
i2i-systems Ransomware: Barracuda Group Exfiltrates 693 GB, Sells Data (September 2026)
i2i-systems: What Happened
In September 2026, i2i-systems was targeted by the ransomware group Barracuda, resulting in a significant breach of its digital infrastructure. The attackers exploited weaknesses in i2i-systems' security posture, gaining unrestricted lateral movement across the environment for over a week. During this window, Barracuda exfiltrated approximately 693 GB of sensitive data, including 44 GB of proprietary development source code and customer data associated with a joint project involving Turk Telekom. The breach also affected related partners, such as Veriskop, as evidenced by the exposure of joint infrastructure data. The stolen data has been listed for sale at $300,000, substantially increasing the risk profile for all organizations involved.
Attack Vector & Technical Detail
Barracuda’s intrusion leveraged poorly secured infrastructure within i2i-systems, enabling the group to bypass internal controls and move laterally without restriction. The attack did not rely on a specific CVE but instead exploited systemic weaknesses in network segmentation and access management. The attackers’ tactics align with MITRE ATT&CK techniques TA0001 (Initial Access), TA0005 (Defense Evasion), and TA0010 (Exfiltration), indicating a coordinated campaign focused on stealth and data theft. While no specific IOCs were provided, the group is known to advertise stolen data on the PrinzEugen leak site (Tor), highlighting the operational sophistication and monetization strategy of the threat actor.
Confirmed Impact
The breach resulted in the confirmed exfiltration of 693 GB of sensitive information, including critical Linux system data, multiple databases, and 44 GB of development source code. Customer data from a joint Turk Telekom project was also compromised, raising concerns about downstream exposure for both organizations and their clients. The presence of joint infrastructure data implicates Veriskop as an additional affected party. The global nature of the breach, combined with the public sale of the data, introduces significant regulatory and reputational risks, particularly regarding intellectual property loss and potential violations of data protection laws.
What This Means for Your Organization
This incident underscores the dangers of insufficient internal segmentation and inadequate monitoring of privileged access. Organizations with joint ventures or shared infrastructure are especially vulnerable to lateral movement by sophisticated threat actors. To mitigate similar risks, it is critical to enforce strict access controls, continuously monitor for anomalous behavior, and segment sensitive assets from less secure environments. Regular security assessments and incident response exercises should be prioritized to identify and remediate systemic weaknesses before they are exploited.
Detection & Response
- Immediate: Review and restrict access to all critical systems, focusing on accounts and services with elevated privileges.
- Hunt: Search for evidence of unauthorized lateral movement, particularly access to development source code repositories and Linux system data.
- Patch: N/A (No specific CVE identified; focus on hardening and segmentation).
Source: https://www.hendryadrian.com/ransom-i2i-systems-sep-2026/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

