Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)
Vexy Ransomware Claims Data-Extortion Attack on Majani (TL-2026-2713) is a medium-severity ransomware operation, first published 2026-09-25. It is attributed to Vexy Ransomware with low confidence, affects Majani Insurance Brokers Ltd Corporate identity/SaaS environment, maps to 12 MITRE ATT&CK techniques (T1078, T1078.004, T1090.003), and is covered by 9 detection rules and 12 indicators of compromise.
Key facts for TL-2026-2713
- Threat ID
- TL-2026-2713
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-09-25
- Last reviewed
- 2026-09-25
- Attribution
- Vexy Ransomware
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- insurance, finance
- Target regions
- East Africa
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Vexy Ransomware Claims Data-Extortion Attack on Majani
Malware and tooling: ParanoidLab, Tox
Emerging ransomware/data-extortion group Vexy Ransomware has listed Majani Insurance Brokers, a Kenyan independent insurance broker, on its TOR data-leak site, claiming 2.1 GB of exfiltrated data and threatening release absent negotiation. The claim follows a pre-existing infostealer-driven credential/cookie exposure and an unresolved external vulnerability in Majani's environment, and remains independently unverified.
How Vexy Ransomware Claims Data-Extortion Attack on Majani works
Majani Insurance Brokers Ltd, a Kenyan independent insurance brokerage operating at majaninsure.com and arranging general business, motor, medical, life, investment, marine, liability, property and agricultural coverage for corporate and individual clients, was named on September 25, 2026 at 13:24 UTC as a victim on the TOR-hosted data-leak site of Vexy Ransomware, an emerging ransomware/data-extortion operation first observed roughly three weeks earlier (earliest tracked victim dated September 2, 2026). The group's leak-site statement claims Majani has been compromised and that sensitive data will be released unless negotiations commence; the listing claims 2.1 GB of exfiltrated data. As of this writing, Vexy's claim is unverified and Majani has issued no public confirmation.
Prior to the leak-site posting, a third-party exposure assessment (ParanoidLab, cited by DeXpose) of Majani's environment identified an active infostealer-driven credential-exposure footprint: 55 passwords (4 flagged critical), 7 session cookies, and compromised credentials tied to 1 confirmed end-user account plus 1 third-party/vendor employee account, alongside detected use of Google Workspace and Microsoft 365, and one identified external attack-surface vulnerability. This combination -- infostealer-harvested credentials and session cookies plus an unresolved internet-facing weakness -- is consistent with, though does not by itself prove, a credential- or exploit-driven initial-access path into a cloud-identity environment ahead of the extortion claim. No encryptor sample, ransom note, or confirmation of file/system encryption has been publicly identified for this specific victim, which distinguishes the incident, at least in its currently public form, as a data-theft/extortion claim rather than confirmed encryption-based ransomware.
Vexy Ransomware itself is a newly emerged, fast-moving data-broker / double-extortion operation first tracked in early September 2026. Across its first three-to-four weeks of activity it posted 16-17 victim listings spanning 11 countries -- concentrated in India, with additional victims in Brazil, Vietnam, Italy, Japan, the UK, the US, Argentina, Mexico, Ecuador and now Kenya -- and roughly 580 GB of cumulative claimed exfiltrated data, most heavily targeting technology, retail/e-commerce and manufacturing organizations. The group operates a TOR (.onion) data-leak site (Apache 2.4.68 on Debian, intermittently available across trackers) and negotiates through a published Tox messenger ID, with two Bitcoin wallet addresses associated with ransom collection. As a licensed insurance intermediary, Majani falls under Kenya's Insurance Regulatory Authority (IRA) rules -- introduced in 2025 -- which mandate disclosure of major cyber incidents, including unauthorized access to customer data, within 24 hours of detection.
