amvinfe

Cyber security researcher and blogger

#InfoSec #DataTheft #Ransomware #DataBreach
2026-02-05

๐€๐ฌ๐ฌ๐š๐ฎ๐ฅ๐ญ ๐จ๐ง ๐ˆ๐ง๐๐ž๐ฉ๐ž๐ง๐๐ž๐ง๐ญ ๐‰๐จ๐ฎ๐ซ๐ง๐š๐ฅ๐ข๐ฌ๐ฆ: ๐”๐ง๐Ÿ๐จ๐ฎ๐ง๐๐ž๐ ๐‹๐ž๐ ๐š๐ฅ ๐€๐ญ๐ญ๐š๐œ๐ค๐ฌ ๐จ๐ฏ๐ž๐ซ ๐ญ๐ก๐ž ๐๐ฅ๐š๐œ๐ค ๐๐š๐ฌ๐ญ๐š ๐ˆ๐ง๐ฏ๐ž๐ฌ๐ญ๐ข๐ ๐š๐ญ๐ข๐จ๐ง

On March 1, 2025, SuspectFile published an article on Black Basta based solely on the original, independent work of Valรฉry RieรŸ-Marchive, Editor-in-Chief of LeMagIT.

At no time did Valรฉry or SuspectFile copy from, or use, any original material by The Hacker News.

It was therefore surprising that The Hacker Newsโ€™ law firm, Dennemeyer & Associates, sent SuspectFile a letter asserting copyright infringement of a Ravie Lakshmanan article on Black Basta, and demanding removal of our article within 24 hours or they would request takedown of our site and monetary damages...

suspectfile.com/assault-on-ind

#Black_Basta #Copyright_infringement #Dennemeyer #DMCA #Legal_action #LeMagIT #Nefedov #THN

amvinfe boosted:
Dissent Doe :cupofcoffee:PogoWasRight@infosec.exchange
2026-02-04

And it's out!

Zack Whittaker and I have released our report on the pilot survey we conducted to increase awareness about threats security researchers and journalists who report on cybersecurity and cybercrime experience.

We are grateful to all those who responded to the survey and shared a bit of their experiences. Based on what we found in a pilot survey with a non-random sample, I really think we need to do a bigger study that can also do a deeper dive into some questions.

You can read the report in html or download the .pdf version:

html: databreaches.net/2026/02/02/un

pdf: databreaches.net/wp-content/up

In conjunction with the release of the report, I've also added a new "Threats" category to DataBreaches.net.

You can also read some overview comments from Zack at
this.weekinsecurity.com/new-su

My post explaining how this all started is at databreaches.net/2026/02/02/th

#cybersecurity #securityresearch #legalthreats #threats #criminals #databreach #vulernabilities #malware #lawsuit #survey

@zackwhittaker @campuscodi @amvinfe @jgreig @dangoodin @GossiTheDog @lawrenceabrams @euroinfosec

amvinfe boosted:
Chum1ng0 - Security Research :verified:chum1ng0@infosec.exchange
2026-01-29
2026-01-25

๐ƒ๐จ๐ฎ๐›๐ฅ๐ž ๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž ๐€๐ญ๐ญ๐š๐œ๐ค ๐‡๐ข๐ญ๐ฌ ๐‘๐ž๐ฌ๐จ๐ฎ๐ซ๐œ๐ž ๐‚๐จ๐ซ๐ฉ๐จ๐ซ๐š๐ญ๐ข๐จ๐ง ๐จ๐Ÿ ๐€๐ฆ๐ž๐ซ๐ข๐œ๐š: ๐Œ๐ž๐๐ฎ๐ฌ๐š ๐š๐ง๐ ๐๐ข๐ฅ๐ข๐ง ๐‚๐ฅ๐š๐ข๐ฆ ๐’๐ž๐ฉ๐š๐ซ๐š๐ญ๐ž ๐ˆ๐ง๐ญ๐ซ๐ฎ๐ฌ๐ข๐จ๐ง๐ฌ

Medusa provided a statement clarifying the sequence of events from their perspective: both #Medusa and #Qilin stole sensitive data and encrypted RCAโ€™s network.

suspectfile.com/double-ransomw

#Data_Breach #HIPAA #RCA #Resource_Corporation_of_America

amvinfe boosted:
Chum1ng0 - Security Research :verified:chum1ng0@infosec.exchange
2026-01-23

Chile's National Cybersecurity Agency launches ciberlupa to search for leaks of citizen data.

Personal Opinion:

I find ANCI's Ciberlupa incredibly useful: a Chilean "Have I Been Pwned" tool that helps people find out if their email/RUT (Chilean tax ID) has been leaked, with good privacy (strong authentication, anonymized database). But there's a critical point that can't be ignored: the risk that, in order to keep it updated and "complete," the line might be crossed at some point, and they might start buying dumps on the dark web or black markets (as has happened in other countries with law enforcement). That would be counterproductive: it would finance more data theft and lose all legitimacy. A concrete proposal: ANCI should publicly commit to strict limitsโ€”only open/published sources (Telegram, hacker forums that upload for free, CERT collaborations, reports from victims/companies). No purchases, not even for "specific investigations," in this citizen-led tool.

security-chu.com/2026/01/ciber

#privacy #hacking #dataprotection #Chile

@PogoWasRight @campuscodi @amvinfe @zackwhittaker @jgreig @lawrenceabrams

2026-01-16

๐–๐ก๐ž๐ง ๐’๐ข๐ฅ๐ž๐ง๐œ๐ž ๐๐ž๐œ๐จ๐ฆ๐ž๐ฌ ๐Œ๐š๐ง๐๐š๐ญ๐จ๐ซ๐ฒ: ๐€ ๐‚๐ก๐ซ๐จ๐ง๐ข๐œ๐ฅ๐ž ๐จ๐Ÿ ๐š๐ง ๐ˆ๐ง๐ฃ๐ฎ๐ง๐œ๐ญ๐ข๐จ๐ง

Writing about cybersecurity required time, study, and rigour for work I felt was necessary. One article naturally led to the next; one case connected to the previous one. It was demanding but manageable, and above all, consistent with the journalistic principles I had chosen to uphold.

suspectfile.com/when-silence-b

@campuscodi @zackwhittaker
@jgreigj @lawrenceabrams @briankrebs @PogoWasRight

#HCRG #Injunctions #Law #Private_Life #UK_High_Court_Injunction

2026-01-14

๐”๐ฉ๐๐š๐ญ๐ž: ๐’๐œ๐จ๐ฉ๐ž ๐จ๐Ÿ ๐ญ๐ก๐ž ๐€๐ฏ๐จ๐ฌ๐ข๐ง๐š ๐‡๐ž๐š๐ฅ๐ญ๐ก๐œ๐š๐ซ๐ž ๐’๐จ๐ฅ๐ฎ๐ญ๐ข๐จ๐ง๐ฌ ๐ƒ๐š๐ญ๐š ๐๐ซ๐ž๐š๐œ๐ก ๐‚๐ฅ๐š๐ซ๐ข๐Ÿ๐ข๐ž๐

In our previous article, we reported on the ransomware attack against Avosina Healthcare Solutions, a company providing billing and IT support services to healthcare organizations in the United States[...]
[...]Additional clarity has now emerged through a disclosure filed with the Office of the Maine Attorney General.

suspectfile.com/update-scope-o

#AvosinaMed #Data_Breach #Infosec #Qilin #Ransomware

2026-01-12

๐“๐ก๐ž ๐€๐ฅ๐ฅ๐ข๐š๐ง๐œ๐ž ๐“๐ก๐š๐ญ ๐๐ž๐ฏ๐ž๐ซ ๐–๐š๐ฌ: ๐€ ๐‚๐ซ๐ข๐ญ๐ข๐œ๐š๐ฅ ๐€๐ง๐š๐ฅ๐ฒ๐ฌ๐ข๐ฌ ๐จ๐Ÿ ๐ญ๐ก๐ž ๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž โ€œ๐€๐ฅ๐ฅ๐ข๐š๐ง๐œ๐žโ€ ๐€๐ง๐ง๐จ๐ฎ๐ง๐œ๐ž๐ ๐›๐ฒ ๐’๐ญ๐จ๐ซ๐ฆ๐จ๐ฎ๐ฌ

One of the clearest examples of this pattern is the alleged seven-group ransomware alliance announced by Stormous in October 2025โ€”an initiative that, in practice, never became operational.

suspectfile.com/the-alliance-t

#Alliance #RaaS #StormouS #Nova #Radar

2026-01-11

We have posted a new update on the case.

