<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Extortion</title><description>Cybersecurity articles tagged #Extortion on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>RingCentral Data Breach Exposes 1.6M Users to ShinyHunters</title><link>https://runtimerebel.com/blog/ringcentral-data-breach-exposes-1-6m-users-to-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/ringcentral-data-breach-exposes-1-6m-users-to-shinyhunters</guid><description>RingCentral data breach impacts 1.6 million users after a sophisticated social engineering attack by ShinyHunters. Names, emails, addresses, and phone numbers exposed.</description><pubDate>Sat, 15 Aug 2026 16:14:41 GMT</pubDate><category>ShinyHunters</category><category>Data Breach</category><category>Social Engineering</category><category>Extortion</category><category>RingCentral</category></item><item><title>Ransom Cartel Ransomware Creator Sentenced to 16 Years in Prison</title><link>https://runtimerebel.com/blog/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison</guid><description>Maksim Silnikau, creator of the Ransom Cartel ransomware operation, receives a 16-year prison sentence following international law enforcement cooperation.</description><pubDate>Thu, 06 Aug 2026 01:56:23 GMT</pubDate><category>Ransom Cartel</category><category>Ransomware</category><category>REvil</category><category>Credential Theft</category><category>Extortion</category></item><item><title>ShinyHunters Breaches Brinks Home, Threatens Data Leak</title><link>https://runtimerebel.com/blog/shinyhunters-breaches-brinks-home-threatens-data-leak</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-breaches-brinks-home-threatens-data-leak</guid><description>ShinyHunters claims a breach of Brinks Home systems, threatening to leak stolen data. This analysis covers the threat actor, potential impact, and mitigation.</description><pubDate>Thu, 30 Jul 2026 17:31:04 GMT</pubDate><category>ShinyHunters</category><category>Brinks Home</category><category>Data Breach</category><category>Data Leak</category><category>Extortion</category><category>Cybercrime</category></item><item><title>Abbott Labs Probes Dual Cyber Incidents, Data Theft, Extortion</title><link>https://runtimerebel.com/blog/abbott-labs-probes-dual-cyber-incidents-data-theft-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/abbott-labs-probes-dual-cyber-incidents-data-theft-extortion</guid><description>Abbott Laboratories confirms unauthorized access to Exact Sciences systems and investigates alleged LabCentral breach amid extortion. Learn about the dual threat.</description><pubDate>Fri, 17 Jul 2026 20:58:16 GMT</pubDate><category>Abbott Laboratories</category><category>Exact Sciences</category><category>LabCentral</category><category>Data Breach</category><category>Extortion</category><category>Cyber Incident</category><category>Healthcare Security</category></item><item><title>Kairos Group Extorts $1M from US Government in Data-Theft Campaign</title><link>https://runtimerebel.com/blog/kairos-group-extorts-1m-from-us-government-in-data-theft-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/kairos-group-extorts-1m-from-us-government-in-data-theft-campaign</guid><description>A US government entity paid $1M to the Kairos group to prevent a data leak, signaling a shift from traditional ransomware to pure data-theft extortion.</description><pubDate>Sat, 04 Jul 2026 17:08:22 GMT</pubDate><category>Kairos</category><category>Data Theft</category><category>Extortion</category><category>US Government</category><category>Ransom ISAC</category></item><item><title>Oracle PeopleSoft RCE via CVE-2026-35273 — Mitigation Guide</title><link>https://runtimerebel.com/blog/oracle-peoplesoft-rce-via-cve-2026-35273-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/oracle-peoplesoft-rce-via-cve-2026-35273-mitigation-guide</guid><description>ShinyHunters (UNC6240) exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) to breach university networks and exfiltrate data for extortion purposes.