volumes rose to nearly 700, with the United States accounting for 55% of attacks.

Sep 30, 20259mo ago

Conduent discloses incident in SEC filing with limited-impact description

In a September 30, 2025 SEC filing, Conduent said it had detected the January ransomware incident and described the impact as limited to a subset of users. Later state-level breach figures indicated the exposure was much larger than that characterization suggested.

Jan 13, 20251y ago

SafePay claims responsibility for Conduent breach

The ransomware group SafePay was identified in reporting as claiming responsibility for the Conduent attack. The breach was described as involving sensitive data including Social Security numbers and medical information.

Conduent detects ransomware incident

Conduent detected a ransomware attack on January 13, 2025. The incident caused several days of operational disruption and involved the alleged theft of about 8 TB of sensitive data.

Jan 1, 20251y ago

World Leaks becomes active as a data-extortion group

World Leaks began operating in early 2025 as a ransomware/extortion group focused primarily on stealing data and threatening publication rather than relying on file encryption. The group reportedly used social engineering, stolen credentials, and exploitation of exposed infrastructure for initial access.

Nov 1, 20197y ago

Data leak sites emerge to support double-extortion ransomware

Ransomware groups began using dark-web data leak sites in late 2019 to pressure victims by publishing stolen data samples, victim details, and deadlines. This marked a shift toward double extortion, combining encryption with threats to expose stolen information.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

15 LINKEDOpen in app
Threat actors
2 linked
Organizations
10 linked
LinkedinEsetAnalyst1AccentureNikeConduentZoho CorporationMicrosoft CorporationSemperisReady1
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.