MITRE ATT&CK techniques used in TL-2026-2713
Initial Access
T1078 Valid Accounts; T1078.004 Cloud Accounts; T1190 Exploit Public-Facing Application
Command and Control
Collection
T1213 Data from Information Repositories
Credential Access
T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information
Impact
Affected products and versions in Vexy Ransomware Claims Data-Extortion Attack on Majani
- Majani Insurance Brokers Ltd — Corporate identity/SaaS environment (Google Workspace, Microsoft 365) and public-facing web infrastructure (majaninsure.com)
Vulnerable versions: N/A - targeted organization/tenant environment, not a versioned software product
Fixed in: N/A
Remediation for Vexy Ransomware Claims Data-Extortion Attack on Majani
Patches
- No CVE or vendor patch has been publicly identified for this claim; remediation centers on closing the external attack-surface vulnerability and completing a full compromise assessment
Immediate actions
- Rotate credentials for all Google Workspace and Microsoft 365 accounts, prioritizing the 1 confirmed compromised end-user account and 1 third-party/vendor employee account identified in the ParanoidLab exposure scan
- Invalidate active session cookies/tokens for the affected accounts to neutralize the 7 leaked cookies and force re-authentication
- Engage incident-response and dark-web-monitoring resources to validate the scope of the claimed 2.1 GB exfiltration and to monitor the Vexy Ransomware TOR leak site for any published data
- Report the incident to Kenya's Insurance Regulatory Authority (IRA) within the mandatory 24-hour disclosure window applicable to licensed insurance intermediaries
Workarounds
- Until credential rotation and MFA enforcement are complete, restrict access to Google Workspace/Microsoft 365 admin consoles and sensitive data repositories to a monitored allow-list of source IPs/devices
Longer-term hardening
- Deploy phishing-resistant MFA across all SaaS/identity providers (Google Workspace, Microsoft 365) to blunt reuse of infostealer-harvested credentials
- Stand up continuous external attack-surface monitoring to identify and close internet-facing vulnerabilities such as the one flagged in the pre-claim scan
- Harden against browser-credential and session-cookie theft (browser credential-store protections, cookie re-binding, EDR detection for stealer-style browser-data access)
- Establish a vendor/third-party risk program covering credential hygiene for outsourced or partner staff with access to Majani systems
Timeline of Vexy Ransomware Claims Data-Extortion Attack on Majani
- Kenya's Insurance Regulatory Authority (IRA) introduces a framework requiring licensed insurers/intermediaries to report major cyber incidents, including unauthorized access to customer data, within 24 hours of detection -- the regulatory backdrop Majani now falls under.
- Vexy Ransomware's earliest tracked victim listing (a Brazilian manufacturing organization) marks the group's first public activity, per WatchGuard's Ransomware Tracker.
- Vexy Ransomware claims Engefitas, a Brazilian adhesive manufacturer, with 27.25 GB of allegedly exfiltrated data, an early indicator of the group's double-extortion data-broker model.
- Vexy Ransomware claims Sancity Soft Touch, an Indian IT services company, continuing a pattern of rapid, geographically dispersed victim postings.
- GalaxyWarden publishes breach analysis of the Sancity listing, noting Vexy's practice of posting claims that are frequently unverified and sometimes recycle older data.
- DeXpose publishes a threat-intelligence blog documenting the Vexy Ransomware claim against Majani Insurance Brokers and recommending dark-web monitoring, compromise assessment, and MFA deployment.
- Vexy Ransomware lists Majani Insurance Brokers on its TOR data-leak site at 13:24 UTC, claiming 2.1 GB of exfiltrated data and threatening release absent negotiation.
- A ParanoidLab exposure scan (cited by DeXpose) of Majani Insurance Brokers' environment identifies 55 exposed passwords (4 critical), 7 session cookies, 1 compromised end-user account, 1 compromised third-party/vendor employee account, and 1 external attack-surface vulnerability, alongside detected Google Workspace and Microsoft 365 usage.
- Ransomware-tracking services (ransomware.live, RansomLook) show Vexy Ransomware with 16-17 total victim postings across 11 countries and roughly 580 GB of cumulative claimed exfiltrated data since its early-September emergence; the group's TOR leak site shows intermittent availability (52%-90% uptime depending on tracker).
Sources cited for Vexy Ransomware Claims Data-Extortion Attack on Majani
- Victim: Majani Insurance Brokers – Vexy Ransomware
- Vexy Ransomware Strikes Majani Insurance Brokers
- Vexy Ransomware | WatchGuard Technologies Ransomware Tracker
- Group: Vexy Ransomware
- Vexy · RansomLook
- Vexy Ransomware Strikes Brazilian Adhesive Producer Engefitas
- Sancity Listed by Vexy Ransomware Group
- MAJANI INSURANCE BROKERS – HackNotice
- Kenya's Watchdog Tightens Grip on Insurers After Spike in Cyber Attacks and Data Breaches
- Kenyan Insurance Companies Ordered to Report Cyber Attacks Within 24 Hours
More in ransomware
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limited
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service Principals
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal Prison
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas
Detection coverage for TL-2026-2713
As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2713 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.