{
	"id": "d720be86-d868-4702-abb8-da41eff3c2cb",
	"created_at": "2026-04-06T00:06:18.742662Z",
	"updated_at": "2026-04-10T13:12:50.636452Z",
	"deleted_at": null,
	"sha1_hash": "1049b390df77f0653b88c90fb01de9339e88cc45",
	"title": "Sodinokibi Ransomware Publishes Stolen Data for the First Time",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 2252781,
	"plain_text": "Sodinokibi Ransomware Publishes Stolen Data for the First Time\r\nBy Lawrence Abrams\r\nPublished: 2020-01-11 · Archived: 2026-04-05 13:28:40 UTC\r\nFor the first time, the operators behind the Sodinokibi Ransomware have released files stolen from one of their victims\r\nbecause a ransom was not paid in time.\r\nSince last month, the representatives of the Sodinokibi, otherwise known as REvil, have publicly stated that they would\r\nbegin to follow Maze's example and publish data stolen from victims if they do not pay a ransom.\r\nhttps://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-publishes-stolen-data-for-the-first-time/\r\nPage 1 of 4\n\n0:00\r\nhttps://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-publishes-stolen-data-for-the-first-time/\r\nPage 2 of 4\n\nVisit Advertiser websiteGO TO PAGE\r\nWhile there have been threats made against Travelex and CDH Investments, they have not carried through with them.\r\nThis all changed today when the public representative of Sodinokibi stated they beginning to \"keep promises\" as they posted\r\nlinks to approximately 337MB of allegedly stolen victim files on a Russian hacker and malware forum.\r\nSodinokibi publishing victim's data\r\nSource: Damien\r\nThey claim this data belongs to Artech Information Systems, who describe themselves as a \"minority- and women-owned\r\ndiversity supplier and one of the largest IT staffing companies in the U.S\", and that they will release more if a ransom is not\r\npaid.\r\n\"This is a small part of what we have. If there are no movements, we will sell the remaining, more important and interesting\r\ncommercial and personal data to third parties, including financial details.\"\r\nAt this time, Artech's site is down and it is not known if it is due to this attack. BleepingComputer has reached out to Artech\r\nwith questions related to the ransomware attack, but have not heard back.\r\nAs we have been saying over and over, ransomware attacks need to be treated with transparency and as a data breach. \r\nBy trying to hide these attacks, and the theft of employee, company, and customer data, companies are not only risking fines\r\nand lawsuits but are also putting personal data at risk.\r\nThis practice of using stolen data as leverage is not going to go away and is only going to get worse.\r\nExpect to see more ransomware operators began to utilize this practice as it becomes the norm in attacks.\r\nhttps://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-publishes-stolen-data-for-the-first-time/\r\nPage 3 of 4\n\nAutomated Pentesting Covers Only 1 of 6 Surfaces.\r\nAutomated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the\r\nother.\r\nThis whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic\r\nquestions for any tool evaluation.\r\nSource: https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-publishes-stolen-data-for-the-first-time/\r\nhttps://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-publishes-stolen-data-for-the-first-time/\r\nPage 4 of 4",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"Malpedia",
		"ETDA"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-publishes-stolen-data-for-the-first-time/"
	],
	"report_names": [
		"sodinokibi-ransomware-publishes-stolen-data-for-the-first-time"
	],
	"threat_actors": [],
	"ts_created_at": 1775433978,
	"ts_updated_at": 1775826770,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/1049b390df77f0653b88c90fb01de9339e88cc45.pdf",
		"text": "https://archive.orkl.eu/1049b390df77f0653b88c90fb01de9339e88cc45.txt",
		"img": "https://archive.orkl.eu/1049b390df77f0653b88c90fb01de9339e88cc45.jpg"
	}
}