CSIDB logo
Threat actor

Sekhmet

Attribution profile

Type
Criminal
Location
Russia
Known incidents
1 incident
First seen
2020-05-30
Last seen
2020-05-30
Updated
2026-08-01 20:28
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Sekhmet is a ransomware group that operates under the alias Sekhmet and is reported to be based in Russia. The actors have identified in the available sources. They have been observed conducting ransomware attacks that combine data encryption with the threat of leaking stolen information unless a payment is made. Their public communications are typically posted on a leak site associated with the group, where they announce compromises and apply pressure on victims.

On May 30 2020 Sekhmet claimed to have attacked Excis, an international information technology firm, describing the impact as “very hard.” The group published a statement on its website criticizing the firm’s IT management as highly unprofotional and warned that it would continue to target the company, asserting that the exploited vulnerabilities could not be patched by the firm’s director or its security staff. As part of the attack Sekhmet released two archives of Excis data for public download but withheld the passwords, promising to release them the following day if the ransom demand was not satisfied. The actors also threatened to contact Excis’s corporate clients to inform them that their data had been left unprotected on the firm’s servers, and they named some of those clients in their posting. No public acknowledgment of the incident appeared on Excis’s own website at the time, and a request for comment from DataBreaches.net went unanswered.

The observed tactics, techniques, and procedures include the use of ransomware to encrypt systems, exfiltration of sensitive data, and the creation of a leak site to publish proof of the breach and to apply extortion pressure. Sekhmet’s approach relies on exploiting specific vulnerabilities in the target’s infrastructure, as they claimed the flaws were unknown to the victim’s IT team and therefore unpatched. The group’s public messaging emphasizes financial gain through ransom payments while simultaneously attempting to damage the victim’s reputation by threatening to notify clients and partners. No definitive links to state sponsors or larger criminal consortia have been established in the reported material, and the only confirmed geographic detail remains the alleged Russian base of operations.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB