Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Exploits CVEs in the wild

FulcrumSec

Also known asFulcrumSec

FulcrumSec is a financially motivated data-theft and extortion threat actor active since at least September 2025, with reporting also describing its emergence around October or the end of 2025. The group targets cloud-native organizations and specializes in high-speed exfiltration of cloud-hosted data rather than relying primarily on file encryption. Reported tradecraft includes exploiting unrotated API keys, exposed or hardcoded GitHub personal access tokens, unrotated JWT signing secrets, misconfigured cloud permissions and storage, over-permissioned cloud identities, exposed credentials in client-side JavaScript, and unpatched internet-facing applications including CVE-2025-55182 (React2Shell). The content also states that FulcrumSec uses legitimate tooling such as rclone for exfiltration, maintains leak or shame infrastructure on both clearnet and Tor, and has a leak-site section referred to as "Index of /Shame." One source says the group refers to its model as "steal and squeeze" and also uses the nickname "The Threat Thespians." The group is consistently described as a hack-and-leak or pure extortion actor, though some reporting also labels it a ransomware group and attributes double-extortion behavior to it in the Global Schools Foundation incident. Victim sectors mentioned in the content include technology, business services, healthcare, consumer services, financial services, and education. Countries represented in the victim reporting include the United States, United Kingdom, India, Denmark, Singapore, and Australia. Named victims in the content include Novo Nordisk, Global Schools Group / Global Schools Foundation, Arup Group, Avnet, youX, and LexisNexis, as well as additional listed victims including Lena Health, Woundtech, MCO, ReFocus AI, Hatica, Analog Gold / Prospector, Nordstern Technologies, ParkEngage, Saleskido, Interzero, IMEVI, Raptor Supplies, Rotary Club, JOT, BookBlock, Crank Communications, CrediElite, and Fashinza. Reported victim counts in the content are approximately 25 to 26 organizations across 11 countries, with most victims headquartered in the United States. The content links FulcrumSec to several notable incidents. In the Novo Nordisk intrusion, FulcrumSec claimed it maintained access for more than two months, stole about 1.3 TB across more than 700,000 files, and demanded $25 million before leaking data. In reporting on youX, the group allegedly abused long-lived production credentials and unrotated JWT secrets. In reporting on LexisNexis, the group allegedly exploited React2Shell and obtained access through an Amazon ECS task role with broad secrets access. In reporting on Arup Group, FulcrumSec claimed initial access via a hardcoded GitHub token on a forgotten subdomain and subsequent access to large volumes of GitHub, Azure, AWS, and database data. The content also attributes the Global Schools Group / Foundation breach and related extortion activity to FulcrumSec, including publication threats and court actions seeking to restrain leaks. Known aliases and related names directly mentioned in the content are FulcrumSec and "The Threat Thespians."

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Software & Services
  • Commercial & Professional Services
  • Health Care Equipment & Services
  • Consumer Services
  • Financial Services
  • Pharmaceuticals, Biotechnology & Life Sciences

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
  • 🇬🇧 United Kingdom
  • 🇮🇳 India
  • 🇩🇰 Denmark
  • 🇸🇬 Singapore
  • 🇦🇺 Australia
MITRE ATT&CK

Tradecraft

28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics37 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589
Gather Victim Identity Information
T1589.001
Credentials
T1598
Phishing for Information
TA0042
Resource Development
1 technique
T1588
Obtain Capabilities
T1588.003
Code Signing Certificates
TA0001
Initial Access
3 techniques
T1078×10
Valid Accounts
T1078.004×2
Cloud Accounts
T1133×5
External Remote Services
T1190×3
Exploit Public-Facing Application
TA0003
Persistence
2 techniques
T1078×10
Valid Accounts
T1078.004×2
Cloud Accounts
T1133×5
External Remote Services
TA0004
Privilege Escalation
1 technique
T1078×10
Valid Accounts
T1078.004×2
Cloud Accounts
TA0005
Stealth
1 technique
T1078×10
Valid Accounts
T1078.004×2
Cloud Accounts
TA0006
Credential Access
5 techniques
T1528×2
Steal Application Access Token
T1539
Steal Web Session Cookie
T1552×3
Unsecured Credentials
T1552.001×6
Credentials In Files
T1552.005
Cloud Instance Metadata API
T1555×3
Credentials from Password Stores
T1649×3
Steal or Forge Authentication Certificates
TA0007
Discovery
3 techniques
T1526×4
Cloud Service Discovery
T1580
Cloud Infrastructure Discovery
T1619
Cloud Storage Object Discovery
TA0009
Collection
4 techniques
T1005
Data from Local System
T1074×5
Data Staged
T1213×9
Data from Information Repositories
T1530×4
Data from Cloud Storage
TA0010
Exfiltration
4 techniques
T1041×10
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1537
Transfer Data to Cloud Account
T1567×4
Exfiltration Over Web Service
T1567.002×5
Exfiltration to Cloud Storage
TA0040
Impact
2 techniques
T1486×9
Data Encrypted for Impact
T1657×3
Financial Theft
IOCS

Observables

2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping28

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables2

Domains, IPs, and hashes tied to this actor, refreshed continuously.