Krybit Claims Buzz Trading 104 Breach While ShinyHunters Claims Alcon as a New Victim + Video

Listen to this Post

Featured ImageIntroduction: Two New Ransomware Claims Raise Fresh Cybersecurity Concerns

The ransomware and cyber-extortion landscape is once again drawing attention after threat intelligence monitoring identified two fresh victim claims on August 2, 2026. According to the ThreatMon Threat Intelligence Team, the Krybit ransomware operation allegedly added South African company Buzz Trading 104 to its victim list, while a separate listing attributed to ShinyHunters named global eye-care company Alcon Inc. as another alleged victim.

These developments are significant, but they require an important distinction: a ransomware or extortion group naming an organization does not automatically prove that the organization was successfully compromised. Threat actors sometimes publish genuine victims, but they can also exaggerate, recycle information, list organizations during negotiations, or make claims that later turn out to be inaccurate.

At the time of this report, the available information confirms that the two organizations were named in threat-intelligence monitoring activity, but it does not independently establish the scope of any intrusion, whether data was stolen, whether systems were encrypted, or whether ransom demands were actually made.

The August 2 ThreatMon Reports

The first alert attributed the claim to Krybit ransomware activity and identified buzztrading104.co.za as the alleged victim. The timestamp supplied in the original report was August 2, 2026, at 19:16 UTC+3.

The second alert appeared several hours earlier and attributed a victim listing involving Alcon Inc. to ShinyHunters. That listing was timestamped August 2, 2026, at 03:00 UTC+3.

The two cases are particularly interesting because they represent different parts of the modern extortion ecosystem. Krybit is primarily associated with ransomware-as-a-service and double-extortion operations, while the FBI describes ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion.

Buzz Trading 104: What We Know

Buzz Trading 104 is a South African manufacturing and distribution business based in Germiston. Its official website describes the company as a manufacturer of plastic-molded products serving multiple industries and says the business has operated in the plastics manufacturing sector since 2003.

The company’s product portfolio includes housewares, storage products, outdoor products, industrial wheelie bins, children’s furniture, plastic packaging and ladders. Its website currently lists hundreds of products across several categories.

Buzz Trading 104 official website

Why Buzz Trading 104 Could Matter to Attackers

A manufacturing company may appear less strategically important than a bank, hospital or technology giant, but that assumption is dangerous. Manufacturers frequently depend on interconnected business systems, supplier relationships, customer databases, inventory platforms, accounting systems and operational technology.

For ransomware affiliates, the attraction can be simple: operational disruption creates urgency. If a company cannot process orders, communicate with customers, access accounting records or coordinate deliveries, the economic pressure to restore operations can become immediate.

Buzz Trading

The Krybit Connection

Krybit is a relatively new ransomware-as-a-service operation that emerged in 2026. Threat intelligence researchers have described it as a cross-platform ransomware operation capable of targeting Windows, Linux, VMware ESXi and NAS environments.

Its reported model follows the now-familiar double-extortion formula: steal information first, encrypt systems where possible, and then threaten to publish the stolen information if the victim refuses to cooperate.

That model means an organization can face two separate forms of damage. The first is operational disruption caused by encryption or compromised infrastructure. The second is the possibility that confidential information could be published or sold.

Krybit Has Already Attracted Security Attention

Krybit’s emergence has been unusually dramatic. Earlier in 2026, rival cybercriminals associated with 0APT breached Krybit’s own infrastructure, exposing information related to the ransomware operation. Bitdefender reported that leaked information included administrative and affiliate data, credentials, cryptocurrency wallet addresses, victim information and ransom-related communications.

The incident demonstrated an uncomfortable reality of the ransomware economy: criminal organizations themselves are vulnerable to compromise.

Krybit nevertheless continued operating after the exposure. Security researchers have continued to document new victim claims, indicating that the infrastructure and affiliate ecosystem did not simply disappear after the internal breach.

ShinyHunters and the Alcon Claim

The second August 2 claim involves Alcon, a major global eye-care company operating across surgical and vision-care markets.

Alcon says it operates in 60 countries and serves patients in more than 140 countries. Its operations include ophthalmic surgical products, intraocular lenses, contact lenses and other vision-care products.

Because Alcon operates within healthcare and medical-device markets, any confirmed compromise could have consequences beyond ordinary corporate data theft. However, there is currently no public evidence in the sources reviewed here establishing that ShinyHunters successfully compromised Alcon or what information, if any, may have been accessed.

ShinyHunters Is Not Simply a Traditional Ransomware Group

Calling every ShinyHunters incident a conventional ransomware attack can create confusion. The FBI describes ShinyHunters primarily as a cybercriminal group specializing in large-scale data breaches and extortion. Its campaigns commonly involve stealing data and demanding payment in exchange for not publishing it.

That distinction matters because data theft can produce enormous consequences even when no computers are encrypted.

A company can remain fully operational while simultaneously suffering a serious security incident involving customer records, employee information, business documents, credentials or internal communications.

The

ShinyHunters has been linked to a series of large-scale extortion campaigns throughout 2026. The FBI has warned that the group has targeted organizations across technology, finance and retail and that threat actors may sometimes exaggerate their claims of access to sensitive information.

That warning is especially relevant to the Alcon claim.

The correct journalistic position is therefore neither to dismiss the claim nor to present it as confirmed. The appropriate classification is alleged victim listing pending independent verification.

Why the Difference Between a Claim and a Breach Matters

A dark-web victim listing is a threat-intelligence signal, not automatically a forensic conclusion.

Threat intelligence teams monitor these listings because they can provide early warning that an organization may be negotiating with attackers, investigating an intrusion, preparing a disclosure or facing an upcoming data leak.

But a listing alone cannot answer several critical questions.

Was the victim actually compromised?

Was data exfiltrated?

Was ransomware deployed?

Was the information authentic?

How much data was allegedly stolen?

Did the attacker obtain credentials?

Was the incident caused by a third-party supplier?

Was the organization already aware of the intrusion?

These questions require evidence.

The Bigger Ransomware Trend

The two claims also illustrate how modern cybercrime continues to move away from the simplistic image of a hacker encrypting computers and demanding cryptocurrency.

Today’s extortion ecosystem is more complicated.

Attackers may steal data without encrypting systems. They may compromise cloud applications instead of traditional servers. They may use stolen identities rather than malware. They may target suppliers instead of the ultimate victim. And they may delay publication for weeks while negotiating privately.

This makes the public leak-site announcement only one visible stage of a much longer attack lifecycle.

Identity Has Become the New Perimeter

One of the most important trends associated with modern ShinyHunters activity is the abuse of identity and cloud access.

Google-linked reporting has described ShinyHunters-related campaigns involving vishing, credential harvesting and attacks against corporate single sign-on environments.

This matters because an attacker who obtains a legitimate employee identity may not need to exploit a sophisticated software vulnerability.

The attacker can simply log in.

From the

The Manufacturing Risk

For Buzz Trading 104, the primary concern would not necessarily be the public website itself.

The more important question is what sits behind the company’s digital perimeter.

Manufacturing businesses commonly rely on email, ERP systems, file servers, accounting platforms, inventory systems, remote-access services, customer databases and supplier communications.

A compromise of one identity can potentially become a pathway into several interconnected systems.

The Healthcare Risk

Alcon presents a different risk profile.

A healthcare technology company can possess valuable intellectual property, corporate information, employee records, customer information, research data and operational documentation.

Even when patient-facing systems are not directly affected, stolen corporate information can have considerable commercial value.

For an extortion group, the value is not necessarily limited to what can be sold. The threat of disclosure itself can become the weapon.

Why Attackers Publicize Victims

Ransomware groups do not publish victim names purely for publicity.

The leak-site model is part of the extortion mechanism.

Publicly naming an organization creates pressure on executives, legal teams, customers, investors and business partners.

It can also demonstrate credibility to potential affiliates.

A ransomware group that constantly publishes new names is effectively advertising its ability to compromise organizations.

The Psychological Side of Extortion

Cyber extortion is partly a psychological operation.

Attackers want defenders to feel that time is running out.

A countdown timer, a victim listing or a threat to publish stolen files can transform a technical incident into an executive crisis.

That is why organizations need incident-response plans that are designed before an attack occurs.

The worst time to decide who speaks to the attacker, who contacts regulators and who approves public statements is during the first chaotic hours of an incident.

What Undercode Say:

The Most Important Word Is “Claimed”

The most important detail in this story is not the word “ransomware.”

It is the word claimed.

Threat actors have a direct financial incentive to make their operations appear successful.

A victim list can therefore function as both an intelligence source and a marketing channel for criminals.

ThreatMon’s Role Is Early Warning

Threat intelligence monitoring can be extremely valuable because leak-site activity may surface before a company publicly acknowledges an incident.

That makes services tracking ransomware infrastructure useful for defenders, journalists and security researchers.

But monitoring does not equal forensic confirmation.

Buzz Trading 104 Deserves Verification

The Buzz Trading 104 listing should be treated seriously enough to warrant verification, but not seriously enough to declare a confirmed breach without evidence.

The

Website availability, however, does not prove that internal systems are unaffected.

A Working Website Means Very Little

One of the easiest mistakes in breach reporting is assuming that a functioning homepage means there was no attack.

Ransomware incidents can affect internal systems while a public website remains online.

Attackers may also steal data without causing visible disruption.

ShinyHunters Requires a Different Lens

The Alcon claim should be analyzed primarily as a potential data-extortion incident rather than automatically labeled a conventional encryption-based ransomware attack.

The

Alcon’s Scale Raises the Stakes

Alcon operates internationally and handles information across a large corporate ecosystem.

That does not mean the alleged incident is necessarily large.

It means the potential consequences of a genuine compromise could be significant.

The Evidence Gap Is Still Large

There is currently a major gap between the threat-intelligence claims and independently verified forensic evidence.

No publicly confirmed dataset, ransom note, technical indicator, intrusion timeline or company disclosure has been established in the sources reviewed for this article.

That gap should remain visible in every responsible report.

Ransomware Groups Can Lie

Threat actors have repeatedly demonstrated that victim lists are not infallible.

Researchers have documented situations where ransomware operations exaggerated victim counts or published questionable claims.

The existence of a leak site does not automatically transform every listing into a confirmed incident.

But Ignoring Claims Is Also Dangerous

The opposite mistake is equally serious.

Security teams should not ignore a victim listing simply because it has not been confirmed.

A credible threat intelligence alert can provide valuable time for investigation.

That time can be used to review authentication logs, endpoint activity, cloud access and unusual outbound traffic.

Early Investigation Can Change the Outcome

If an attacker is still inside a network, discovering the activity quickly can potentially prevent additional data theft.

That makes the first hours after a credible allegation especially important.

The objective is not to panic.

The objective is to investigate.

Credentials Should Be Reviewed

Any organization named by an extortion group should prioritize investigation of privileged accounts, remote-access accounts, service accounts and recently created identities.

Unexpected MFA registrations, unusual login locations and impossible-travel events can provide valuable clues.

Cloud Logs Matter

Modern extortion operations increasingly involve cloud applications and SaaS platforms.

Consequently, organizations should investigate cloud audit logs rather than concentrating exclusively on traditional endpoint telemetry.

Third-Party Access Matters Too

A compromise does not necessarily begin inside the victim’s own infrastructure.

Suppliers, managed service providers, identity platforms and software integrations can become pathways into corporate environments.

This is especially important for multinational organizations with complex technology ecosystems.

Data Exfiltration Is the Critical Question

For an extortion claim, defenders need to determine whether information actually left the environment.

Large outbound transfers, unusual cloud-storage activity, archive creation and unexpected connections to external infrastructure can become important forensic evidence.

Encryption Is Only One Indicator

Organizations should not limit their investigation to ransom notes or encrypted files.

An attacker may steal data and leave without deploying encryption.

That scenario can still produce a major breach.

The Ransomware Economy Is Becoming More Modular

Modern ransomware groups increasingly resemble businesses.

Developers create malware.

Affiliates obtain access.

Negotiators communicate with victims.

Infrastructure operators maintain leak sites.

Money launderers move cryptocurrency.

The division of labor makes the ecosystem resilient.

Krybit Fits the RaaS Pattern

Krybit’s reported affiliate model reflects this broader criminal-business structure.

Security researchers have documented its cross-platform capabilities and double-extortion strategy.

ShinyHunters Fits the Extortion Pattern

ShinyHunters represents another evolution of the same economic concept.

Instead of depending entirely on encryption, the group can monetize stolen information by threatening disclosure.

The FBI specifically warns that ShinyHunters uses large-scale data theft and extortion.

The Dark Web Is Only Part of the Story

The visible leak-site post may represent the final stage of an attack that started much earlier.

Initial access could have happened days or weeks before the victim was publicly named.

That means defenders should investigate historical logs rather than looking only at activity from August 2.

Historical Logs Could Be Crucial

Organizations investigating these claims should preserve authentication records, endpoint telemetry, VPN logs, cloud audit trails, email logs and network-flow information.

Evidence can disappear quickly through log rotation.

Preservation should therefore happen before routine cleanup removes valuable data.

Public Communication Requires Discipline

A company named on a leak site should avoid making assumptions before completing an investigation.

Saying too much can create unnecessary panic.

Saying too little can also damage trust.

The best communication is factual, measured and transparent about what is known and unknown.

Customers Need Accurate Information

Customers often hear about cyber incidents through social media before companies issue formal statements.

That creates a dangerous information vacuum.

If an incident is confirmed, organizations should explain what happened, what information was affected, what has been contained and what customers should do.

Law Enforcement Can Become Relevant

A confirmed extortion attempt may require coordination with law enforcement and regulatory authorities.

Organizations should preserve evidence rather than deleting attacker communications or modifying systems without documenting the changes.

Ransom Payment Is Not a Simple Solution

Paying an attacker does not automatically restore trust.

It does not guarantee that stolen data will be deleted.

It does not guarantee that the attacker will not return.

And it does not eliminate regulatory or legal responsibilities.

Backups Remain Essential

Reliable offline or otherwise protected backups remain one of the strongest defenses against destructive ransomware.

But backups must be tested.

A backup that cannot be restored under pressure is not a dependable recovery strategy.

Recovery Speed Is a Security Control

The ability to restore systems quickly changes the economics of ransomware.

When organizations can recover independently, attackers lose one of their strongest forms of leverage.

Resilience therefore becomes part of cybersecurity rather than merely an IT responsibility.

Threat Intelligence Should Feed Security Operations

Threat intelligence should not exist as a separate stream of information that nobody acts upon.

When a victim claim appears, security teams should have a defined workflow for validating it.

The process should connect intelligence analysts, SOC personnel, incident responders, legal teams and executive leadership.

Defensive Command: Search Authentication Logs

During an investigation, defenders can begin with searches for suspicious authentication events. For Linux environments, a basic defensive review can include:

grep -Ei "failed|invalid|authentication failure|accepted" /var/log/auth.log

The command is only a starting point and should be adapted to the organization’s logging architecture.

Defensive Command: Search Windows Security Logs

For Windows environments, defenders can review recent authentication activity through PowerShell:

Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4624,4625} -MaxEvents 500

Event 4624 represents successful logons, while 4625 represents failed logons. Analysts should correlate the events with users, source addresses, timestamps and expected business activity.

