>>520162737 (OP)
Their GRU buddies managed to detonate ransomware on a few thousand systems largely taking down manufacturing operations in one area of our Fortune 500 company (hint: it was a direct result of 3 years of jeetification at that point)
My division was better safeguarded than most against ransomware so we only lost ~5TB of dated spreadsheets and testing tools exfiltrated from an old internal file share
They demanded 7M ransom for the ransomware decryption keys and taking down alll the stolen data they had already puished on Tor (not just ours they had like 35 TB exfiltrated from across the org) plus even a detailed pen-test report how they got in. They even threatened to snitch to SEC for breach non-disclosure if we fail to do so in time ourselves (recent trend)
We pretended to negotiate and actually got to work, in less than 2 weeks business was back as usual. SEC 8-K was never filed.
In late Dec 2023 FBI finally seized the rack with servers hosting their Tor leak site and our stolen files. It was located in Tampa, Florida, lol. Leak site domain went offline and never came back.
Extremely skilled, motivated, funded, tough opps but predictable. Work best against multinational conglomerates with exploitable weak links (IT jeets) and dumb executives