FulcrumSec
FulcrumSec is a financially motivated data-theft and extortion threat actor active since at least September 2025, with reporting also describing its emergence around October or the end of 2025. The group targets cloud-native organizations and specializes in high-speed exfiltration of cloud-hosted data rather than relying primarily on file encryption. Reported tradecraft includes exploiting unrotated API keys, exposed or hardcoded GitHub personal access tokens, unrotated JWT signing secrets, misconfigured cloud permissions and storage, over-permissioned cloud identities, exposed credentials in client-side JavaScript, and unpatched internet-facing applications including CVE-2025-55182 (React2Shell). The content also states that FulcrumSec uses legitimate tooling such as rclone for exfiltration, maintains leak or shame infrastructure on both clearnet and Tor, and has a leak-site section referred to as "Index of /Shame." One source says the group refers to its model as "steal and squeeze" and also uses the nickname "The Threat Thespians." The group is consistently described as a hack-and-leak or pure extortion actor, though some reporting also labels it a ransomware group and attributes double-extortion behavior to it in the Global Schools Foundation incident. Victim sectors mentioned in the content include technology, business services, healthcare, consumer services, financial services, and education. Countries represented in the victim reporting include the United States, United Kingdom, India, Denmark, Singapore, and Australia. Named victims in the content include Novo Nordisk, Global Schools Group / Global Schools Foundation, Arup Group, Avnet, youX, and LexisNexis, as well as additional listed victims including Lena Health, Woundtech, MCO, ReFocus AI, Hatica, Analog Gold / Prospector, Nordstern Technologies, ParkEngage, Saleskido, Interzero, IMEVI, Raptor Supplies, Rotary Club, JOT, BookBlock, Crank Communications, CrediElite, and Fashinza. Reported victim counts in the content are approximately 25 to 26 organizations across 11 countries, with most victims headquartered in the United States. The content links FulcrumSec to several notable incidents. In the Novo Nordisk intrusion, FulcrumSec claimed it maintained access for more than two months, stole about 1.3 TB across more than 700,000 files, and demanded $25 million before leaking data. In reporting on youX, the group allegedly abused long-lived production credentials and unrotated JWT secrets. In reporting on LexisNexis, the group allegedly exploited React2Shell and obtained access through an Amazon ECS task role with broad secrets access. In reporting on Arup Group, FulcrumSec claimed initial access via a hardcoded GitHub token on a forgotten subdomain and subsequent access to large volumes of GitHub, Azure, AWS, and database data. The content also attributes the Global Schools Group / Foundation breach and related extortion activity to FulcrumSec, including publication threats and court actions seeking to restrain leaks. Known aliases and related names directly mentioned in the content are FulcrumSec and "The Threat Thespians."
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
- Commercial & Professional Services
- Health Care Equipment & Services
- Consumer Services
- Financial Services
- Pharmaceuticals, Biotechnology & Life Sciences
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇬🇧 United Kingdom
- 🇮🇳 India
- 🇩🇰 Denmark
- 🇸🇬 Singapore
- 🇦🇺 Australia
Tradecraft
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated cloud extortion group targeting cloud-native businesses, stealing sensitive data for extortion and resale using a 'steal and squeeze' model without encryption or disruptive ransomware activity.
Financially motivated cloud-focused extortion group using a 'steal and squeeze' model: stealing sensitive data from cloud-native companies and extorting victims without deploying encryption or disruptive ransomware.
Conducting a ransomware/data extortion attack against Novo Nordisk, stealing approximately 1.3 TB of data, demanding a $25 million ransom, and leaking part of the stolen data after unsuccessful negotiations.
Associated with a data security incident involving the acquisition of sensitive student and parent information and the threatened or actual publication of that data.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.