CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group Lists Hyundai Turkey Assessment Data on Dark Web Leak Site
CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group (TL-2026-2023), also tracked as DataBreachPlus, is a high-severity ransomware operation, first published 2026-08-15. It is attributed to CRPx0 with medium confidence, affects Hyundai Motor Company Hyundai Turkey (hyundai.com.tr) recruitment /, maps to 14 MITRE ATT&CK techniques (T1005, T1027.010, T1036), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-2023
- Threat ID
- TL-2026-2023
- Also known as
- DataBreachPlus
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-08-15
- Last reviewed
- 2026-08-15
- Attribution
- CRPx0
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- automotive, aviation, banking, insurance, defense, retail, health, media-and-marketing, consulting, fashion-and-textiles
- Target regions
- turkey, united states of america, netherlands, sweden, Europe
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group
Malware and tooling: CRPx0, CRPx0 C2-triggered Python encryption framework
CRPx0, an active double-extortion ransomware-as-a-service operation also tracked as DataBreachPlus, listed Hyundai's Turkish operations (hyundai.com.tr) on its dark-web leak site on 2026-08-01, claiming roughly 1.5GB of exfiltrated candidate-assessment and recruitment data with a countdown timer. The listing is one entry in a broader wave in which CRPx0 added at least 10-11 Turkey-based and multinational organizations (Turkish Airlines, Kuveyt Turk, Anadolu Sigorta, Aselsan, and others) to its portal within the same week, aggregating roughly 21.6GB of claimed HR and executive-assessment data for underground sale.
How CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group works
CRPx0 is a financially motivated, Python-based ransomware-as-a-service operation first observed in December 2025 and also marketed under the identity DataBreachPlus. Unlike conventional automated ransomware, CRPx0's loader maintains persistent command-and-control (C2) communication and waits for operator instructions before selectively triggering file encryption -- a 'C2-triggered encryption' model that lets affiliates conduct internal reconnaissance and bulk exfiltration before locking systems, maximizing extortion leverage. The malware suite bundles a ransomware/encryption module (crypter.py, Python Fernet-based encryption, appends the .crpx0 extension) with cryptocurrency-theft components: a clipboard hijacker that regex-matches and swaps wallet addresses in real time, and a BIP39 seed-phrase/config-file harvester (finder.py) that also collects browser cookies, Discord tokens, and other stored credentials. Initial access is achieved via social-engineering lures -- disguised as cracked media/OnlyFans archives or counterfeit FedEx shipping notices -- that deliver malicious ZIP archives containing shortcut files invoking the Python interpreter. Cross-platform persistence is established via a Windows HKCU Run key (observed value name 'CryptoGuard') and a scheduled task ('CryptoUpdate', consistent with schtasks.exe abuse) on Windows, and via LaunchAgent property lists (observed: com.sys32.data.plist, com.cryptoprice.guard.plist) on macOS, with working directories such as ~/.sys32data and %APPDATA%\sys32data. CRPx0 operates a RaaS affiliate program offering a 70% cut of extortion proceeds paid within 24 hours in Bitcoin or Monero, supplying affiliates with payload builders and an onion-hosted negotiation dashboard; negotiation and sales channels include Tox and Session messenger identifiers, a Telegram channel (@DataBreachPlus), and a ProtonMail address, alongside a clearnet leak portal (databreach.space) and a separate .su leak-site domain (crpx0.su). In the confirmed incident anchoring this threat, CRPx0 listed Hyundai's Turkish operations (hyundai.com.tr) on its leak site with 'pending' status, claiming roughly 1.5GB of exfiltrated data comprising candidate interview answers and evaluation scores, recruitment-tracking records, proctored-exam photos/videos, executive psychometric/personality assessment reports, and internal recruitment-related email correspondence. The listing had drawn over 3,100 unique views and carried a countdown timer of roughly four days before threatened public release. This listing is not isolated: within the same week CRPx0 added at least 10-11 Turkey-based and multinational victims to its portal -- including Turkish Airlines (4.2GB claimed, recruitment/assessment data), Kuveyt Turk (0.8GB), Anadolu Sigorta, Aselsan, QNB Finansbank/QNB Turkiye, Dogan Holding, Anadolubank, A101, Togg, and Johnson & Johnson -- aggregating a claimed 21.6GB of HR, recruitment, and executive-assessment data marketed as a bundled underground sale on forums such as altenens.is. The consistent targeting of centralized HR/recruitment-assessment portals across otherwise unrelated sectors (automotive, aviation, banking, insurance, defense, retail) suggests either a shared third-party HR/assessment platform vendor or a deliberate campaign focus on recruitment-data aggregators as a high-value, under-defended target class. CRPx0 has separately been linked to prior high-profile automotive-sector activity in threat-intel reporting (distinct from and unrelated to the 2024 Black Basta attack on Hyundai Motor Europe and the 2025 Hyundai AutoEver America SSN/driver's-license breach, neither of which has been attributed to CRPx0).
MITRE ATT&CK techniques used in TL-2026-2023
Collection
T1005 Data from Local System; T1113 Screen Capture
Defense Evasion
T1027.010 Obfuscated Files or Information: Command Obfuscation; T1036 Masquerading
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1543.001 Create or Modify System Process: Launch Agent; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Execution
T1059.006 Command and Scripting Interpreter: Python; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Credential Access
T1552.001 Unsecured Credentials: Credentials In Files; T1555 Credentials from Password Stores
Initial Access
Affected products and versions in CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group
- Hyundai Motor Company — Hyundai Turkey (hyundai.com.tr) recruitment / candidate-assessment systems
Vulnerable versions: N/A -- data-extortion claim against recruitment data, not a software version - Turkish Airlines (THY) — Recruitment / personnel-assessment data
Vulnerable versions: N/A - Kuveyt Turk — Internal data (financial services)
Vulnerable versions: N/A - Anadolu Sigorta — Internal data (insurance)
Vulnerable versions: N/A - Aselsan — Internal data (defense electronics)
Vulnerable versions: N/A
Remediation for CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group
Patches
- Not applicable -- this is a social-engineering-delivered ransomware/data-extortion campaign, not a software vulnerability; no vendor patch mitigates initial access
Immediate actions
- Identify and inventory any HR/recruitment-assessment portals (self-hosted or third-party) that store candidate interview data, proctored-exam media, or executive psychometric reports, and verify their exposure/access controls
- Monitor for the group's negotiation/leak channels (Telegram @DataBreachPlus, Tox ID 17EB54B8455144E088C7E77F88A97221C319F0CFE4FE306853EEB113EE8DB5607BB6EE481C7C, Session ID 050546f6719172e04151c31acb37a242fa3eeff5766aa57331d26cc06e83e9e25b) and leak domains (databreach.space, crpx0.su) for organizational mentions
- Block known CRPx0/DataBreachPlus C2 and backup infrastructure at the network perimeter: fanonlyatn.xyz, caribb.ru, mekhovaya-shuba.ru, beboss34.ru, and IPs 31.31.198.206, 145.43.86.37, 43.165.176.201, 210.149.87.82
- Hunt for the documented Windows persistence artifacts (HKCU Run key value 'CryptoGuard', scheduled task 'CryptoUpdate', working directory %APPDATA%\sys32data) and macOS artifacts (LaunchAgents com.sys32.data.plist / com.cryptoprice.guard.plist, working directory ~/.sys32data)
Workarounds
- Restrict outbound access from HR/recruitment-assessment systems to only required SaaS endpoints to limit bulk exfiltration paths
- Enforce MFA and network segmentation for any centralized recruitment/candidate-assessment portal given the group's apparent focus on this data class
Longer-term hardening
- Restrict unauthorized Python interpreter execution via AppLocker/WDAC (Windows) and Gatekeeper/notarization enforcement (macOS) given CRPx0's Python-based delivery
- Deploy EDR/DLP tuned to detect clipboard-content modification (cryptocurrency-clipper behavior) and bulk local file enumeration targeting seed-phrase/wallet-config filenames
- Monitor outbound connections for beaconing to newly registered or low-reputation domains, particularly .ru and .xyz TLDs, consistent with the group's C2-triggered-encryption model
- User-awareness training addressing the group's specific lure themes (fake OnlyFans/cracked-media archives, counterfeit FedEx shipping notices) delivering password-protected or disguised-shortcut ZIP archives
Timeline of CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group
- CRPx0 (DataBreachPlus) ransomware-as-a-service operation first observed/tracked by researchers, per WatchGuard's CRPxO ransomware tracker.
