Extortion crew names Europe's standards bodies as victims

The extortion crew Coinbase Cartel has listed CEN and CENELEC, the two Brussels based organisations that write Europe's technical standards, on its dark web leak site. The entry appeared on August 1 alongside three other names. Neither body has confirmed an intrusion, and the crew has published a description of them rather than proof.

IntelFusions tracks extortion leak site postings continuously through ransomware.live. In our records the listing carries no stated data volume, no file listing and no samples.

Who the targets are

CEN, the European Committee for Standardization, and CENELEC, its electrotechnical counterpart, develop the European Standards that national standards bodies across the continent then adopt. A large share of that output is harmonised standards, the documents manufacturers use to show a product meets the requirements of EU legislation. The organisations do not run factories or hold consumer records at scale, so the material worth worrying about in any real compromise is the surrounding paperwork: draft standards still under committee discussion, membership and national delegate correspondence, and internal scheduling for work in progress.

That last category is why a listing like this is worth more than a shrug. Standards work is deliberately slow and consensus driven, and it touches a very large contact list of national bodies, trade associations and corporate technical staff. Correspondence stolen from the centre of that network is high grade phishing material against everyone in it, whether or not any individual standard is sensitive.

Three other names went up the same day: a US construction and design build contractor listed as M. B. Kahn Construction, a technology firm listed as Xs Cad, and a fertility clinic network listed as MIM Fertility. The clinic is the entry with the clearest human cost if the claim proves real, because reproductive medicine records are among the most sensitive categories any healthcare provider holds.

The crew

Coinbase Cartel has been posting since mid March in our data, with 102 listings across 26 countries. The group's habit is naming large and instantly recognisable brands, and it does so far more often than an operation of its size normally would. We covered that pattern in July when it named Caterpillar and Colliers, and the same caution applies now. The group's chosen name references a cryptocurrency exchange that is not itself among the organisations it has listed.

Treat it as a claim

Everything here is an unverified extortion claim published on the group's own infrastructure. It is not proof of a breach, and a listing that leads with a boilerplate corporate description and offers no samples is the weakest form such a claim can take. Crews that lean on recognisable names have a standing incentive to stretch, including by folding in data taken from a supplier, a contractor or an older unrelated incident and filing it under a bigger name.

What to do

National standards bodies, technical committee members and suppliers who correspond with either organisation should assume, as a precaution rather than a conclusion, that recent email threads could be repurposed as lures, and should treat unexpected attachments referencing committee work or draft standards with suspicion. Belgian and EU level incident response contacts are the right escalation route for member bodies seeking confirmation, and our Belgium country profile tracks the national picture. Background on the crew sits on our Coinbase Cartel profile. IntelFusions will update this story if either organisation comments or the group publishes data.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions