Incident analysis
Raqib was listed by Umbra ransomware, a group with 10 victims recorded in this database. The listing appeared on the group's leak site on October 7, 2026.
Sector context. Technology companies hold intellectual property, customer data, and source code — all highly valuable assets. A successful ransomware attack can also put downstream customers at risk through supply chain exposure.
Umbra typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.