N4ughtysecTU
In March 2022, a hacking group calling themselves N4ughtySecTU claimed to have breached TransUnion’s systems and threatened to leak four terabytes of data if the credit bureau didn’t pay a $15-million (R242-million) ransom.
N4ughtysecTU is a threat actor known for targeting financial sector entities with data theft and extortion since 2022.
N4ughtysecTU is a threat actor of unknown type that emerged in March 2022, claiming a breach against TransUnion and threatening a data leak with a ransom demand. The group targets critical entities in the financial sector, specifically credit bureaus handling sensitive data. Their primary TTPs involve data theft, extortion, and ransomware-style threats, though specific tools are undisclosed. Defenders should focus on monitoring data leak extortion groups, securing backups, and strengthening phishing defenses against ransom-themed emails targeting financial institutions.
In March 2022, a hacking group calling themselves N4ughtySecTU claimed to have breached TransUnion’s systems and threatened to leak four terabytes of data if the credit bureau didn’t pay a $15-million (R242-million) ransom.
N4ughtysecTU targets the financial sector, specifically credit bureaus.
In the claimed incident against TransUnion in March 2022, N4ughtysecTU threatened to leak 4 TB of data.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.