2026-08-23NOTABLEHWZ confirms the theft and names no provider; the only source connecting a provider to it is the extortion group's own leak-site listing
Payload
actor · actor:payload-ransomware single-source
Data-extortion group operating a leak site; on 2026-08-20 it listed a Zurich-area IT and data-centre provider, claiming roughly 490 GB and naming eight affected customer domains including that of HWZ Hochschule fuer Wirtschaft Zuerich, which separately confirmed to students that data was stolen through a service provider's infrastructure. The connection between the named provider and the school rests solely on the group's own listing (Ransomware.live listing, 2026-08-20; Inside Paradeplatz, 2026-08-22).
Coverage
1
first 2026-08-23 → last 2026-09-01
Latest activity
2026-09-01
HWZ confirms the theft and names no provider; the only source connecting a provider to it is the extortion…
Peak priority
notable
1 notable
Targets
education
sectors: education, public-sector, technology · regions: switzerland, europe
Sources cited
5
5 hosts
Defender insights
What each entry about Payload tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessTrusted Relationship
Initial Access TA0001
T1199Trusted Relationship×1
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Evidence: 2026-08-23/payload-zurich-it-provider-hwz-student-data · ATT&CK page ↗
Entries about Payload (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- ictk.ch1 (20%)
- inside-it.ch1 (20%)
- insideparadeplatz.ch1 (20%)
- netzwoche.ch1 (20%)
- ransomware.live1 (20%)
All cited sources (5)
- ictk.chictk.chhttps://ictk.ch/inhalt/hwz-opfer-eines-schweren-cyberangriffs
- inside-it.chInside IThttps://www.inside-it.ch/hwz-daten-landen-im-darkweb-20260831
- insideparadeplatz.chInside Paradeplatzhttps://insideparadeplatz.ch/2026/08/22/cyber-attacke-konto-daten-von-hwz-studenten-geschnappt/
- netzwoche.chNetzwochehttps://www.netzwoche.ch/news/2026-08-26/hacker-greifen-hwz-daten-ueber-externen-dienstleister-ab
- ransomware.liveRansomware.live (Payload leak-site listing)https://www.ransomware.live/id/UXVhbGlmbGV4IERhdGFjZW50ZXIgfCBIV1otU3R1ZGllbmduZ2UgKGZoLWh3ei5jaCksIG15ZW5iLmNoLCBldGNAcGF5bG9hZA==