Two ransomware gangs and a data- stealing extortion group have adopted a new strategy to force victim companies to pay ransoms to prevent their stolen data from being leaked.

This new strategy includes adding a search function to the leak , which allows for easy finding of victims or even specific details that have been leaked.
See also: 0mega ransomware: Targets organizations using double extortion tactics
As we said above, at least two ransomware gangs and one gang have adopted this strategy, and more threat actors are likely to follow suit.
Easily find victims' stolen data
Last week, the ALPHV/BlackCat announced that it had created a searchable database of victims who do not pay the ransom.
The hackers made it clear that the repositories are indexed and it is easy to search for information by filename or based on the content available in documents and images.
The results come from the “Collections” section of the BlackCat ransomware gang’s leak site and may not be the most accurate, but the strategy shows that cybercriminals are constantly evolving to put more pressure on victims .
See also: Mangatoon: Data breach affected millions of accounts

The BlackCat ransomware operators claim to have adopted this strategy to make it easier for other cybercriminals to find passwords or confidential information about victim companies. The gang already tried this strategy in mid-June, when it created a searchable site for data allegedly stolen after an attack on a hotel and spa in Oregon.
The site allowed spa guests and employees to check if their personal information had been stolen during the attack .
This strategy is a step forward in the field of extortion, as it puts pressure on the victim to pay the ransom and remove the data to avoid the potential risk of class action lawsuits.
See also: Hackers have stolen over $2 billion from Web3 projects in 2022
Late last week, BleepingComputer noticed that the LockBit offered a redesigned version of its data breach site that allowed searching for victim companies. However, LockBit's search is limited to finding victims by name. Still, it makes it easier to identify data leaks from specific companies.
Another leak site that has implemented a search function is the one published by the Karakurt.
“Ransomware continues to evolve at a breakneck pace…,” said Erich Kron of KnowBe4 Inc. “The ability to structure and easily search for information makes it easier for other cybercriminals to use the stolen data to launch other attacks, especially social engineering attacks, such as phishing.”
Source: www.bleepingcomputer.com