- Early wave of CRPx0 victim notifications concentrated in the US, per WatchGuard tracker data (38 known victims, primarily US with additional Netherlands and Sweden victims).
- Mallory.ai publishes a detailed CRPx0/DataBreachPlus malware profile documenting the Python-based loader, Fernet-encryption ransomware module, clipper/seed-harvester components, IOCs, and MITRE ATT&CK mapping.
- DuoCircle's weekly cybersecurity news roundup reports CRPx0's listing of Hyundai's Turkish operations with 1.5GB of claimed exfiltrated assessment data.
- Anadolu Sigorta (Turkish insurance) is recorded as a CRPxO-claimed victim on Ransomware.live and corroborated by RedPacketSecurity.
- CRPxO claims a ransomware/data-extortion attack on Kuveyt Turk (Turkish banking sector), publishing 0.8GB of claimed exfiltrated data.
- Brinztech reports CRPxO aggregating claims across 11 major Turkish and multinational enterprises into a single ~21.6GB HR/executive-records sale thread posted to the altenens.is underground forum.
- FalconFeeds.io publishes an alert identifying that CRPx0 has added multiple Turkey-based/multinational victims to its dark-web portal in the same window: A101, Aselsan, Hyundai, Anadolu Sigorta, Dogan Holding, Johnson & Johnson, Turkish Airlines, Anadolubank, QNB Turkiye, and Kuveyt Turk.
- CRPx0 claims a breach of Turkish Airlines (THY), advertising 4.2GB of claimed candidate-record, interview-result, and psychometric-report data; status reported as pending verification.
- GBHackers reports CRPx0 listed Hyundai's Turkish operations (hyundai.com.tr) on its dark-web leak site with a 'pending' status, claiming ~1.5GB of candidate-assessment/recruitment data, over 3,100 unique leak-site views, and a countdown timer of roughly four days.
- DarknetSearch publishes an analysis of the CRPx0 Hyundai Turkey leak-site claim, noting the claim remains unverified and describing the group's general double-extortion tactics.
Sources cited for CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group
- CRPx0 Ransomware Claims Hyundai Turkey Breach, Steals 1.5GB of Assessment Data
- CRPxO Ransomware Group Profile
- Crpx0 Ransomware Operations: Double Extortion, Crypto Theft, and Network Footprint
- CRPx0 Ransomware Operation Deploys Cross-Platform Python Framework with C2-Triggered Encryption
- Threat Actor 'CRPxO' Claims 21.6 GB Data Breach Exposing HR and Executive Records Across 11 Major Turkish and Multinational Enterprises
- Darknet Search Tracks CRPx0 Hyundai Breach
- CRPxO Ransomware Recruits Affiliates for Dual Extortion (Clipper/Stealer Campaign)
- CRPx0 / DataBreachPlus Malware Profile
- Iran Hits Infrastructure, EY Data Leak, CRPx0 Breaches Hyundai -- Cybersecurity News [July 27, 2026]
- FalconFeeds.io: CRPx0 ransomware group has added multiple Turkey-based victims to their dark web portal
- Hackmanac: CRPx0 hacking group claims to have breached Turkish Airlines
- Ransom! KUVEYT TURK (JUL-2026)
- Ransomware.live -- Victim: ANADOLU SIGORTA (CRPxO)
- [CRPXO] - Ransomware Victim: ANADOLU SIGORTA
- [CRPXO] - Ransomware Victim: KUVEYT TURK
Threats related to CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group
Detection coverage for TL-2026-2023
As of 2026-08-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2023 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2023
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.