Ransomware  List - 2026  2025  2024  2023  2021  2020  2019  2018

H  AI  APT  Attack  BigBrothers  BotNet  Congress  Cryptocurrency  Cyber  CyberCrime  Exploit  Hack  ICS  Incindent  IoT  Mobil  OS  Phishing  Ransom  Safety  Security  Social  Spam  Virus  Vulnerebility | 2026  2025  2024  2023

DATE

NAME

Info

CATEG.

WEB

13.9.26

Conti ransomware gang member sentenced to 4 years in prison A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. Ransom BleepingComputer

13.9.26

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. Ransom BleepingComputer

13.9.26

CISA: WatchGuard RCE flaw now exploited in ransomware attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. Ransom BleepingComputer

13.9.26

Veradigm warns of patient data breach after ransomware gang claims attack Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. Ransom BleepingComputer

2.9.26

Berlin confirms data theft after Rhysida ransomware attack claims Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. Ransom BleepingComputer

31.8.26

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding Ransom The Hacker News
24.8.26 Inside the Ecosystem & Operations: LockBit 5.0 Ransomware Group LockBit began operating independently under the name ABCD ransomware in September 2019, and from the end of December 2019, it established the current LockBit brand by using the .lockbit extension. Ransom S2W
24.8.26 July 2026 Threat Trend Report on Ransomware The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Ransom AHNLAB
23.8.26 Rogue ransomware affiliate poses as recovery firm to steal payments A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. Ransom BleepingComputer
22.8.26 CISA: Medusa ransomware hit over 500 critical infrastructure orgs The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. Ransom BleepingComputer

22.8.26

Clop created custom web shell for Windchill data theft attacks A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. Ransom BleepingComputer
22.8.26 CISA: Windows Task Host flaw now exploited by ransomware gangs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. Ransom BleepingComputer

20.8.26

Philips and GE investigating Clop ransomware data theft claims Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data Ransom BleepingComputer

19.8.26

Clop Returns with Custom Implant in Mass-Extortion Campaign “Clop's” exploitation of CVE-2026-12569 in PTC Windchill has returned the group to mass exploitation, delivering a custom web shell that provides full data-theft capability from the moment of deployment, with no additional tooling required. Ransom RELIAQUEST

19.8.26

Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out. Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Ransom CHECKPOINT

19.8.26

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete Ransom The Hacker News

18.8.26

The Gentlemen ransomware: Inside one of the fastest-growing extortion operations The Gentlemen grew from affiliate roots into a major ransomware brand. The group's operators appear to have leveraged relationships, expertise, and credibility developed as the ArmCorp affiliate team to accelerate growth after launching their own ransomware-as-a-service (RaaS) operation. Ransom BARRACUDA

18.8.26

C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. Ransom Zscaler

16.8.26

Shell investigates 'potential incident' after Clop data theft claims Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. Ransom BleepingComputer

16.8.26

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. Ransom BleepingComputer

16.8.26

DeadLock ransomware uses blockchain to resist infrastructure takedown The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. Ransom BleepingComputer

15.8.26

US and South Korea warn of Gunra ransomware targeting govt agencies U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. Ransom BleepingComputer

13.8.26

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Stor ... Ransom SECURITYAFFAIRS

13.8.26

Akira Hits Safe Mode: Ransomware Rebooting Around EDR After gaining access via an exposed SonicWall VPN, an Akira affiliate rebooted the victim host into Safe Mode with Networking to defeat EDR, a first for this ransomware variant in our telemetry. Ransom Huntress

12.8.26

INC Ransom Targeted 24 Law Firms, but Only 10 are Listed INC was on an encryption streak against US law firms in March 2026. SOCRadar identified 24 individualized extortion sites, hosted across two IP addresses, that we assess with high confidence are tied to INC Ransom. Each one is built for a specific US law firm, complete with its own countdown timer and highly likely shared with the victim firm’s customers to increase the pressure. Ransom SOCRADAR

