CSIDB logo
Threat actor

Cyclops

Attribution profile

Type
Crime Syndicate
Location
Russia
Known incidents
1 incident
First seen
2023-06-29
Last seen
2023-06-29
Updated
2026-07-30 22:21
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Cyclops is a ransomware group that operates under the alias Cyclops and is reported to be based in Russia. The group describes itself as relatively new and claims to work through an affiliate model, with a spokesperson who identifies themselves as “Booda” and communicates via the Qtox platform. Cyclops provides proof of its operations by publishing links to downloadable files and accompanying screencaps on a leak site, which it uses to demonstrate successful intrusions and data exfiltration. The group’s public statements indicate that it distinguishes between its core operations and actions carried out by affiliated actors, as seen in its response to inquiries about the Atherfield Medical & Skin Cancer Clinic incident.

In June 2023 Cyclops claimed responsibility for a cyberattack on Atherfield Medical & Skin Cancer Clinic in Australia, asserting that an unauthorized third party accessed the clinic’s network and exfiltrated sensitive information. The leaked data included patient names, dates of service, the types of medical tests performed, and the personal banking details of doctors associated with the clinic. Specifically, the ECG Test Results folder contained subfolders for each year from 2020 through 2023, with files named using the patient’s first and last name combined with the date of the echocardiogram, all saved as password‑protected PDF documents. DataBreaches noted that the files were encrypted but did not attempt to crack the passwords, observing that even the disclosure of names, dates, and test types would constitute a breach of protected health information under frameworks such as HIPAA, although the legal context in Australia differs. The clinic’s practice manager, identified only as Kaylene, confirmed the incident, stating that forensic specialists were engaged, systems were being secured, and affected individuals were being notified with guidance on protective measures. The clinic apologized for any inconvenience and emphasized that the investigation was ongoing, with the full scope of the breach still undetermined at the time of reporting.

Following the initial claim, Cyclops published the stolen data externally on 1 July 2023, a timeline corroborated by the clinic’s receipt of the notification and its subsequent public statements. DataBreaches indicated that it would continue to monitor the situation for further developments. The group’s spokesperson, Booda, told DataBreaches that the attack was conducted by an affiliate and promised to follow up with that affiliate regarding the password protection applied to the individual files, although no update had been received by the article’s publication date. The incident highlights the ransomware group’s use of data leak tactics, its reliance on affiliate actors for operational execution, and its engagement with victims and journalists through encrypted communication channels. No additional details about the group’s broader targeting patterns, tooling, or strategic objectives are publicly available in the provided sources.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB