top of page
  • X
  • Facebook
  • Linkedin
  • Instagram
Search

The Same Crew That Steals Your Data, Now Plans Your Murder

3 minutes ago
4 min read

A 24 year old was arrested in the Netherlands a few weeks back. The FBI calls him a leader of one of the busiest data extortion crews. The same name behind a run of breaches this year that dumped records on millions of people. On its own that's a solid arrest and a slow news day. Then police went through his laptop. Next to the stolen data and the attack tooling, they say they found plans to arrange two murders.


That last part is honestly what makes the whole story interesting and very few are treating it that way.


The attacker in your head is out of date


For years we've all been force fed this picture of the same guy. You know, the guy in the black hoodie slouched over a laptop in some dark corner of a coffee bar somewhere. Somebody far away who wants your files, wants money and would never come near you in person. That picture built the way companies defend themselves. Cyber guards the network. Physical guards the building and the people. Two teams, two budgets, and one quiet assumption holding up both of those silos. The guy who steals the data isn't the guy who'd ever hurt anyone, let alone murder someone.


That assumption was arrested recently.


We've watched this line blur for a while now. The crews running extortion are the same ones making swatting calls that drop a tactical team on somebody's porch. The home invasions hitting crypto holders run straight off customer lists that leaked in a breach. The data was never the end of it though. The data is a map to a person. And now we are starting to see some of these people are willing to walk that map all the way to the front door.


Why nobody is covering this


This works because of how the org chart is drawn. A breach hits and the whole machine spins up around the information. Legal, IT, the forensics firm and the notification letters. Not one step in a normal incident response plan asks the question that now matters. Does this breach put a real person in danger? If it does, who protects them?


Look at who sits in that stolen file. The executive and his home address off a benefits form. Travel records that show where he goes and when. Family members on the insurance plan. An org chart that tells a threat source who matters. Your cyber team sees a data problem and they are not entirely wrong. They're just holding one end of a rope with a person tied to the other. The people who would actually protect that person usually never hear the breach happened. This is typically because it landed on the far side of the wall between your two teams.


The threat crosses the line that splits your teams, so neither one owns it.


You are already in the file


You don't get to opt out of this, sorry. If you've been breached, or you do business with anyone who has, the raw material is already out there. Home addresses, routines, who matters to whom. It is rare that this information expires. It sits in a dump somebody bought for a few hundred bucks, waiting for a reason to matter.


So the question isn't whether your data is out there. It is. The question is whether anybody in your organization is collecting, processing and reading that data the way an attacker does. As a file on a human being, instead of a line item on a compliance report.


What you can do this week


Write down the people in your company who are both a data target and a physical one. Executives, founders, anyone with public heat, anyone whose money or ownership makes them worth leaning on. Almost nobody has that list written down, and it's the only list that matters here.


Pull their exposure the way an attacker would. Search the breach dumps your people are already in. See what a stranger could assemble about where an executive lives, how he travels, who his family is. What you can pull together in an afternoon, a patient person can pull together in a week and have the foundations of a plan to act on.


Walk one scenario end to end with both teams in the same room. A breach tonight exposes an executive's home address and travel calendar. Ask your cyber lead what they do. Ask your physical lead what they do. Watch the moment each one assumes the other has the person covered. That pause is your exposure.


Add the step, or steps, your incident response plan is missing. Every plan has a line for notifying regulators and customers. Almost none has a line for deciding whether an exposed person needs physical protection, who makes that call, and how fast you can stand it up.


Then ask it straight in your next leadership meeting. Who owns the safety of our people, not our network. If the data belongs to cyber and the badges belong to facilities and nobody owns the human sitting between them, you just found the hole before somebody else did.


The threat moved into the space between your two programs. Right now, it is likely that nobody on your team is responsible for following it from a stolen record to a person in danger.


That's the work we do. We came up on the offensive side and we run both halves of this house, so we model the attacker who steals the data and the attacker who uses it to find somebody, because more and more that's the same attacker. We tie protective services for high risk people straight to the digital exposure that put them on a list in the first place. And our threat emulation doesn't stop politely at the network edge the way a pure cyber shop does. The crew that got picked up this month already told you who you're up against. The hard part is that most companies are still only defending against half of him.


We're based in Dallas, Texas, and we go wherever the problem is. Red Cell Security provides cybersecurity and physical security consulting to clients across the US and around the world.


 
 
 

Comments


© 2026 by Red Cell Security, LLC.

Phone

Email

Connect

  • X
  • Facebook
  • LinkedIn
  • Instagram
bottom of page