I ask everyone in this series why they agreed to talk to me, and it is usually a wasted question. My last subject told me there were no particular goals and that maybe he would shed some light on the topic. The group calling itself the BASHE Hack Team gave me a different sort of answer.
“We’re giving this interview to increase our visibility. The more people talk about us, the more they fear us. This gives us the opportunity to raise the prices for buyouts and earn more.”
That answer sets the terms for everything that follows. By their own account, coverage raises the price they can ask, and an interview is coverage. They said it before I had put a single question to them about their business.
That creates an obvious problem, because publishing the interview serves the purpose they described. I have published it with the record attached. The second half of this piece sets their answers against what they told another journalist six months ago, against what their leak site has listed since, and against what happened in June when they claimed a large breach at an airport.
Who Bashe are, on the public record
Bashe surfaced in mid-April 2024 and has worn three names since: APT73 first, then Eraleig, then Bashe. Researchers noticed early that the leak site was a near copy of LockBit’s, down to the same section headings, which is why the group is usually described as a LockBit spinoff or at least a crew working from LockBit’s furniture. The name comes from Chinese mythology, a serpent large enough to swallow an elephant, and the group has said in public that this is the point of it.
SOCRadar counted 63 named victims by December 2024. Vectra puts the running total near 79 organisations across North America, the United Kingdom, France, Germany, India and Australia, in technology, business services, manufacturing, logistics, finance, transport, construction and healthcare. Our own confirmed-attack records, which need corroboration beyond a leak-site post before an entry goes in, carry four. That is not evidence the rest were invented. Leak-site posts and confirmed incidents have never been the same thing, and the number four reflects our own inclusion rules as much as it reflects Bashe.
I reached them the way I reached my last subject, over Tox, from contact details mined out of three years of offline forum copies. I introduced myself, gave them a way to verify my Tox ID, and pointed them at two decades of published work so they could decide for themselves whether I was worth answering. They accepted on 17 August and said they would answer within a day or two. The answers came back on 26 August, all twenty-six of them, in two parts, nine days after the request.
One note on language before you read them. My last subject took my questions in English and answered in Russian, and everything you read there had passed through my translation. This time there is no translation layer. Bashe answered in English, and the answers below are theirs, grammar included. I have not reworded any of it. The rough English is the best evidence I can offer you that this is correspondence and not a press release.
What I have not done, again, is verify them. I cannot confirm their scale, their affiliate arrangements, or that the group answering me on Tox is the same set of people behind every listing that has carried the name. Read this as testimony from inside a criminal business, not as fact I am standing behind.
Establishing contact
Five opening questions, to work out who I was dealing with. They answered three and turned the other two back on me, which no subject has done to me before.
Who am I speaking to?
▮ BASHE Hack TeamBashe hacker group.
Are you familiar with my research and achievements throughout the years?
▮ BASHE Hack TeamWe’re not familiar with your research.
Are you 100% interested in giving me this interview?
▮ BASHE Hack TeamWe’re interviewed quite often. Our fame is a way to attract attention and make money.
Is there anything specific that you want to ask me before we begin the interview?
▮ BASHE Hack TeamAre you sure your passwords are secure enough right now?
Is there a very specific question that you want me to ask you, or a set of questions about a specific topic?
▮ BASHE Hack TeamIt seems like you’re the one interviewing us, not the other way around.
The interview
What is your primary purpose for giving this interview? What do you hope to accomplish?
▮ BASHE Hack TeamWe’re giving this interview to increase our visibility. The more people talk about us, the more they fear us. This gives us the opportunity to raise the prices for buyouts and earn more.
Do you agree to have me go public and publish the interview with your answers?
▮ BASHE Hack TeamWe don’t mind.
How did you get started in the cybercrime ecosystem?
▮ BASHE Hack TeamWe gathered people, each of whom was good at doing their job. Then we discovered that together our skills are worth significantly more. No romance: we saw the market, we entered the market.
How would you describe yourself? A vendor of a service or a solution, an active threat actor, or a ransomware operator?
▮ BASHE Hack TeamBusinessmen. We sell a very specific service, the ability to keep a problem confidential.
How did you get involved with computers?
▮ BASHE Hack TeamIt’s hard not to get carried away with computers in the 21st century. Especially when you realize how much money people trust to machines that are easy to hack.
