French fintech firm Harvest SAS has fallen victim to a sophisticated ransomware attack orchestrated by a newly identified cybercrime group known as “Run Some Wares.” The threat group, which has recently gained attention for targeting high-value sectors, claimed responsibility on April 10, 2025, following an earlier compromise of Harvest’s official website (harvest[.]eu). Although internal systems were reportedly breached on February 27, Harvest initially referred to the event only as a "cyber incident" in public statements made in early April. Harvest, a leading provider of digital wealth management solutions based in Paris, has now suffered a massive data breach as part of a double extortion scheme. The attackers encrypted vital company data and threatened to leak it unless a ransom was paid. After the company failed to meet their demands, the group released a vast collection of sensitive materials via their dark web platform. The exposed data includes confidential financial records, corporate strategies, employee contracts, legal documents, source code, encryption credentials, and a large volume of client-related information. The incident directly impacts Harvest's core operations and poses serious risks for its clients. Cybersecurity professionals warn that the leaked data significantly increases the chances of financial fraud, identity theft, and potential regulatory scrutiny. The breach also endangers third-party partners who may become secondary targets due to their links with Harvest, underscoring the broader consequences of such intrusions. Run Some Wares, having now executed attacks on at least five major companies across the finance and manufacturing sectors, is rapidly building a reputation for highly targeted and sophisticated ransomware campaigns. According to a report by CybelAngel, organizations must strengthen their cybersecurity posture through dark web intelligence gathering, refined incident response plans, and proactive threat monitoring to mitigate the growing risks from such advanced adversaries.
A critical vulnerability has been identified in PX4 Autopilot, widely used in drones and autonomous vehicles across global industries. Highlighted by Cybersecurity and Infrastructu...
Cybercriminals are now weaponizing legitimate hotel reservation data to trick travelers into surrendering their payment details. This "Reservation Hijack Scam" stands out b...
A serious security issue has been discovered in nginx-ui, which can allow attackers to take full control of a system. This vulnerability is tracked as CVE-2026-33026. The problem e...