// CRIMINAL ECONOMY
Cybercrime
Ransomware operations, threat-actor profiles, breach economics, and the criminal markets that fund all of it.
- Live Stripe keys for 659 merchants, published for freeStripe was not breached. A forum dataset holds live API keys for 659 of its merchants, plus 35GB pulled from them. We told Stripe before publishing this.
- Verified.ru: inside the archive of a cybercrime bureaucracyA 152,973-message archive of the Verified forum shows how Russian-speaking cybercrime governed itself between 2005 and 2010, using rules, penalty points and bans.
- McDonald’s employee data listed for sale in wider Entra campaignA forum seller claims 1.7 million McDonald’s employee records pulled from its Azure tenant. We analysed the sample, and the four other brands listed alongside it.
- 7.3M chess.com records leaked, and the data is realA 15.5 GB file of 7.3 million chess.com user records is circulating free on two leak forums. We verified it: the data is genuine and days old, but the shape points to scraping, not a breach.
- Quake3 and morgot: tracing REvil’s source-code developerQuake3, a moderator on the XSS.is cybercrime forum, is the persona DEF CON 33 research placed at REvil’s source-code development, and the man the German BKA named in April 2026. We trace the forum record that ties the handles together.
- Pokémon Center vending ‘breach’ is old 2016 dataA seller is marketing a ‘live’ breach of automated-retail vendor SwyftStore across 28 brands including Pokémon Center. The sample is genuine Zoom/Swyft data, but every record dates from 2016.
- Israeli population registry for sale, but the data is oldA vendor is selling what they call Israel’s current 9.22M-record population registry. Our analysis of the 100k sample says the data is genuine, but every date in it stops in 2005.
- Żabka confirms breach via supplier account, data for saleŻabka has confirmed unauthorized access through an external provider’s account after a dataset was listed for €5,000. We reviewed the sample; the company has not confirmed its scale.
- 5socks.net: 20 years of proxy crime, 2004 to seizure5socks.net sold access to hacked residential IPs from 2004 until the FBI seized it in May 2025. Dancho Danchev traces the service back to its Russian origins.
- Deadlock: ransomware that hides its C2 on the blockchainDeadlock ransomware uses Polygon smart contracts for takedown-resistant command and control and a vulnerable driver to kill EDR. A profile of 2026’s most technically novel new group.
- Clover Health discloses social-engineering breach in 8-KClover Health disclosed in a July 17 SEC filing that three employee accounts were compromised via social engineering, risking protected health data.
- DragonForce: the cartel that absorbed its rivalsDragonForce rebranded as a ransomware cartel offering white-label infrastructure, absorbed RansomHub affiliates, and hit UK retail. A profile of its model, decline, and tactics.
- ShinyHunters’ Salesforce extortion wave hits Fluke, IngramShinyHunters listed Fluke (21M Salesforce records claimed) and Ingram Content on its leak site, extending a 2026 Salesforce extortion campaign now drawing class-action lawyers.
- LockBit 5.0: the comeback nobody wantedLockBit relaunched as version 5.0 in September 2025 and surged to 7% of June 2026 attacks. A profile of the disrupted brand’s resurgence, new encryptor, and affiliate model.
- Deutsche Bank breached via supplier as Unsafe gang leaks dataA ransomware group called Unsafe posted Deutsche Bank employee data samples from a third-party supplier. The bank confirms a supplier breach but denies any internal compromise.
- Scattered Spider duo jailed 5.5 years over £29M TfL hackTwo Scattered Spider members were jailed 5.5 years each on July 16 over the 2024 Transport for London hack, the UK’s first conviction under Computer Misuse Act Section 3ZA.
- World Leaks dumps 19,000 files tied to India nuclear plantWorld Leaks published 19,000 files (14.3GB) tied to India’s Kudankulam nuclear plant after Reliance Infrastructure refused to pay. The data leaked via a third-party server.
- Akira: the edge-VPN ransomware that never slowed downAkira has stayed a top-tier ransomware operation into 2026 by hammering SonicWall SSL-VPNs via CVE-2024-40766, deploying within an hour and using BYOVD to bypass EDR.
- Coca-Cola’s Fairlife halts US production after ransomwareCoca-Cola disclosed a ransomware attack on its Fairlife dairy subsidiary in a July 16 SEC filing, suspending all US production. No group has claimed it.
- Qilin: the RaaS that ran H1 2026 ransomwareQilin, formerly Agenda, was the most prolific ransomware-as-a-service of H1 2026 with 641 claimed victims, including the Asahi brewery attack.
- The week the West went after ransomware’s plumbingIn 48 hours the US, UK and EU indicted a bulletproof host and sanctioned VPN and cryptor sellers behind LockBit, Play and BlackSuit ransomware.
- Anubis ransomware is exploiting Citrix Bleed 2 for accessArctic Wolf says Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) and abusing legitimate RMM tools to breach networks, then deploying an irreversible data wiper.
- Kairos took $1M from a US government body and encrypted nothingA US government entity paid Kairos about $1 million to keep stolen files offline, a Ransom-ISAC case study shows. Kairos never encrypted a machine, it just threatened to publish.
- XSS forum: from DaMaGeLaB to the 2025 takedownInside XSS.is, the Russian cybercrime forum seized in 2025. A data-led profile from 123,241 leaked messages: what it traded, who ran it, its place in the ransomware kill chain, and a searchable country IoC table.























