SYMBOLCOMMON_NAMEaka. SYNONYMS

IRLeaks  (Back to overview)


IRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB of sensitive data from 20 million user profiles. They have also compromised data from 23 leading Iranian insurance companies, offering over 160 million records for sale. Their operations involve extortion tactics, as seen in the ransom negotiations with Tosan, and they utilize malware such as StealC for data extraction. IRLeaks communicates primarily in Persian and has been active in selling stolen data on cybercriminal marketplaces.


Associated Families

There are currently no families associated with this actor.


References
2024-09-09SC MagazineSC Staff
Significant ransom payment by major Iranian IT firm underway
IRLeaks
2024-09-04CybershafaratTreadstone 71
Major IR leaks
IRLeaks
2024-01-04OODA LoopOODA Loop
Pilfered Data From Iranian Insurance and Food Delivery Firms Leaked Online
IRLeaks
2024-01-03CISO SeriesSean Kelly
Cybersecurity News: Google $5B suit settled, Orbit Chain loses $80M, FDA cyber agreement
IRLeaks
2024-01-02HackReadWAQAS
Iranian Food Delivery Giant Snappfood Cyber Attack: 3TB of Data Stolen
IRLeaks

Credits: MISP Project