Cyber Analysis Group - CyberAGroup - OSINT Darkweb Investigations  - Insider Threat - Crypto - Online threat & exposure - SOCMINT - Canadian

Companies spend millions locking their front doors and checking supply chains. Yet they consistently overlook one of the oldest and most damaging attack vectors: the insider threat.

Extortion groups have realized that fighting modern defenses is unnecessary when an employee with legitimate access can simply hand over the keys.
A prime example is the data extortion group CoinbaseCartel. Instead of deploying encryptors, they focus purely on stealing sensitive data, actively seeking corporate insiders to get it.

When we examined their recent ransom attempt, which included 3.8 million Canadian customer records from the infamous 2019 Desjardins breach, their recruitment strategy was written right in the dump:

"We are looking for direct insiders at major corporations. With our solid reputation, we guarantee safety and huge payouts. Let's connect and discuss further."

The irony is clear. The original Desjardins breach happened because an internal employee stole the data in the first place, and that same data is still being used for extortion today. Cybercriminals recognize the massive return on investment: why spend weeks trying to break in when crypto can buy legitimate access?

Perimeter defense matters, but real security requires watching the inside:

-Enforce strict least-privilege access across all systems
-Monitor and flag unusual bulk data downloads
-Watch for abnormal user behavior within legitimate accounts
-Recognize that human risk includes direct financial solicitation, not just phishing

If you only guard the gate, you will miss who is walking out the back door.

 

From CoinbaseCartel's Onion: