Wallstreet is a nascent cyber extortion and ransomware group that emerged in early 2026, focusing on financial gain through data theft and extortion. They utilize double-extortion tactics, targeting various sectors with sensitive data breaches to pressure victims into compliance. Their primary operations are conducted via a Tor-based data leak site.
Key insights
•Gains access through compromised credentials and remote-access services like VPN and RDP.
•Utilizes exfiltration tactics to steal sensitive corporate and personal data before public exposure.
•Employs direct extortion, threatening to leak stolen data unless ransom is paid.
•Targets organizations in healthcare, municipal law enforcement, manufacturing, and automotive sectors.
•Operates internationally, with notable activity in the United States and Ecuador.