FulcrumSec is a financially motivated cybercriminal group known for double extortion and sophisticated ransomware attacks.
Analyst brief
FulcrumSec is a financially motivated cybercriminal group specializing in data theft, extortion, and sophisticated ransomware attacks. They target the education and healthcare sectors in Singapore and Denmark, with confirmed victims like Novo Nordisk and Arup Group. Their TTPs involve double extortion, exploitation of hardcoded credentials and misconfigured cloud permissions, and long dwell times for in-depth data analysis. Defenders should prioritize anomalous behavior detection, strict access and permission audits, and monitoring for prolonged covert activity.
FulcrumSec
activeunknown
FulcrumSec is a financially motivated data-theft-extortion group known for sophisticated ransomware attacks and double extortion tactics. They have exploited vulnerabilities such as hardcoded credentials and misconfigured cloud permissions to gain access to targets, including Novo Nordisk and Arup Group. Their operations involve extensive dwell time, with claims of spending months analyzing stolen data before contacting victims. FulcrumSec has demonstrated a targeted approach, often demanding ransoms that are strategically calculated based on the victim's financial profile.