Lamashtu is a financially motivated data-theft group targeting agriculture and food production sectors.
Analyst brief
Lamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026. It targets the agriculture and food production sectors in Egypt and Thailand, alongside a broader victim profile across multiple regions. Key TTPs include operating a Tor-hosted leak site (Lamashtu[.]Blog) with countdown timers, structured Breach Impact Reports, and proof-of-life thumbnails to pressure victims. Defenders should monitor for data exfiltration indicators, patch vulnerabilities particularly in third-party agricultural supply chains, and prepare for potential large-scale data leaks exceeding 760 GB of confirmed exfiltration.
Lamashtu
activeunknown
Lamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with countdown timers, structured Breach Impact Reports, and proof-of-life thumbnails to pressure victims. The group has claimed 17+ victims across France, Romania, Thailand, Malaysia, Egypt, and the UAE within its first weeks of activity, targeting energy, pharmaceutical, retail, hospitality, and film sectors, with confirmed exfiltration totaling 760+ GB.
The Lamashtu group targets the agriculture and food production sectors in Egypt and Thailand, but maintains a broader victim profile including energy, pharmaceutical, retail, hospitality, and film sectors.
What TTPs does Lamashtu use to pressure victims?+
Lamashtu pressures victims through its Tor-hosted leak site (Lamashtu[.]Blog) by presenting countdown timers, structured Breach Impact Reports, and proof-of-life thumbnails of exfiltrated data.