Tower Ransomware Claim: 207-Victim Group Named It | #ransomware | #cybercrime


A ransomware group has put a dual-listed insurer on notice, and the insurer is pushing back on the word “confirmed.” On October 3, 2026, Insurance Business reported that Tower Limited, the New Zealand insurer known as Tower Insurance, is investigating a claim from a cyber-extortion group that says it stole company data. Tower told Stuff on October 2 that the information circulating on cyber forums is unverified. The company said it has brought in outside consultants and notified the relevant authorities, and it has not confirmed that any customer data was actually taken.

That gap between “named on a leak site” and “breach confirmed” is where this story sits, and it is a gap that matters a lot to brokers, policyholders, and anyone watching how a dual-listed company handles disclosure. Tower trades on both the NZX and the ASX, which means any confirmed data loss would trigger continuous disclosure obligations most ransomware victims never face. Four weeks after the extortion group first posted its claim, Tower still has not told either exchange anything, because as of this reporting there is nothing confirmed to tell them.

Google · Preferred Sources

Don’t miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

What Tower Said After Being Named on a Ransomware Leak Site

Tower’s public line has stayed consistent and deliberately narrow. The company said it is aware of unverified information posted on cyber forums describing a potential threat, according to the account Stuff published on October 2 and that Insurance Business cited in its October 3 report. Tower said it is running what Insurance Business described as a methodical investigation, working with external cybersecurity consultants, and that it has notified relevant authorities. It also said it will notify affected customers and stakeholders immediately if any are identified.

Insurance Business separately reported that Tower is maintaining heightened monitoring while the investigation continues. None of that language amounts to a denial, and none of it amounts to a confirmation either. It is the standard holding position companies take while forensic teams work out whether a leak-site listing reflects a real intrusion, a resold or recycled dataset, or an empty claim designed purely to generate headlines and anxious broker phone calls.

That phone-call detail is not incidental. Insurance Business framed its story specifically around brokers fielding client questions, which tells you something about who feels the pressure first when a carrier’s name shows up on a dark-web page. Policyholders do not wait for forensic certainty. They call their broker, and the broker needs an answer before Tower has one to give.

Who Is Coinbase Cartel, the Group Behind the Claim?

The group that listed Tower calls itself Coinbase Cartel, sometimes written as CoinbaseCartel or coinbasecartel. It is not a household name on the level of LockBit, but it has built a sizable footprint in a short time. Bitdefender traces the group’s first appearance to September 2025, when it claimed 14 victims in its debut month. It has not slowed down since.

What sets Coinbase Cartel apart operationally is that it skips encryption entirely. Threat-intelligence firm Hive Pro describes it as an “encryption-free data extortion group,” meaning it steals data and threatens to publish it rather than locking victims out of their own systems with ransomware payloads. Hive Pro also assesses that the group operates under the alias shinysp1d3r and functions as an affiliate within a broader collective it calls Scattered Lapsus$ Hunters, or SLSH. That is a threat-intelligence judgment, not a law enforcement attribution, and no government agency has publicly tied Coinbase Cartel to an arrest or takedown as of this reporting.

French threat-intelligence firm Intrinsec describes a clear preference for Western targets, with the United States and France drawing the heaviest concentration of claimed victims. Hive Pro’s victim mapping adds notable clusters in the United Arab Emirates, Germany, and Brazil. Bitdefender found that the group’s healthcare victims skew heavily toward the UAE specifically, while its broader targeting leans into healthcare, technology, and transportation as the three sectors it hits most often.

Timeline: From the August Leak-Site Listing to October’s Public Reporting

The public record on dates is more solid than the public record on what was actually taken. Ransomware-tracking sites, including Ransomware.live, show Tower was added to Coinbase Cartel’s leak site on August 22, 2026. That listing sat largely unremarked for roughly six weeks until Stuff reported Tower’s awareness of the claim on October 2, and Insurance Business followed with its own account on October 3, the date this story broke more widely into trade press.

That six-week gap between a leak-site posting and mainstream pickup is not unusual. Extortion groups post hundreds of claims across dozens of active leak sites every month, and most of them never reach a general news audience unless a journalist, a researcher, or the victim itself brings it forward. In Tower’s case, it appears to have been Tower’s own disclosure to Stuff, prompted by the fact that the listing had started generating questions from brokers and customers, that pushed the story into daylight.

