hensi
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor tracked under the alias hensi was identified following a security incident disclosed by Scania on 28 May 2025. According to Scania’s statement, the actor obtained stolen credentials from an external IT partner and used them to access the insurance.scania.com web application. Once inside the application, the actor exfiltrated insurance claim documents that contained personal data and potentially sensitive financial or medical information. After the data theft, the actor initiated contact with Scania employees through email, delivering extortion demands and warning that the stolen material would be released if those demands were not satisfied. To increase pressure, the actor subsequently uploaded samples of the compromised data to various hacking forums. Scania reported that the compromised application was taken offline immediately after the discovery of the breach. The company also launched an internal investigation, notified relevant privacy authorities, and described the overall impact as limited despite the nature of the exposed data.
No mention of malware families, exploit kits, or custom tooling accompanied the hensi activity in the publicly available reporting. The actor’s tactics centered on credential abuse, followed by direct email extortion and the public leakage of data samples on underground forums. The stated objective appears to be financial gain through extortion, as the actor explicitly demanded compliance under threat of data release. No public attribution to a nation‑state, criminal syndicate, or other affiliate has been made regarding hensi, and the actor remains unlinked to any broader campaign. The Scania breach constitutes the sole publicly documented operation associated with the alias, illustrating a pattern of stealing data via compromised credentials and then leveraging it for extortion. Authorities were engaged and the affected system was isolated.
Incidents
Attributed incidents are available to members.
1 incident