How popular and far-reaching in the cybercrime ecosystem is what you are currently doing?
▮ BASHE Hack TeamQuite popular. As long as information has a price, there will be people willing to determine that price.
What are your current projects and future plans?
▮ BASHE Hack TeamTo scale up. To increase the average check. To work less and to get more. Any normal business has roughly the same plans.
Do you view yourself as a pure opportunist, a businessman, or do you hold any ideological justifications for your actions?
▮ BASHE Hack TeamOnly financial benefit. We are not saving the world, building a new order, or writing manifestos. If money starts growing on trees tomorrow, maybe we’ll start gardening.
How do you compartmentalise your digital life as an operator from your personal, real-world life?
▮ BASHE Hack TeamIt’s very simple: in one life, journalists ask us such questions but we don’t tell the journalists about the second.
What is the biggest misconception the general public has about the people behind the screen in the cybercrime ecosystem?
▮ BASHE Hack TeamBehind the monitor, there’s always a mad genius in a hood, there are six screens around, and green numbers are scrolling across the walls. Most people look much duller than their newspaper headlines.
The more people talk about us, the more they fear us.
Have you ever been scammed or ripped off by other actors within the underground community?
▮ BASHE Hack TeamIt’s quite difficult to join our team. And to join us, an affiliate must pay for it himselve. So, in any case, any of our affiliates pays for any potential fraud.
What is the most common, fundamental security failure you see in corporate networks today?
▮ BASHE Hack TeamOverconfidence. Companies like to think that problems happen to someone else. That’s why security usually becomes truly important only after we’ve already requested a ransom.
If paying ransoms were made globally illegal tomorrow, how would your business model pivot?
▮ BASHE Hack TeamA ban doesn’t destroy demand. But we’ll keep the specific adaptation plan to ourselves. We do not provide free business consulting to competitors in interviews.
Where do you see the ransomware industry in five years? Will it consolidate, become more fragmented, or evolve into something entirely different?
▮ BASHE Hack TeamAs long as disclosing information can cause financial or reputational damage to the owner, someone will definitely try to set a price for silence.
How competitive is the ransomware landscape between different groups?
▮ BASHE Hack TeamWe do our job and don’t pay attention to others.
What does “retirement” or exit look like for people who leave this activity?
▮ BASHE Hack TeamWe don’t have pensions. There’s only the moment when you’ve earned enough to stop answering journalists’ questions.
How might changes in cryptocurrency regulation or tracing capabilities affect operations?
▮ BASHE Hack TeamNo way. Every year we’re told that now we’ve definitely been cornered. Then a year passes, the rules change, the tools change, but we’re still here and we’re still making money. Let them regulate. We’re even curious about what they’ll come up with next.
What question do you wish more interviewers or researchers would ask people in your position?
▮ BASHE Hack Team“How much did you earn?” Everything else is an attempt to find deep meaning where the money is.
If you could speak directly to organisations that might become victims, what would you want them to hear?
▮ BASHE Hack TeamKeep cutting corners on safety. We like your strategy.
What does “success” actually mean inside this world?
▮ BASHE Hack TeamWhen everyone knows about you, but no one knows who you are.
Is there anything else we have not covered that someone trying to understand this world should know?
▮ BASHE Hack TeamStop looking for ideology, philosophy, and great goals here. This is a market. Someone has data. Someone is afraid of losing it or seeing it published. And someone knows how to turn that fear into money. Everything else, you journalists, fill in yourself.
Everything else, you journalists, fill in yourself.
After the conversation
What they told another journalist
Bashe told me they are interviewed often, and they were not exaggerating. On 15 February 2026, six months before my questions reached them, Marco A. De Felice published an interview with the same group at SuspectFile. I read it after their answers reached me and found several of my answers already sitting in it.
In February, asked about rivals, they said they do not compete with anyone, they do their job and do it well. In August, asked how competitive the landscape is, they told me they do their job and do not pay attention to others. In February their main goal was money. In August it was only financial benefit. The wording is close enough across six months to suggest answers prepared in advance rather than composed for each interviewer.
The repeated material is also the most flattering material: the discipline, the professionalism, the indifference to law enforcement. That is worth holding in mind when reading it.
