FulcrumSec
Threat Actor
FulcrumSec is a financially motivated cloud extortion group—also known as The Threat Thespians—that has been active since late 2025. Operating primarily via a "steal and squeeze" model, they gain entry into enterprise environments and steal sensitive corporate and user data to demand multi-million-dollar ransoms.
Incidents Associated with this Threat
- March 10, 2026: Pharmaceutical Maker Novo Nordisk Suffers Ransomware Attack
Malware Used by this Threat Actor
No malware identified for this threat actor.
