Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Find Your iPhone MAC Address in Seconds

    What to Do When Your iPhone Suddenly Can’t Find You

    Affordable Asus portable monitor with 15-inch IPS display drops to lowest-ever price

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      What the polls say about how Americans are using AI

      February 27, 2026

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026
    • Business

      Met Office ‘supercomputing as a service’ one year old

      March 12, 2026

      Tech hiring evolves as candidates ask for AI compute alongside pay and perks

      March 11, 2026

      Oracle is spending billions on AI data centers as cash flow turns negative

      March 11, 2026

      Google: Cloud attacks exploit flaws more than weak credentials

      March 10, 2026

      Could this be the key to eternal storage? Experts claim new DNA HDD can be ‘erased and overwritten repeatedly’

      March 9, 2026
    • Crypto

      Banks Respond to Kraken’s Federal Reserve Access as Trump Sides with Crypto

      March 4, 2026

      Hyperliquid and DEXs Break the Top 10 — Is the CEX Era Ending?

      March 4, 2026

      Consensus Hong Kong 2026: The Institutional Turn 

      March 4, 2026

      New Crypto Mutuum Finance (MUTM) Reports V1 Protocol Progress as Roadmap Enters Phase 3

      March 4, 2026

      Bitcoin Short Sellers Caught Off Guard in New White House Move

      March 4, 2026
    • Technology

      Find Your iPhone MAC Address in Seconds

      March 13, 2026

      Affordable Asus portable monitor with 15-inch IPS display drops to lowest-ever price

      March 12, 2026

      Crimson Desert adds Denuvo DRM a week before release date, causing pre-order cancellations

      March 12, 2026

      Lisuan Extreme LX 7G106

      March 12, 2026

      Premium mopping technology in an affordable robot vacuum: Mova S70 Roller review

      March 12, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Warlock claims more victims as cyber attacks hit Colt and Orange
    Technology

    Warlock claims more victims as cyber attacks hit Colt and Orange

    TechAiVerseBy TechAiVerseAugust 23, 2025No Comments5 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Warlock claims more victims as cyber attacks hit Colt and Orange
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Warlock claims more victims as cyber attacks hit Colt and Orange

    Ransomware gang Warlock is adding more victims to its data leak site as the impact of a spreading wave of cyber attacks continues to be felt

    By

    • Alex Scroxton,
      Security Editor

    Published: 20 Aug 2025 17:17

    Warlock, the emergent cyber crime gang that claims it is holding UK network and telecoms services provider Colt’s data to ransom, appears to have hit multiple other victims in the past few weeks, it has emerged.

    This is according to data supplied through the open source RansomLook.io information service, which is currently tracking 475 ransomware gangs across hundreds of dark web forums, markets and other channels. Warlock has claimed a total of 22 new victims since since 16 August, according to the data.

    Besides Colt, these include a number of other tech firms, including mobile operator Orange, which today (20 August) confirmed a cyber attack affecting its Belgian subsidiary and last month reported a major security incident in its home country, France.

    In a statement, Orange said it had detected a cyber attack on its IT systems resulting in criminal access to data on 850,000 customers. It claimed no credentials, email addresses, or banking or financial details were compromised, but information including names, phone and SIM card numbers, tariff plan data and Personal Unlocking Key (PUK) codes were.

    The compromise of PUK codes is a particularly urgent concern, as these eight-digit numbers are designed as a security measure to protect SIM cards from unauthorised use should the user accidentally lock their SIM.

    “As soon as the incident was detected, our teams blocked access to the affected system and tightened our security measures. Orange Belgium also alerted the competent authorities and filed an official complaint with the judicial authorities,” a spokesperson said.

    Colt curtailed

    Colt, meanwhile, continues to reckon with the impact of Warlock’s attack as its investigation continues to unfold. The organisation today confirmed that it had determined some customer data had been stolen, and that establishing the precise nature of this data is its current priority.

    Currently unavailable are the Colt Online customer portal, number hosting application programming interfaces (APIs), the Colt On Demand network-as-a-service portal, any ability to order or deliver new services, and several undisclosed customer-focused automated processes and systems.