</description><pubDate>Thu, 11 Jun 2026 20:55:48 GMT</pubDate><category>CVE-2026-35273</category><category>ShinyHunters</category><category>Oracle PeopleSoft</category><category>UNC6240</category><category>Extortion</category></item><item><title>Silent Ransom Group Targets US Law Firms via Vishing and Intrusions</title><link>https://runtimerebel.com/blog/silent-ransom-group-targets-us-law-firms-via-vishing-and-intrusions</link><guid isPermaLink="true">https://runtimerebel.com/blog/silent-ransom-group-targets-us-law-firms-via-vishing-and-intrusions</guid><description>Silent Ransom Group (Luna Moth) targets US law firms using vishing and physical intrusions for data extortion. Technical analysis and mitigation strategies.</description><pubDate>Tue, 09 Jun 2026 05:28:46 GMT</pubDate><category>Silent Ransom Group</category><category>Luna Moth</category><category>Vishing</category><category>Law Firms</category><category>Extortion</category><category>Social Engineering</category></item><item><title>UNC3753 Targets US Law Firms with Vishing &amp; Physical Intrusions</title><link>https://runtimerebel.com/blog/unc3753-targets-us-law-firms-with-vishing-physical-intrusions</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc3753-targets-us-law-firms-with-vishing-physical-intrusions</guid><description>UNC3753 (Luna Moth) leverages vishing and physical office intrusions to steal sensitive data from US law firms and professional services, leading to swift extortion.</description><pubDate>Fri, 05 Jun 2026 16:59:08 GMT</pubDate><category>UNC3753</category><category>Luna Moth</category><category>Silent Ransom Group</category><category>Vishing</category><category>Social Engineering</category><category>Data Theft</category><category>Extortion</category><category>Law Firms</category><category>Physical Intrusion</category><category>RMM</category><category>WinSCP</category><category>Rclone</category></item><item><title>ShinyHunters Leak 234 GB of DentaQuest Data Impacting 2.6 Million</title><link>https://runtimerebel.com/blog/shinyhunters-leak-234-gb-of-dentaquest-data-impacting-2-6-million</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-leak-234-gb-of-dentaquest-data-impacting-2-6-million</guid><description>The ShinyHunters extortion group leaked 234 GB of data from DentaQuest, impacting 2.6 million individuals. Learn about the risks and how to protect PHI.</description><pubDate>Fri, 05 Jun 2026 13:14:00 GMT</pubDate><category>ShinyHunters</category><category>DentaQuest</category><category>Data Leak</category><category>Extortion</category><category>Healthcare Security</category></item><item><title>Charter Communications Data Breach: Millions of Records Exposed</title><link>https://runtimerebel.com/blog/charter-communications-data-breach-millions-of-records-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/charter-communications-data-breach-millions-of-records-exposed</guid><description>ShinyHunters leaked data allegedly from Charter Communications, potentially exposing nearly 5 million customer records. Organizations must assess third-party risk.</description><pubDate>Fri, 29 May 2026 17:20:56 GMT</pubDate><category>ShinyHunters</category><category>Charter Communications</category><category>Data Breach</category><category>Extortion</category><category>Data Leak</category></item><item><title>The Com: Analyzing the Intersection of Cybercrime and Physical Violence</title><link>https://runtimerebel.com/blog/the-com-analyzing-the-intersection-of-cybercrime-and-physical-violence</link><guid isPermaLink="true">https://runtimerebel.com/blog/the-com-analyzing-the-intersection-of-cybercrime-and-physical-violence</guid><description>Analysis of The Com, a criminal ecosystem using social engineering and SIM swapping to fund violent activities, sextortion, and neo-Nazi accelerationism.</description><pubDate>Fri, 29 May 2026 13:20:49 GMT</pubDate><category>The Com</category><category>Social Engineering</category><category>Scattered Spider</category><category>Extortion</category><category>Physical Security</category></item><item><title>Silent Ransom Group Targets Law Firms via Physical Social Engineering</title><link>https://runtimerebel.com/blog/silent-ransom-group-targets-law-firms-via-physical-social-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/silent-ransom-group-targets-law-firms-via-physical-social-engineering</guid><description>FBI warns of Silent Ransom Group (Luna Moth) targeting law firms using physical social engineering and data theft for extortion. Learn how to defend.