An extortion crew with almost no North American victims

On 26 August a ransomware leak site added twelve entries in a single batch. A Thai organic supermarket chain. A Vietnamese fashion label. An Egyptian frozen vegetable exporter, an Indian cancer care platform, a Guatemalan hardware wholesaler and a Gabonese public administrative body, among others. Not one of the twelve was an American company.

That is the pattern, not an off day.

The crew behind those listings is Krybit, which we track as Slice Flux. Since 3 April 2026 it has named 119 organizations on its leak site across 56 separate posting days, according to IntelFusions' own incident records. By our count, four of those 119 entries describe a US or Canadian organization. For comparison, roughly a third of every extortion claim we recorded in the past 90 days named a victim in the United States. Krybit is running at about 3%.

Everything on a leak site is an unverified claim written by the criminals themselves. None of the organizations named has confirmed a breach, and a listing is a bid for pressure as much as it is proof of an intrusion. What the listings do show reliably is where a crew is fishing.

Fishing where nobody is watching

Krybit's victims are overwhelmingly small and mid sized firms in Thailand, Vietnam, Malaysia, India, Egypt, Gabon, Guatemala, Brazil and Argentina, with a European tail that takes in Italy, Germany and the Czech Republic. Technology suppliers, business services firms, healthcare providers and manufacturers dominate the list. These are not household names, and that is the appeal. A Thai metal sheet distributor or an Indian contract research firm has no press office, rarely answers to a breach notification regulator, and stands almost no chance of being written up anywhere. Extortion is quieter, and the negotiation is cheaper, when nobody is going to ask the victim about it in public.

It is the same blind spot we ran into reporting on Latin America's public bodies appearing on leak sites earlier this month. Absence of coverage is not absence of victims.

The country tags are wrong, which helps

There is a second reason this crew is hard to see. The country labels attached to leak site entries are often simply wrong. In the 26 August batch alone, a Thai metal products manufacturer was tagged as United States, while a Vietnamese fashion brand and a Thai systems integrator were both tagged as Brazil. Build a national picture straight from those tags and you place the victims on the wrong continent. The figures above come from reading each victim description rather than trusting the tag, and we would encourage anyone else counting leak site activity by country to do the same.

Assume the encryptor reaches your backups

Krybit surfaced in late March 2026 as a ransomware as a service operation, recruiting affiliates on an 80/20 revenue split and advertising encryptors for Windows, Linux, ESXi and network attached storage. That last pair matters more than the branding. Virtualization hosts and NAS boxes are where a mid sized company's virtual machines and backup copies actually live, and they are usually the least monitored assets on the network. Organizations in the regions this crew favors should treat ESXi hosts and storage appliances as primary targets rather than collateral damage, and confirm that at least one backup copy sits genuinely out of reach of a compromised domain administrator account.

The crew has also spent real energy on its rivals rather than its victims: Krybit and a competing group called 0APT breached each other and leaked each other's operator data. Criminal infighting makes for good reading, but it is not protection. The listings have kept coming right through it.

This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions