Global Secret Group — Ransomware Profile

Global Secret Group, also tracked as GSG, is a data theft extortion crew that Arete reports emerged in 2026 leveraging the leaked LockBit 3.0 (LockBit Black) source code. Arete states the group operates through Tor-based negotiation portals and qTox communications, and that its data leak site provides step-by-step guidance on purchasing Bitcoin, including references to Coinbase and Binance, to streamline ransom payment. Arete ranked it among the five most active threat groups it observed in July 2026, alongside INC Ransom, Qilin, Anubis and DragonForce. WatchGuard classifies the operation as a data broker first seen in January 2026 that uses direct extortion, double extortion and free data leaks, which places its first observed activity several months earlier than Arete's June 2026 start date.

Also tracked as

GSG

IntelFusions coverage (3)

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions