Attribution: Financially motivated cybercriminal group
First Observed: 2025
Primary Operations: Data exfiltration, cloud compromise, source code theft, intellectual property theft, credential exposure, data extortion, public dataset releases
FulcrumSec is a financially motivated cybercrime group known for large-scale data theft, cloud infrastructure compromises, source code exposure, and public dataset releases. Active since at least 2025, the group has built a reputation around publishing extensive technical details about alleged intrusions, often combining data extortion with detailed narratives describing how access was obtained and what information was compromised.
Unlike traditional ransomware operations that focus on encryption and operational disruption, FulcrumSec’s activity centers on data theft, public exposure, reputational pressure, and public shaming campaigns. The group frequently publishes technical evidence, infrastructure details, source code repositories, exposed credentials, internal documentation, and breach narratives alongside extortion demands.
Overview
FulcrumSec operates a public-facing extortion model in which organizations are listed alongside breach allegations, technical findings, dataset descriptions, negotiation updates, and campaign branding. The group frequently claims access to cloud-hosted environments, SaaS platforms, source code repositories, enterprise data stores, and proprietary business systems.
Its operations appear heavily focused on maximizing reputational and commercial impact by targeting organizations that maintain large quantities of sensitive business information, customer data, proprietary research, intellectual property, or development assets.
Known and alleged victims
Organizations publicly named by FulcrumSec across its extortion platform, campaign pages, and disclosure operations include:
- Novo Nordisk
- Global Schools Group
- Arup Group
- Stuf Storage
- Hatica
- MyComplianceOffice (MCO)
- LexisNexis
- YouX
- ReFocus
- Woundtech
- Lena Health
- Raptor Supplies
- Avnet
- FashionZA
- CrediElite
- Rotary International
- IMEVI
- Interzero
- SalesKido
- ParkEngage
- Nordstern Technologies / NCS
Several organizations listed above have not yet been the subject of public breach claims covered by BreachNews. Their appearance on FulcrumSec campaign pages should not be interpreted as confirmation of compromise. However, the listings provide insight into the group’s targeting patterns and future disclosure activity.
2026 Campaign Escalation and Recent Coverage
Throughout 2026, FulcrumSec significantly increased both the scale and visibility of its operations. While earlier activity focused on cloud exposures and enterprise datasets, more recent campaigns have targeted proprietary research, software development environments, source code repositories, healthcare data, educational institutions, and high-value corporate intellectual property.
BreachNews has reported on the following FulcrumSec-linked incidents:
- Novo Nordisk alleged 1.3TB breach involving source code, clinical data, AI assets, and pharmaceutical research
- Global Schools Group student, parent, and employee data breach claim
- MyComplianceOffice dataset release following alleged failed negotiations
- Hatica breach involving enterprise collaboration environments and Slack workspaces
- Arup Group cloud infrastructure breach claim
- Stuf Storage breach involving customer and operational data
In several cases, FulcrumSec has followed breach claims with public dataset releases, source code publication, credential disclosures, or detailed technical narratives describing alleged intrusion paths.
Latest activity tracker
This section is continuously updated as new FulcrumSec activity is reported.
- June 2026: FulcrumSec claims theft of approximately 1.3TB of Novo Nordisk data, including source code repositories, proprietary AI models, pharmaceutical research assets, and clinical trial information
- June 2026: Global Schools Group allegedly breached, with student, parent, and employee data reportedly exposed
- June 2026: Full MyComplianceOffice dataset allegedly released following failed negotiations
- June 2026: Arup Group cloud infrastructure breach claim published
- June 2026: Hatica enterprise collaboration platform data allegedly exposed
- June 2026: Stuf Storage dataset allegedly released following extortion efforts
- June 2026: FulcrumSec expands public campaign branding through Index of Shame, The Hardcoded Horror Show, and Slopocalypse Now
Campaign branding and disclosure operations
Unlike many data extortion groups, FulcrumSec organizes disclosures into branded campaigns that group victims according to the alleged security failures discovered during intrusions.
- The Hardcoded Horror Show: Focuses on exposed credentials, hardcoded secrets, API keys, authentication tokens, cloud credentials, and source code weaknesses. Campaign messaging suggests the group targets organizations that allegedly exposed access credentials through development repositories, application code, or cloud environments.
- Index of Shame: Focuses on organizations allegedly exposing sensitive information through publicly accessible infrastructure, open directories, weak access controls, exposed databases, cloud storage buckets, and internet-facing systems.
- Slopocalypse Now: A forthcoming campaign focused on AI companies, machine learning providers, and organizations handling large volumes of sensitive user information.
The campaign structure allows FulcrumSec to publicly group victims according to the type of security weakness allegedly exploited while reinforcing a recognizable brand identity across disclosures.
The Hardcoded Horror Show
FulcrumSec describes The Hardcoded Horror Show as a campaign focused on organizations that allegedly exposed credentials, secrets, authentication tokens, API keys, cloud credentials, and database connection strings within source code, application bundles, repositories, or development environments.
