LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › fulcrum.pro Listed by cactus Ransomware Group

HIGH severityUnverified claimHow we verify

fulcrum.pro Listed by cactus Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 10, 2024
fulcrum.pro Listed by cactus Ransomware Group

Reported April 10, 2024.

HIGH
Severity
April 10, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The fulcrum.pro Listed by cactus Ransomware Group (reported April 10, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On April 10, 2024, the ransomware group known as cactus listed fulcrum.pro on its leak site, claiming to have exfiltrated internal files in a ransomware attack. For anyone whose personal or professional details may sit inside those files—employees, executives, or others connected to the organisation—the practical stakes are immediate: personal identifying information, financial records, and private correspondence can be used for fraud, identity theft, or targeted social engineering long after the initial incident.

Public detail remains limited. The number of people affected is unknown, and independent confirmation of the full scope has not been widely reported. What is known comes largely from the group's own claims, which must be treated as unverified until corroborated.

Breaking down the breach

According to the listing reported on April 10, 2024, cactus claimed to have carried out a ransomware attack against fulcrum.pro that involved the exfiltration of internal files. The group posted download links on its dark-web infrastructure and described the material as including employees' and executives' personal data, corporate correspondence, agreements, private and corporate financial documents, and personal identifying information, among other items.

No public figures have been released for the volume of data, the exact date of intrusion, or the technical method used. The number of individuals whose information may be involved is listed as unknown. The listing itself constitutes a claim by the group rather than independently verified fact; organisations named on ransomware leak sites sometimes later confirm or dispute the details, but no such confirmation is part of the available record here.

Inside cactus

Cactus is a ransomware operation that has been active in the public threat landscape for some time. Like many contemporary groups, it typically follows a double-extortion model: encrypting systems to disrupt operations while also stealing data and threatening to publish it if a ransom is not paid. Victims are commonly listed on dedicated leak sites hosted on Tor, often with sample files or full archives offered for download to pressure the organisation.

The group has previously claimed attacks against a range of companies across different sectors, using the same pattern of data theft followed by public listing. In this case, cactus claims to have taken internal files from fulcrum.pro and made them available via its infrastructure. No additional statements or specific demands attributed to cactus regarding this particular victim appear in the reported facts beyond the listing and the data descriptions provided.

Who is fulcrum.pro?

Fulcrum.pro is the organisation named in the cactus listing. Public background indicates it operates as a commercial entity that maintains the usual range of internal corporate records—employee and executive information, contracts, financial documents, and correspondence. Organisations of this type routinely hold data that is both operationally sensitive and personally identifiable.

A breach involving such material is consequential because the data can affect not only the company's day-to-day functions and reputation but also the privacy and financial security of the individuals whose details appear in those files. Even when the precise business focus of an organisation is not exhaustively detailed in breach reports, the presence of personal identifying information and financial records raises clear risks for the people connected to it.

What data was at risk

The cactus listing describes the exfiltrated material as internal files containing employees' and executives' personal data, corporate correspondence, agreements, private and corporate financial documents, and personal identifying information, among other items. These categories are presented as the group's own description of what it claims to hold.

Exact contents, file counts, and the full extent of exposure remain unconfirmed by independent sources. Organisations of this kind typically store employee records, payroll and banking details, contracts, internal emails, and various forms of personal identifying information. Because the precise inventory has not been publicly verified beyond the group's claims, it is not possible to state with certainty which specific records were taken or how many people are represented in them.

The real-world impact

For individuals whose data may be included, the risks are concrete. Personal identifying information combined with financial documents can enable identity fraud, unauthorised account openings, or targeted phishing that appears legitimate because it references real internal details. Corporate correspondence and agreements can be used to craft convincing social-engineering attacks against colleagues, partners, or clients. Even if the data is not immediately sold or widely distributed, its presence on a leak site increases the chance of later misuse.

For the organisation itself, the incident can mean operational disruption from the ransomware component, potential regulatory scrutiny depending on jurisdiction and the nature of the data, and lasting reputational effects. Because the number of people affected is unknown and the full dataset has not been independently catalogued, the scale of downstream harm cannot yet be quantified. The primary concern remains the exposure of personal and financial material that individuals have little ability to control once it leaves the organisation's systems.

What to do if you're exposed

If you have a past or present connection to fulcrum.pro—as an employee, executive, contractor, or business contact—treat the possibility of exposure seriously. Monitor bank and credit accounts for unusual activity, place fraud alerts or credit freezes where available, and be cautious of unexpected emails or calls that reference internal company details. Change passwords on any accounts that may have shared credentials or recovery information linked to work email, and enable multi-factor authentication wherever possible.

Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. This provides one practical way to gauge whether personal details appear in publicly tracked leaks and to decide on further protective steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyfulcrum.pro security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See fulcrum.pro’s full breach history →

More recent breaches

securityinstrument.com Listed by cactus Ransomware GroupJuly 6, 2024isometrix.com Listed by cactus Ransomware GroupJune 2, 2024fpr-us.com Listed by cactus Ransomware GroupMay 30, 2024newagesys.com Listed by cactus Ransomware GroupFebruary 29, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the fulcrum.pro Listed by cactus Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by cactus — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram