Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors fulcrumsec

Description

FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis. Known victims: 21

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

FulcrumSec is a medium-sophistication cybercrime group specializing in data extortion through rapid cloud database exfiltration via unrotated API keys and misconfigured permissions. Active since September 2025, they have targeted over 21 organizations across multiple sectors, including fintech, healthcare, and AI, without encrypting stolen data. Their operations have raised concerns due to their efficient attack methods and focus on financial gain.

Goals & Targeting

FulcrumSec's strategic objectives center around maximizing financial gain through the rapid exfiltration and sale of sensitive data. Their targeting profile focuses on sectors with abundant digital assets stored in cloud environments, particularly those with weaker security postures, such as misconfigured APIs and unmanaged access keys. The group selects victims based on their susceptibility to such exploits rather than specific industries or geographies, but financial and healthcare sectors have been heavily targeted due to the high value of their data.

Enhanced Description

FulcrumSec operates as a cybercriminal organization primarily engaged in data extortion activities. Since their emergence around September 2025, the group has demonstrated a unique approach by exploiting vulnerabilities such as unrotated API keys and misconfigured cloud permissions. This targeting strategy allows them to rapidly exfiltrate sensitive information from cloud-hosted databases without deploying encryption, which is uncommon among ransomware groups but still lucrative for their operations. Their victims include high-profile organizations like youX, LexisNexis, Avnet, and Novo Nordisk, indicating a broad attack surface across various industries. FulcrumSec's primary motivation is financial gain, aligning with their criminal nature. The group has been particularly active in 2026, with their latest activity recorded on June 16, 2026 They have positioned themselves as a significant threat to organizations relying heavily on cloud services, exploiting configuration weaknesses rather than conducting more complex attacks.

Key Capabilities

  • High-speed cloud database exfiltration via API key exploitation
  • Exploitation of misconfigured cloud permissions
  • Data extortion without encryption deployment
  • Efficient attack lifecycle for rapid victim identification and data theft

MITRE ATT&CK Tactics

Credential Access
Data Exfiltration
Lateral Movement
Discovery

ATT&CK Techniques

T1078.005 - OS Credential Dumping: Cloud API Keys
T1603.001 - Exploit Public-Facing Misconfigurations
T1091 - Data Exfiltration Using DNS
T1021.004 - Internal Spear Phishing

Software / Tooling

Custom cloud configuration exploitation tools
API key management utilities
Network monitoring and data transfer scripts

Campaigns & Victims

FulcrumSec has launched multiple campaigns targeting over two dozen organizations, including fintech, healthcare, AI startups, and education sectors. Their operational tempo suggests a focus on quick hits with minimal dwell time, exploiting easy-to-reach vulnerabilities. Campaign patterns indicate a preference for smaller to medium-sized enterprises with significant cloud assets but weaker security controls.

IOC Patterns

  • Exploitation of unrotated API keys in cloud environments
  • Misconfigured cloud permissions leading to unauthorized access
  • High volume data transfers from cloud infrastructure without encryption

Recommended Actions

  • Implement strict rotation policies for API keys and service accounts
  • Conduct regular audits of cloud permissions and configurations
  • Migrate sensitive assets to secure, private locations with least privilege applied
  • Monitor for unusual network activity indicative of data exfiltration
  • Leverage automated tools to detect misconfigurations in cloud services
  • Enhance incident response plans focusing on rapid detection of unauthorized access

Suggested Tags

Crime
Data Extortion
Ransomware
Cloud Security
Financial Crime

Confidence Assessment

High confidence in the group's existence and data extortion methods based on victim reports and attack patterns. However, specific technical details about their tools and exact TTPs remain unclear due to limited public reporting.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

25

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Crime
Data Extortion
Ransomware
Cloud Security
Financial Crime

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 1, 2026
Last Seen
Jun 16, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.