~/f4n6 $ grep -r "Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations" ./investigations/ --include="*.md"

Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations

Jeff Davies 16 Jul 2026 7 min read

1. Executive summary

A GuidePoint Security report details how data-extortion groups — principally FulcrumSec (active since ~September 2025) and DragonForce (active since 2023) — are using LLMs not for intrusion but to analyse stolen data and manufacture psychological leverage during ransom negotiations. FulcrumSec claims 25 victims and several terabytes exfiltrated using low-complexity techniques (hardcoded/exposed credentials, unpatched applications, misconfigured storage), with AI used post-exfiltration to produce detailed data inventories and formatted breach reports distributed to journalists. Attribution to both named actors is unconfirmed: neither FulcrumSec nor DragonForce has a MITRE ATT&CK profile in the verified reference data. The bottom-line risk for EMEA financial services is that standard data-loss extortion is being amplified by AI-driven data analysis, increasing the credibility and pressure of ransom demands even when the initial intrusion technique is unsophisticated.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 18: classification of ICT-related incidents and cyber threats AI-amplified extortion changes the severity classification calculus: the impact is not just data volume but the actor's demonstrated ability to analyse and weaponise stolen IP and regulatory exposure. Financial entities must account for negotiation-leverage factors (not just data volume) when classifying incident severity under their ICT incident management process.
DORA Art. 19: reporting of major ICT-related incidents to competent authorities FulcrumSec's explicit strategy of framing breaches to attract class-action lawsuits — coupled with claims of detailed knowledge of victim security posture — creates heightened legal and reputational exposure that may cross the major-incident threshold. Incident response teams should assess whether AI-amplified extortion narratives constitute a reportable major incident earlier in the lifecycle, not only upon confirmation of data exfiltration.

3. Technical analysis & attack chain

Attribution caveat: FulcrumSec and DragonForce are named in the source material and the GuidePoint Security report. Neither actor has a MITRE ATT&CK profile in the verified reference data. Attribution is unconfirmed; treat both names as designations from a single vendor report (GuidePoint Security) corroborated by the Risky Business newsletter.

FulcrumSec attack chain

  1. Initial access — FulcrumSec gains entry using low-complexity techniques: hardcoded or exposed credentials, unpatched applications, or misconfigured storage. No zero-days or sophisticated exploit chains are described. The group does not require AI for the intrusion phase.
  2. Data exfiltration — The group claims to have stolen several terabytes of data across 25 organisations. In the Novo Nordisk compromise (June 2026), FulcrumSec claimed 1.3TB comprising 700,717 files, including five undisclosed drug programs, in-development drug and RNA delivery programs, and private AI models for medical/drug discovery purposes.
  3. AI-assisted data analysis — Post-exfiltration, FulcrumSec uses a "team of AI agents" to analyse stolen data. In the Novo Nordisk case, the group used AI to analyse stolen private AI models and assess the competitive value of the exfiltrated IP, claiming it could save competitors three to five years of program development. This analysis directly informed the initial ransom demand of USD $25 million.
  4. AI-assisted report generation — FulcrumSec uses AI to produce formatted breach reports (complete with logo, file listings, file-content breakdowns, and images of files) distributed to threat researchers and journalists (e.g., vx-underground) to apply public pressure. After the Avnet compromise (October 2025), the group provided vx-underground with "an autobiography, a breakdown of the data they possess, their motives for the compromise, information on their logo design, a complete file listing from the compromise, a breakdown of the files, and images of the files."
  5. Cost-shifting to victim — FulcrumSec claimed it used an OpenAI API key stolen from the victim to pay for ChatGPT to summarise the victim's own data, meaning the victim's own infrastructure funded the analysis used against them.
  6. Negotiation pressure — FulcrumSec couples stolen-data inventories with assessments of the victim's security posture. In the Novo Nordisk case, the group described the victim's security as "absolutely catastrophic" and "boggles the mind" — framing designed to imply regulatory and legal exposure and attract class-action litigation.

DragonForce attack chain (negotiation phase only)

  1. LLM-driven psychological pressure — GuidePoint Security assesses that DragonForce uses LLMs to "manufacture plausible [psychological] pressure" during negotiations.
  2. False legal-counsel claims — DragonForce claims to have legal counsel on staff, implying it has insight into the victim's reporting requirements and legal exposure from a data leak. GuidePoint assesses this as a negotiation tactic to increase perceived consequences of non-payment.

Separate AI-driven intrusion campaigns referenced

  • INC and Lynx ransomware groups — linked to the so-called "FortiBleed" campaign, described as an AI-driven hacking operation using credential harvesting to feed data extortion campaigns. Neither INC nor Lynx has a MITRE ATT&CK profile in the verified reference data; attribution is unconfirmed.
  • JADEPUFFER (Sysdig report) — described as "agentic ransomware: a complete extortion operation driven end-to-end by an LLM." The malware encrypted files but did not store or send encryption keys, making recovery impossible. Its ransom note used the example Bitcoin address from Bitcoin documentation and an email address not appearing in threat intelligence databases or victim forums, suggesting it has never been used. This is assessed as immature/low-impact.

Industry context: The source notes that data extortion is becoming the preferred business model over encryption-based ransomware because it is quieter and easier to execute, while improved backup strategies reduce encryption leverage. However, data extortion payment rates are falling. The INC/Lynx strategy is to use AI to hack more frequently to compensate; FulcrumSec's strategy is to maximise per-victim profit through AI-amplified negotiation leverage.

