CRIMINAL ECONOMY
Cybercrime
Ransomware operations, threat-actor profiles, breach economics, and the criminal markets that fund all of it.
The business of cybercrime: the initial-access brokers who sell the way in, the infostealer economy that feeds them, the dark-web markets where data is sold, and our own desk that tests leak claims before they become headlines. See how initial-access brokers fuel ransomware and the breach verification desk.
For live exposure data, look up any domain with Stealercheck and track active operators on the Ransomtracker.
Start here
- Initial access brokers: ransomware’s supply chain
- Breach verification desk: is the leak real?
- Bulletproof hosting: where attackers run infrastructure
- The Telegram stealer-log economy
- Exploit.in: inside a Russian hacker forum, 2005 to 2008
Latest cybercrime coverage
- Novo Nordisk breach lawsuits: what the complaints get wrongTwo class actions over the Novo Nordisk data breach cite our FulcrumSec reporting for its scale, then skip how the attackers got in and what data was exposed.
- Conti was hiring: the ransomware crew’s entrance examGermany named Vitaly Kovalev as Conti’s boss in 2025. RAMP forum messages show the other end: a recruiter, a written hacking exam, and when the hiring stopped.
- Exploit.in: inside a Russian hacker forum, 2005 to 2008Inside the Exploit.in database, 2005 to 2008: 9,647 members of the Russian hacker forum, 60% who never posted, and 205 handles still on the boards today.
- Telegram 120M leak: we counted 63M, most from 2020A forum listing advertises 120 million Telegram records. Ransomnews parsed the 3.7GB file: 63.1 million rows, 74% Iranian, and most of it dates to 2020.
- Condé Nast: 32.8M user records for sale, sample verifiedA 32.8M-record Condé Nast user database is on sale for $15,000 on a Russian-language hacker forum. We tested the sample: genuine account data, and the rest of the December WIRED hack.
- The Town 2025 ticketing data sold as a Ticketmaster breachA seller is offering 412,192 Latin American ticket-buyer records from The Town 2025, including 250,000 Brazilian CPFs, at about four cents a head. We tested the sample.
- Micro-Comm hack is separate from the US water attacksThe FBI water-sector PLC alert and the Barracuda ransomware breach at supplier Micro-Comm landed a day apart. The evidence says they are not the same story.
- Love Electric driver data for sale: NI, licence numbersA seller is offering 877,000 driver records from UK EV salary sacrifice broker Love Electric, including National Insurance and driving licence numbers. We checked the sample.
- Live Stripe keys for 659 merchants, published for freeStripe was not breached. A forum dataset holds live API keys for 659 of its merchants, plus 35GB pulled from them. We told Stripe before publishing this.
- Verified.ru: inside the archive of a cybercrime bureaucracyA 152,973-message archive of the Verified forum shows how Russian-speaking cybercrime governed itself between 2005 and 2010, using rules, penalty points and bans.
- McDonald’s employee data listed for sale in wider Entra campaignA forum seller claims 1.7 million McDonald’s employee records pulled from its Azure tenant. We analysed the sample, and the four other brands listed alongside it.
- 7.3M chess.com records leaked, and the data is realA 15.5 GB file of 7.3 million chess.com user records is circulating free on two leak forums. We verified it: the data is genuine and days old, but the shape points to scraping, not a breach.
- Quake3 and morgot: tracing REvil’s source-code developerQuake3, a moderator on the XSS.is cybercrime forum, is the persona DEF CON 33 research placed at REvil’s source-code development, and the man the German BKA named in April 2026. We trace the forum record that ties the handles together.
- Pokémon Center vending ‘breach’ is old 2016 dataA seller is marketing a ‘live’ breach of automated-retail vendor SwyftStore across 28 brands including Pokémon Center. The sample is genuine Zoom/Swyft data, but every record dates from 2016.
- Israeli population registry for sale, but the data is oldA vendor is selling what they call Israel’s current 9.22M-record population registry. Our analysis of the 100k sample says the data is genuine, but every date in it stops in 2005.
- Żabka confirms breach via supplier account, data for saleŻabka has confirmed unauthorized access through an external provider’s account after a dataset was listed for €5,000. We reviewed the sample; the company has not confirmed its scale.
- 5socks.net: 20 years of proxy crime, 2004 to seizure5socks.net sold access to hacked residential IPs from 2004 until the FBI seized it in May 2025. Dancho Danchev traces the service back to its Russian origins.
- Deadlock: ransomware that hides its C2 on the blockchainDeadlock ransomware uses Polygon smart contracts for takedown-resistant command and control and a vulnerable driver to kill EDR. A profile of 2026’s most technically novel new group.
- Clover Health discloses social-engineering breach in 8-KClover Health disclosed in a July 17 SEC filing that three employee accounts were compromised via social engineering, risking protected health data.
- DragonForce: the cartel that absorbed its rivalsDragonForce rebranded as a ransomware cartel offering white-label infrastructure, absorbed RansomHub affiliates, and hit UK retail. A profile of its model, decline, and tactics.
- ShinyHunters’ Salesforce extortion wave hits Fluke, IngramShinyHunters listed Fluke (21M Salesforce records claimed) and Ingram Content on its leak site, extending a 2026 Salesforce extortion campaign now drawing class-action lawyers.
