Cyber Threat Actor: Devman
| Actor Type | Location | Known Incidents |
Criminal
|
—
|
2 incidents |
|---|
Profile
Devman is an alias that appeared in a public claim regarding a cyber‑attack on DXS International, a United Kingdom‑based technology supplier that provides services to England's National Health Service. On 14 December 2025 the actor asserted that it had exfiltrated roughly 300 GB of data from the company's office servers and threatened to release the information unless its demands were satisfied. DXS International confirmed the breach, noting that the incident affected its office servers but that front‑line clinical operations remained unaffected and that the overall impact on its services was minimal.
On 25 November 2025 the same alias was linked to a ransomware operation against the Georgia Superior Court Clerks’ Cooperative Authority, a state‑level entity that supports court operations across Georgia, United States. The actor claimed responsibility for the attack, which disrupted core administrative functions used by the judiciary and related services. The source did not provide additional specifics about the scope, duration, or any data‑theft component associated with this incident.
The observed behavior of Devman includes the use of ransomware to disrupt systems and the separate claim of data exfiltration for extortion, as demonstrated in the two reported incidents. No particular malware families, initial‑access methods, or tooling details have been disclosed in the available sources, so the actor's technical profile remains unspecified. Likewise, no public attribution to a state sponsor, criminal group, or other affiliate has been made, leaving any affiliations unknown. These two episodes represent the only publicly documented campaigns tied to the Devman alias, showing targeting of a UK healthcare‑technology provider and a US state judiciary body, and they constitute the current factual basis for any further description of the actor's activity. The publicly available reports do not include indicators of compromise, specific IP addresses, or associated infrastructure that could be used to trace the actor's activity.