</description><pubDate>Thu, 28 May 2026 05:30:39 GMT</pubDate><category>Silent Ransom Group</category><category>Luna Moth</category><category>Law Firm Security</category><category>Social Engineering</category><category>Extortion</category></item><item><title>Charter Data Breach Confirmed: ShinyHunters Extortion Threat</title><link>https://runtimerebel.com/blog/charter-data-breach-confirmed-shinyhunters-extortion-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/charter-data-breach-confirmed-shinyhunters-extortion-threat</guid><description>Charter Communications confirms a data breach following an extortion threat by ShinyHunters.</description><pubDate>Tue, 26 May 2026 20:46:11 GMT</pubDate><category>Charter Communications</category><category>ShinyHunters</category><category>Data Breach</category><category>Extortion</category><category>Telecommunications</category><category>Third Party Risk</category></item><item><title>Grafana GitHub Token Leak: Codebase Access and Extortion Attempt</title><link>https://runtimerebel.com/blog/grafana-github-token-leak-codebase-access-and-extortion-attempt</link><guid isPermaLink="true">https://runtimerebel.com/blog/grafana-github-token-leak-codebase-access-and-extortion-attempt</guid><description>Grafana discloses a security incident where an unauthorized party used a GitHub token to download source code, leading to a failed extortion attempt.</description><pubDate>Sun, 17 May 2026 08:48:24 GMT</pubDate><category>Grafana</category><category>GitHub</category><category>Token Leak</category><category>Codebase Theft</category><category>Extortion</category></item><item><title>BlackFile: Analyzing UNC6671 Vishing &amp; Cloud Data Extortion</title><link>https://runtimerebel.com/blog/blackfile-analyzing-unc6671-vishing-cloud-data-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/blackfile-analyzing-unc6671-vishing-cloud-data-extortion</guid><description>Examines UNC6671&apos;s BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 &amp; Okta. Actionable mitigations included.</description><pubDate>Fri, 15 May 2026 20:32:33 GMT</pubDate><category>UNC6671</category><category>BlackFile</category><category>Vishing</category><category>AitM</category><category>Microsoft 365</category><category>Okta</category><category>SharePoint</category><category>OneDrive</category><category>Data Exfiltration</category><category>Extortion</category><category>Social Engineering</category></item><item><title>ShinyHunters Defaces Canvas Login Portals in Extortion Campaign</title><link>https://runtimerebel.com/blog/shinyhunters-defaces-canvas-login-portals-in-extortion-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/shinyhunters-defaces-canvas-login-portals-in-extortion-campaign</guid><description>ShinyHunters breached Instructure, defacing Canvas login portals for numerous educational institutions, potentially impacting user credentials and initiating extortion.</description><pubDate>Fri, 08 May 2026 00:50:31 GMT</pubDate><category>ShinyHunters</category><category>Instructure</category><category>Canvas LMS</category><category>Extortion</category><category>Education Sector</category><category>Defacement</category><category>Credential Theft</category></item><item><title>Instructure Data Breach: Student IDs and Private Messages Exposed</title><link>https://runtimerebel.com/blog/instructure-data-breach-student-ids-and-private-messages-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/instructure-data-breach-student-ids-and-private-messages-exposed</guid><description>Edtech leader Instructure discloses a data breach involving student IDs and user messages after hackers disrupted services and threatened data leaks.</description><pubDate>Mon, 04 May 2026 08:56:48 GMT</pubDate><category>Instructure</category><category>Canvas LMS</category><category>EdTech</category><category>PII Leak</category><category>Extortion</category></item><item><title>Instructure Data Breach: ShinyHunters Claims Theft of Employee Data</title><link>https://runtimerebel.com/blog/instructure-data-breach-shinyhunters-claims-theft-of-employee-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/instructure-data-breach-shinyhunters-claims-theft-of-employee-data</guid><description>Educational technology giant Instructure confirms an internal data breach after the ShinyHunters threat group claims to have stolen sensitive corporate data.