New Leak Site Tied to Active Initial Access Broker Emerges on Underground Forums
A new Tor-based site, ALP-001, has transitioned from selling network footholds to publicly naming victims, marking a shift from initial access brokerage to full-scale cyber extortion.
A new Tor-based site, ALP-001, has transitioned from selling network footholds to publicly naming victims, marking a shift from initial access brokerage to full-scale cyber extortion.
Accessible only via Tor, ALP-001 describes itself as a "Data Leaks / Access Market," combining elements of a ransomware leak portal and an access shop. The group's first publicly named victim is Pellenc, a French manufacturer, with 228 GB of data allegedly at risk. The post includes a payment deadline in early April 2026, consistent with double-extortion tactics.
Researchers have linked ALP-001's operators to an established Initial Access Broker (IAB) active on underground forums, previously known as "Alpha Group" and "DGJT Group." This connection is based on reused contact IDs and matching listings for the same victim organization.
Traditionally, Initial Access Brokers sell compromised credentials or remote entry points to other threat actors. ALP-001, however, operates its own data leak site, reflecting a broader trend where access brokers evolve into standalone ransomware or data-extortion groups. ALP-001's operators are known for their skill in compromising and monetizing initial access, though their ability to manage large data sets is less certain.
Accessible only via Tor, ALP-001 describes itself as a "Data Leaks / Access Market," combining elements of a ransomware leak portal and an access shop.
The group specializes in exploiting perimeter technologies, frequently targeting exposed SSH servers and VPN appliances from vendors like Fortinet, Cisco, and Citrix. These services, accessible from the network edge, are vulnerable to credential stuffing, brute force attacks, and unpatched vulnerabilities. Upon gaining access, the broker typically establishes persistent access for later sale or direct extortion.
ALP-001 represents a maturing operation that blends access-broker tradecraft with ransomware tactics. The Pellenc listing, with its deadline and structured details, suggests the group is testing ransomware-style shaming, though large-scale data publication is not yet evident. Organizations should treat ALP-001 primarily as a high-quality access broker with extortion ambitions.
Organizations should audit configurations, apply security patches, and restrict access to edge services. Security teams should also monitor for persistence mechanisms and enforce multi-factor authentication to reduce the risk of credential misuse. Continuous monitoring of underground forums and data leak sites is recommended for early warnings of potential threats.
Based on reporting by GBHackers.
