CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2664

As cited

Copy frozen at (site build).

ransomware

Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations

Ransomware operators are leveraging AI not primarily to conduct breaches but to strengthen negotiation tactics with victims to demand higher ransoms. FulcrumSec, a data extortion group active since September 2025, exploits basic security gaps such as hardcoded credentials, unpatched software, and misconfigured storage to breach organizations, claiming over 25 victims and multiple terabytes of stolen data.

Why it matters: Organizations face dual pressure from both initial compromise through elementary security failures and elevated ransom demands amplified by AI-driven negotiation techniques, requiring immediate remediation of exposed credentials and misconfigurations alongside incident response readiness.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations

FulcrumSec, a data extortion group active since September 2025, exploits hardcoded credentials, unpatched applications, and misconfigured storage to breach organizations and steal data. Rather than using artificial intelligence (AI) for initial compromise, the group leverages AI during ransom negotiations to generate pressure on victims for higher payouts. The group reports breaching 25 organizations and exfiltrating several terabytes of data.

Why it matters: Organizations targeted by extortion groups face increased ransom demands when attackers use AI-generated leverage in negotiations; practitioners should prioritize eliminating hardcoded credentials, patching vulnerable applications, and auditing storage configurations to prevent the initial access vectors this group exploits.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary