CSIDB logo
Threat actor

Lynx

Attribution profile

Type
Crime Syndicate
Location
United States of America
Known incidents
2 incidents
First seen
2020-01-01
Last seen
2025-01-01
Updated
2026-08-01 02:12
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Lynx is a threat actor known by the aliases Lynx and Lynx Hacker, with public references indicating a possible base of operations in the United States of America. The name appears in both ransomware activity and in a security‑research context where the same alias was used to disclose a vulnerability. These references treat Lynx as a distinct entity that has been linked to multiple cyber incidents across different years.

The actor’s observed targeting includes the manufacturing sector, specifically an Australian auto parts manufacturer, and the retail sector, represented by a mobile device case seller. Geographically, the ransomware incident explicitly affected an Australian organization, while the retail case does not specify a location in the available sources. Strategic objectives differ between the incidents: the ransomware operation employed double extortion, threatening to publish stolen data unless a payment was made, indicating a financially motivated goal, whereas the retail breach involved the actor seeking public disclosure of the vulnerability and providing the stolen data to a breach notification service rather than requesting a bounty.

Notable tactics, techniques, and procedures referenced in the sources include the use of a path traversal vulnerability in a customization upload script to gain initial access to the retail website, and the employment of double extortion tactics in the ransomware attack. The actor reportedly accessed employee resumes, approximately nine gigabytes of personal customer photos, ZenDesk ticketing systems, API credentials, hashed passwords, addresses, email addresses, phone numbers, and transaction records during the retail incident. In the ransomware case, Lynx claimed the theft of 350 gigabytes of internal operational data encompassing employee information, financial records, engineering specifications, and sales materials.

Attribution details are limited; the only publicly stated geographic clue is the possible United States location, and no state sponsorship or criminal‑consortium affiliation is explicitly documented in the provided material. The actor’s activities have been described as those of a relatively new ransomware group that has targeted over one hundred entities globally, including additional Australian businesses, suggesting a broader campaign pattern beyond the single manufacturing incident.

Significant publicly reported operations associated with Lynx include the 2025 ransomware attack on the Australian auto parts manufacturer, which involved data theft and double extortion demands, and the 2020 breach of the mobile device case retailer where a path traversal flaw was exploited, leading to extensive data exposure and subsequent notification efforts via the Have I Been Pwned service. These examples illustrate the actor’s use of both vulnerability exploitation and ransomware deployment to achieve their objectives.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB