Listen to this Post

Introduction
A startling alert has emerged from the cyber‑threat front: on 14 November 2025 at 21:46:18 UTC+3, the hacker collective known as Incransom surfaced on the dark web claiming to have targeted the website eakas.com. According to the threat intelligence team of ThreatMon Threat Intelligence Team, this may only be the latest in a growing list of victims for a group that has quickly become notorious. The message, concise but chilling, cited ransomware activity under the hashtag DarkWeb and Ransomware—signalling a surge in audacity by cyber‑criminals.
In this context, it is crucial for organisations, IT teams and security‑minded professionals to understand what this attack means, how it fits into the broader ransomware ecosystem and what steps might lie ahead.
Main Narrative
On 14 November 2025, at 21:46:18 UTC+3, the group Incransom publicly declared that they had added eakas.com to their victim list. The statement was logged by the ThreatMon team who monitor dark‑web announcements and ransomware group activity.
The wording: “The ‘incransom’ Ransomware group has added http://eakas.com
to its victims.” – timestamped 1:04 AM, Nov 15 2025 (local time) — suggests the breach was live, recent and publicly claimed.
No additional details were provided in that short announcement about how the attack was conducted, what data may have been exfiltrated, or any ransom terms. The target, eakas.com, appears in the statement simply by URL; it is not clear from the announcement if the site is organisational, personal, or what sector is involved.
What makes this particularly noteworthy is the context: Incransom is rapidly climbing the ranks of cyber‑extortion groups. According to profile data, the group first appeared around early 2024 and is known for deploying double‑extortion techniques—encrypting systems while simultaneously stealing data to increase pressure on victims.
Cyber Defence
+2
Ransomware Live
+2
Victim listings attributed to the group number over 500, spanning industries and geographies (including the United States, Europe, South Africa and others) and targeting everything from mid‑sized businesses to governmental or institutional organisations.
Ransomware Live
+1
What the announcement reveals is less important than what it implies: this is not a minor “ransomware script kiddie” event; this is organised, industrial‑scale extortion. For eakas.com and for similar organisations, the message is clear—they were caught in the cross‑hairs.
The lack of further detail might indicate one of several scenarios: the group is still assessing data for public release; the victim may be negotiating; or perhaps the announcement is intended to panic and force a reaction. In any case, it signals to other potential victims that Incransom is active and willing to broadcast attacks.
This public claim is part of a tactic developed by modern ransomware groups: announcing victims publicly before or alongside ransom demands ramps up pressure, damages reputations and signals urgency. The strategy leverages fear of exposure as a tool alongside fear of data loss.
What Undercode Say:
Organisational Risk is Real and Growing
Incransom’s announcement reinforces what security watchers have been warning: ransomware is no longer just about encryption and downtime. The rapid shift to double‑extortion means stolen data is now the new battleground. If eakas.com indeed is the victim, the fact that only a simple announcement was published suggests the attacker either wants maximum publicity or is setting the stage for a large‑scale leak.
Organisations must treat this kind of threat as strategic — not just a technical event. Incransom’s operational tempo (hundreds of victims within a year) means the business‑impact risk is approaching the level of a major enterprise crisis. The time to react is before the breach, not after.
From a tactical viewpoint, the public naming of eakas.com serves three functions: first, it validates the group’s credibility to future victims (showing “we did it”); second, it pressures the target by public shame; third, it markets the ransomware business model by serving as a warning to others. Organisations must recognise they are not simply defending servers — they are defending trust, brand and operational continuity.
Another insight is sectoral breadth: the victim roster for Incransom spans manufacturing, healthcare, education, logistics, even governmental entities. This wide net means that no industry is safe and that security postures based on “we’re small, so we won’t be hit” are dangerously complacent.
Ransomware Live
What the eakas.com breach also emphasises is the importance of monitoring dark‑web intelligence and threat actor behaviour. ThreatMon’s role in publishing the detection shows the intelligence side of cybersecurity must operate not just inside the firewall but out on the open web, tracking claims, leaks and chatter.
In terms of response, the advice must be layered: patch protocols, phishing awareness, network segmentation, data backups — but equally critical are incident‑response plans, legal readiness (for data‑breach regulation), and reputational playbooks. A board must view ransomware not as an IT issue but a strategic risk.
Given the speed of Incransom’s operations, prevention alone may not suffice. Organisations would do well to assume they may become targets at some point. The difference will be in how prepared they are: visibility, rapid containment, data isolation, and crisis communications.
Finally, this public claim marks a potential turning point: the mere act of naming a target shows confidence by the attacker that they will not be stopped or traced. Incransom may be reaching a stage of operational maturity that rivals older groups like the INC Ransom group (noting confusion between names) which have been analysed to perform multi‑staged attacks exploiting vulnerabilities like CVE‑2023‑3519.
Vectra AI
+1
If Incransom continues on this trajectory, ransomware will increasingly become a corporate governance issue, a boardroom topic, a supply‑chain liability — not just an IT headache. This is the age of “we will leak your data publicly unless you pay” and the clock is ticking.
Fact Checker Results
✅ The group Incransom is publicly documented and known to use double‑extortion tactics.
Cyber Defence
+1
❌ There is no independent confirmation available (as of now) that eakas.com has been encrypted or data has been leaked; the announcement alone does not constitute proof of impact.
❌ The article’s timestamp corresponds with the claim but detailed technical evidence (breach vectors, ransom note, data dump) is not available in the public domain.
Prediction
Based on the pattern of Incransom’s operations, we are likely to see three key developments:
Within the next weeks, it is probable that more information about the eakas.com incident will surface — either a data leak, ransom negotiation disclosure, or public listing on the attacker’s leak site.
Organisations in the supply‑chain of eakas.com should brace for potential second‑wave effects (if attackers stole credentials or pivoted into partners) and treat this incident as a wake‑up call for vulnerability management.
The public naming tactic by Incransom will likely become more frequent. Other companies will appear on similar lists, and the taboo of “we don’t advertise breaches” will erode. Boards will need to adopt ransomware threat disclosure readiness as standard practice. 🔮
If you’d like, I can check whether eakas.com’s response has been made public or monitor for further leak listings.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