Organizations publicly displayed within the campaign include:
- Avnet
- Arup Group
- Novo Nordisk
- Additional unnamed organizations marked as “Coming Soon”
Campaign messaging accuses organizations of exposing credentials through application code and development infrastructure rather than falling victim to sophisticated intrusion techniques.
Index of Shame
Index of Shame is presented as a campaign targeting organizations allegedly exposing sensitive information through publicly accessible infrastructure and misconfigured systems.
Organizations displayed within the campaign include:
- FashionZA
- CrediElite
- Rotary International
- Raptor Supplies
- IMEVI
- Interzero
- SalesKido
- ParkEngage
- Nordstern Technologies / NCS
Campaign material claims exposed information may include customer records, payment information, healthcare data, application secrets, encryption keys, configuration files, credentials, and database connection information.
Slopocalypse Now
FulcrumSec has begun promoting a forthcoming campaign called Slopocalypse Now.
Published campaign material frames AI companies as custodians of large volumes of sensitive personal information, including healthcare records, financial information, legal documents, private communications, and enterprise data.
No victims have yet been publicly disclosed as part of the campaign. However, the messaging suggests future disclosures may focus on AI providers, enterprise AI platforms, model developers, and organizations operating large language model infrastructure.
Tactics and operational patterns
FulcrumSec demonstrates a consistent operational model centered on data theft and public disclosure rather than encryption-based ransomware.
- Cloud environment compromise: Targeting AWS, Azure, SaaS platforms, and cloud-hosted infrastructure
- Credential harvesting: Leveraging exposed secrets, API keys, access tokens, authentication credentials, and hardcoded secrets
- Source code theft: Extracting repositories, development assets, CI/CD configurations, and internal tooling
- Data-first extortion: Prioritizing exfiltration and publication over operational disruption
- Technical disclosure campaigns: Publishing extensive details regarding alleged intrusion paths, exposed systems, and security weaknesses
- Public shaming operations: Organizing victims into themed campaigns designed to emphasize alleged security failures
Focus on intellectual property and research assets
Unlike many extortion groups that focus primarily on customer records, FulcrumSec increasingly targets intellectual property, proprietary research, source code repositories, AI assets, internal development environments, and enterprise knowledge systems.
Recent claims involving pharmaceutical research, enterprise software platforms, educational institutions, healthcare organizations, and cloud infrastructure suggest the group seeks to maximize leverage by targeting information that may hold strategic or commercial value beyond traditional personally identifiable information.
Victim sectors
Organizations targeted by FulcrumSec span multiple industries, including healthcare, education, technology, professional services, storage providers, AI companies, cybersecurity vendors, enterprise software vendors, manufacturing, supply chain, and nonprofit organizations.
The group’s victimology suggests a preference for organizations with extensive cloud footprints, large data repositories, significant intellectual property holdings, SaaS dependencies, or complex development environments.
Data publication model
FulcrumSec frequently follows breach claims with public releases of datasets, source code archives, internal documentation, cloud infrastructure data, credential collections, and technical evidence intended to support its allegations.
Some releases have included detailed explanations of the alleged intrusion path, affected systems, exposed repositories, cloud assets, and development environments.
This publication-heavy approach reduces reliance on prolonged negotiations and allows the group to build credibility through repeated releases, even when organizations decline to engage.
Messaging and positioning
The group’s public communications frequently frame its activity as exposing negligence rather than purely criminal conduct. Messaging often focuses on alleged security failures, weak credential management, cloud misconfigurations, exposed secrets, development mistakes, and operational security weaknesses.
This narrative-driven approach, combined with technical disclosures, public evidence, and branded campaign structures, has helped FulcrumSec establish a recognizable identity within the broader cybercrime ecosystem.
Threat assessment
FulcrumSec has rapidly evolved from a relatively unknown actor into one of the more active data extortion groups tracked by BreachNews. Its focus on cloud environments, source code repositories, intellectual property, credential exposure, AI-related targets, and public dataset releases differentiates it from many traditional ransomware operations.
The group’s repeated publication of datasets, source code, credentials, technical evidence, and detailed intrusion narratives suggests organizations should take its claims seriously, particularly when cloud infrastructure, development environments, SaaS platforms, or proprietary business assets are involved.
Notes
All breach claims attributed to FulcrumSec should be treated as unverified unless confirmed by affected organizations or independently validated. However, the group’s history of publishing datasets, source code, credentials, and technical evidence following breach claims indicates that many incidents warrant close scrutiny.
Update (June 24, 2026): Added campaign intelligence covering The Hardcoded Horror Show, Index of Shame, and Slopocalypse Now. Added newly identified organizations appearing across FulcrumSec campaign pages and updated assessment of the group’s branding, victimology, and operational focus.











