FulcrumSec

Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:30:07

Targeted industries: healthcare-and-pharmaceutical professional-services manufacturing

Context

FulcrumSec is a financially motivated data-theft-extortion group known for sophisticated ransomware attacks and double extortion tactics. They have exploited vulnerabilities such as hardcoded credentials and misconfigured cloud permissions to gain access to targets, including Novo Nordisk and Arup Group. Their operations involve extensive dwell time, with claims of spending months analyzing stolen data before contacting victims. FulcrumSec has demonstrated a targeted approach, often demanding ransoms that are strategically calculated based on the victim's financial profile.

Reports & references

  • resecurity.com — Cybercriminals Are Targeting Edtech Data Breaches And Ransomware Attacks On The Rise (report)
  • blog.bushidotoken.net — Uk Cybercrime Journal Arup Group (report)
  • techrepublic.com — News Novo Nordisk 1 3Tb Theft 25M Demand Emea (report)

External references