CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Payload

actor · actor:payload-ransomware single-source

Data-extortion group operating a leak site; on 2026-08-20 it listed a Zurich-area IT and data-centre provider, claiming roughly 490 GB and naming eight affected customer domains including that of HWZ Hochschule fuer Wirtschaft Zuerich, which separately confirmed to students that data was stolen through a service provider's infrastructure. The connection between the named provider and the school rests solely on the group's own listing (Ransomware.live listing, 2026-08-20; Inside Paradeplatz, 2026-08-22).

Coverage
1
first 2026-08-23 → last 2026-09-01
Latest activity
2026-09-01
HWZ confirms the theft and names no provider; the only source connecting a provider to it is the extortion…
Peak priority
notable
1 notable
Targets
education
sectors: education, public-sector, technology · regions: switzerland, europe
Sources cited
5
5 hosts

Defender insights

What each entry about Payload tells a defender to do, newest first.

2026-08-23NOTABLEHWZ confirms the theft and names no provider; the only source connecting a provider to it is the extortion group's own leak-site listing

Story timeline

  1. 2026-08-23A Zurich business school tells students their bank details and sick-leave records were stolen, not from its own systems, but through the infrastructure of an IT service provider whose leak-site listing names seven other Swiss customers alongside it, and does not close the list
    active-threatsHWZ confirms the theft and names no provider; the only source connecting a provider to it is the extortion group's own leak-site listing
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessTrusted Relationship

Initial Access TA0001

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-08-23/payload-zurich-it-provider-hwz-student-data · ATT&CK page ↗

Entries about Payload (1)

2026-08-23 · view entry permalink →

NOTABLEupdatedNATOC2

A Zurich business school tells students their bank details and sick-leave records were stolen, not from its own systems, but through the infrastructure of an IT service provider whose leak-site listing names seven other Swiss customers alongside it, and does not close the list

HWZ Hochschule für Wirtschaft Zürich, a Zurich university of applied sciences business school, wrote to its students and alumni to confirm that an analysis of stolen data had identified personal information belonging to them, names, addresses and phone numbers, records from student administration, bank details, and data from sick-leave notifications (Inside Paradeplatz, 2026-08-22). On where it came from, the school is specific and, notably, exculpatory of its own estate: "Nach aktuellem Untersuchungsstand erfolgte ein Angriff über die Infrastruktur des Dienstleisters" (according to the current state of the investigation, an attack took place via the service provider's infrastructure) and it states separately that HWZ's own local IT infrastructure was not affected. The school has involved the police and asked recipients not to circulate unconfirmed information.

Two days before that letter was reported, the extortion group Payload listed a Swiss data-centre operator on its leak site, claiming roughly 490 GB of data and naming eight affected customer domains, the school's among them, alongside seven other organisations. The listing gives only domain names; no cited source describes what those other customers do, and this entry does not guess. The timing is consistent with a single underlying event, and the school's own description of a provider-side compromise matches the shape of the listing. But the connection is not independently established: no source other than the leak-site listing itself links that named provider to HWZ. The school names no provider. Neither outlet covering the story names one through its own reporting. This entry therefore does not name the company either, naming a firm as breached on the unverified assertion of the group extorting it is exactly the failure mode this pipeline's sourcing rules exist to prevent, and a different provider name circulating in the primary's reader comments is speculation with no sourcing at all.

What is established is the structure, and it is the reason a Swiss federal SOC should care about a business school's mailing list. One managed-IT or hosting compromise produced simultaneous personal-data exposure at several independent organisations that had no intrusion of their own, no security failure of their own to remediate, and (in HWZ's case) no ability to tell affected people anything until the provider's investigation reached them. The named customer set is seven organisations plus one higher-education institution, and the listing ends that enumeration with "etc.", so eight is a floor rather than the full extent. That is the ordinary shape of a regional IT provider's book of business, and therefore the ordinary shape of this blast radius: the organisations that know they are affected are the ones the attacker chose to name.

Nach aktuellem Untersuchungsstand erfolgte ein Angriff über die Infrastruktur des Dienstleisters

Inside Paradeplatz, quoting HWZ's letter to students

We can confirm that personal data are among the stolen data. (translated from German)

HWZ media office, via Inside IT
Updaterun 2026-09-01T0411Z-intelsummarysourcesevidencebody

Inside IT reported on 2026-08-31, under the headline "HWZ-Daten landen im Darkweb" ("HWZ data lands on the dark web"), that data from the breach has been published; the outlet attributes the provider-side intrusion to a ransomware group but hedges that attribution itself with "offenbar" (apparently) (Inside IT, 2026-08-31). That supersedes the position HWZ gave Netzwoche on 2026-08-26, when the school stated there were no indications the stolen data had been published or misused (Netzwoche, 2026-08-26). HWZ's confirmation that personal data are among the stolen records (quoted by Inside IT in the same article, but itself given to a separate Inside IT report the prior week) restates rather than extends what this entry already established from HWZ's original letter to students. The named provider's identity is still established only by the extortion group's own leak-site listing, and no source has named it independently.

incident23 Aug 05:18Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • ictk.ch1 (20%)
  • inside-it.ch1 (20%)
  • insideparadeplatz.ch1 (20%)
  • netzwoche.ch1 (20%)
  • ransomware.live1 (20%)