Defensive Command: Look for Recently Modified Files

On Linux systems, investigators can identify files modified within a recent timeframe:

find /var/www /home -type f -mtime -3 -ls

This does not prove malicious activity, but unexpected modifications can become useful evidence when correlated with other telemetry.

Defensive Command: Preserve Evidence

Evidence collection should be performed carefully and according to the organization’s incident-response procedures.

A simple first principle is to preserve original logs before deleting, rotating or overwriting them.

Forensic copies should be stored separately from systems that may still be compromised.

The Bigger Lesson for Manufacturers

Manufacturers should treat cybersecurity as part of operational continuity.

An incident affecting email, ERP, inventory, customer service or file storage can quickly become a physical business problem.

Cybersecurity and supply-chain resilience are therefore increasingly connected.

The Bigger Lesson for Healthcare Technology

Healthcare companies and medical-device manufacturers face an additional challenge.

Their digital systems support businesses connected to products, clinicians, customers and patients.

A breach does not automatically mean patient harm, but the potential consequences make early detection particularly important.

The Bigger Lesson for Everyone

The most dangerous assumption in cybersecurity is that an organization will know when it has been attacked.

Modern attackers increasingly attempt to remain invisible.

They may use legitimate credentials.

They may access cloud services.

They may steal data quietly.

They may wait before publishing a victim.

The public ransomware announcement can therefore arrive long after the initial compromise.

Deep Analysis: What Happens After a Victim Listing?

Step 1 — Validate the Claim

Security teams should first establish whether the listing is genuine and whether the named organization is actually the intended entity.

Typos, impersonation and false claims are common enough that validation should be mandatory.

Step 2 — Check for Internal Indicators

The next step should be a rapid review of identity, endpoint, network and cloud telemetry.

The objective is to identify suspicious activity that overlaps with the alleged attack window.

Step 3 — Review Privileged Access

Privileged accounts deserve immediate attention.

Investigators should determine whether administrator accounts were accessed from unusual locations, whether new MFA devices were registered and whether authentication patterns changed unexpectedly.

Step 4 — Examine Data Movement

The investigation should then focus on possible data staging and exfiltration.

Large archives, unusual compression activity, cloud-storage transfers and unexpected outbound connections can help establish whether information may have been removed.

Step 5 — Determine Operational Impact

For Krybit-style ransomware, defenders should determine whether systems were encrypted, whether backups were affected and whether lateral movement occurred.

For ShinyHunters-style extortion, the focus should also include potential unauthorized access to databases, SaaS platforms and corporate documents.

Step 6 — Preserve the Timeline

Investigators should build a timeline beginning before the public claim.

The first suspicious login may have occurred long before the victim appeared on a leak site.

Step 7 — Separate Facts From Claims

Every incident report should distinguish between confirmed evidence, suspected activity, threat-actor claims and information that remains unknown.

This prevents speculation from becoming institutional fact.

Step 8 — Monitor for Publication

If attackers threaten to publish stolen information, organizations should monitor for new releases while continuing their forensic investigation.

Publication monitoring can help determine whether claimed stolen files are authentic.

Step 9 — Prepare Customer Communication

If sensitive information is confirmed to have been exposed, communication plans should be activated quickly.

Customers should receive clear information rather than vague reassurance.

Step 10 — Continue Monitoring After Recovery

Recovery does not necessarily mean the threat has disappeared.

Attackers may retain credentials, persistence mechanisms or stolen information.

Post-incident monitoring is therefore essential.

Why August 2 Matters

The August 2 claims demonstrate how quickly ransomware intelligence can move from underground leak infrastructure into public discussion.

Within hours, a victim name can spread across social media, security communities and news outlets.

That creates pressure on the alleged victim even before investigators determine what actually happened.

The Information Vacuum Problem

When organizations do not immediately confirm or deny a claim, speculation fills the gap.

Threat actors understand this.

That is why victim listings themselves can become part of the extortion strategy.

The announcement creates uncertainty, and uncertainty creates pressure.

