Skip to content
N0N RANSOMWARE CLAIMS DESTRUCTIVE CLOUD ACCESS / ORDER-FILE DELETION ...

N0N RANSOMWARE CLAIMS DESTRUCTIVE CLOUD ACCESS / ORDER-FILE DELETION ...

X • September 20, 2026

Dark Web Intelligence on X: "🇺🇸 FANATICS — N0N RANSOMWARE CLAIMS DESTRUCTIVE CLOUD ACCESS / ORDER-FILE DELETION

A threat actor branding as N0n is advertising what they claim is destructive control over Fanatics (US sports commerce) cloud data, including ongoing deletion of order archives.

• ~46,902 order files (~108 GB) with customer personal data

• Accounts-payable invoices for league/brand partners

• Customer balances, bank-transaction archives, tax-exemption certificates

• Deadline framed around 2026-09-23 01:01 UTC

Destructive-deletion claims are designed for pressure and are frequently unverifiable from the ad alone. Fanatics has not been independently confirmed as compromised in public primary statements located at time of writing. Volume, authenticity, and whether production systems remain under attacker control are unverified.

We assess this as an unverified threat-actor claim involving alleged Fanatics commerce data, NOT confirmation of a Fanatics breach.

If authentic, customer and payment-adjacent records could support fraud, phishing, and extortion follow-ons.

#DDW #DarkWeb #Fanatics #Ransomware #Ecommerce #ThreatIntelligence #CyberSecurity"

🇺🇸 FANATICS — N0N RANSOMWARE CLAIMS DESTRUCTIVE CLOUD ACCESS / ORDER-FILE DELETION

A threat actor branding as N0n is advertising what they claim is destructive control over Fanatics (US sports commerce) cloud data, including ongoing deletion of order archives.

• ~46,902 order files (~108 GB) with customer personal data

• Accounts-payable invoices for league/brand partners

• Customer balances, bank-transaction archives, tax-exemption certificates

• Deadline framed around 2026-09-23 01:01 UTC

Destructive-deletion claims are designed for pressure and are frequently unverifiable from the ad alone. Fanatics has not been independently confirmed as compromised in public primary statements located at time of writing. Volume, authenticity, and whether production systems remain under attacker control are unverified.

We assess this as an unverified threat-actor claim involving alleged Fanatics commerce data, NOT confirmation of a Fanatics breach.

If authentic, customer and payment-adjacent records could support fraud, phishing, and extortion follow-ons.

🇺🇸 FANATICS — N0N RANSOMWARE CLAIMS DESTRUCTIVE CLOUD ACCESS / ORDER-FILE DELETION

A threat actor branding as N0n is advertising what they claim is destructive control over Fanatics (US sports commerce) cloud data, including ongoing deletion of order archives.

• ~46,902 order files (~108 GB) with customer personal data

• Accounts-payable invoices for league/brand partners

• Customer balances, bank-transaction archives, tax-exemption certificates

• Deadline framed around 2026-09-23 01:01 UTC

Destructive-deletion claims are designed for pressure and are frequently unverifiable from the ad alone. Fanatics has not been independently confirmed as compromised in public primary statements located at time of writing. Volume, authenticity, and whether production systems remain under attacker control are unverified.

We assess this as an unverified threat-actor claim involving alleged Fanatics commerce data, NOT confirmation of a Fanatics breach.

If authentic, customer and payment-adjacent records could support fraud, phishing, and extortion follow-ons.

Extracted Entities

Attack Types (1)

Companies (1)

MITRE ATT&CK (1)

Ransomware Groups (1)