CASE OBSERVATIONS · TUNGTEK

Ransomware .PIZ
across 3 active cases.

Changed file extensions, inaccessible databases and backups. TUNGTEK is assessing each sample through RFC to establish prospects for data extraction, with conclusions limited to the evidence from each ticket.

Updated 3 anonymized ticketsAssessment ongoing
Explore the ticket findings
Illustration of server and NAS storage being examined on a data recovery workbench in a lab, with the TUNGTEK signature.
Illustration of the intake process
A new in-depth article covers 8 .PIZ tickets.
This article retains the initial findings as of 23 September 2026. Read the expanded analysis: .PIZ Ransomware 2026: From Threat Intelligence to 8 Cases at TUNGTEK →

What do .PIZ indicators tell us?

In cases received by TUNGTEK in September 2026, some important files had an added extension of .piz and the systems displayed ransom notes. Examined samples showed altered data; comparable samples contained a trailing structure called META. These indicators help the technical team classify and compare samples within each case.

The .piz extension alone cannot identify the attacker group, algorithm, exploited vulnerability or recovery prospects. The tickets are at different assessment stages. TUNGTEK has not published a conclusion about the intrusion path or a universal extraction tool for all .piz files.

AN IMPORTANT DISTINCTION

RFC assesses specific samples and their current state. A sample that meets implementation criteria does not mean the entire system has been recovered.

Three tickets, three data scopes

Customer names, contact details, victim identifiers and internal data have been omitted. The following findings can be shared publicly from TUNGTEK’s technical records as of the update date.

#1339Sample qualifies for implementation

SQL Server database

The case includes a database file .mdf.piz and a backup sample .bak.piz. RFC recorded 96% on one MDF file selected for assessment, sufficient to plan extraction for that sample. This is an assessment metric for that individual sample, not the ticket’s actual extracted data percentage.

#1340Sample analysis ongoing

Encrypted files and ransom note

The technical team received the note and samples with the extension .piz and observed similarities in the trailing file structure. The current evidence supports format identification and RFC preparation; it is insufficient to determine whether a processing tool can be developed or what proportion can be extracted.

#1341Early RFC stage

Server / NAS, prioritizing databases and backups

Initial samples carrying the extension .piz show encryption indicators. The team is prioritizing receipt of the relevant database and backup samples to assess usability. No RFC score is available for the priority files at this stage.

Illustration of server drives and storage on a workbench for SQL database sample assessment, with the TUNGTEK signature.
Illustration of MDF / BAK sample assessment; this is not customer data.

Similarities between samples are indicators for further comparison, rather than evidence that every case involves the same group. Each technical decision remains based on the sample files, storage structure, backups and data integrity in that system.

You have just found .piz files. What next?

  1. 01

    Isolate affected systems

    Disconnect network access under the incident response procedure and identify affected servers and storage devices. Avoid additional writes to data that needs examination.

  2. 02

    Preserve the evidence

    Keep the ransom note, representative files with the extension .piz , corresponding originals if available, backups and relevant logs. Record paths, sizes and discovery times; create read-only copies and hashes when handing over samples.

  3. 03

    Prioritize the data you need first

    List databases, backups, virtual machines and files essential to operations. Avoid mass renaming, overwriting backups or running tools of unknown origin on the original data.

  4. 04

    Perform RFC before choosing an approach

    Assess samples and integrity, test suitable copies and establish acceptance criteria. Report results by data type before extraction begins.

Illustration of NAS devices and server drives documented and stored separately on a technical workbench, with the TUNGTEK signature.
Preserving the current state and assessment samples is the first step in RFC.

Guidance on system isolation and evidence preservation draws on the CISA #StopRansomware Guide. You can also use No More Ransom’s Crypto Sheriff for public identification checks; search results do not replace RFC assessment of the actual files.

What cannot yet be concluded

Is .PIZ definitely a known ransomware strain?

No. File extensions and structural indicators help group samples within tickets, but cannot establish a ransomware family or attacker attribution on their own.

Does an RFC score of 96% mean 96% of all data can be recovered?

No. This is an assessment result for a specific MDF file in Ticket #1339, qualifying that sample for implementation. Actual results are established only after extraction, usability checks and acceptance.

Is there a public tool for every .piz file?

No suitable tool was found in the offline catalog checked for Ticket #1339. Public tool availability can change; do not download a tool merely because it mentions the same extension.

Start with evidence.
Decide on verified findings.

This article will be updated as each ticket reaches conclusions that can be shared publicly. No rate is promised for a new case before RFC.