    “We would like to reassure you that this cyber incident is limited to our business support systems, which are strictly separated from our customer infrastructure, ensuring that authentication systems are not shared between the two environments,” said a Colt spokesperson. “We’re working around the clock to restore our systems. It’s too early to give an exact timeline at the moment, but we’ll provide regular updates to keep you informed.”

    According to screenshots obtained by independent security analyst Kevin Beaumont, Warlock will leak Colt’s data within the next week if its attempt to sell the dataset fails.

    SharePoint vulns behind Warlock’s rise

    According to Microsoft’s security experts, Warlock has been exploiting two security bypass vulnerabilities in SharePoint Server – collectively known as ToolShell, which were discovered in July and swiftly patched at the time amid warnings that the resulting exploit chain was being used by Chinese state cyber spies.

    According to data obtained by cyber security news outlet Recorded Future under the UK Freedom of Information Act (FoIA), the Information Commissioner’s Office (ICO) was aware of three instances of personal data breaches arising from exploitation of ToolShell as of 28 July. However, the use of ToolShell does not necessarily indicate the involvement of Warlock.

    Meanwhile, Trend Micro researchers have revealed how the Warlock campaign exemplifies the speed with which threat actors can weaponise enterprise vulnerabilities for high-impact activities.

    “Through the exploitation of the SharePoint vulnerabilities, attackers were able to bypass authentication, achieve remote code execution [RCE], and rapidly pivot across compromised networks,” said the Trend Micro team.

    Trend Micro described a complex yet effective attack chain through which Warlock is using targeted HTTP POST requests to upload webshells to vulnerable SharePoint servers, then escalating their attacks through abuse of Group Policy, credential theft, and lateral movement with both legitimate Windows tools and custom-build malwares, ultimately leading to the execution of the ransomware locker, which encrypts files with the extension .x2anylock, while data is exfiltrated using RClone.

    Its locker malware appears to be a custom derivative of the leaked LockBit 3.0 builder, Trend said, noting how that in a remarkably short period of time, Warlock had evolved into a rapidly growing global threat with its enthusiastic adoption of ToolShell setting the stage for future, more sophisticated campaigns.

    “This end-to-end attack highlights the dangers of delayed patching and the importance of layered defence,” the team added.

    Read more on Data breach incident management and recovery


    • Warlock claims ransomware attack on network services firm Colt

      By: Alex Scroxton


    • August Patch Tuesday addresses 107 vulnerabilities

      By: Tom Walat


    • Eight critical RCE flaws make Microsoft’s latest Patch Tuesday list

      By: Alex Scroxton


    • News brief: SharePoint attacks hammer globe

      By: Staff report

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleIs it time to build an AI factory?
    Next Article Commvault users told to patch two RCE exploit chains
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Find Your iPhone MAC Address in Seconds

    March 13, 2026

    Affordable Asus portable monitor with 15-inch IPS display drops to lowest-ever price

    March 12, 2026

    Crimson Desert adds Denuvo DRM a week before release date, causing pre-order cancellations

    March 12, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025714 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025299 Views

    Wired Headphones Are Making A Comeback, And We Have Gen Z To Thank

    July 22, 2025210 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025171 Views
    Don't Miss
    Technology March 13, 2026

    Find Your iPhone MAC Address in Seconds

    Find Your iPhone MAC Address in Seconds If you are a reader experiencing an access…

    What to Do When Your iPhone Suddenly Can’t Find You

    Affordable Asus portable monitor with 15-inch IPS display drops to lowest-ever price

    Crimson Desert adds Denuvo DRM a week before release date, causing pre-order cancellations

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Find Your iPhone MAC Address in Seconds

    March 13, 20264 Views

    What to Do When Your iPhone Suddenly Can’t Find You

    March 13, 20263 Views

    Affordable Asus portable monitor with 15-inch IPS display drops to lowest-ever price

    March 12, 20266 Views
    Most Popular

    Over half of American adults have used an AI chatbot, survey finds

    March 14, 20250 Views

    UMass disbands its entering biomed graduate class over Trump funding chaos

    March 14, 20250 Views

    Outbreak turns 30

    March 14, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.