Security News

Ransomware Affiliate Goes Rogue, Running a Private Extortion Site and Keeping the Proceeds

Infosecurity Magazine · 6 Oct 2026
Key Takeaway Scan your code repositories, including their full history, for leaked passwords, keys and tokens, rotate any you find, and make sure internet-facing APIs require authentication.

Threat intelligence firm CloudSEK has detailed how a Russian-speaking cybercriminal known as "Azazel" betrayed the ransomware-as-a-service (RaaS) group he worked with. In a report titled The Gentlemen Files, published on October 5, researchers said they found two exposed servers he managed. They held several terabytes of data stolen from logistics, insurance, pharmaceutical, AI, medical device and government victims across six countries. According to the report, he built his own leak site, called Leakned, and collected extortion payments without routing them through The Gentlemen program.

CloudSEK described two different attack methods. In one, Azazel harvested secrets from exposed GitLab infrastructure, including access tokens, database credentials, API keys and SSH private keys, which gave access to cloud systems and databases. The report suggests developers had deleted these secrets from the current version of their code, but they remained in earlier commits, where he found them.

In the other, he targeted a medical-imaging company through a server-side request forgery flaw in an unauthenticated AI medical-imaging API. This let him discover internal services and then hunt for credentials in a weeks-long, multi-stage compromise that led to 6TB of stolen data. CloudSEK also said he used an AI coding assistant, connected via MCP, to send commands to a compromised machine, and judged his skill well above that of a typical affiliate.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.