Menu
Browse

Cyber Threat Actor: Fulcrumsec

Updated 2026-07-18 01:53
Actor Type Location Known Incidents
 Icon
Criminal
2 incidents
Profile

Fulcrumsec, also observed operating under the alias FulcrumSec, is a ransomware‑oriented threat actor that has claimed responsibility for attacks on organizations in the education and pharmaceutical sectors. The group’s public statements and leak site postings indicate a focus on extracting monetary gain through extortion demands and the subsequent sale of exfiltrated data on dark‑web markets. In the incident involving the Global Schools Foundation, a Singapore‑based non‑profit, Fulcrumsec appeared on the ransomware.live leak site, signaling a ransomware operation against an educational entity. The Novo Nordisk intrusion, disclosed in early 2026, saw the group copy source code, AI models, proprietary drug information, clinical trial data and pseudonymized personal details, then demand a $25 million payment before offering the stolen material for sale while withholding certain sensitive sets as part of a harm‑reduction approach.

The actor’s observed tactics include the use of dormant credentials and a compromised GitHub token to gain initial access to internal IT systems, as described in the Novo Nordisk case. While specific malware families were not named in the available sources, the group’s self‑identification as a ransomware entity implies the deployment of ransomware payloads to encrypt data and facilitate extortion. Their tooling style appears to rely on leveraging legitimate access mechanisms—such as stolen credentials and API tokens—rather than custom‑built exploit frameworks, suggesting a focus on credential abuse and token misuse for intrusion. No publicly attributed state sponsorship or affiliation with a known criminal consortium has been documented for Fulcrumsec in the referenced material.

Representative operations attributed to Fulcrumsec include the ransomware leak targeting the Global Schools Foundation and the large‑scale data theft and extortion campaign against Novo Nordisk. These incidents illustrate the actor’s ability to strike both a non‑profit educational organization and a multinational pharmaceutical corporation, employing credential‑based access to harvest valuable intellectual property and personal data for financial gain. The group’s public communications consistently emphasize monetary extortion and the monetization of stolen information, without any explicit claims of political or ideological motives in the supplied sources.

Incidents
Attributed incidents available to members
2 incidents
Sources
Sources available to members
0 sources