August 20 Security Briefing: Sakura Internet, Ransom Busters, and Mabna Institute
This briefing covers Sakura Internet's expanded sales-system investigation, the Ransom Busters recovery impersonation scheme, and the expanded Mabna Institute indictment. Together, they show why early credential control, verification of unsolicited recovery offers, and strong protection for research accounts matter.

Three developments shape the August 20 briefing. Sakura Internet expanded an intrusion investigation from compromised rental servers to a sales-management system. GuidePoint Security described Ransom Busters, an actor that approached ransomware victims as a supposed recovery service before their incidents were public. The U.S. Department of Justice expanded its case against the Mabna Institute, detailing a long-running campaign against university and research accounts. Although the cases differ, each centers on control of trusted access: administrative credentials, the communications channel used during an incident, and academic email accounts.
Sakura Internet expands its sales-system investigation
Sakura Internet updated its second notice at 18:40 JST on August 19. The company said unauthorized access may also have reached its sales-management system, extending the scope of an investigation that began with compromised rental-server accounts. The maximum affected population cited in the notice is 1,360,563 member accounts. The data set includes account identifiers and password hashes, while the company says payment-card data is not stored in that system. The change in scope illustrates why responders should follow credentials and management paths rather than stop at the first compromised host.
The company had already addressed 583 rental-server accounts in the earlier phase, invalidated related credentials, removed malware, and strengthened monitoring. The sales-system review shows that those containment steps must be paired with an assessment of reused passwords, stored tokens, automation scripts, and remote-management tooling. An organization facing a similar event should preserve authentication logs before and after credential resets, identify shared administrator identities, and watch for access from new networks, unexpected API-key use, and dormant-account reactivation.

Password hashes still require a prompt user response. Depending on the algorithm and configuration, attackers can attempt offline guessing, and password reuse can turn one exposure into account takeover elsewhere. Notices should therefore explain how to change the affected password, review reuse across other services, and enable multi-factor authentication where available. Internally, the response should connect the customer database to the administrative identities and automated processes that can reach it.
Ransom Busters impersonates a recovery provider
GuidePoint Security's GRIT team described an actor calling itself Ransom Busters that contacted ransomware victims before their incidents were public. The messages asked to reach a chief executive or IT leader, claimed access to ransomware operators' administration panels, and offered to recover files and delete stolen data. The requested payment ranged from $20,000 to $60,000. Knowledge of a non-public incident is the central warning sign: the offer should be treated as part of the threat investigation, not as an independently trusted service.
Across two response cases, GRIT found overlapping use of SoftPerfect Network Scanner, s5cmd for cloud data transfer, and the Remotely remote-management tool installed through PowerShell. The environments also shared a local backdoor configuration and an attacker-controlled host artifact. Combined with observations across several ransomware-as-a-service operations, the team assessed with moderate confidence that Ransom Busters was a single affiliate using a new extortion tactic rather than a legitimate recovery firm. That confidence level and the supporting evidence should remain attached to any internal reporting.

A recipient should preserve the original message, headers, attachment hashes, wallet addresses, and contact timing, then route the material to the existing incident-response lead. Samples should be reviewed only in an isolated analysis environment. A claim that data will be deleted is not a technical assurance, and payment decisions should not be based on the third party's narrative. Legal counsel, insurers, law enforcement, and qualified responders should work through one approved communications channel so executives and employees do not answer from personal mailboxes or messaging accounts.
Mabna Institute charges expand
The U.S. Department of Justice unsealed a superseding indictment that brings the Mabna Institute case to 17 defendants, including eight newly charged individuals. Nine defendants had been charged in 2018. The allegations describe hacking-for-hire activity conducted for Iranian government bodies, universities, and paying customers. The university campaign allegedly began around 2013 and continued through at least December 2017, targeting more than 100,000 professor accounts and compromising roughly 8,000. The release cites 144 U.S. universities and 178 foreign universities, with South Korea among the listed countries.
The alleged workflow combined spearphishing, credential theft, access to email and online-library services, and exfiltration of academic material. DOJ says at least 31.5 terabytes of academic data and intellectual property were moved to infrastructure controlled by members of the conspiracy. The charges also describe websites that sold stolen resources or access through compromised professor accounts. Because an indictment is an allegation rather than a conviction, the figures and actions should be attributed to the Justice Department's case.

Universities and research institutions need controls that accommodate international collaboration without treating every overseas login as malicious. High-value accounts such as faculty, principal investigators, and library administrators should receive stronger authentication and session controls. Detection should connect unusual login context with mailbox forwarding rules, app passwords, long-lived sessions, and bulk downloads. Access should also be reviewed when a researcher changes roles or a project ends, because forgotten accounts and shared links can outlive their original purpose.
Operational priorities for today
The three cases suggest a practical sequence. Expand containment from the affected host to every credential, token, and management tool that could reach connected systems. Treat unsolicited recovery and negotiation approaches as another threat channel and verify them only through an approved response lead. Finally, correlate identity events with data access so that email compromise, library use, and large downloads can be evaluated as one user journey rather than isolated alerts.
- Review recent use of administrator accounts, API keys, and remote-management tools on one timeline.
- Preserve ransomware-related external messages and route them only through the approved response channel.
- Check MFA coverage and legacy authentication paths for faculty, researchers, and library administrators.
- Correlate mailbox rules, persistent sessions, and bulk data downloads by user identity.
- Include password-reuse guidance and post-reset login monitoring in customer notifications.
The value of this briefing is not in memorizing three names. Sakura Internet shows why investigation scope must follow credentials into connected systems. Ransom Busters shows why an offer of help can be part of the extortion chain. The Mabna Institute case shows how long-lived research accounts can become a route to intellectual-property theft. Teams can turn the news into action by confirming that they can identify every credential tied to a compromised host, control outside communications through one channel, and correlate identity activity with access to sensitive data.
Sources reviewed
- 不正アクセスによる情報漏えいの可能性に関するお知らせ(第二報)さくらインターネット · Official source
- Beware the Ransomware Rescuer: Ransom BustersGuidePoint Security · Official source
- 17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian EntitiesU.S. Department of Justice · Official source
SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.



Comments
No comments yet.