Global Secret Group is a ransomware and data-extortion threat actor active in 2026. It has been observed publicly claiming numerous victims across multiple countries, with a concentration of victims in the United States and additional victims in Europe, Canada, India, the United Arab Emirates, Cyprus, and Argentina. Reported victim organizations span manufacturing, financial services, health care, real estate, professional services, construction, retail, transportation, technology, and nonprofit organizations, indicating broad opportunistic targeting rather than a narrowly specialized victim profile. The group is associated with ransomware incidents that also involve theft of victim data and public victim claims, consistent with leak-site style extortion operations. Reported cases describe both ransomware attacks and accompanying data breaches, indicating that exfiltration is a routine part of its operations. Weekly ransomware tracking placed the group among the more active claimants during late July 2026, including a notable spike to dozens of claimed victims in one reporting week, followed by a drop from the top rankings the next week. High-confidence reporting supports Global Secret Group as an extortion-oriented cybercriminal actor rather than a state-linked espionage cluster. Its observed behavior includes initial compromise leading to post-exploitation activity, data theft, and extortion through public naming of victims. No reliable attribution to a specific country of origin is currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against The Rubber Group.
Conducting a ransomware attack and associated data breach against 4M REALTY COMPANY.
Conducting a ransomware attack resulting in a data breach against Coggins Insurance Agency.
Conducting a ransomware attack resulting in a data breach against MACOFIN HELLAS S.A.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.