11.8.26

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data Ransom The Hacker News

11.8.26

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. Ransom The Hacker News

9.8.26

Ransom Cartel ransomware creator sentenced to 16 years in prison Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. Ransom BleepingComputer

6.8.26

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel , the Ransom The Hacker News

3.8.26

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Ransom The Hacker News

2.8.26

Microsoft Teams vishing attacks lead to Chaos ransomware attacks Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. Ransom BleepingComputer

30.7.26

Toy Ghouls’ new toy: the GenieLocker ransomware The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian). Ransom SECURELIST

30.7.26

Coca-Cola confirms data theft in Fairlife ransomware attack The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. Ransom BleepingComputer

27.7.26

LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations A new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. Ransom SECURITYAFFAIRS

26.7.26

Clop ransomware targets Windchill, FlexPLM in data theft attacks The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Ransom BleepingComputer

25.7.26

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in Ransom The Hacker News

25.7.26

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to Ransom The Hacker News

25.7.26

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. Ransom BleepingComputer

23.7.26

Ransomware in 2026: Same Business, New Rules The ransomware economy has been rewired. Meet the eight ransomware groups driving the shift, from affiliate breakaways to AI-assisted attacks based on Group-IB Threat Intelligence. Ransom GROUP-IB

23.7.26

INC Ransomware affiliate targets ESXi & NAS Devices in AD environment Using the Hunt.io platform, Ctrl-Alt-Intel researchers discovered an exposed operator working directory containing evidence of an active ransomware intrusion against a Chinese technology organisation. Ransom Ctrl-Alt-Intel

23.7.26

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT , the Rust Ransom The Hacker News

23.7.26

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. Ransom BleepingComputer

23.7.26

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. Ransom BleepingComputer

21.7.26

A new extortion cocktail: office printers, small ransoms, and BitLocker We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations. Ransom SECURELIST

21.7.26

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin Ransom The Hacker News

21.7.26

JadePuffer agentic attacks now target AI model data with ransomware The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. Ransom BleepingComputer

21.7.26

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER , the AI-agent-driven operator it first documented earlier this month. Ransom The Hacker News

19.7.26

Coca-Cola says Fairlife ransomware attack halts US dairy production The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. Ransom BleepingComputer

19.7.26

New Spirals ransomware encrypts victim network in under 24 hours A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. Ransom BleepingComputer
17.7.26 US sanctions VPN, malware providers for enabling ransomware attacks The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. Ransom BleepingComputer
14.7.26 U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling Ransom The Hacker News
12.7.26 Ryuk ransomware member pleads guilty in the US, faces 15 years in prison A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. Ransom BleepingComputer
12.7.26 Former ransomware negotiator gets 4 years for BlackCat attacks A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. Ransom BleepingComputer
10.7.26 Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to Ransom The Hacker News
9.7.26 GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security Ransom The Hacker News
5.7.26 JadePuffer ransomware used AI agent to automate entire attack Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. Ransom BleepingComputer
5.7.26 FortiBleed credential-theft campaign linked to Lynx ransomware The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. Ransom BleepingComputer
4.7.26 Blackfield ransomware asks Nidec Corporation for $2 million ransom The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. Ransom BleepingComputer
4.7.26 CISA: Windows BlueHammer flaw now exploited by ransomware gangs CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. Ransom BleepingComputer
4.7.26 New Avalon Malware Framework Packs CrownX Ransomware Capabilities Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by Ransom The Hacker News
3.7.26 Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability Ransom The Hacker News
2.7.26 FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An Ransom The Hacker News
30.6.26 The Gentlemen are knocking: сustom backdoors and evolving tactics Kaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant. Ransom SECURELIST
27.6.26 Malicious Edge extension abuses Native Messaging as bridge to malware A malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. Ransom BleepingComputer
21.6.26 New Prinz Eugen ransomware prioritizes recent files for encryption A new ransomware operation named 'Prinz Eugen' prioritizes recently modified files for encryption and leaves no ransom note on the system. Ransom BleepingComputer
21.6.26 Gentlemen ransomware uses multiple EDR killers to disable defenses The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. Ransom BleepingComputer
20.6.26 Ransomware gang abuses Microsoft Teams relays to hide malicious traffic DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure. Ransom BleepingComputer
20.6.26 The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response Ransom The Hacker News
18.6.26 INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most Ransom The Hacker News
14.6.26 Ukrainian national pleads guilty to role in Conti ransomware operation A Ukrainian national extradited from Ireland to the United States last year has pleaded guilty to conspiracy charges tied to the Conti ransomware operation. Ransom BleepingComputer
14.6.26 Authorities dismantle 'AudiA6' ransomware crypto-laundering service Law enforcement has dismantled the “AudiA6” cryptocurrency service allegedly used by ransomware actors and other cybercriminals to launder more than $380 million. Ransom BleepingComputer
13.6.26 Check Point links VPN zero-day attacks to Qilin ransomware gang Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks. Ransom BleepingComputer
13.6.26 Silent Ransom Group targets law firms with fake IT support calls The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant. Ransom BleepingComputer
12.6.26 The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate Ransom The Hacker News
29.5.26 Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs Most Akira write-ups focus on the ransom note or the encryption routine. By the time those show up the interesting forensic work is over. The questions that matter to defenders sit earlier. Ransom SANS
24.5.26 Police seize “First VPN” service used in ransomware, data theft attacks A virtual private network service called 'First VPN,' used in ransomware and data theft attacks, has been taken offline in a joint international law enforcement operation. Ransom BleepingComputer
23.5.26 First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. Ransom The Hacker News
20.5.26 Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing Ransom The Hacker News
16.5.26 Foxconn confirms cyberattack claimed by Nitrogen ransomware gang Foxconn, the world's largest electronics manufacturer, says some of its North American factories are now working to resume normal operations after a cyberattack. Ransom BleepingComputer
12.5.26 Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak American educational technology company Instructure, the parent company of Canvas, said it reached an "agreement" with a decentralized Ransom The Hacker News
10.5.26 Trellix source code breach claimed by RansomHouse hackers The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion. Ransom BleepingComputer
10.5.26 Why ransomware attacks succeed even when backups exist Backups don't fail because they're missing, they fail because attackers destroy them first. Acronis explains how ransomware targets backup systems before encryption, leaving no path to recovery Ransom BleepingComputer
6.5.26 MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in what has been described as a "false flag" operation. Ransom The Hacker News
3.5.26 Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks A new disclosed cPanel flaw tracked as CVE-2026-41940 is being mass-exploited to breach websites and encrypt data in "Sorry" ransomware attacks. Ransom BleepingComputer
3.5.26 US ransomware negotiators get 4 years in prison over BlackCat attacks Two former employees of cybersecurity incident response companies Sygnia and DigitalMint were sentenced to four years in prison each for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. Ransom BleepingComputer
2.5.26 Broken VECT 2.0 ransomware acts as a data wiper for large files Researchers are warning that the VECT 2.0 ransomware has a problem in the way it handles encryption nonces that leads to permanently destroying larger files rather than encrypt them. Ransom BleepingComputer
1.5.26 Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks The U.S. Department of Justice (DoJ) on Thursday announced the sentencing of two cybersecurity professionals to four years each in prison for their role in Ransom The Hacker News
28.4.26 VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi Threat hunters are warning that the cybercriminal operation known as VECT 2.0 acts more like a wiper than a ransomware due to a critical flaw in its Ransom The Hacker News
26.4.26 Trigona ransomware attacks use custom exfiltration tool to steal data Recently observed Trigona ransomware attacks are using a custom, command-line tool to steal data from compromised environments faster and more efficiently. Ransom BleepingComputer
26.4.26 Kyber ransomware gang toys with post-quantum encryption on Windows A new Kyber ransomware operation is targeting Windows systems and VMware ESXi endpoints in recent attacks, with one variant implementing Kyber1024 post-quantum encryption. Ransom