- LockBit 5.0: the comeback nobody wantedLockBit relaunched as version 5.0 in September 2025 and surged to 7% of June 2026 attacks. A profile of the disrupted brand’s resurgence, new encryptor, and affiliate model.
- Deutsche Bank breached via supplier as Unsafe gang leaks dataA ransomware group called Unsafe posted Deutsche Bank employee data samples from a third-party supplier. The bank confirms a supplier breach but denies any internal compromise.
- Scattered Spider duo jailed 5.5 years over £29M TfL hackTwo Scattered Spider members were jailed 5.5 years each on July 16 over the 2024 Transport for London hack, the UK’s first conviction under Computer Misuse Act Section 3ZA.
Every cybercrime article
Every article we have published in this section, newest first.
- Novo Nordisk breach lawsuits: what the complaints get wrong
- Conti was hiring: the ransomware crew’s entrance exam
- Exploit.in: inside a Russian hacker forum, 2005 to 2008
- Telegram 120M leak: we counted 63M, most from 2020
- Condé Nast: 32.8M user records for sale, sample verified
- The Town 2025 ticketing data sold as a Ticketmaster breach
- Micro-Comm hack is separate from the US water attacks
- Love Electric driver data for sale: NI, licence numbers
- Live Stripe keys for 659 merchants, published for free
- Verified.ru: inside the archive of a cybercrime bureaucracy
- McDonald’s employee data listed for sale in wider Entra campaign
- 7.3M chess.com records leaked, and the data is real
- Quake3 and morgot: tracing REvil’s source-code developer
- Pokémon Center vending ‘breach’ is old 2016 data
- Israeli population registry for sale, but the data is old
- Żabka confirms breach via supplier account, data for sale
- 5socks.net: 20 years of proxy crime, 2004 to seizure
- Deadlock: ransomware that hides its C2 on the blockchain
- Clover Health discloses social-engineering breach in 8-K
- DragonForce: the cartel that absorbed its rivals
- ShinyHunters’ Salesforce extortion wave hits Fluke, Ingram
- LockBit 5.0: the comeback nobody wanted
- Deutsche Bank breached via supplier as Unsafe gang leaks data
- Scattered Spider duo jailed 5.5 years over £29M TfL hack
- World Leaks dumps 19,000 files tied to India nuclear plant
- Akira: the edge-VPN ransomware that never slowed down
- Coca-Cola’s Fairlife halts US production after ransomware
- Qilin: the RaaS that ran H1 2026 ransomware
- The week the West went after ransomware’s plumbing
- Anubis ransomware is exploiting Citrix Bleed 2 for access
- Kairos took $1M from a US government body and encrypted nothing
- XSS forum: from DaMaGeLaB to the 2025 takedown
- 1.16 billion attacks: how the FortiBleed crew broke FortiGate
- FortiBleed: exposed firewalls are a ransomware early warning
- Novo Nordisk hit by FulcrumSec: the stealer logs saw it coming
- The Gentlemen ransomware: 483 victims and a leaked playbook
- Ransomware runs office hours: what 16,699 leak posts reveal
- 62% of database ransom wallets were never paid
- Ransomware ditched encryption in May 2026: here’s why
- Initial Access Brokers 2026: ransomware’s supply chain
- How initial access brokers price corporate access in 2026: an explainer for defenders
- How to investigate a phishing kit: tutorial with urlscan.io, PhishTank, and Sublime Security
- Tracing crypto laundering: tutorial with Chainabuse, OXT, Walletexplorer, and Etherscan
- Why double extortion isn’t enough anymore: the rise of triple and quadruple extortion
- BEC vs ransomware: which is more profitable per attack in 2026?
- Bulletproof hosting in 2026: where attackers actually run their infrastructure
- Inside a money mule recruitment thread on Telegram
- Crypto laundering pipelines after the 2025 mixer takedowns
- The 2026 cybercrime economy by the numbers
- The economics of AI agent jailbreaks: who profits when an LLM goes off-rails
- The Telegram stealer-log economy: how stolen credentials are sold
- How stealer logs power modern ransomware attacks
- Redline, Lumma, Vidar, Raccoon: the major infostealer families of 2026
- What are stealer logs? A field guide to the credential-theft economy
- Play: the closed-shop ransomware brand quietly hitting cities, schools, and critical infrastructure
- Hive: the ransomware operation the FBI spent seven months inside
- DarkSide: Colonial Pipeline, the pseudo-code-of-conduct, and the rebrand to BlackMatter
- Akira: the retro-themed ransomware operation quietly eating mid-market enterprise
- Black Basta: Conti’s most successful successor and its healthcare specialism
- Ryuk: the big-game hunter that made ransomware a boardroom problem
- Cl0p: the mass-exploitation specialists behind Accellion, GoAnywhere, and MOVEit
- BlackCat / ALPHV: the Rust-powered RaaS that ended in an exit scam
- REvil / Sodinokibi: the big-game hunters who hit Kaseya, JBS, and then disappeared twice
- Conti: anatomy of a ransomware corporation, and how it imploded
- LockBit: the ransomware brand that redefined the industry, and got taken down
- Ransomware-as-a-service (RaaS): how cybercrime got its franchise model
- A brief history of ransomware: from the AIDS Trojan to the RaaS empires























