What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Ox Thief threatened to expose data it claimed to have stolen unless an alleged victim paid a ransom. The group also said it might contact Edward Snowden, journalists and digital-rights organizations—a tactic meant to make the prospect of resisting the demand feel more costly. But reporting did not verify the alleged theft, and it did not establish that the attackers encrypted any files.
What did Ox Thief threaten?
On March 18, 2025, Dark Reading reported that Ox Thief had posted on a Tor-based leak site claiming to have stolen 47 GB of sensitive files. The group offered sample files for the alleged victim to assess and threatened to publish the material unless it was paid. The 47 GB figure was the group’s claim, not a verified measurement. Dark Reading reported the threat.
The Register, citing analysis by Fortra’s dark-web analysts, identified Broker Educational Sales & Training (BEST) as the alleged victim. Ox Thief claimed the material included employee personal data, client and company information, financial reports, insurance documents, contracts and database material. The Register cautioned that it had not independently verified either the group’s claims or the alleged theft. The Register’s account described the posting and the claims about BEST.
Why did the crew mention Edward Snowden?
Snowden was one name in a broader threatened-outreach list that also included journalist Brian Krebs, Have I Been Pwned founder Troy Hunt, the Electronic Frontier Foundation (EFF) and European digital-rights organization NOYB. The reports establish that Ox Thief threatened to contact these people and organizations; they do not establish that it actually did so or that Snowden received any data.
#1 Best Overall
The point of naming high-profile journalists and privacy advocates was to add public scrutiny and reputational pressure to the financial demand. Ox Thief also described potential legal and business consequences, attempting to make paying seem less costly than resisting. Nick Oram, Fortra’s senior manager of domain and dark-web monitoring solutions, characterized the approach this way:
“Ox Thief’s’ approach marks a concerning evolution in ransomware tactics, leveraging legal liability and media scrutiny to pressure victims into compliance. By explicitly outlining potential fines, class action lawsuits, and government penalties, the group is attempting to reframe the cost-benefit analysis of paying versus resisting extortion.”
Oram’s statement describes the pressure strategy; it does not confirm that any listed legal or financial consequence occurred.
Was this ransomware or data extortion?
The reporting confirms a threatened data leak in exchange for payment, but The Register said it had no information establishing that file-encrypting ransomware was used. Without evidence of encryption, “data extortion” is the more precise description: the alleged leverage was stolen information and a threat to publish it. Calling this a confirmed ransomware deployment would go beyond what the reports established.
Free tools Windows power users keep installed
One-click scans. No signup required.
What is confirmed—and what remains unverified?
- Observed: Ox Thief’s threat postings existed, and Fortra analysts reviewed them, according to The Register.
- Claimed, not independently verified: Ox Thief said it stole 47 GB from BEST and described categories of data it allegedly held.
- Not established: The reports did not confirm a BEST compromise, the amount or contents of stolen data, a ransom payment, publication of the alleged data, or file encryption.
- Not established: There is no reported confirmation that Ox Thief contacted Snowden or any of the other named people or organizations.
The reports also provide no reliable figure for the ransom amount, payment rate, number of victims or confirmed data release. Those details should not be inferred from the 47 GB claim or the threats themselves.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What makes the threat notable?
The case combined several forms of pressure in one posting: a conventional leak threat, named outreach to prominent public figures and advocacy groups, and warnings about legal, regulatory, media, reputational and incident-response costs. That combination is notable as an extortion tactic, but the available reporting does not show whether it succeeded.
Quick Recap
Best Value
- No more exposed information in unprotected notary journals. This product shields clients' confidential information from prying eyes. It allows the Notary Public to keep the journal open during the transaction, as NO prior client information is viewable.
- Shields clients' AND Notary Publics' confidential information
- GLBA and HIPAA require non-disclosure policies and procedures. Notary Privacy Guard is a compliance tool for the professional Notary Public.
- Decreases Notary Public's liability from exposing client information
- Journal column headers are printed on the Notary Privacy Guard, no having to peek underneath to complete the journal entry. Becomes part of the journal and also acts as a place marker.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

