Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Money Message is a double-extortion ransomware group that emerged in March 2023, best known for the MSI (Micro-Star International) breach, with limited public activity since.
Money Message emerged in March 2023, first reported by Zscaler ThreatLabz, conducting double-extortion attacks that encrypt data and threaten leak-site publication. Its highest-profile incident was the April 2023 breach of Taiwanese hardware maker MSI, where the group claimed roughly 1.5 TB of stolen data and a $4 million demand; the leaked data reportedly included firmware code-signing keys, raising supply-chain concern. MSI publicly confirmed a cyberattack.
The group continued claiming victims into 2024 but at a far lower tempo than major brands such as LockBit or Play, and public reporting on new Money Message activity has been sparse since, consistent with a dormant or low-activity status.
Money Message has claimed victims in Egypt among its listings. Such leak-site claims are extortion allegations and should be treated as unverified rather than confirmed breaches unless independently corroborated.