FulcrumSec — Ransomware Profile

FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis.

Also tracked as

The Threat Thespians

IntelFusions coverage (1)

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions