Ransomware

Deloitte Responds After Ransomware Group Claims Data Theft

Deloitte has issued a response after the Brain Cipher ransomware group claimed to have stolen over 1 TB of information belonging to the company.

Deloitte hacked

Deloitte has issued a statement in response to a ransomware group’s claims regarding the theft of a significant amount of information belonging to the company. 

The ransomware group calling itself Brain Cipher listed Deloitte UK on its Tor-based website last week, claiming to have obtained over one terabyte of data (they claim this is the volume of the data when compressed).

The hackers are threatening to make the stolen files available in five days from now, unless a ransom is paid. 

“We are aware of the claims by the threat actor,” a Deloitte spokesperson told SecurityWeek. “Our investigation indicates that the allegations relate to a single client’s system which sits outside of the Deloitte network. No Deloitte systems have been impacted.”

Brain Cipher has been around since at least April 2024, but it became known in June, after it targeted an Indonesian data center and caused significant disruption to government and other critical services in the country. 

The threat group has targeted dozens of organizations, including in the healthcare, education and manufacturing sectors. They deliver file-encrypting malware that is based on LockBit, and also steal data from victims. Some ties have been found to the ransomware groups named SenSayQ and EstateRansomware.

Advertisement. Scroll to continue reading.

This is the second time Deloitte has had to respond to hacking claims in recent months. In September, the notorious hacker IntelBroker claimed to have stolen sensitive data, but the audit and consulting giant said at the time that impact was limited.

Related: BT Investigating Hack After Ransomware Group Claims Theft of Sensitive Data

Related: Energy Sector Contractor ENGlobal Targeted in Ransomware Attack

Related: Two UK Hospitals Hit by Cyberattacks, One Postponed Procedures

Related Content

Data Breaches

The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.

Data Breaches

Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.

Data Breaches

Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.

Artificial Intelligence

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous...

Data Breaches

In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information.

Data Breaches

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Data Breaches

The company unintentionally disclosed users’ information to a third party impersonating a government agency.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version