Ransomware group
Fulcrumsec ransomware: victims and leak site activity
The Fulcrumsec ransomware group has listed 26 victims on its leak site since May 2026; its latest post is from 1 September 2026. Most affected countries: United States, United Kingdom and India. Most targeted sector: Technology.
Total posts
26
First seen
2026-05-01
Latest post
2026-09-01
Countries hit
11
About Fulcrumsec
FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis.
Most targeted countries
- United States 13
- United Kingdom 3
- India 2
- Australia 1
- Colombia 1
- Germany 1
- Denmark 1
- Japan 1
- Mexico 1
- Netherlands 1
Most targeted sectors
- Technology 7
- Professional Services 6
- Healthcare 3
- Retail & E-Commerce 3
- Financial Services 2
- Education 1
- Manufacturing 1
- Transportation 1