FulcrumSec — Ransomware Profile
FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis.Also tracked as
The Threat Thespians
IntelFusions coverage (1)
- Cloud extortion crew steals secrets via service accounts 2026-08-06 · Cyber Incidents
Tools & malware
- Rclone Exfiltration Tool
Recent claimed victims
- Dustin Group 2026-09-11
- Manchester Airports Group 2026-09-01
- Novo Nordisk 2026-06-16
- Global Schools Foundation 2026-06-10
- Arup Group 2026-05-10
- Stuf Storage 2026-05-08
- Avnet 2026-05-01
- LexisNexis 2026-05-01
- Crank Communications 2026-05-01
- youX / Drive IQ 2026-05-01
- IMEVI 2026-05-01
- JOT 2026-05-01
- BookBlock 2026-05-01
- Analog Gold / Prospector 2026-05-01
- Woundtech 2026-05-01
- MCO 2026-05-01
- Raptor Supplies 2026-05-01
- Lena Health 2026-05-01
- ReFocus AI 2026-05-01
- ParkEngage 2026-05-01
- Saleskido 2026-05-01
- CrediElite 2026-05-01
- Interzero 2026-05-01
- Nordstern Technologies 2026-05-01
- Hatica 2026-05-01