Also known as: Valancia, Valencia
ValenciaLeaks is a data-extortion group that surfaced in August–September 2024, focused on exfiltrating large volumes of data and publishing it on a dedicated leak site, with documented victims including the City of Pleasanton, CA (283 GB exfiltrated) and pharmaceutical firm Duo Pharma Biotech. Known victims: 5
Objectives
Executive Summary
ValenciaLeaks, also known as Valancia or Valencia, is a medium-sophisticated criminal threat actor specializing in data extortion and ransomware attacks. Emerging in August–September 2024, the group has targeted industries such as local government and pharmaceuticals, exfiltrating large volumes of sensitive data to publish on a dedicated leak site. With notable victims including the City of Pleasanton, CA (283 GB stolen) and Duo Pharma Biotech, ValenciaLeaks poses an increasing threat to organizations seeking financial gain through ransom demands.
Goals & Targeting
ValenciaLeaks appears to target sectors where sensitive data has high commercial or reputational value. Their primary focus is on exfiltrating large volumes of data from governments, healthcare organizations, and corporate entities. The group's choice of victims reflects a strategic interest in industries that are likely to pay ransoms due to the sensitive nature of their data or the potential for reputational damage if leaked publicly. ValenciaLeaks' targeting profile suggests an emphasis on North American and European organizations, though their geographic scope may expand as they gain more resources and sophistication.
Enhanced Description
ValenciaLeaks is a relatively new but rapidly evolving cybercriminal group that has gained notoriety for its data extortion campaigns. The group primarily operates in the darknet, leveraging sophisticated techniques to infiltrate target networks, steal sensitive information, and extort payment in exchange for data integrity. ValenciaLeaks first appeared on threat intelligence radar in August–September 2024, with its initial campaign targeting municipalities and healthcare organizations. Their modus operandi involves large-scale data theft using a combination of phishing, social engineering, and credential harvesting to breach their targets' systems. Once inside, the group deploys custom or modified tools to exfiltrate massive amounts of data, which they subsequently leak on dedicated websites. The group's victims have included the City of Pleasanton, CA (283 GB stolen) and pharmaceutical firm Duo Pharma Biotech, indicating a preference for high-profile targets with significant data assets.
Key Capabilities
MITRE ATT&CK Tactics
Campaigns & Victims
ValenciaLeaks has demonstrated a rapid operational tempo, with its first campaigns unfolding quickly in late 2024. The group's victims so far include local government and pharmaceutical sectors, indicating a preference for industries with significant data assets that are more likely to comply with their demands. Notable operations include the extraction of 283 GB from the City of Pleasanton, CA, and an attack on Duo Pharma Biotech. While the group's campaign patterns are still emerging, they appear to focus on breaching targets within a relatively short timeframe (weeks) before initiating exfiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in ValenciaLeaks' precise toolset and TTPs beyond data exfiltration and phishing. Further sightings and analysis are required to fully characterize the group's capabilities and campaign patterns.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics