RANSOMWARE VICTIMDUPLICATE CLAIM

UMSA

shadowbyt3$📅 February 17, 2026
8
same group

Attack Intelligence

UMSA was compromised in a ransomware attack attributed to shadowbyt3$ in February 2026. The organization, operating in an undisclosed sector in Unknown, was added to the group's data leak site as part of an extortion campaign.

shadowbyt3$ operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

File: UMSA_LEAK.7z

Additional Details

Other Victims — shadowbyt3$ (8)

Quick Facts

Attack DateFeb 17, 2026
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

shadowbyt3$
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.