2026-01-09

We have updated the article

2026-01-09

๐„๐ฑ๐œ๐ฅ๐ฎ๐ฌ๐ข๐ฏ๐ž โ€“ ๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž ๐š๐ญ๐ญ๐š๐œ๐ค ๐š๐ ๐š๐ข๐ง๐ฌ๐ญ ๐‚๐จ๐ฉ๐ž๐œ: ๐€๐ง๐ฎ๐›๐ข๐ฌ ๐œ๐ฅ๐š๐ข๐ฆ๐ฌ ๐ž๐ฑ๐Ÿ๐ข๐ฅ๐ญ๐ซ๐š๐ญ๐ข๐จ๐ง ๐จ๐Ÿ ๐Ÿ” ๐“๐ ๐จ๐Ÿ ๐๐š๐ญ๐š

According to Anubis, approximately 6 terabytes of corporate data were exfiltrated from compromised servers during the operation. The group also claims that it was unable to encrypt Copecโ€™s entire network, despite having gained initial access to internal systems by exploiting a vulnerability in a corporate VPN.

suspectfile.com/exclusive-rans

#Copec #Anubis #Ransomware #Infosec #Data_Breach

2025-12-30

We have updated with an editorial note.

2025-12-29

๐‚๐จ๐ง๐๐žฬ ๐๐š๐ฌ๐ญ ๐”๐ง๐๐ž๐ซ ๐€๐ญ๐ญ๐š๐œ๐ค: ๐“๐ž๐ฅ๐ฅ๐ข๐ง๐  ๐ญ๐ก๐ž ๐‚๐จ๐ฆ๐ฉ๐ฅ๐ž๐ฑ๐ข๐ญ๐ฒ ๐จ๐Ÿ ๐‚๐ฒ๐›๐ž๐ซ๐ฌ๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ

The recent incident involving Condรฉ Nast is more than a simple data breach: it is a concrete example of how cybersecurity journalism often unfolds in real time, with incomplete information and through direct interactions with individuals outside official channels.

suspectfile.com/conde-nast-und

#Condรจ_Nast #Business_Sector

2025-12-23

๐€๐ง๐ฎ๐›๐ข๐ฌ ๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž: ๐ˆ๐ง๐ฌ๐ข๐๐ž ๐ญ๐ก๐ž ๐Œ๐ข๐ง๐๐ฌ๐ž๐ญ ๐š๐ง๐ ๐Œ๐ž๐ญ๐ก๐จ๐๐ฌ ๐จ๐Ÿ ๐š ๐Œ๐จ๐๐ž๐ซ๐ง ๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž ๐†๐ซ๐จ๐ฎ๐ฉ

The group also displays explicit contempt for what it defines as human incompetence: unprepared administrators, insufficient investments in security, and managerial decisions driven by short-term cost savings. In this narrative, the victim is not merely a target, but also partially responsible for its own damage...

suspectfile.com/anubis-ransomw

#Interview #Anubis #RaaS #Ransomware

amvinfe boosted:
Dissent Doe :cupofcoffee:PogoWasRight@infosec.exchange
2025-12-20

ANNOUNCE: Survey on threats experienced by journalists and security researchers

Are you a security researcher or a journalist in the cybersecurity/cybercrime space?

DataBreaches.net and Zack Whittaker at this.weekinsecurity.com are conducting a survey on the types of threats researchers and journalists have faced, including legal threats or legal process and threats of violence from cybercriminals.

The survey is at forms.gle/P9jr6VxfD1LV6odg9

Please complete the survey and share the link on social media and with your colleagues and friends to help us understand how widespread some problems may be.

Reposts with more tags to other individuals would be appreciated.

#journalism #pressfreedom #cybersecurity #risk #threats

@campuscodi @zackwhittaker @jgreig @lawrenceabrams @briankrebs @amvinfe

2025-12-18

๐’๐ž๐œ๐ฎ๐ซ๐จ๐ญ๐ซ๐จ๐ฉ: ๐Ÿ๐ซ๐จ๐ฆ ๐š๐Ÿ๐Ÿ๐ข๐ฅ๐ข๐š๐ญ๐ข๐จ๐ง ๐ญ๐จ ๐ข๐ง๐๐ž๐ฉ๐ž๐ง๐๐ž๐ง๐œ๐ž, ๐ญ๐ก๐ž ๐ž๐ฏ๐จ๐ฅ๐ฎ๐ญ๐ข๐จ๐ง ๐จ๐Ÿ ๐š ๐ฒ๐จ๐ฎ๐ง๐  ๐ซ๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž ๐ ๐ซ๐จ๐ฎ๐ฉ

