The Babuk2 ransomware group has been caught issuing extortion demands based on false claims and recycled data from previous breaches. The administrator, known as Bjorka, has been active on various forums and Telegram, with a history of involvement in other data breaches and extortion attempts. The Halcyon RISE Team’s analysis suggests that the data being used is recycled from past incidents, despite Babuk2’s claims of conducting multiple attacks in early 2025. The high-profile nature of some of Babuk2’s claims, including an alleged significant incident targeting Indian military and government data, necessitates heightened vigilance among decision-makers and cybersecurity professionals. Halcyon analysts identified that the group appears to be leveraging data from earlier breaches to support their extortion claims. The Babuk2 case serves as a stark reminder of the deceptive tactics employed by cybercriminals and the need for robust verification processes in the face of extortion attempts. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 20 Mar 2025 12:05:08 +0000