news

Devman Group: New $91M ransom demand

Devman Group demands $91M after stealing 12TB of data, highlighting modern ransomware trends: massive thefts, targeted financial extortion, and high ransom demands.

Samuel Samuel · 1757947862 · 1 min read · 355
Devman Group: New $91M ransom demand

DEVMAN GROUP: New $91M ransom demand

On September 6, a new entry appeared on 𝗯𝗿𝗲𝗮𝗰𝗵.𝗵𝗼𝘂𝘀𝗲 linked to the emerging ransomware group hashtag Devman.

The demand? $91 million. The justification? According to Devman, the ransom amount was calculated based on stolen financial documents showing that the victim company had large cash reserves. The scope? The group claims to have stolen 12 TB of data after remaining in the network for several months, with persistence since May 25.

A key detail: this is not just about encryption. Devman’s extortion model increasingly relies on the victim’s financial intelligence to adjust ransom amounts, thereby applying tailored pressure.

📊 Reviewing entries on Breach House, Devman joins a growing ecosystem of ransomware groups. In the days before, two other cases were also recorded:

• Promisedland, Taiwan: ransom demand of $1,000,000

• Pure-Chemical, India: ransom demand of $5,000,000

Alongside Devman, two other actors stand out with recent activity:

1. Qilin, with dozens of victims across critical sectors.

2. Cactus, another expanding group combining unique encryption methods with double extortion.

These three groups illustrate today’s ransomware reality: higher ransom demands, targeted financial pressure, and massive data thefts.

At Darkeye Industries, we monitor these developments in real time, collecting leaks and ransom notes to map the evolution of cyber-extortion. Because understanding who Devman is today… may anticipate who comes next tomorrow.

Discover all attacks and leaks and check if your data has been compromised at:

📌 Breach House

🔎 HaveIbeenramsoned?

Share //
Samuel

Darkeye Research Team

Samuel

Tracking ransomware crews, breach disclosures and the tooling that matters — field notes from the Darkeye desk.

Intel briefing

Get breach reports before they trend

Ransomware intel and breach disclosures in your inbox. Signal only, no noise.

Read next //

Recent notable cases in 2025
news

Recent notable cases in 2025

Recent ransomware attacks in 2025 affected hospitals, governments, banks, and companies worldwide. BlackSuit, Royal, and other groups caused massive data breaches and financial losses. Early detection

Samuel · 1757939622

Keep investigating //

Discussion (0)

Sign in to join the discussion

Share your take with the Darkeye community.

No comments yet. Be the first to weigh in.