4. Mitigation & containment

P1 — Within 24 hours

  • Audit for exposed credentials and hardcoded secrets — FulcrumSec's primary initial-access vector is hardcoded or exposed credentials. Conduct a sweep of code repositories, configuration files, CI/CD pipelines, and container images for embedded credentials, API keys (including OpenAI keys), and service-account tokens. Rotate any discovered credentials immediately.
  • Review external-facing storage — FulcrumSec exploits misconfigured storage. Audit all internet-facing S3 buckets, Azure Blob containers, SharePoint sites, and NAS devices for public or overly permissive access. Restrict to authenticated access with least-privilege IAM policies.
  • Hunt for FulcrumSec TTPs — Search SIEM and DLP logs for large-volume outbound data transfers to unrecognised destinations, particularly following access via credential-based authentication from unusual IPs or locations. Correlate with any access to OpenAI API endpoints from non-standard identities.

P2 — Within 72 hours

  • Validate patch posture on internet-facing applications — FulcrumSec exploits unpatched applications for initial access. Prioritise patching of all externally facing web applications, VPN gateways, and remote-access infrastructure. The source notes that Microsoft's July 2026 Patch Tuesday addressed 570 vulnerabilities (plus ~50 earlier in July), ~10% rated critical, and that AI-assisted patch reverse-engineering by threat actors increases the risk window for unpatched systems.
  • Review OpenAI/API key governance — Given FulcrumSec's documented abuse of stolen OpenAI keys, inventory all OpenAI (and other LLM provider) API keys across the estate. Enforce key rotation, rate limiting, IP allow-listing, and budget alerts. Monitor billing for anomalous usage patterns.
  • Prepare for AI-amplified extortion scenarios — Update incident response playbooks to account for extortion narratives that include detailed data inventories, security-posture critiques, and legal/regulatory framing. Pre-engage legal counsel and communications teams on response strategies for AI-generated breach reports distributed to media.

P3 — Within 7 days

  • Enhance data classification and DLP controls — FulcrumSec's leverage depends on understanding the value of stolen data. Ensure DLP policies tag and monitor high-value IP, financial models, and proprietary algorithms for anomalous access and exfiltration patterns.
  • Assess third-party exposure — Given FulcrumSec's targeting of supply-chain organisations (e.g., Avnet), review ICT third-party risk under DORA Art. 28 and Art. 30 frameworks for providers with access to sensitive data repositories.

5. Indicators of compromise

No atomic indicators of compromise (IPs, domains, hashes, email addresses) are present in the source material. The source references an email address in the JADEPUFFER ransom note but states it does not appear in threat intelligence databases and does not provide the address itself.

Behavioural indicators

Behaviour Where to observe Confidence
Large-volume outbound data transfer following credential-based authentication from unusual location SIEM / NGFW / DLP Medium — consistent with FulcrumSec TTPs, single-sourced to GuidePoint
Access to OpenAI API endpoints using credentials not associated with known internal AI initiatives Cloud access logs / API gateway logs / OpenAI billing dashboard Medium — corroborated by FulcrumSec's claimed abuse of stolen OpenAI keys
Anomalous OpenAI API usage spikes (billing/usage) on keys associated with service accounts OpenAI billing dashboard / API usage monitoring Medium — single-sourced to FulcrumSec claim via Risky Biz
Newly registered or previously unseen email addresses initiating extortion contact Email gateway / ticketing system Low — general indicator, not specific to named actors
Formatted breach reports with actor logo, file listings, and file-content breakdowns distributed to journalists or threat researchers on X/social media Threat-intel monitoring / brand-protection platforms Medium — corroborated by vx-underground public posting

6. Detection

Insufficient indicators to author detection rules. The source material describes behavioural patterns and operational methodologies but does not contain specific artefacts (file hashes, mutex names, registry keys, command-line strings, ransom-note text, C2 domains, or hard-coded values) suitable for YARA or Sigma rule construction.

7. Sources

  • Risky Business News / Tom Uren (ed. Amberleigh Jack), "Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations," https://news.risky.biz/srsly-risky-biz-ransomware-uses-ai-to-amp-up-negotiations/, 2026-07-16
  • GuidePoint Security report (referenced by source; original report URL not provided in source material), published ~July 2026
  • DataBreaches[dot]Net (referenced by source as recipient of FulcrumSec communication regarding Novo Nordisk), June 2026
  • vx-underground X account (referenced by source as recipient of FulcrumSec Avnet breach report), October 2025
  • Sysdig report on JADEPUFFER (referenced by source; original report URL not provided), early July 2026

8. Adverse Trace position

This advisory describes an evolution in extortion economics, not a new vulnerability or exploit. The technical intrusion methods used by FulcrumSec (exposed credentials, unpatched applications, misconfigured storage) are well-understood and individually low-sophistication; the novelty is the post-exfiltration use of AI to analyse stolen data, quantify its competitive value, and manufacture negotiation leverage — including the abuse of victims' own OpenAI API keys to fund the analysis. Attribution to FulcrumSec, DragonForce, INC, and Lynx is unconfirmed (no MITRE ATT&CK profiles in verified reference data) and rests primarily on a single GuidePoint Security report corroborated by the Risky Business newsletter; clients should verify before treating these as established threat-actor designations. For EMEA financial services, the immediate risk is not a new attack vector but an increased likelihood that standard data-loss incidents escalate into high-pressure extortion scenarios with credible, data-backed demands. We will monitor for IOCs from the GuidePoint report and any subsequent victim disclosures, and will issue a follow-up if atomic indicators become available.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies