Ransomware operators have expanded double-extortion tactics by targeting people around a victim organization, including senior executives, employees, customers, and business partners, to force ransom payments. Reporting tied the approach primarily to the Clop ecosystem, with similar behavior also attributed to REvil affiliates. Attackers were described as prioritizing executive mailboxes and workstations to find sensitive files, litigation records, and internal discussions that could be used to embarrass leadership or strengthen negotiations.
The pressure campaign also extended beyond the company itself, with gangs emailing victims’ customers and associates to amplify reputational and legal risk. One cited case involved RaceTrac Petroleum, where data stolen via exploitation of a zero-day in Accellion File Transfer Appliance services used by a third party included some customer contact details, though the company said its corporate network and payment systems were not affected. Similar outreach was reportedly used against people linked to the University of California, underscoring how ransomware groups increasingly use public exposure and direct contact with stakeholders as leverage even when stolen data may later be leaked regardless of payment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Fabian Wosar said REvil had also started using customer-email pressure tactics, and Bleeping Computer reported the operation was planning DDoS attacks or VOIP calls to victims' customers to intensify extortion pressure.
Clop sent emails to victims' customers, buyers, partners, and employees warning that stolen data would be published unless the victim organization contacted the attackers. Researchers described this as an escalation of double-extortion pressure tactics.
In February, REvil posted a job notice seeking people to perform DDoS attacks and make VoIP calls to victims and their business partners as part of its extortion model. The move signaled REvil's planned expansion beyond data-theft pressure into service-based harassment tactics.
Arete IR said an affiliate of the REvil ransomware-as-a-service operation used stolen documents related to ongoing litigation and internal discussions, then emailed executives directly threatening to release alleged evidence of management misconduct.
Victim accounts and incident responders said that over recent months, actors in the Clop ransomware ecosystem searched breached networks for workstations used by executives and managers, then exfiltrated sensitive emails and files to increase ransom pressure.
People associated with the University of California received extortion emails similar to those sent in other Clop cases. The article says several recent university incidents appeared linked to exploitation of the same Accellion vulnerability.
Several gigabytes of RaceTrac files, including employee tax and financial records, were posted to Clop's victim-shaming site as part of the gang's extortion campaign.
RaceTrac said unauthorized parties accessed a subset of its data stored in Accellion File Transfer Service, including email addresses and first names of some RaceTrac Rewards users. The company said the incident was limited to Accellion services and did not affect its corporate network or payment-processing systems.
Attackers exploited a zero-day vulnerability in Accellion File Transfer Appliance software for several months, and Clop used it to compromise dozens of companies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
krebsonsecurity.com
Open sourcebleepingcomputer.com
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.