Ransomware group

Fulcrumsec ransomware: victims and leak site activity

The Fulcrumsec ransomware group has listed 26 victims on its leak site since May 2026; its latest post is from 1 September 2026. Most affected countries: United States, United Kingdom and India. Most targeted sector: Technology.

Total posts 26
First seen 2026-05-01
Latest post 2026-09-01
Countries hit 11

About Fulcrumsec

FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis.

Leak site (Tor)
http://4e3p3in2bl67hxchuwza7qvnpe7pyeloyztr5fnh257fxkovfhappjyd.onion

Fulcrumsec victims per year

26 2026

All 26 victims

Search every post in the full table.
Victim Country Sector Discovered
Manchester Airports Group United Kingdom Transportation
Novo Nordisk Denmark Healthcare
Global Schools Foundation Singapore Education
Arup Group United Kingdom Professional Services
Stuf Storage United States Retail & E-Commerce
Avnet United States Technology
Lena Health United States Healthcare
Woundtech United States Healthcare
youX / Drive IQ Australia Technology
LexisNexis United States Professional Services
MCO United States Financial Services
ReFocus AI United States Technology
Hatica United States Technology
Analog Gold / Prospector United States Other
Nordstern Technologies Mexico Technology
ParkEngage United States Retail & E-Commerce
Saleskido India Professional Services
Interzero Germany Professional Services
IMEVI Colombia Professional Services
Raptor Supplies Netherlands Retail & E-Commerce
Rotary Club United States Professional Services
JOT Japan Other
BookBlock United Kingdom Technology
Crank Communications United States Technology
CrediElite United States Financial Services
Fashinza India Manufacturing