The raw log shows something the interview itself does not. My questions went out on 17 August. The answers came back nine days later, and all twenty-six of them landed inside ten minutes, between 17:29:19 and 17:39:36 on the evening of 26 August. Twenty-six answers inside ten minutes is consistent with a document written in advance and pasted in three parts.
The affiliate entry fee
I asked whether they had ever been ripped off by other actors. My previous subject answered that directly, right down to the line in the budget he sets aside for it. Bashe did not address it directly.
They told me it is difficult to join them, that an affiliate has to pay to get in, and that as a result any affiliate has already paid for any fraud he might later commit. SuspectFile put that entry fee at 0.25 BTC and reported the group calling it both revenue and a filter. Read together, the two accounts describe a structure in which an affiliate pays before he is in a position to cause a loss, which addresses one of the commonest complaints in this economy. They did not say whether the group has been cheated by anyone other than an affiliate.
The leak-site record
In February they told SuspectFile they stay away from healthcare, schools and CIS countries. On 27 April 2026 a listing for Medika Plaza, an Indonesian healthcare company, went up on their site. Healthcare appears in the sector breakdown of every independent profile of this group I can find. Roughly ten weeks separate the statement from the listing.
Then June. The group claimed more than 500,000 emails and 4,470 files from Flughafen Wien, the operator of Vienna Airport. The airport’s spokesman, Peter Kleemann, said what had actually leaked were old and meaningless cargo loading lists from a single mailbox, that passenger and operationally critical data were untouched, and that the airport was running normally. The airport called in outside experts and went to the authorities, so this is a company treating the incident seriously rather than waving it off. The two accounts differ substantially in scale.
I am not in a position to settle which account is accurate. What is on the record is that the figure of 500,000 circulated more widely than the airport’s response did, and that the relationship between visibility and price is the one Bashe set out in their first answer.
CloudSEK went further and concluded that a set of Bashe’s bank listings, including claims against institutions in India and Indonesia, were built from recycled data out of older breaches rather than fresh intrusions. I cannot independently verify every case in that analysis, and I would want to see the underlying comparisons before treating it as settled. It is presented here as one published assessment among several, and Bashe have not responded to it publicly.
The two answers that stand on their own
Two answers survive all of that, because neither of them depends on Bashe being who they claim to be.
The first is that security becomes truly important only after the ransom has been requested. I have watched that happen at close range for twenty years, in companies far better resourced than the ones on this group’s site, and I have not heard it put better. The second is what they would say to organisations that might become victims: keep cutting corners on safety, we like your strategy. It is phrased as a taunt rather than advice, but the underlying point is the one security teams have been making internally for years.
There is also one contradiction they walked into without noticing. They would not describe how they would adapt if ransom payments were banned worldwide, on the grounds that they do not hand free consulting to competitors. Four answers later, competitors are people they pay no attention to at all. The two positions are difficult to reconcile.
On publishing this at all
A group that tells you the interview is a pricing instrument has handed you a reason not to run it. I have published it on the basis that the admission is more useful to readers than it is to Bashe.
Anyone dealing with the group can now read, in its own words, that visibility is treated as a lever on price. That is context a company in the middle of a negotiation would not otherwise have, and there was no way to establish it except by letting them state it.
Their closing description of the trade as a market is accurate as far as it goes. What it leaves out is how much of the reputation that sets the price is built through publicity rather than demonstrated on a network.
There is a third set of questions in this arrangement, which I told them about at the start and have not sent yet. I said it would be my longest. It is going to be my shortest. Vienna, the Medika Plaza listing, and the question they told me they wish somebody would ask them, which is how much they have earned.
Notes and sources
- Previous interview in this series: a representative of RTM Locker on the RaaS market.
- SuspectFile, “Inside Bashe: The Interview with the Ransomware Group Known as APT73,” 15 February 2026: suspectfile.com
- SOCRadar, “Dark Web Profile: Bashe (APT73)”: socradar.io
- CloudSEK, “Unmasking Media-Hungry Ransomware Groups: Bashe (APT73)”: cloudsek.com
- Vectra AI threat actor profile, Eraleig / APT73 / Bashe: vectra.ai
- Vienna Airport response reported by VIENNA.AT, 24 June 2026: vienna.at
- Related reading on Ransomnews: what double extortion actually is, tracking affiliates across rebrands, reading leak sites without being played, and the wider threat-group catalogue.
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
