Lamashtu
- First seen
- 2026-04-15 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:26:55
Targeted industries: energy-and-utilities healthcare-and-pharmaceutical retail-and-hospitality media-and-entertainment
Targeted regions: country_code:fr country_code:ro country_code:th country_code:my country_code:eg country_code:ae
Context
Lamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with countdown timers, structured Breach Impact Reports, and proof-of-life thumbnails to pressure victims. The group has claimed 17+ victims across France, Romania, Thailand, Malaysia, Egypt, and the UAE within its first weeks of activity, targeting energy, pharmaceutical, retail, hospitality, and film sectors, with confirmed exfiltration totaling 760+ GB.
Reports & references
- redpiranha.net — Threat Intelligence Report April 21 April 27 2026 (report)