Maze Ransomware Operators Publish User Information on a website where they identified the names and websites of eight businesses who allegedly refused to pay the ransom. Businesses who fell victim to Maze ransomware are now facing another threat: their data could become public. Maze operators publish data on that page, such as the initial date of contamination, certain compromised records (office, text and PDF files), the overall volume of data allegedly obtained from the company. Cisco Talos attributed to the same perpetrator, and PowerShell was used to dump large amounts of data using FTP.”]
Source: https://hackercombat.com/maze-ransomware-operators-publish-user-information/