SYS::ONLINE
Wasteland.
Briefs2196
Issues24
SinceFeb 2026
LIVE
█ Ransomware RXPE-GROUP-COINBAS 2026-08-23

RXPE Group: CoinbaseCartel Leak Site Extortion Claim

"On 22 August 2026, the extortion crew tracked as CoinbaseCartel added Chinese power electronics manufacturer RXPE Group to its dark web victim listing, publishing proof samples and threatening to release sensitive…"

On 22 August 2026, the extortion crew tracked as CoinbaseCartel added Chinese power electronics manufacturer RXPE Group to its dark web victim listing, publishing proof samples and threatening to release sensitive manufacturing and engineering data. Monitoring attributed to the ThreatMon Threat Intelligence Team timestamped the listing at roughly 17:00 UTC+3, with ShinyHunters adding BOK Financial to its own leak site about thirteen minutes later. RXPE Group has not confirmed the claim, has not issued a public statement, and no regulator filing or national CERT advisory has surfaced. Everything currently in the public record originates from the attackers' own leak infrastructure and from third-party trackers that scrape it, which is a materially weaker evidence base than a victim notification.

What Happened

The listing appeared on CoinbaseCartel's Tor-based extortion site on 22 August 2026 and, according to UNDERCODE NEWS, centres on manufacturing files rather than the customer PII that dominates most leak site postings. Multiple ransomware trackers independently recorded the entry, which establishes that the listing exists but says nothing about whether the underlying intrusion succeeded, what was actually taken, or whether any encryption occurred.

That distinction matters more than usual here. Every source reporting on RXPE is OTHER-tier: aggregator sites and monitoring feeds republishing the same ThreatMon alert. There is no independent forensic corroboration, no third-party incident response confirmation, and no acknowledgement from RXPE itself. Treat the claim as an allegation under active verification.

The listing follows a pattern CoinbaseCartel has run repeatedly through mid-2026. DeXpose documented the group claiming CEN and CENELEC, the European standardisation bodies headquartered in Belgium, on 1 August 2026, and Serruya Private Equity on 14 August 2026. In both cases the group posted near-identical extortion text: "The full leak will be published soon unless a company representative contacts us via the channels provided." That boilerplate is the group's standard opening move, and its reappearance against RXPE suggests process rather than a bespoke operation.

Accounts of the group's own scale conflict. The CyberThreatIntelligence.net profile page lists CoinbaseCartel with "207 total victims" in its summary field while the narrative body of the same record states the group "has listed 186 victims since May 2023." Both figures come from the same OTHER-tier source and are not reconciled there. Neither should be quoted as authoritative. Similarly, the two records covering the Serruya Private Equity listing disagree on basics: CyberThreatIntelligence.net files it under Israel with the domain serruyaprivateequity.com, while DeXpose reports it as a Canadian private equity firm at serruyaequity.com. When trackers cannot agree on the nationality of a victim listed eight days earlier, apply matching scepticism to the RXPE entry.

What Was Taken

No volume figure, file count, or record count has been published for RXPE. The claim describes manufacturing files, which for this victim is a meaningfully different exposure profile than a consumer data breach.

RXPE, also known as Liaoning Rongxin Xingye Power Technology, develops, designs, manufactures and services high-power electronics equipment. Its stated markets span electricity generation, transmission and distribution, industrial systems, metallurgy, rail transportation, renewable energy, mining, petroleum and chemicals. A successful exfiltration from an engineering environment at a company like that plausibly reaches engineering drawings, control system configurations, firmware, test and commissioning data, supplier and bill-of-materials records, and project documentation tied to named grid or rail deployments. None of that is confirmed. It is the reasonable exposure envelope if the claim holds, not a finding.

For scale on how claimed volumes behave against verified ones, the RingCentral case is instructive. SecurityWeek reported that ShinyHunters claimed over 623GB on its leak site, then published a 280GB archive roughly a week later after RingCentral declined to pay. HaveIBeenPwned subsequently indexed approximately 1.6 million unique email addresses from that archive, alongside names, addresses and phone numbers. RingCentral itself confirmed a July intrusion via "sophisticated social engineering" but has not confirmed the attackers' claims or the impacted-individual count. Initial leak site claims routinely overstate what eventually lands.

Why It Matters

Three things make this listing worth tracking beyond routine leak site noise.

First, CoinbaseCartel's self-description contradicts the "ransomware group" label attached to it in most reporting. The profile compiled by CyberThreatIntelligence.net quotes the group stating it focuses "exclusively on data exfiltration" and that its "operations never involve system encryption or operational disruption." If accurate, RXPE may face no downtime at all, only a data release deadline. That changes the defender playbook substantially: backup restoration is irrelevant, and the entire incident lives or dies on exfiltration detection, legal exposure, and negotiation posture. It also means detection engineering tuned for encryption behaviour will miss this actor entirely.

Second, industrial engineering data has a different decay curve than PII. Stolen email addresses lose value as people change jobs. A grid-scale converter design, a protection relay configuration, or commissioning documentation for a rail traction system stays useful to competitors and to anyone mapping critical infrastructure for years. Downstream operators who bought RXPE equipment inherit part of this risk without having been breached themselves.

Third, the third-party dimension. Lidl's July 2026 disclosure is the cleanest recent illustration: attackers never touched Lidl's own online shop systems, and the compromise happened at a service provider holding a separately stored customer data file. Lidl notified customers across Germany, Belgium and the Netherlands, informed the Dutch Data Protection Authority, and the breached IT provider filed a police report. If RXPE's exposure includes customer project files, its utility and industrial clients may end up in a comparable position, learning about their exposure from someone else's incident.

The Attack Technique

The initial access vector for the RXPE listing is unknown. No source describes how CoinbaseCartel entered, when the intrusion began, or how long the actor had access.

What exists is a generic actor profile. CyberThreatIntelligence.net maps CoinbaseCartel to two MITRE ATT&CK techniques: T1091, Replication Through Removable Media, covering lateral movement or initial access via malware copied to USB media and executed through Autorun or user deception, which is directly relevant to segmented and air-gapped manufacturing networks; and T1133, External Remote Services, covering abuse of external-facing VPNs, Citrix and similar remote access gateways for initial access and persistence. These are profile-level technique mappings drawn from the group's documented history, not evidence of what happened at RXPE.

Broader context is worth holding alongside this. RingCentral attributed its July compromise to a sophisticated social engineering campaign rather than a software exploit, and Ryde's early-August breach involved an unauthorised party accessing systems and copying customer data overnight before being cut off. Identity abuse, remote access misuse and social engineering continue to outperform vulnerability exploitation as entry paths for extortion-focused actors.

What Organizations Should Do

  1. Instrument for exfiltration, not encryption. An actor claiming to skip encryption entirely defeats ransomware detection built around mass file modification and shadow copy deletion. Alert on volumetric egress, unusual archive creation, and traffic to cloud storage and file transfer services from engineering and PLM systems specifically.
  2. Audit every external remote access path. Enumerate VPN concentrators, Citrix and RDP gateways, vendor jump hosts and legacy remote maintenance links into OT and manufacturing networks. Enforce phishing-resistant MFA on all of them, and confirm no service or maintenance account bypasses it.
  3. Enforce removable media controls in plant environments. Given the T1091 mapping, restrict hardware installation, disable Autorun across engineering workstations, and require scanned, controlled media for any commissioning or field service transfer. Air-gapped is not the same as isolated when technicians carry USB drives.
  4. Extend monitoring to your suppliers' exposure. The Lidl case shows breaches arriving through providers rather than your own perimeter. Track leak site listings for your equipment vendors, integrators and engineering service partners, and know in advance what project data each one holds.
  5. Pre-write the disclosure and notification path. Ryde published a dated, multi-language incident page, notified the Norwegian Data Protection Authority and police, and stated clearly what was and was not affected while the investigation was still open. That posture is achievable only if drafted before the incident.
  6. Treat leak site claims as leads, not conclusions. Validate independently before briefing executives or customers. Claimed volumes shrink, victim identities get misattributed, and tracker records conflict, as the contradictory Serruya listings and CoinbaseCartel victim counts demonstrate.

Sources: CoinbaseCartel Claims Ransomware Attack on China’s RXPE Group, Putt... | Lidl discloses online shop breach after service provider hack | 1.6 Million Likely Impacted by RingCentral Data Breach - SecurityWeek | Two Major Organizations Surface in Dark Web Ransomware Activity as... | Serruya private equity Ransomware Attack by Coinbasecartel (2026)... | CoinbaseCartel Targets Serruya Private Equity in Ransomware Attack... | Coinbasecartel Ransomware Attack on CEN and Cenelec - DeXpose | Security Incident August 2026