```html ```
top of page

They Skipped the Leak Site and Published the Ransom Note on the Victim's Own Website. It Is Still There After the Cleanup — In Google.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 3 hours ago
  • 9 min read

Somebody calling themselves AMOZIHEV took a run at Colibri Group, and they did not do any of the things a ransomware crew is supposed to do.


There is no leak site. There is no onion address. There is no countdown timer on a dark-web portal that four hundred threat-intel analysts screenshot and nobody else ever sees. There is no post on a breach forum.


What there is, instead, is a notice addressed to Colibri Group, published on Colibri Group's own production websites, in front of Colibri Group's own paying customers. The title on every one of them is identical:


AMOZIHEV — NOTICE TO COLIBRI GROUP


We found it on five separate brands. As of this morning, all five sites are clean, restored, working normally. And Google still shows that headline as the title of every one of them.


That last sentence is the reason to write this. Everything before it is a defacement. That is something else.



Who Colibri is, because it matters to how this lands


Colibri Group is not a household name and is very likely in your life anyway. It is the company behind Elite Learning and Colibri Healthcare, which sell continuing-education credits to nurses and allied health professionals. It is behind McKissock, Colibri Real Estate and Allied Schools, which do real-estate licensing. It is behind STC, which does securities licensing. It is behind Becker, which is how a very large share of American CPAs studied for their exams. It bought an AI training company called Audirie in June.


So the customer base is nurses, real-estate agents, securities professionals and accountants — people who arrive at these pages through a search engine, with a regulatory deadline, needing a credit to keep a licence.


Hold that thought.



Not a defaced homepage. The whole estate.


The reflex read is "ransomware gang also defaces the front page," which crews have done since about 2021. That is not what this is, and the tell is in the URLs.


Two of the five indexed hits are not homepages. They are deep interior pages:


  • a Nevada real-estate licence requirements page, several directories down on colibrirealestate.com

  • a Series 16 securities exam-prep product page on stcusa.com

You do not reach a state-licensing requirements page by overwriting index.html. Getting the same notice onto a homepage and a state licensing subpage and a healthcare CE catalogue across five different brands means the substitution happened somewhere shared — an origin, a CDN configuration, a CMS template, a build pipeline, or the thing the actor themselves claims.


Because they do claim it. The notice says the page is proof that they control the DNS, that they have full access to Colibri's infrastructure, and that the scope covers "every service under Colibri Group — McKissock, Becker, Elite Learning — including Audirie."


We have not verified that. Colibri's nameservers are AWS Route 53 and resolve normally today; the fronting is Cloudflare. We see no independent evidence of a registrar or DNS compromise, and there are several duller explanations for site-wide substitution. The DNS claim is an assertion by someone whose entire product is leverage, and we are reporting it as an assertion.



What the DNS actually shows, and the brand that breaks the story


We resolved all nine brands ourselves. Eight of them — Elite Learning, Colibri Healthcare, Allied Schools, Colibri Real Estate, STC, McKissock, Becker and the Colibri Group site itself — sit behind the same Cloudflare edge, in the same address block, with their zones on AWS Route 53.


That is a shared control plane, and it is the boring, sufficient explanation for how one actor put identical content on five brands including deep interior pages. You do not need nine compromises. You need one seat. And to be fair to Colibri: consolidating a multi-brand estate onto one CDN and one DNS provider is normal, competent practice. The observation is not that they did something stupid. It is that the blast radius of a single credential in that estate is nine public brands — which is a thing worth knowing before it is demonstrated for you.


Then there is Audirie, and Audirie is where the notice starts to wobble.


Audirie is the AI training company Colibri acquired in June. It has not been integrated. Its nameservers are GoDaddy, not Route 53. It is hosted on Netlify, not the shared Cloudflare edge. It has no infrastructure in common with any of the other eight.


The notice names Audirie explicitly as being in scope. We can find no indexed AMOZIHEV title for audirie.com, and if the actor really held DNS-level control of "the infrastructure," Audirie would have required a completely separate compromise at a different registrar in a different account.


There are two readings and we cannot separate them from outside. Either the actor has access at a layer above infrastructure — an identity provider, a corporate tenant — where staff of a newly acquired company would be in scope even though its website is not. Or they read the org chart. Colibri announced the Audirie acquisition by press release in June; naming the newest brand is a cheap way to sound like you have seen everything.


The second reading is the more economical one. We are not asserting it. But anyone assessing this notice should notice that the one brand which does not share infrastructure is also the one brand named without evidence.



The register is different too


The note does not read like the corporate legalese the LockBit lineage settled into. It reads like a person.


It says the access is "of the highest level — we could have deleted everything." It says they could have quietly sold the data on darknet markets or wiped the files, and chose to make contact instead. It offers to help fix the infrastructure. It says "we don't want anyone else getting the spoils," followed by a smiley face. It gives a deadline of Monday 17 August at 23:59 UTC, with a separate forty-eight-hour clause for getting in early. And it says this is not the first time this has happened.


Strip the theatre and the message is the one Henry Hill's associates had a shorter phrase for: fuck you, pay me. No brand, no affiliate programme, no press contact. Someone with access, a deadline, and a sense of humour.





