BreachCensus

fulcrumsec

First seen May 1, 2026Active26 claimed victims

The claims below are reproduced as posted by fulcrumsec on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
Manchester Airports GroupSeptember 1, 2026ransomlook
Novo NordiskJune 16, 2026ransomware_live
Global Schools FoundationJune 10, 2026ransomware_live
Arup GroupMay 10, 2026ransomware_live
Stuf StorageMay 8, 2026ransomware_live
FashinzaMay 1, 2026ransomware_live
CrediEliteMay 1, 2026ransomware_live
Crank CommunicationsMay 1, 2026ransomware_live
BookBlockMay 1, 2026ransomware_live
JOTMay 1, 2026ransomware_live
Rotary ClubMay 1, 2026ransomware_live
Raptor SuppliesMay 1, 2026ransomware_live
IMEVIMay 1, 2026ransomware_live
InterzeroMay 1, 2026ransomware_live
SaleskidoMay 1, 2026ransomware_live
ParkEngageMay 1, 2026ransomware_live
Nordstern TechnologiesMay 1, 2026ransomware_live
Analog Gold / ProspectorMay 1, 2026ransomware_live
HaticaMay 1, 2026ransomware_live
ReFocus AIMay 1, 2026ransomware_live
MCOMay 1, 2026ransomware_live
LexisNexisMay 1, 2026ransomware_live
youX / Drive IQMay 1, 2026ransomware_live
WoundtechMay 1, 2026ransomware_live
Lena HealthMay 1, 2026ransomware_live
AvnetMay 1, 2026ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).