DisclosureLens
GLOBALMalwareRansomwareShadowbyt3$Shadowbyt3Ransom DemandedActor NamedMedium

UMSA PTY LTD

bd_bef6556f29545858 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Feb 17, 2026

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for UMSA PTY LTD

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group Shadowbyt3$ on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: Not FoundDiscovered: 2026-02-25

Source: Ransomware.live

Post text · scraped from the leak site

File: UMSA_LEAK.7z

Incident timeline — mostly unverified

? — ?

Breach window unknown

Feb 17, 2026

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2026-02-17

shadowbyt3$

According to ransomware.live, ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.

31 tracked hereFull profile →