CSIDB logo
Incident

sa2000.com

Incident posture

Attack window
Jun 2026
Location
-
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-10 09:37

Linked entities

Victim
sa2000.com
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

sa2000.com was compromised by the Stormous ransomware group, resulting in the exfiltration of approximately 150 gigabytes of data. The stolen information includes accounting records such as purchase and payable invoices, along with other financial documents. The breach underscores the risk posed by ransomware operations that focus on exfiltrating sensitive corporate data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On 2026-06-09, the ransomware group Stormous posted an update on the ransomware.live site indicating a full data dump from sa2000.com. The update stated that 150 GB of data had been extracted from the victim's systems. The extracted data included accounting information such as purchase invoices and payable invoices. The post was labeled UPDATE-FULL DATA DUMP. The entry appears in the recent victims list with source report ID 95fcd638-1379-43b2-82b0-9812887b1623 and article date 2026-06-10. The discovery timestamp is noted as yesterday relative to the article date.

The exposed dataset consists of 150 GB of files, with the specific contents described as accounting records including purchase and payable invoices. Stormous claimed responsibility for the intrusion and the data exfiltration in the posted update. The incident was made publicly available through the ransomware.live platform on 2026-06-10. The source material does not provide details on how the breach was detected, what containment measures were undertaken, or any remediation actions taken by sa2000.com. No additional information regarding ransom demands, data leakage beyond the accounting files, or system restoration is included in the provided article. The known facts of the sa2000.com incident are limited to the disclosure of the data dump size, the type of data compromised, the responsible group, and the date of public reporting.

Sources

Sources available to members: 1 source.

CSIDB