Summary
Written by ThreatClusterfrom file listing, victim profile, leak post, screenshot, ransom noteThe leak claims password hashes, passwords (including plaintext passwords), sensitive information and clients’ data were stolen from Terralogic (domain corp.terralogic.com), with affected platforms including Active Directory, Nutanix, Hyper-V, NAS, NTLM hash databases and password manager. SECP0 states the data will be published, followed by clients’ data, and that SEC complaint forms will be filed; they warn of consequences for Terralogic and its clients, including lawsuits. Publication status is published, posted on 2025-03-14.
Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.
Victim profile
- Platforms
- Nutanix Hyper-V NAS Active Directory
What was taken
Announcement for the Terralogic and its clients
Ransom note
Published by the group on their leak site, reproduced verbatim.
1. We will begin publishing their data. 2. This will be followed by the publication of their clients' data. 3. Alongside the release of client data, we will file complaint forms with the SEC, particularly regarding clients related to NASDAQ (hello, market maker). 4. Next, we will notify all affected parties: employees, clients of their clients, including clients of the laboratory network. This will lead to devastating consequences for everyone, especially for Terralogic, as the owners of businesses that entrusted their networks to Terralogic will have the right to file lawsuits. We predict that if Terralogic continues to ignore us completely, it will end with the company's leadership in prison and some client businesses shutting down due to investor withdrawal. The choice is yours.
Also stated on the leak page
Fields this group publishes that do not map to a standard column. Labels are the site's own.
- breach_details
- The primary domain corp.terralogic.com offline; encryption of Nutanix servers, Hyper-V servers, and NAS devices with backups.
- proof_pack_link
- /files/ceb12a9f49ae0c43/
Leak-site images (1)
Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.