BleepingComputer

25.4.26 Former ransomware negotiator pleads guilty to BlackCat attacks 41-year-old Angelo Martino, a former employee of cybersecurity incident response company DigitalMint, has pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023. Ransom

BleepingComputer

23.4.26 The Gentlemen ransomware now uses SystemBC for bot-powered attacks A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack carried out by a gang affiliate. Ransom

BleepingComputer

22.4.26 SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation Threat actors associated with The Gentlemen ransomware‑as‑a‑service (RaaS) operation have been observed attempting to deploy a known proxy Ransom The Hacker News
22.4.26 Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023 A third individual who was employed as a ransomware negotiator has pleaded guilty to conducting ransomware attacks against U.S. companies in 2023. Ransom The Hacker News
19.4.26 NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support NAKIVO Inc. announced the general availability of NAKIVO Backup & Replication v11.2, focused on fast, reliable, and proactive data protection. Ransom

BleepingComputer

19.4.26 Payouts King ransomware uses QEMU VMs to bypass endpoint security The Payouts King ransomware is using the QEMU emulator as a reverse SSH backdoor to run hidden virtual machines on compromised systems and bypass endpoint security. Ransom

BleepingComputer

12.4.26 Healthcare IT solutions provider ChipSoft hit by ransomware attack Dutch healthcare software vendor ChipSoft has been impacted by a ransomware attack that forced the company to take offline its website and digital services for patients and healthcare providers. Ransom

BleepingComputer

11.4.26 Microsoft links Medusa ransomware affiliate to zero-day attacks Microsoft says that Storm-1175, a China-based financially motivated cybercriminal group known for deploying Medusa ransomware payloads, has been deploying n-day and zero-day exploits in high-velocity attacks. Ransom

BleepingComputer

8.4.26 Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver ( BYOVD ) technique Ransom The Hacker News
6.4.26 Die Linke German political party confirms data stolen by Qilin ransomware The Qilin ransomware group has claimed responsibility for an attack against Die Linke ('The Left'), forcing an IT systems outage at the political party, and threatening sensitive data leak. Ransom

BleepingComputer

6.4.26 Evolution of Ransomware: Multi-Extortion Ransomware Attacks Multi-extortion ransomware relies on stolen data to pressure victims with public leaks. Penta Security explains how its D.AMO platform keeps exfiltrated files encrypted and useless to attackers. Ransom

BleepingComputer

5.4.26 Google Drive ransomware detection now on by default for paying users Google announced that the AI-powered Google Drive ransomware detection feature has reached general availability and is now enabled by default for all paying users. Ransom BleepingComputer
28.3.26 Yanluowang ransomware access broker gets 81 months in prison A Russian national was sentenced to nearly 7 years in prison after pleading guilty to acting as an initial access broker (IAB) for Yanluowang ransomware attacks. Ransom

BleepingComputer

27.3.26 Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware A pro-Ukrainian group called Bearlyfy has been attributed to more than 70 cyber attacks targeting Russian companies since it first surfaced in the threat Ransom The Hacker News
24.3.26 U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage A 26-year-old Russian citizen has been sentenced in the U.S. to 6.75 years (81 months) in prison for his role in assisting major cybercrime groups, including the Yanluowang ransomware crew, in conducting numerous attacks against Ransom The Hacker News
21.3.26 Ransomware gang exploits Cisco flaw in zero-day attacks since January The Interlock ransomware gang has been exploiting a maximum severity remote code execution (RCE) vulnerability in Cisco's Secure Firewall Management Center (FMC) software in zero-day attacks since late January. Ransom BleepingComputer
21.3.26 Marquis: Ransomware gang stole data of 672K people in cyberattack Marquis, a Texas-based financial services provider, revealed this week that a ransomware gang stole the data of over 670,000 individuals in an August 2025 cyberattack that also disrupted operations at 74 banks across the United States. Ransom

