A second brand new extortion operation surfaced over the weekend, and its victim list looks nothing like the one that appeared alongside it. A group calling itself Global Secret Group turned up in leak-site tracking on 26 July 2026 with 28 organizations already posted, among them Acens, a Spanish cloud hosting and backup provider. Every one of the claims is unverified, and no named organization has confirmed a breach.
The listings arrived as a complete site rather than a trickle, which is how a new leak site usually registers: the group had been building its page before anyone was watching, and the whole list became visible at once. The victim pages carry sequential identifiers running up to 30, so this looks like the group's entire output to date rather than a single day's work.
Why the hosting provider matters most
Most of the 28 names are small and mid-sized companies, but Acens is the entry with real downstream consequences. The group's own victim card describes it as a Spanish hosting business with 201 to 500 employees and roughly 46 million dollars in revenue. When an extortion crew claims a hosting and backup provider, the risk does not stop at that provider. Customer data, site backups and management credentials frequently sit on the same infrastructure, which is what turns one listing into a supply chain problem. Any organization hosting with a provider named on a leak site should be asking its account team direct questions now rather than waiting for a public statement.
Who else is on the list
The rest of the list is strikingly ordinary. It includes a US veterinary clinic, a carpet retailer, a decal manufacturer, a tax preparation firm, a small law practice, an Argentine hospitality business, and fuel distributors in Canada and Brazil. Technology firms make up the largest slice at nine listings, followed by retail with five, then financial services, professional services and energy with three each. Healthcare accounts for two, including SPDM, listed as a Brazilian healthcare organization.
The claims stretch across 14 countries. Thirteen of the named organizations are American, and the remainder are spread over Canada, Brazil, Spain, the United Kingdom, Germany, Finland, Cyprus, India, the United Arab Emirates, South Korea, Iraq, Argentina and China. The Chinese listing, video surveillance maker Uniview Technologies, stands out. Russian-speaking extortion crews generally avoid Chinese targets, so its presence is at least a hint that this operation is either based elsewhere or simply picking targets indiscriminately.
Two debuts in a single day
Global Secret Group appeared on the same day as Exfil Squad, another first-time brand that posted 14 listings naming Microsoft, Allstate, Frontier Airlines and two US city governments. The contrast is instructive. One new brand led with household names and enormous record counts, the other with a long tail of small businesses and a hosting provider. Both are equally unproven, but a list of unglamorous small companies is the harder one to wave away, because it matches how extortion crews actually earn money.
Neither debut is unusual on its own. The leak-site ecosystem has been fragmenting for months, with a steady stream of small brands appearing, posting a handful of victims, then folding or rebranding. The thing worth watching is whether Global Secret Group posts anything after its opening batch. Brands that never add a victim beyond their launch list are usually recycling data stolen by somebody else, while brands that keep posting tend to have working intrusion capability.
What you should do
- If your organization is named, or your hosting or backup provider is, treat it as a live incident until proven otherwise. Preserve logs, rotate credentials, and review the past 90 days for unfamiliar remote access and bulk file reads.
- Do not read silence as safety. Leak-site listings routinely precede any disclosure by weeks.
- Confirm that backups are genuinely offline or immutable, and that restoring them does not depend on the same credentials an intruder would already hold.
- Treat any record counts in the postings as marketing until independently verified. New brands have every incentive to inflate them.
IntelFusions tracks this group on its Global Secret Group profile, which updates as new listings appear. We do not link to extortion sites, and no indicators beyond the group's Tor address have been published so far.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.