</description><pubDate>Mon, 04 May 2026 00:50:54 GMT</pubDate><category>Instructure</category><category>ShinyHunters</category><category>Canvas LMS</category><category>Data Breach</category><category>Extortion</category></item><item><title>Checkmarx Data Leak: LAPSUS$ Group Targets GitHub Repositories</title><link>https://runtimerebel.com/blog/checkmarx-data-leak-lapsus-group-targets-github-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-data-leak-lapsus-group-targets-github-repositories</guid><description>LAPSUS$ threat actors leaked source code stolen from Checkmarx&apos;s private GitHub repositories. Analyze the impact of this supply chain security incident.</description><pubDate>Tue, 28 Apr 2026 16:42:35 GMT</pubDate><category>Lapsus Group</category><category>Checkmarx</category><category>Github Leak</category><category>Source Code Theft</category><category>Extortion</category></item><item><title>ADT Confirms Data Breach Amid ShinyHunters Extortion Threat</title><link>https://runtimerebel.com/blog/adt-confirms-data-breach-amid-shinyhunters-extortion-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/adt-confirms-data-breach-amid-shinyhunters-extortion-threat</guid><description>ADT confirms a data breach following a ShinyHunters extortion attempt. Customer data is at risk; security professionals must advise enhanced vigilance.</description><pubDate>Sat, 25 Apr 2026 00:43:18 GMT</pubDate><category>ADT</category><category>ShinyHunters</category><category>Data Breach</category><category>Extortion</category><category>Cybercrime</category><category>Threat Intelligence</category></item><item><title>Angelo Martino Pleads Guilty to Aiding BlackCat Ransomware Attacks</title><link>https://runtimerebel.com/blog/angelo-martino-pleads-guilty-to-aiding-blackcat-ransomware-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/angelo-martino-pleads-guilty-to-aiding-blackcat-ransomware-attacks</guid><description>Angelo Martino pleaded guilty to collaborating with BlackCat (ALPHV) ransomware operators, facilitating credential-based breaches and high-stakes negotiations.</description><pubDate>Tue, 21 Apr 2026 16:30:02 GMT</pubDate><category>BlackCat</category><category>ALPHV</category><category>Ransomware as a Service</category><category>Extortion</category><category>Credential Theft</category></item><item><title>Kraken Extorted by Hackers Following Insider Account Breach</title><link>https://runtimerebel.com/blog/kraken-extorted-by-hackers-following-insider-account-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/kraken-extorted-by-hackers-following-insider-account-breach</guid><description>Kraken faces extortion after a social engineering attack on a support agent led to unauthorized internal system access and threatened customer data exposure.</description><pubDate>Wed, 15 Apr 2026 00:45:28 GMT</pubDate><category>Kraken</category><category>Insider Threat</category><category>Extortion</category><category>Social Engineering</category><category>Crypto Security</category></item><item><title>Hims Data Breach Exposes Patient PHI — Technical Impact Analysis</title><link>https://runtimerebel.com/blog/hims-data-breach-exposes-patient-phi-technical-impact-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/hims-data-breach-exposes-patient-phi-technical-impact-analysis</guid><description>Analysis of the Hims &amp; Hers Health data breach exposing sensitive PHI. Learn how threat actors use health data for targeted extortion and phishing campaigns.</description><pubDate>Sat, 11 Apr 2026 00:38:27 GMT</pubDate><category>Hims Hers Health</category><category>Phi Exposure</category><category>Telehealth Security</category><category>Data Exfiltration</category><category>Extortion</category></item><item><title>Wynn Resorts Breach: 21,000 Employees Impacted by ShinyHunters</title><link>https://runtimerebel.com/blog/wynn-resorts-breach-21000-employees-impacted-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/wynn-resorts-breach-21000-employees-impacted-by-shinyhunters</guid><description>Casino operator Wynn Resorts confirms a data breach affecting 21,000 employees following an extortion attempt by the ShinyHunters threat group.