Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)

Vexy Ransomware Claims Data-Extortion Attack on Majani (TL-2026-2713) is a medium-severity ransomware operation, first published 2026-09-25. It is attributed to Vexy Ransomware with low confidence, affects Majani Insurance Brokers Ltd Corporate identity/SaaS environment, maps to 12 MITRE ATT&CK techniques (T1078, T1078.004, T1090.003), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2713

Threat ID
TL-2026-2713
Severity
MEDIUM
Status
ACTIVE
Category
RANSOMWARE
First published
2026-09-25
Last reviewed
2026-09-25
Attribution
Vexy Ransomware
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
insurance, finance
Target regions
East Africa
Detection rules
9
Indicators of compromise
12

Malware and tooling in Vexy Ransomware Claims Data-Extortion Attack on Majani

Malware and tooling: ParanoidLab, Tox

Emerging ransomware/data-extortion group Vexy Ransomware has listed Majani Insurance Brokers, a Kenyan independent insurance broker, on its TOR data-leak site, claiming 2.1 GB of exfiltrated data and threatening release absent negotiation. The claim follows a pre-existing infostealer-driven credential/cookie exposure and an unresolved external vulnerability in Majani's environment, and remains independently unverified.

How Vexy Ransomware Claims Data-Extortion Attack on Majani works

Majani Insurance Brokers Ltd, a Kenyan independent insurance brokerage operating at majaninsure.com and arranging general business, motor, medical, life, investment, marine, liability, property and agricultural coverage for corporate and individual clients, was named on September 25, 2026 at 13:24 UTC as a victim on the TOR-hosted data-leak site of Vexy Ransomware, an emerging ransomware/data-extortion operation first observed roughly three weeks earlier (earliest tracked victim dated September 2, 2026). The group's leak-site statement claims Majani has been compromised and that sensitive data will be released unless negotiations commence; the listing claims 2.1 GB of exfiltrated data. As of this writing, Vexy's claim is unverified and Majani has issued no public confirmation.

Prior to the leak-site posting, a third-party exposure assessment (ParanoidLab, cited by DeXpose) of Majani's environment identified an active infostealer-driven credential-exposure footprint: 55 passwords (4 flagged critical), 7 session cookies, and compromised credentials tied to 1 confirmed end-user account plus 1 third-party/vendor employee account, alongside detected use of Google Workspace and Microsoft 365, and one identified external attack-surface vulnerability. This combination -- infostealer-harvested credentials and session cookies plus an unresolved internet-facing weakness -- is consistent with, though does not by itself prove, a credential- or exploit-driven initial-access path into a cloud-identity environment ahead of the extortion claim. No encryptor sample, ransom note, or confirmation of file/system encryption has been publicly identified for this specific victim, which distinguishes the incident, at least in its currently public form, as a data-theft/extortion claim rather than confirmed encryption-based ransomware.

Vexy Ransomware itself is a newly emerged, fast-moving data-broker / double-extortion operation first tracked in early September 2026. Across its first three-to-four weeks of activity it posted 16-17 victim listings spanning 11 countries -- concentrated in India, with additional victims in Brazil, Vietnam, Italy, Japan, the UK, the US, Argentina, Mexico, Ecuador and now Kenya -- and roughly 580 GB of cumulative claimed exfiltrated data, most heavily targeting technology, retail/e-commerce and manufacturing organizations. The group operates a TOR (.onion) data-leak site (Apache 2.4.68 on Debian, intermittently available across trackers) and negotiates through a published Tox messenger ID, with two Bitcoin wallet addresses associated with ransom collection. As a licensed insurance intermediary, Majani falls under Kenya's Insurance Regulatory Authority (IRA) rules -- introduced in 2025 -- which mandate disclosure of major cyber incidents, including unauthorized access to customer data, within 24 hours of detection.

MITRE ATT&CK techniques used in TL-2026-2713

Initial Access

T1078 Valid Accounts; T1078.004 Cloud Accounts; T1190 Exploit Public-Facing Application

Command and Control

T1090.003 Multi-hop Proxy

Collection

T1213 Data from Information Repositories

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.001 Domains

Reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information

Impact

T1657 Financial Theft

Affected products and versions in Vexy Ransomware Claims Data-Extortion Attack on Majani

  • Majani Insurance Brokers Ltd — Corporate identity/SaaS environment (Google Workspace, Microsoft 365) and public-facing web infrastructure (majaninsure.com)
    Vulnerable versions: N/A - targeted organization/tenant environment, not a versioned software product
    Fixed in: N/A

Remediation for Vexy Ransomware Claims Data-Extortion Attack on Majani

Patches

  • No CVE or vendor patch has been publicly identified for this claim; remediation centers on closing the external attack-surface vulnerability and completing a full compromise assessment

Immediate actions

  • Rotate credentials for all Google Workspace and Microsoft 365 accounts, prioritizing the 1 confirmed compromised end-user account and 1 third-party/vendor employee account identified in the ParanoidLab exposure scan
  • Invalidate active session cookies/tokens for the affected accounts to neutralize the 7 leaked cookies and force re-authentication
  • Engage incident-response and dark-web-monitoring resources to validate the scope of the claimed 2.1 GB exfiltration and to monitor the Vexy Ransomware TOR leak site for any published data
  • Report the incident to Kenya's Insurance Regulatory Authority (IRA) within the mandatory 24-hour disclosure window applicable to licensed insurance intermediaries

Workarounds

  • Until credential rotation and MFA enforcement are complete, restrict access to Google Workspace/Microsoft 365 admin consoles and sensitive data repositories to a monitored allow-list of source IPs/devices

Longer-term hardening

  • Deploy phishing-resistant MFA across all SaaS/identity providers (Google Workspace, Microsoft 365) to blunt reuse of infostealer-harvested credentials
  • Stand up continuous external attack-surface monitoring to identify and close internet-facing vulnerabilities such as the one flagged in the pre-claim scan
  • Harden against browser-credential and session-cookie theft (browser credential-store protections, cookie re-binding, EDR detection for stealer-style browser-data access)
  • Establish a vendor/third-party risk program covering credential hygiene for outsourced or partner staff with access to Majani systems

Timeline of Vexy Ransomware Claims Data-Extortion Attack on Majani

  • Kenya's Insurance Regulatory Authority (IRA) introduces a framework requiring licensed insurers/intermediaries to report major cyber incidents, including unauthorized access to customer data, within 24 hours of detection -- the regulatory backdrop Majani now falls under.
  • Vexy Ransomware's earliest tracked victim listing (a Brazilian manufacturing organization) marks the group's first public activity, per WatchGuard's Ransomware Tracker.
  • Vexy Ransomware claims Engefitas, a Brazilian adhesive manufacturer, with 27.25 GB of allegedly exfiltrated data, an early indicator of the group's double-extortion data-broker model.
  • Vexy Ransomware claims Sancity Soft Touch, an Indian IT services company, continuing a pattern of rapid, geographically dispersed victim postings.
  • GalaxyWarden publishes breach analysis of the Sancity listing, noting Vexy's practice of posting claims that are frequently unverified and sometimes recycle older data.
  • DeXpose publishes a threat-intelligence blog documenting the Vexy Ransomware claim against Majani Insurance Brokers and recommending dark-web monitoring, compromise assessment, and MFA deployment.
  • Vexy Ransomware lists Majani Insurance Brokers on its TOR data-leak site at 13:24 UTC, claiming 2.1 GB of exfiltrated data and threatening release absent negotiation.
  • A ParanoidLab exposure scan (cited by DeXpose) of Majani Insurance Brokers' environment identifies 55 exposed passwords (4 critical), 7 session cookies, 1 compromised end-user account, 1 compromised third-party/vendor employee account, and 1 external attack-surface vulnerability, alongside detected Google Workspace and Microsoft 365 usage.
  • Ransomware-tracking services (ransomware.live, RansomLook) show Vexy Ransomware with 16-17 total victim postings across 11 countries and roughly 580 GB of cumulative claimed exfiltrated data since its early-September emergence; the group's TOR leak site shows intermittent availability (52%-90% uptime depending on tracker).

Sources cited for Vexy Ransomware Claims Data-Extortion Attack on Majani

More in ransomware

Detection coverage for TL-2026-2713

As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2713 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats