Menu
Browse

Cyber Incident Victim: Rex Mundi victim

Date:

Apr 2014

Location:

Belgium

Summary

A Belgian hosting firm was targeted by hacker group Rex Mundi, which stole customer data and demanded a ransom under threat of public release and website attacks. The group leaked partial data to validate the breach, consistent with their history of similar cyber extortion schemes against other companies.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

In April 2014, the Belgian hosting provider AlfaNet became the target of a blackmail campaign by the hacker group Rex Mundi. The attackers breached AlfaNet’s systems and exfiltrated customer data, subsequently demanding a ransom of 15,000 Euros within 48 hours. Rex Mundi threatened to publicly release the stolen data and launch attacks against AlfaNet-hosted websites if their demands were not met. To substantiate their claims, the group leaked samples of the compromised data. Security experts, including Bart Blaze, urged AlfaNet to avoid paying the extortion fee, citing precedent that cybercriminals often sell or leak data regardless of payment compliance. Blaze further advised the company to investigate the breach, notify affected customers, and review system logs for intrusion patterns. AlfaNet had not issued a public statement regarding mitigation efforts or compliance with the demands at the time of reporting.

Cyber Incident Image

Rex Mundi had prior involvement in similar breaches, including attacks against French telecommunications provider Numericable and email service Habeas. The AlfaNet incident exposed risks of customer data exposure, operational disruption from potential website attacks, and reputational damage to the hosting firm. Experts emphasized that data theft incidents of this nature typically escalate regulatory scrutiny and erode client trust. The article did not specify the volume or sensitivity of data stolen from AlfaNet beyond the confirmed samples. No information was provided regarding AlfaNet’s internal detection methods, containment measures, or coordination with law enforcement. The outcome of the extortion demand remained unresolved in the reported timeline.

Sources
Sources available to members
1 source