</description><pubDate>Tue, 07 Apr 2026 08:34:56 GMT</pubDate><category>Wynn Resorts</category><category>ShinyHunters</category><category>Employee Data</category><category>PII Exposure</category><category>Extortion</category></item><item><title>Insider Threat: Former Engineer Locks 254 Windows Servers in Extortion</title><link>https://runtimerebel.com/blog/insider-threat-former-engineer-locks-254-windows-servers-in-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/insider-threat-former-engineer-locks-254-windows-servers-in-extortion</guid><description>A former infrastructure engineer pleaded guilty to a $750,000 extortion plot after locking administrators out of 254 Windows servers and deleting backups.</description><pubDate>Fri, 03 Apr 2026 12:22:29 GMT</pubDate><category>Insider Threat</category><category>Windows Server</category><category>Extortion</category><category>Identity Management</category><category>Incident Response</category></item><item><title>Lapsus$ Claims AstraZeneca Breach: Sensitive Code and Data at Risk</title><link>https://runtimerebel.com/blog/lapsus-claims-astrazeneca-breach-sensitive-code-and-data-at-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/lapsus-claims-astrazeneca-breach-sensitive-code-and-data-at-risk</guid><description>The Lapsus$ extortion group claims to have compromised AstraZeneca internal code repositories, employee credentials, and sensitive personnel data.</description><pubDate>Tue, 24 Mar 2026 16:29:45 GMT</pubDate><category>Lapsus</category><category>AstraZeneca</category><category>Extortion</category><category>Data Breach</category><category>Source Code Leak</category></item><item><title>INC Ransomware Oceania: Healthcare and Government Sectors Under Siege</title><link>https://runtimerebel.com/blog/inc-ransomware-oceania-healthcare-and-government-sectors-under-siege</link><guid isPermaLink="true">https://runtimerebel.com/blog/inc-ransomware-oceania-healthcare-and-government-sectors-under-siege</guid><description>INC Ransomware has launched a series of attacks against healthcare and government agencies in Oceania, using double extortion to compromise sensitive data.</description><pubDate>Thu, 12 Mar 2026 00:30:05 GMT</pubDate><category>INC Ransomware</category><category>Oceania</category><category>Healthcare Security</category><category>Australia</category><category>New Zealand</category><category>Extortion</category></item><item><title>Alabama Man Pleads Guilty to Extortion via Social Media Hijacking</title><link>https://runtimerebel.com/blog/alabama-man-pleads-guilty-to-extortion-via-social-media-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/alabama-man-pleads-guilty-to-extortion-via-social-media-hijacking</guid><description>Devin Deandre Moore admits to hijacking hundreds of accounts for sextortion. Analysis of the TTPs used in this large-scale digital extortion campaign.</description><pubDate>Mon, 02 Mar 2026 20:13:38 GMT</pubDate><category>Social Media Hacking</category><category>Extortion</category><category>Cyberstalking</category><category>Phishing</category><category>Identity Theft</category></item><item><title>Olympique Marseille Confirms Data Leak Following Heller Cyberattack</title><link>https://runtimerebel.com/blog/olympique-marseille-confirms-data-leak-following-heller-cyberattack</link><guid isPermaLink="true">https://runtimerebel.com/blog/olympique-marseille-confirms-data-leak-following-heller-cyberattack</guid><description>French football club Olympique de Marseille investigates a data breach after the Heller extortion group leaked 3.5 GB of sensitive player and staff records.</description><pubDate>Thu, 26 Feb 2026 16:24:27 GMT</pubDate><category>Olympique De Marseille</category><category>Heller Group</category><category>Data Leak</category><category>Sports Industry</category><category>Extortion</category><category>France</category></item><item><title>Wynn Resorts Data Breach: ShinyHunters Exfiltrates Employee PII</title><link>https://runtimerebel.com/blog/wynn-resorts-data-breach-shinyhunters-exfiltrates-employee-pii</link><guid isPermaLink="true">https://runtimerebel.com/blog/wynn-resorts-data-breach-shinyhunters-exfiltrates-employee-pii</guid><description>Wynn Resorts confirms a data breach impacting employee PII, attributed to the ShinyHunters extortion gang. Analysis covers TTPs and mitigation strategies.</description><pubDate>Wed, 25 Feb 2026 04:42:06 GMT</pubDate><category>Wynn Resorts</category><category>ShinyHunters</category><category>Data Breach</category><category>Employee Data</category><category>Extortion</category><category>PII</category></item></channel></rss>