Here is the part that has no precedent and no takedown


We checked nine Colibri properties in a real browser this morning: Elite Learning, Colibri Healthcare, Allied Schools, Colibri Real Estate, STC, Colibri Group, McKissock, Becker, Audirie — including the exact deep URLs that were indexed. Every single one returned a normal page with a normal title. Incident response worked. The sites are fixed.


At the same hour, on the same day, a search for AMOZIHEV returned those five URLs with the ransom note as their title — not in a cached copy, not behind a "cached" link. The headline Google serves for the live URL, the blue line a customer clicks, is the extortion notice. The page underneath it is a nursing CE catalogue.


Think about what that costs the attacker to maintain. Nothing.


Every extortion channel before this one had an ending. A clearnet mirror gets an abuse complaint. A forum post dies when the forum gets seized. An onion site cannot be taken down but also cannot be found by anybody outside the industry. A defaced homepage gets restored from backup and it is over in an hour.


An extortion notice resident in a search index has none of those properties. The attacker needed control of the estate only long enough to be crawled. After that, the persistence is provided free and indefinitely by a third party the victim cannot instruct and the attacker never has to touch again. There is no infrastructure to seize, because the hosting is Google's.


And the victim cannot fix it by fixing the site. They can request a recrawl, resubmit a sitemap, use URL Inspection — but they cannot compel it, and the latency on a deep interior page of a mid-traffic commercial site is days to weeks. Which produces the perverse result: the lower-traffic the page, the longer the ransom note stays up. A Nevada licensing requirements page does not get crawled hourly. The obscure pages, the ones nobody worried about, are the ones that hold the message longest.


An incident response team that closed the ticket when the origin came back clean has left the note live in the only place the customers actually look.



What a nurse sees


This is where the target selection stops being incidental.


Somebody types "Nevada real estate license requirements." Somebody types "Elite Learning nursing CE." They are not doing security research. They have a licence renewal deadline and a credit card. The result they get back is an extortion notice addressed to the company they were about to pay.


They do not know whether their own data was in it. They do not know whether the site is safe to buy from. They have no way to tell that the notice is stale and the site behind it is fine, because from the search results page those two things look exactly the same.


That is the leverage. Not "your data will appear on a leak site in six days." Your customers are being told right now, in the moment they were going to buy, by Google. The pressure is on revenue, in real time, and it keeps running after the technical incident is closed.



We cannot find that anyone else has written this up


We checked our own corpus first — every index, 17.9 million documents. AMOZIHEV returns zero. Bing returns zero. DuckDuckGo returns zero. No vendor blog, no ransomware tracker, no journalist. urlscan.io has captures of these domains going back years and not one of the defaced state; the nearest bound we have is a clean capture of becker.com on 7 August.


So the entire public record of this incident is five titles in one search engine's index, which is also the mechanism of the attack. We have archived what we can — page text, screenshots, the live-state check with timestamps — because that record is going to disappear the moment Google recrawls, and then the only people who will know this happened are Colibri and the person who did it.


Colibri Group has not, as far as we can find, said anything publicly. We are not treating that as evasion — the deadline in the notice has not expired and a company in the middle of a live extortion negotiation with a Monday deadline has legitimate reasons to be quiet.



What to actually do about this


If you are Colibri, you already know. Everyone else:


Add "verify the search index" to your defacement runbook. Right now the last step is "origin restored, confirm the page loads." That is not the end. The end is confirming that the title and description a customer sees in search results are yours again. Check every affected URL in Search Console, force reindexing, and do not close the incident until the SERP is clean. Nobody has this step because until now the index was never where the hostage was.


Inventory what a shared thing can reach. Five brands went down together because something underneath them is shared. If you run a multi-brand estate, the honest question is not "can someone deface a site" but "what is the smallest number of things someone has to own to change every page of every brand at once." For most acquisitive companies the answer is one shared CMS, one shared CDN account, or one DNS zone.


Monitor your own brand in search, as a security control. Not for marketing rank — for content. A daily check that your titles are still your titles is cheap, and it would have caught this before a customer did. This class of attack is invisible to every tool you own: your origin logs are clean, your WAF is clean, your uptime monitor is green, and your front page in Google says someone else's name.


And take DNS and registrar hardening seriously even though this one is unproven. Registry lock, MFA on the registrar, separated admin identities. The claim here may be bluster. The reason it is a plausible bluster is that most organisations could not disprove it about themselves either.


We are keeping a watch on this one — whether the titles persist, whether more Colibri URLs surface with the same headline as the index catches up, and whether AMOZIHEV turns out to have a history under another name. If you saw the live page before it was restored, we would like to hear from you.




Reporting as of 2026-08-11. The live-state check across nine Colibri Group properties was run in a real browser at 13:52–13:56 UTC and every property was restored and serving normal content. Notice wording is reconstructed from search-engine index snippets — we never saw the live defaced page, and no urlscan.io capture of it exists — so treat the quoted phrasing as approximate. The DNS-control claim, the infrastructure-access claim and any data theft are the actor's assertions and are unverified by us. We deliberately do not reproduce the actor's contact channel.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=amozihev-colibri-search-index-is-the-hostage



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page