Security

LockBit 5 Lists ADT, Qilin Adds Aurore Development and TECNICI ASSOCIATI, ShinyHunters Claims CyrusOne Breach

Dark-web monitoring by ThreatMon on August 23 confirmed LockBit 5's posting of ADT, Qilin's addition of two Italian firms, and ShinyHunters' claim of a CyrusOne breach. The same day brought a WordPress ClickFix campaign exposed by Check Point and continued activity from a Lazarus-linked zero-day exploit chain.

H
By Hassan Al-Rashid Security Editor
August 24, 2026 / Updated August 25, 2026 / 6 min read

Dark-web monitoring by ThreatMon's Threat Intelligence Team on August 23 confirmed three new ransomware victim additions across two of the most active criminal operations. LockBit 5 posted the US home security giant ADT to its leak site; Qilin added the Italian real-estate developer Aurore Development and the engineering consultancy TECNICI ASSOCIATI STP; and the ShinyHunters extortion group claimed responsibility for a breach at CyrusOne, the Texas-based data-center operator. The same 24-hour window brought Check Point Research's disclosure of a global WordPress ClickFix campaign and continued activity from a Lazarus-linked zero-day exploit chain first reported August 22.

The ADT Posting

LockBit 5's listing of ADT marks the first time the retooled operation has publicly claimed a US consumer-security brand. The post, dated August 23 and visible on LockBit's Tor leak site, alleges the exfiltration of 2.1 TB of customer data including 6.4 million account records, internal CRM data and a subset of encrypted alarm-system event logs. ADT confirmed in a Form 8-K filed with the SEC late on August 23 that it had "identified a cybersecurity incident affecting a subset of our customer-support systems" and had engaged Mandiant and CrowdStrike. The company has not confirmed LockBit's specific claims; LockBit has set a 14-day countdown for the data release.

The Italian Qilin Cases

Qilin, a Russia-aligned ransomware-as-a-service operation that re-emerged in March after a brief law-enforcement disruption, added two Italian firms to its leak site on August 23. Aurore Development, a Rome-based real-estate developer with roughly 280 employees, had its financial records and project files posted; TECNICI ASSOCIATI STP, a Bologna engineering consultancy, saw its client list and project specifications dumped. Italian law enforcement has not yet commented. Qilin's affiliate model — where independent operators run the encryption while Qilin provides the leak infrastructure — has made it the second-most-active operation in 2026 by victim count, with 287 confirmed postings as of August 22, according to the eCrime.ch tracker.

CyrusOne and ShinyHunters

ShinyHunters, the extortion-focused group that split from the broader Scattered Spider umbrella in 2024, claimed responsibility for a CyrusOne breach that it says exposed 1.8 TB of customer colocation metadata, including physical-cabinet locations, network diagrams and a subset of customer support tickets. CyrusOne operates 50+ data centers across the US, Europe and Asia; the metadata alone would be a treasure trove for follow-on attacks against the company's enterprise tenants. ShinyHunters' preferred tactic is now pure data-theft extortion — they encrypt nothing and demand payment in exchange for not publishing the data — which has made them harder to track via traditional endpoint-detection tools.

The WordPress ClickFix Campaign

Check Point Research on August 23 disclosed a global ClickFix social-engineering campaign that compromised more than 7,400 poorly-maintained WordPress sites and turned them into a distributed network for surveillance, data theft, and ransomware delivery. The campaign relies on fake CAPTCHA prompts that prompt visitors to "verify you are human" by pasting a PowerShell command into the Windows Run dialog, a technique that has become the most effective initial-access vector of 2026. Check Point's telemetry puts the daily infection rate at roughly 22,000 end-user machines, with peaks in the US, India and Brazil.

What to Watch Through Year-End

Three checkpoints follow. The LockBit 5 14-day countdown for ADT's data release — due September 6 — will determine whether LockBit 5's retooling has restored the operation's reputation after its February 2024 disruption, and whether ADT pays or fights. The SEC's forthcoming disclosure-rule enforcement actions against the four publicly traded companies named in last week's batch of extortion postings (ADT, CyrusOne, a separately disclosed LexisNexis AWS breach from August 18, and a Wesco CRM incident) will test whether the 8-K materiality standard is being interpreted strictly or loosely. And the Q3 2026 data-breach numbers from Identity Theft Resource Center, due in October, will reveal whether the 47% year-on-year increase tracked through Q2 is accelerating or moderating — a leading indicator for the cyber-insurance pricing cycle.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.