---
title: Ransomware Groups Use Artificial Intelligence to Refine Extortion Tactics and Target High-Value Victims
url: https://www.elseif.net/ransomware-groups-use-artificial-intelligence-to-refine-extortion-tactics-and-target-high-value-victims
published: 2026-10-09T14:05:05+00:00
language: en
section: Agents
source: https://www.cybersecurity360.it/nuove-minacce/ransomware/levoluzione-del-ransomware-come-lai-potenzia-le-negoziazioni/
organizations: FulcrumSec, Novo Nordisk, ChatGPT, GitHub, DataBreaches.net, Seriously Risky Biz
publisher: elseif
---

# Ransomware Groups Use Artificial Intelligence to Refine Extortion Tactics and Target High-Value Victims

Modern ransomware collectives are shifting their operational focus from technical system intrusion to strategic data extortion by employing artificial intelligence to optimize negotiations and maximize financial gains. This evolution marks a departure from traditional hacking methods, as criminal organizations now prioritize the theft of sensitive information over the encryption of files, using advanced language models to identify high-value data and craft persuasive demands against targeted corporations.

The landscape of cyber threats has transformed because many organizations have improved their backup procedures, allowing them to restore data without paying ransoms. Consequently, attackers have adapted by threatening to publish stolen confidential information rather than simply locking systems. Analyst Tom Uren described this shift during a podcast discussion, noting that while many cybersecurity professionals view ransomware as a hacking enterprise, it is increasingly becoming an extortion problem centered on convincing victims to pay money through psychological pressure rather than increased technical intrusion.

Criminal groups are adopting a high-value, low-volume business model to counter declining global ransom payment rates. Instead of launching widespread attacks that require significant operational effort to manage encryption algorithms, these groups now reduce the total number of incidents to focus on a few selected victims. They dedicate extensive time to analyzing stolen materials to extract the maximum economic value from each breach. This approach turns extortion into a task of high-precision analytics, where attackers study the compromised data deeply before making contact.

The group known as FulcrumSec exemplifies this new methodology through its attack on the pharmaceutical company Novo Nordisk. Rather than developing complex zero-day exploits to penetrate networks, the attackers utilized simple access methods, often relying on previously stolen credentials. The sophistication of the operation lay in the post-breach phase, where the group focused on understanding the expropriated data. In this specific case, the attackers stole proprietary artificial intelligence models and vast amounts of information from cloud storage systems and code repositories.

FulcrumSec spent up to six months examining the stolen material, utilizing language models to extract the most valuable insights. In a notable instance, the group used ChatGPT accounts stolen from the victim itself to process the data. This analytical work allowed the extortionists to present highly detailed ransom demands, explicitly stating why the stolen data was important according to their own large language model analysis. When direct negotiations failed, the group escalated pressure by sending a report to a public data breach platform, highlighting alleged corporate vulnerabilities and the value of the stolen intellectual property to cause reputational damage.

Novo Nordisk faced a second extortion attempt shortly after the initial theft, with another cyber actor demanding fifty million dollars. The pharmaceutical company maintained a rigid stance and refused to pay any ransom. Despite their criminal activities, members of FulcrumSec attempted to present themselves as ethical operators in their communications, claiming they did not wish to publish sensitive personal data and even asking the victim to help draft documents securely before any potential release.

The use of advanced language models has also removed historical barriers for non-English speaking criminal groups. Previously, a lack of familiarity with Western laws and the English language hindered negotiation efforts. Now, artificial intelligence allows these groups to generate persuasive, error-free communications, effectively solving cultural and linguistic obstacles. By automating the search through massive volumes of stolen data, extortionists can rapidly identify critical leverage points to use during negotiations, signaling a future where artificial agents may further refine these coercive tactics.
