Since the end of June a data theft crew called Settra has named 64 organizations on its dark web leak site. It did that on 12 days.
The rest of the time it is simply not there.
That cadence is the story. Over the same stretch Akira, a far better known operation, listed exactly the same number of organizations, 64, and spread them over 34 separate posting days. Qilin posted 312 across 61 days, close to daily. Settra works in dumps: eight names on 31 August, nine more on 3 September, and nothing in between. Those two batches alone left it fourth among every extortion crew we tracked last week, behind Qilin and The Gentlemen and the newcomer Za Woo.
Visible two days a month, busy all of them
Everything on a leak site is an unverified claim written by criminals about their own work. None of the organizations Settra names has confirmed a breach, and a listing is a bid for leverage as much as it is evidence of an intrusion. What the listings do show reliably is when a crew is working, and Settra's work arrives almost entirely in bursts.
The practical effect is that anyone who checks leak sites on an ordinary day sees nothing at all from this group. We covered its opening dump, a dozen victims named in a single day, at the end of June. On most days since there has been nothing new to look at, and yet the crew has reached 64 claims across 19 countries in ten weeks. A weekly sweep of leak sites will catch a group like Qilin every time and miss this one most weeks.
Domains, not company names
Settra writes its listings differently from most of its peers too. Of the 64 entries, 59 are a bare domain rather than a company name, which makes the crew harder to find for anyone searching on an organization's legal name rather than its website. The recent batches are also a step up in size of target. The 31 August set included the domains of the American network infrastructure firm Zayo and the fleet telematics supplier Zonar Systems, and the 3 September set listed the Italian diagnostics maker DiaSorin. Earlier batches named the Korean industrial group Doosan and the London listed miner Petra Diamonds. All of these remain claims made by the crew, and none has been confirmed by the companies.
Backups will not settle this one
Our own profile of Settra records a group that steals data and threatens to publish it, negotiating over Tox, with no encryptor observed in its operations. That changes what defence looks like. Restoring from backup resolves nothing when the leverage is publication rather than downtime, so the detection signal that matters is bulk outbound transfer from file shares and document stores, not the sudden appearance of encrypted files. Organizations should also treat leak site monitoring as a retrospective exercise rather than a daily one. Against a crew that surfaces twice a month, a check that happens to fall between dumps returns a clean result that means nothing.
This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.