BleepingComputer

20.3.26 LeakNet ransomware uses ClickFix, Deno runtime in stealthy attacks The LeakNet ransomware gang is now using the ClickFix technique for initial access into corporate environments and deploys a malware loader based on the open-source Deno runtime for JavaScript and TypeScript. Ransom BleepingComputer
18.3.26 Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access Amazon Threat Intelligence is warning of an active Interlock ransomware campaign that's exploiting a recently disclosed critical security flaw in Cisco Ransom The Hacker News
18.3.26 LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader The ransomware operation known as LeakNet has adopted the ClickFix social engineering tactic delivered through compromised websites as an initial Ransom The Hacker News
15.3.26 US charges another ransomware negotiator linked to BlackCat attacks The U.S. Department of Justice charged another former DigitalMint employee for his involvement in an insider scheme in which ransomware negotiators secretly partnered with the BlackCat (ALPHV) ransomware operation. Ransom BleepingComputer
8.3.26 Termite ransomware breaches linked to ClickFix CastleRAT attacks Ransomware threat actors tracked as Velvet Tempest are using the ClickFix technique and legitimate Windows utilities to deploy the DonutLoader malware and the CastleRAT backdoor. Ransom

BleepingComputer

7.3.26 Phobos ransomware admin pleads guilty to wire fraud conspiracy A Russian national pleaded guilty to a wire fraud conspiracy charge related to his role in administering the Phobos ransomware operation, which breached hundreds of victims worldwide. Ransom

BleepingComputer

7.3.26 Mississippi medical center reopens clinics hit by ransomware attack The University of Mississippi Medical Center (UMMC) says it has resumed normal operations, nine days after a ransomware attack blocked access to electronic medical records and took down many of its IT systems. Ransom

BleepingComputer

1.3.26 Ransomware payment rate drops to record low as attacks surge The number of ransomware victims paying threat actors has dropped to 28% last year, an all-time low, despite a significant increase in the number of claimed attacks. Ransom

BleepingComputer

1.3.26 Marquis sues SonicWall over backup breach that led to ransomware attack Marquis Software Solutions has filed a lawsuit against SonicWall, accusing the cybersecurity company of gross negligence and misrepresentation that allegedly led to a ransomware attack disrupting operations at 74 U.S. banks. Ransom

BleepingComputer

24.2.26 Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed Ransom The Hacker News
22.2.26 Japanese tech giant Advantest hit by ransomware attack Advantest Corporation disclosed that its corporate network has been targeted in a ransomware attack that may have affected customer or employee data. Ransom

BleepingComputer

22.2.26 CISA: BeyondTrust RCE flaw now exploited in ransomware attacks Hackers are actively exploiting the CVE-2026-1731 vulnerability in the BeyondTrust Remote Support product, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns. Ransom

BleepingComputer

22.2.26 Mississippi medical center closes all clinics after ransomware attack The University of Mississippi Medical Center (UMMC) closed all its clinic locations statewide on Thursday following a ransomware attack. Ransom

BleepingComputer

21.2.26 Poland arrests suspect linked to Phobos ransomware operation Polish police have detained a 47-year-old man suspected of ties to the Phobos ransomware group and seized computers and mobile phones containing stolen credentials, credit card numbers, and server access data. Ransom

BleepingComputer

21.2.26 Washington Hotel in Japan discloses ransomware infection incident The Washington Hotel brand in Japan has announced that that its servers were compromised in a ransomware attack, exposing various business data. Ransom BleepingComputer
14.2.26 Crazy ransomware gang abuses employee monitoring tool in attacks A member of the Crazy ransomware gang is abusing legitimate employee monitoring software and the SimpleHelp remote support tool to maintain persistence in corporate networks, evade detection, and prepare for ransomware deployment. Ransom