This updated interview provides a direct look at Securotropโ€™s current modus operandi, the technological innovations of their proprietary ransomware, and the strategic choices that have allowed the group to consolidate itself as an independent actor.

suspectfile.com/securotrop-fro

#Interview #Qilin #RaaS #Ransomware #Securotrop

2025-12-14

๐‘๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž ๐ข๐ง ๐ฉ๐ฎ๐›๐ฅ๐ข๐œ ๐ฌ๐ž๐ซ๐ฏ๐ข๐œ๐ž๐ฌ: ๐ฐ๐ก๐ž๐ง ๐š ๐œ๐ฒ๐›๐ž๐ซ๐š๐ญ๐ญ๐š๐œ๐ค ๐›๐ž๐œ๐จ๐ฆ๐ž๐ฌ ๐š๐ง ๐ข๐ง๐ฌ๐ญ๐ข๐ญ๐ฎ๐ญ๐ข๐จ๐ง๐š๐ฅ ๐œ๐ซ๐ข๐ฌ๐ข๐ฌ

When a ransomware attack hits a hospital, an educational institution, or a government agency, official narratives often describe it as an โ€œIT incident.โ€ It is a reassuring definition, but profoundly misleading. In these contexts, ransomware is not a technical problem: it is an institutional crisis event, capable of disrupting fundamental rights, exposing sensitive data, and putting the entire public decision-making chain under pressure.

suspectfile.com/ransomware-in-

#Ransomware #Infosec #Healthcare #Education #Government_Agencies

amvinfe boosted:
Dissent Doe :cupofcoffee:PogoWasRight@infosec.exchange
2025-12-09

I commented on an attack on Trumbull County, Ohio, by Anubis that @amvinfe reported this week. I will continue to try to follow up, but in the meantime, I posted this:

"Tell the truth, or someone will tell it for you โ€” Trumbull County, Ohio edition."
databreaches.net/2025/12/09/te

#databreach #ransomware #wiper #govsec #incidentresponse #transparency #Anubis #Trumbull_County

amvinfe boosted:
Dissent Doe :cupofcoffee:PogoWasRight@infosec.exchange
2025-12-09

Updated my post on the Anubis attack on Mid South Pulmonary Specialists after getting additional info from Anubis.

It seems they used their wiper to delete all of MSPS's backups, and then encrypted all of their systems.

That sounds pretty grim. MSPS has not posted anything (perhaps they can't) or issued any notice anywhere about whether patient care has been affected at all by any breach.

databreaches.net/2025/12/07/th

#HIPAA #healthsec #cybersecurity #databreach #ransomware #Anubis #wiper #backups #incidentresponse

@campuscodi @amvinfe

2025-12-08

๐“๐ก๐ž ๐ƒ๐š๐ญ๐š ๐๐ซ๐ž๐š๐œ๐ก ๐ญ๐ก๐ž ๐“๐ซ๐ฎ๐ฆ๐›๐ฎ๐ฅ๐ฅ ๐‚๐จ๐ฎ๐ง๐ญ๐ฒ ๐ƒ๐ž๐ง๐ข๐ž๐: ๐Ÿ‘๐Ÿ“๐ŸŽโ€ฏ๐†๐ ๐จ๐Ÿ ๐’๐ž๐ง๐ฌ๐ข๐ญ๐ข๐ฏ๐ž ๐ƒ๐š๐ญ๐š ๐๐ฎ๐›๐ฅ๐ข๐ฌ๐ก๐ž๐ ๐›๐ฒ ๐ญ๐ก๐ž ๐€๐ง๐ฎ๐›๐ข๐ฌ ๐†๐ซ๐จ๐ฎ๐ฉ

The group also claims to have remained active inside the network the entire time:
โ€œWe remained inside their network the entire time.โ€
โ€œWe watched them perform their security audit and collect artifactsโ€ฆ They prepared a report saying โ€˜Everything is fine and secure.โ€™ We laughed for a long time.โ€

suspectfile.com/the-data-breac

#Trumbull_County #Anubis #Ransomware #Infosec #HIPAA

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst