✅ Report Title: Threat Group Profiling - Crimson Collective
✅ Executive Summary:
📌 Who is the Crimson Collective?
- The Crimson Collective emerged in September 2025 as an international cyber threat group that conducts financially motivated data theft and extortion activities targeting various industries such as gaming, telecommunications, and software.
- The group announces its hacking incidents by publishing stolen data samples on Telegram and attempts to negotiate with victim companies through multiple communication channels.
- As of October 20, 2025, their Telegram channel had approximately 2,200 subscribers.
- In September 2025, the group launched its first attack by defacing the website of a Japanese gaming company (referred to as Company N) and claiming to have gained internal system access.
- In October 2025, the group demanded ransom from an enterprise open-source software company (referred to as Company R), threatening to leak data. After the company refused, they released a list of approximately 800 Customer Engagement Reports (CERs).
- The group also announced collaboration with Scattered Lapsus$ Hunters to run an “Extortion-as-a-Service” model, posting Company R-related data for sale on a Data Leak Site (DLS) and initiating ransom negotiations.
📌 Activity Timeline (Chronological Order)
| No | Date (UTC+9) | Target Country | Target | Description |
|---|---|---|---|---|
| 1 | 2025-09-24 11:06 | Japan | N******* | The hacker “crimson” defaced the subdomain topics of Japanese gaming company N. |
| 2 | 2025-09-24 | - | - | Launched Telegram channel “Crimson Collective.” |
| 3 | 2025-09-24 23:30 | Japan | N******* | Claimed to have attacked Company N. |
| 4 | 2025-09-26 01:20 | Mexico | Claro Colombia | Claimed to have attacked Mexican telecom company Claro Colombia (claro[.]com[.]co). |
| 5 | 2025-10-01 22:58 | United States | R** H** | Claimed to have reported a vulnerability to U.S. software Company R. |
| 6 | 2025-10-01 23:06 | United States | R** H** | Claimed to have stolen 28,000 repositories and Consulting Engagement Reports (CER) from Company R. |
| 7 | 2025-10-01 23:07 | United States | R** H** | Claimed to have compromised Company R’s infrastructure and published a file tree. |
| 8 | 2025-10-01 23:14 | United States | R** H** | Published a screenshot of stolen backup file “git[.]tar[.]gz” (570GB). |
| 9 | 2025-10-06 03:20 | United States | R** H** | Announced collaboration with Scattered Lapsus$ Hunters and launched a Company R's Data Leak Site (DLS). |
| 10 | 2025-10-11 04:30 | Germany | Yunex Traffic | Claimed to sell 1TB of data from German mobility company Yunex Traffic. |
| 11 | 2025-10-11 06:55 | Thailand | JobThai | Claimed to sell S3 Bucket and user database from Thai job platform JobThai. |
| 12 | 2025-10-11 10:27 | United States, Brazil | ChevroletDigital | Claimed to sell ChevroletDigital (chevroletdigital-pp[.]accurate[.]com[.]br) customer IDs, financial data, certificates, and internal emails. |
| 13 | 2025-10-11 10:35 | Japan | N******* | Published stolen screenshots from Company N. |
| 14 | 2025-10-11 23:42 | Colombia | Loteria de Medellin | Claimed to sell Loteria de Medellin (loteriademedellin[.]com[.]co) database (1TB compressed). |
| 15 | 2025-10-13 23:58 | United States | R** H** | Announced sale of Company R's Consulting Data. |
| 16 | 2025-10-13 23:58 | Mexico | Claro Colombia | Announced sale of Claro Colombia (claro[.]com[.]co) database. |
| 17 | 2025-10-15 09:34 | United States | R** H** | Exclusive sale announcement for Company R's Consulting Data ($70,000–$100,000). |
| 18 | 2025-10-15 09:34 | Mexico | Claro Colombia | Exclusive sale announcement for Claro Colombia Database ($20,000–$30,000). |
📌 Key Activities
1) Website Defacement of Japanese Game Company (Company N)
- (2025-09-24 11:06) The topic domain of a Japanese gaming giant company (Company N) was defaced by a hacker known as “crimson.”
- (2025-09-24 23:30) After launching their Telegram channel, Crimson Collective posted: “found inside n******* data that mario got cucked by peach that was the final scenario,” along with screenshots allegedly showing access to Company N’s internal systems.
- (2025-10-11 10:35) Crimson Collective later posted, “Who said we did not have n******* topics files?” sharing further screenshots to support their hacking claims.
- The leaked screenshots contained multiple folders labeled “infra-test,” “mail,” “dev,” “production,” and “staging.”
- (2025-10-15) According to Japan’s Sankei Shimbun, Company N stated: “There is no confirmation of personal data leakage or internal intrusion. Some external servers displaying our website were altered, but no customer data was affected.”
2) Data Theft from Enterprise Open-Source Software Company (Company R)
- (2025-10-01 22:58) Crimson Collective claimed they reported a vulnerability to Company R’s security team but received no response.
- (2025-10-01 23:06) The group posted an image of git[.]tar[.]gz on Telegram, claiming to have stolen approximately 570GB of data from over 28,000 internal repositories of Company R.
- The stolen data reportedly included around 800 Customer Engagement Reports (CERs) containing sensitive client information such as network details and authentication tokens.
- (2025-10-03) Company R confirmed unauthorized access to its internal GitLab instance, stating: “An unauthorized third party copied a portion of data from our internal GitLab instance used for collaboration.”
3) Collaboration with Scattered Lapsus$ Hunters
- (2025-10-06) After publicizing the data breach, Crimson Collective announced cooperation with ShinyHunters and Scattered Lapsus$ Hunters.
- (2025-10-10) Scattered Lapsus$ Hunters stated they would negotiate ransom on behalf of Crimson Collective, threatening to release the data if no agreement was reached by October 10 (local time).
- (2025-10-16) Scattered Lapsus$ Hunters’ Data Leak Site (DLS) was defaced by an anonymous user and became inaccessible.
- The anonymous user claimed to be a former employee of ChangeNOW, previously hacked by Scattered Lapsus$ Hunters, and said they conducted the defacement out of revenge after being fired due to the breach incident.
🧑💻 Author: S2W TALON
👉 Contact us: https://s2w.inc/en/contact
*The full report is available upon request or with a subscription to the S2W platform.