Why the Investigation Is Taking Weeks, Not Days

Forensic verification of a leak-site claim is slower than most outsiders expect. Investigators have to establish whether the data sample a group posts, if any, actually originated inside the victim’s own systems rather than being scraped from a prior, unrelated breach, purchased from a broker, or stitched together from multiple smaller leaks to look bigger than it is. Tower’s own statement, that it has found no reliable number of affected individuals or specific categories of exposed information so far, is consistent with a company still in that verification phase rather than one stonewalling a confirmed incident.

What Data Coinbase Cartel Claims to Have, and What Remains Unverified

This is the part of the story where caution matters most. Multiple ransomware-tracking services that monitor leak sites have recorded Tower’s listing, but they disagree, or simply do not say, how much data is actually involved. One automated tracking entry carried an unverified reference to 486 compromised users attached to the listing, but that figure comes from automated scraping of the leak-site posting itself, not from any confirmed forensic count, and other tracking records explicitly state they could not establish a reliable number of affected individuals or specific data categories at all.

No source reviewed for this story identifies a confirmed file count, database size, or specific category of exposed information, such as policy numbers, claims history, or payment details. No CVE, exploit, or initial-access technique has been publicly tied to the alleged intrusion. That absence of technical detail is itself informative. When ransomware groups have strong proof, they typically publish samples designed to maximize pressure, screenshots of file directories, snippets of customer records, internal emails. The relatively thin public evidence trail around Tower’s listing is one reason the company has been able to maintain, credibly so far, that the claim remains unverified.

Coinbase Cartel’s 2026 Victim Count, by Tracker

Because no single authority audits ransomware leak sites, different trackers report different running totals for Coinbase Cartel depending on when they last crawled the group’s site. The spread below shows how fast the group’s claimed victim list has grown through 2026, and why any single snapshot should be read as a point-in-time estimate rather than a final figure.

DateClaimed Victim CountSource
September 202514 (first month)Bitdefender
March 202622 (first tracked month)Breachsense
June 22, 2026~143Intrinsec
August 18, 2026204RansomNews tracker
August 22, 2026Tower Insurance listedRansomware.live, Hacker Feeds, Recent Breaches
September 30, 2026207Ransomware.live

The variance between trackers, roughly 143 to 207 claimed victims depending on the cutoff date, reflects how these aggregation services crawl Tor-hosted leak pages on different schedules and sometimes count delisted or disputed entries differently. It is a reminder that leak-site victim counts, including the one that includes Tower, are a measure of what a criminal group has publicly claimed, not an audited tally of confirmed breaches.

How Tower’s Response Compares to Other Insurer Breach Playbooks

The insurance sector has spent the past two years building a fairly standard playbook for leak-site claims: acknowledge awareness quickly, decline to confirm specifics, bring in outside forensics, and notify regulators before notifying the press. Tower’s response tracks that playbook closely. It named external cybersecurity consultants, said it notified relevant authorities, and committed to notifying affected individuals if the investigation identifies any. What it has not done, at least not publicly as of October 3, is file anything with the NZX or ASX, because New Zealand’s continuous disclosure rules only require that once information is confirmed to be material, not while a claim remains unverified.

That is a meaningfully different posture from companies that confirm a breach early and then manage the fallout publicly. The cyber insurance industry, which Tower itself sits adjacent to as a carrier, has its own stake in how these claims get verified. Our earlier look at how Coalition, Chubb, and At-Bay price cyber risk found that insurers increasingly treat unverified leak-site listings as a distinct risk category from confirmed breaches, precisely because the two carry very different claims exposure.

Coinbase Cartel vs. Other Major Extortion Operations

Coinbase Cartel sits in a specific niche within the broader extortion ecosystem. The table below sets out how its stated operating model compares with other groups that have made headlines in 2026, based on what each group’s own activity or public threat-intelligence reporting shows.

GroupPrimary MethodNotable 2026 Activity
Coinbase CartelData-theft extortion, no encryption (Hive Pro)~207 claimed victims by Sept. 30; named Tower Insurance Aug. 22
ShinyHuntersData theft, WAF-bypass intrusionsClaimed FBI and Oracle PeopleSoft-linked breach activity, per our ShinyHunters profile
KillSecRansomware-as-a-service, extortionTeen leader arrested; DOJ charged “Archduke” in a multinational operation, per our KillSec coverage

The common thread across all three is a shift away from pure file-encrypting ransomware toward data-theft extortion, where the threat is publication rather than operational disruption. That shift matters for insurers like Tower specifically, because data-theft-only claims can trigger privacy-notification and liability obligations even when a victim’s actual IT operations never go down.

The Business Model: Why Groups Skip Encryption Entirely

Encryption-based ransomware has a structural weakness that extortion-only groups have learned to exploit: once a victim restores from backup, the leverage disappears. Data-theft-only groups like Coinbase Cartel sidestep that problem. Backups do nothing to un-steal data that has already left the network, which means the only remaining leverage point is the threat of publication itself.

That model also lowers the bar to entry. Deploying working encryption malware across a target’s entire environment without detection takes real engineering effort. Exfiltrating a batch of files and posting a listing on a leak site takes considerably less. Hive Pro’s description of Coinbase Cartel as an affiliate operation within a larger collective fits this pattern: smaller, nimbler cells running extortion campaigns under a shared brand or shared leak-site infrastructure, rather than one unified criminal enterprise.

Market and Regulatory Stakes for a Dual-Listed Insurer

Tower’s position on both the NZX and ASX raises the stakes of this investigation beyond a typical single-market breach scare. Continuous disclosure regimes on both exchanges require listed companies to inform the market promptly once information becomes material, but “unverified” is doing real regulatory work in Tower’s statements. Until forensic investigators can say with confidence that customer data left Tower’s systems, and roughly how much, the company has a defensible basis for withholding a market announcement.

No source reviewed for this story reports any Tower share-price movement tied to the claim, which is itself consistent with a market that has not yet treated the leak-site listing as confirmed, material news. That could change quickly if forensic investigators find evidence supporting the extortion group’s claim, or if Coinbase Cartel escalates by publishing a larger data sample to pressure Tower into a faster response.

Historical Context: Insurers Are a Growing Target for Data-Theft Extortion

Insurers sit on exactly the kind of data that makes extortion groups salivate: policyholder identities, claims histories, health information tied to life and health products, and payment details. That concentration of sensitive records is part of why the sector has become a recurring target across 2026’s ransomware wave. Our earlier coverage of data-theft extortion surging across schools and hospitals documented the same pattern across other data-rich, often under-resourced sectors, and insurers increasingly fit that profile even when they are large, well-capitalized firms.

Tower’s own sector, cyber insurance underwriting, has also faced scrutiny over how carriers audit the security posture of the vendors and partners they rely on. That tension, between insurers writing cyber risk policies for others while managing their own exposure, is not new, but a leak-site claim against an actual insurer sharpens it considerably. It also echoes broader concerns about unused cloud access sitting on corporate boards’ risk registers, where the gap between what a company believes is secured and what is actually exposed keeps showing up as the root cause once an incident gets investigated.

What Brokers and Policyholders Should Do Right Now

Insurance Business framed its story around brokers fielding client questions, and that framing points to the most practical takeaway for anyone with a Tower policy today. There is no confirmed breach to act on yet, which means there is no confirmed list of affected customers to notify. Brokers advising clients should stick to what Tower itself has said: the company is investigating, has engaged outside consultants, and has committed to notifying anyone affected if the claim is substantiated.

Policyholders worried about exposure can take the same general precautions recommended after any leak-site listing, regardless of confirmation status: monitor for unusual account activity, be skeptical of unsolicited calls or emails claiming to be from Tower, and avoid clicking links in messages referencing the breach claim, since extortion-adjacent phishing campaigns often piggyback on real leak-site news within days of it becoming public.

What Security Researchers’ Threat Profiles Suggest About Coinbase Cartel’s Next Moves

Published threat-intelligence profiles from Bitdefender, Hive Pro, and Intrinsec consistently describe Coinbase Cartel as an opportunistic, high-volume operation rather than a group that lingers on a small number of high-value targets. Intrinsec’s tracking shows the group’s claimed-victim count roughly tripling between Bitdefender’s early-2026 snapshot and its own June count, which points to an operation prioritizing throughput over negotiation leverage on any single victim.

That pattern suggests Tower is one listing among many rather than a specifically targeted campaign, though that framing offers limited comfort if the underlying data claim turns out to be real. High-volume data-theft groups tend to extract what they can quickly, list the victim, and move on to the next target rather than mounting extended, bespoke negotiations, which is also consistent with why Tower’s listing sat quietly for roughly six weeks before drawing wider press attention.

Predictions: Where This Investigation Likely Goes From Here

  • Tower’s forensic investigation will likely produce a public update within weeks rather than months, given the broker and customer pressure Insurance Business described, even if that update is simply “no evidence of compromise found.”
  • If investigators confirm any customer data exposure, expect Tower to file disclosures with both the NZX and ASX promptly afterward, given the dual-listing obligations at stake.
  • Coinbase Cartel will almost certainly continue adding victims at a similar or faster pace through the rest of 2026, based on the group’s trajectory from 14 victims in September 2025 to roughly 207 by late September 2026.
  • Expect continued disagreement between ransomware trackers over Coinbase Cartel’s exact victim count, since none of the services crawling the group’s leak site operate on a shared or audited methodology.
  • Regardless of how the Tower claim resolves, expect more insurers to appear on data-theft leak sites over the coming months, following the same pattern already visible across healthcare and education sectors this year.

Why This Story Matters Beyond One Insurer

The Tower case is a useful stress test for how companies, regulators, and the press should handle leak-site claims before forensic certainty exists. Treating every leak-site listing as a confirmed breach risks punishing companies for criminal claims that sometimes turn out to be exaggerated, recycled, or outright false. Treating every listing as noise risks leaving real victims unprotected while a company stalls behind the word “unverified.” Tower’s current position, informing the market it is investigating without confirming specifics, threads that needle, at least for now, and how it plays out will likely shape how other dual-listed companies respond the next time their name turns up on a Tor-hosted extortion page.

The broader lesson for any organization handling sensitive customer data is that the investigation timeline, not the leak-site posting date, is what determines public perception. Coinbase Cartel posted its claim on August 22. It took Tower roughly six weeks to get ahead of the story publicly, and that gap is where speculation, broker anxiety, and reputational risk tend to accumulate fastest.

Frequently Asked Questions

Has Tower confirmed a data breach?

No. Tower has described the ransomware group’s claim as unverified information posted on cyber forums and says its investigation, conducted with external cybersecurity consultants, has not confirmed that any customer data was taken.

Who is Coinbase Cartel?

Coinbase Cartel is a cyber-extortion group first observed in September 2025 that steals data without encrypting victims’ systems. Threat-intelligence firm Hive Pro assesses it as an affiliate operation, also using the alias shinysp1d3r, within a broader collective it calls Scattered Lapsus$ Hunters.

How many victims has Coinbase Cartel claimed in 2026?

Tracking services report different totals depending on when they last crawled the group’s leak site, ranging from about 143 victims as of June 22, 2026, according to Intrinsec, to 207 as of September 30, 2026, according to Ransomware.live.

When was Tower added to the leak site?

Ransomware-tracking services, including Ransomware.live, show Tower was listed on Coinbase Cartel’s leak site on August 22, 2026. Tower’s own public acknowledgment of the claim followed roughly six weeks later, in early October 2026.

Has Tower disclosed anything to the NZX or ASX?

As of this reporting, Tower had made no announcement to either exchange. Continuous disclosure obligations generally apply once information is confirmed to be material, and Tower has not confirmed the extortion group’s claim.

What kind of data does Coinbase Cartel typically steal?

Published threat-intelligence reporting from Bitdefender and Hive Pro says the group’s claimed victims cluster most heavily in healthcare, technology, and transportation, with notable activity also in manufacturing and business services. No specific data categories have been confirmed in Tower’s case.

Should Tower customers take any action now?

There is no confirmed list of affected customers to act on yet. General precautions, such as watching for unusual account activity and being skeptical of unsolicited messages referencing the claim, are reasonable while the investigation continues.

Has law enforcement taken any action against Coinbase Cartel?

No public law enforcement takedown, arrest, or formal attribution tied to Coinbase Cartel has been reported as of this story. Hive Pro’s assessment linking the group to a wider collective is a threat-intelligence judgment, not a law enforcement finding.

Related Coverage

Marcus Chen

Gaming & Consumer Tech Editor

Marcus Chen is a senior editor at Tech Insider, where he leads coverage of the US online gaming market, including sweepstakes and social casinos, alongside consumer technology. He evaluates operators on their published terms, licensing and RNG certifications, stated redemption policies, and corroborating independent reporting, and writes plainly about what the evidence supports. Tech Insider does not run first-party money tests and does not gamble with reader funds. Marcus has reported on the technology and online-gaming industries for more than a decade.

View all articles



Click Here For The Original Source.

——————————————————–

..........

.

.