CRPX 0 is a malware group that gained attention for its tactic of offering free OnlyFans accounts to entice victims into clicking links that deploy malware. Since launching a leak site on August 7, it has listed 47 victims, primarily targeting dental practices in the U.S. CRPx0 claims to have exfiltrated significant data from these victims, but a review of their websites found no breach notices. Data requests sent to the victims received no responses, making the claims unverified.
Particularly concerning cases involve Phoenix Dignity, a non-profit for human trafficking survivors, and Encore Enterprises, which the group claims had over 700 GB of sensitive data leaked. CRPx0's operations rely on exploiting vulnerabilities, and they communicate a philosophy of revealing what organizations try to conceal, indicating a growing trend of data breaches and the importance of timely notifications from affected entities.