The Most Important Defensive Advantage

The strongest advantage defenders have is not a particular antivirus product.

It is visibility.

Organizations that understand who is logging in, what systems are being accessed, what data is moving and what identities are changing are in a much stronger position to detect attacks.

The Most Important Business Advantage

Resilience is equally important.

A company with tested backups, segmented networks, strong identity controls and rehearsed incident-response procedures has more options when attackers arrive.

Options reduce extortion pressure.

The Most Important Editorial Lesson

Cybersecurity reporting must resist the temptation to turn an allegation into a confirmed breach.

The public deserves accurate information.

Victims deserve fair treatment.

Security teams deserve actionable intelligence.

Threat actors should not be allowed to control the narrative simply because they published a company name.

❌ No Independent Confirmation of the Buzz Trading 104 Breach

The available evidence confirms that ThreatMon reported a Krybit victim listing involving Buzz Trading 104, but the reviewed sources do not independently establish that Buzz Trading 104 was successfully compromised, encrypted or had data stolen.

❌ No Independent Confirmation of the Alcon Breach

The ShinyHunters listing naming Alcon is also an allegation at this stage. No public Alcon disclosure confirming a ShinyHunters compromise was identified in the sources reviewed for this article. Alcon’s official newsroom remains active with regular corporate announcements.

✅ Krybit and ShinyHunters Are Established Cybercrime Threats

Krybit is documented as an emerging ransomware-as-a-service operation, while the FBI identifies ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion. Their existence and broader malicious activity are well documented, even though these specific August 2 victim claims remain unverified.

Prediction

(+1) Threat Intelligence Monitoring Will Become More Important

As ransomware groups increasingly publish alleged victims, organizations will rely more heavily on automated dark-web monitoring to identify claims before they become major public incidents.

(+1) Identity Security Will Become a Primary Battleground

The continued use of stolen credentials, phishing and cloud access means identity protection will become increasingly important alongside traditional endpoint security.

(+1) More Ransomware Groups Will Favor Data Theft

The economics of extortion increasingly favor stealing valuable information even when attackers cannot encrypt an entire environment.

(+1) Manufacturing Will Receive Greater Attention

Manufacturing organizations remain attractive because operational disruption can produce immediate financial pressure, making them valuable targets for financially motivated attackers.

(+1) Healthcare Technology Will Remain High Value

Organizations involved in healthcare, medical devices and life sciences will continue to attract attackers because their data, intellectual property and operational dependencies can carry significant strategic value.

(-1) False Victim Claims Will Continue

Some ransomware and extortion groups will continue publishing exaggerated or inaccurate victim claims as a way to strengthen their reputation and pressure organizations.

(-1) Public Confusion Will Increase

The growing speed of social-media reporting means unverified claims can spread faster than organizations can investigate them.

(+1) Verification Will Become a Competitive Advantage

Security teams capable of rapidly distinguishing a genuine intrusion from an unsupported threat-actor claim will be better positioned to protect customers, employees and corporate reputation.

Final Assessment

The August 2, 2026 ThreatMon alerts should be regarded as important threat-intelligence signals, not confirmed breach disclosures.

Krybit’s alleged addition of Buzz Trading 104 and ShinyHunters’ alleged addition of Alcon demonstrate two different versions of the same modern extortion economy: one built around ransomware and double extortion, the other heavily centered on large-scale data theft and public pressure.

The claims deserve investigation because both threat actors have established records of malicious activity. But responsible cybersecurity reporting must stop short of declaring either organization breached until stronger evidence emerges.

For Buzz Trading 104, the central question is whether Krybit obtained unauthorized access, stole information or deployed ransomware.

For Alcon, the central question is whether ShinyHunters obtained authentic corporate or sensitive information and whether the organization has identified an associated intrusion.

Until those questions are answered, the most accurate description remains simple: both organizations have reportedly been named as victims, but the specific August 2 claims remain unverified.

▶️ Related Video (80% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube