CMD Organization
CMD Organization is a ransomware and data-extortion threat group that publicly claims intrusions against organizations and uses leak-site shaming to pressure victims.
Profile source: Mallory opens in a new tabCMD Organization
Family profile
CMD Organization is a ransomware and data-extortion threat group that publicly claims intrusions against organizations and uses leak-site shaming to pressure victims. The group has been observed listing victims on extortion infrastructure and publishing sample stolen documents to support its claims. Reporting also associates it with an auction-style monetization model in which allegedly stolen datasets are offered to the highest bidder, indicating a financially motivated operation centered on double-extortion and possible data resale.
Observed victimology includes educational institutions, and the group has appeared in weekly ransomware claim tracking as an active but not top-tier actor, with multiple claimed victims across separate reporting periods in mid-2026. In one publicly reported university intrusion, the group claimed theft of a large volume of sensitive data, issued a cryptocurrency ransom demand, and threatened timed publication of additional material. That incident was also characterized by disruptive actions beyond exfiltration, including deletion of files from affected storage systems, consistent with coercive pressure designed to hinder recovery and increase leverage.
Tactics attributed to CMD Organization include unauthorized network access, data exfiltration, extortion via leak-site publication, deadline-based ransom demands, and destructive or disruptive post-compromise activity such as file deletion. The groupβs operating model suggests overlap between ransomware and pure extortion tradecraft: public victim naming, proof-of-compromise releases, and sale or threatened release of stolen information. Available information supports classifying CMD Organization as a cybercriminal extortion actor. No high-confidence public attribution to a nation-state sponsor is currently available.
Operational record
Recent claims
MITRE ATT&CK