BleepingComputer

11.2.26 Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools Cybersecurity researchers have disclosed details of an emergent ransomware family dubbed Reynolds that comes embedded with a built-in bring your own Ransom The Hacker News
10.2.26 BYOVD component included in ransomware payload itself, rather than as a separate tool. Ransom SECURITY.COM
10.2.26 Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools Cybersecurity researchers have disclosed details of an emergent ransomware family dubbed Reynolds that comes embedded with a built-in bring your own Ransom The Hacker News
10.2.26 Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server SmarterTools confirmed last week that the Warlock (aka Storm-2603) ransomware gang breached its network by exploiting an unpatched Ransom The Hacker News
8.2.26 Payments platform BridgePay confirms ransomware attack behind outage A major U.S. payment gateway and solutions provider says a ransomware attack has knocked key systems offline, triggering a widespread outage affecting multiple services. The incident began on Friday and quickly escalated into a nationwide disruption across BridgePay's platform. Ransom

BleepingComputer

8.2.26 Ransomware gang uses ISPsystem VMs for stealthy payload delivery Ransomware operators are hosting and delivering malicious payloads at scale by abusing virtual machines (VMs) provisioned by ISPsystem, a legitimate virtual infrastructure management provider Ransom

BleepingComputer

3.2.26 Marquis blames ransomware breach on SonicWall cloud backup hack Marquis Software Solutions, a Texas-based financial services provider, is blaming a ransomware attack that impacted its systems and affected dozens of U.S. banks and credit unions in August 2025 on a security breach reported by SonicWall a month later. Ransom

BleepingComputer

3.2.26 Initial access hackers switch to Tsundere Bot for ransomware attacks A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access trojan to gain network access that could lead to ransomware attacks. Ransom

BleepingComputer

3.2.26 FBI seizes RAMP cybercrime forum used by ransomware gangs The FBI has seized the notorious RAMP cybercrime forum, a platform used to advertise a wide range of malware and hacking services, and one of the few remaining forums that openly allowed the promotion of ransomware operations. Ransom

BleepingComputer

25.1.26 INC ransomware opsec fail allowed data recovery for 12 US orgs An operational security failure allowed researchers to recover data that the INC ransomware gang stole from a dozen U.S. organizations. Ransom

BleepingComputer

25.1.26 Ingram Micro says ransomware attack affected 42,000 people ​Information technology giant Ingram Micro has revealed that a ransomware attack on its systems in July 2025 led to a data breach affecting over 42,000 individuals. Ransom

BleepingComputer

23.1.26 New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack Cybersecurity researchers have disclosed details of a new ransomware family called Osiris that targeted a major food service franchisee operator in Ransom The Hacker News
18.1.26 Black Basta boss makes it onto Interpol's 'Red Notice' list The identity of the Black Basta ransomware gang leader has been confirmed by law enforcement in Ukraine and Germany, and the individual has been added to the wanted list of Europol and Interpol. Ransom

BleepingComputer

18.1.26 South Korean giant Kyowon confirms data theft in ransomware attack The Kyowon Group (Kyowon), a South Korean conglomerate, disclosed that a cyberattack has disrupted its operations and customer information may have been exposed in the incident. Ransom

BleepingComputer

18.1.26 Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice Ukrainian and German law enforcement authorities have identified two Ukrainians suspected of working for the Russia-linked ransomware-as-a-service Ransom The Hacker News
17.1.26 University of Hawaii Cancer Center hit by ransomware attack ​University of Hawaii says a ransomware gang breached its Cancer Center in August 2025, stealing data of study participants, including documents from the 1990s containing Social Security numbers. Ransom

BleepingComputer

3.1.26 US cybersecurity experts plead guilty to BlackCat ransomware attacks Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023 Ransom

BleepingComputer

3.1.26 Romanian energy provider hit by Gentlemen ransomware attack A ransomware attack hit Oltenia Energy Complex (Complexul Energetic Oltenia), Romania's largest coal-based energy producer, on the second day of Christmas, taking down its IT infrastructure. Ransom

BleepingComputer