Ransomware List - 2026 2025 2024 2023 2021 2020 2019 2018
H AI APT Attack BigBrothers BotNet Congress Cryptocurrency Cyber CyberCrime Exploit Hack ICS Incindent IoT Mobil OS Phishing Ransom Safety Security Social Spam Virus Vulnerebility | 2026 2025 2024 2023
DATE | NAME |
Info | CATEG. |
WEB |
|
13.9.26 |
Conti ransomware gang member sentenced to 4 years in prison | A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. | Ransom | BleepingComputer |
|
13.9.26 |
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers | Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. | Ransom | BleepingComputer |
|
13.9.26 |
CISA: WatchGuard RCE flaw now exploited in ransomware attacks | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. | Ransom | BleepingComputer |
|
13.9.26 |
Veradigm warns of patient data breach after ransomware gang claims attack | Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. | Ransom | BleepingComputer |
|
2.9.26 |
Berlin confirms data theft after Rhysida ransomware attack claims | Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. | Ransom | BleepingComputer |
|
31.8.26 |
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets | Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding | Ransom | The Hacker News |
| 24.8.26 | Inside the Ecosystem & Operations: LockBit 5.0 Ransomware Group | LockBit began operating independently under the name ABCD ransomware in September 2019, and from the end of December 2019, it established the current LockBit brand by using the .lockbit extension. | Ransom | S2W |
| 24.8.26 | July 2026 Threat Trend Report on Ransomware | The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. | Ransom | AHNLAB |
| 23.8.26 | Rogue ransomware affiliate poses as recovery firm to steal payments | A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. | Ransom | BleepingComputer |
| 22.8.26 | CISA: Medusa ransomware hit over 500 critical infrastructure orgs | The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. | Ransom | BleepingComputer |
|
22.8.26 |
Clop created custom web shell for Windchill data theft attacks | A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. | Ransom | BleepingComputer |
| 22.8.26 | CISA: Windows Task Host flaw now exploited by ransomware gangs | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. | Ransom | BleepingComputer |
|
20.8.26 |
Philips and GE investigating Clop ransomware data theft claims | Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data | Ransom | BleepingComputer |
|
19.8.26 |
Clop Returns with Custom Implant in Mass-Extortion Campaign | “Clop's” exploitation of CVE-2026-12569 in PTC Windchill has returned the group to mass exploitation, delivering a custom web shell that provides full data-theft capability from the moment of deployment, with no additional tooling required. | Ransom | RELIAQUEST |
|
19.8.26 |
Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out. | Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. | Ransom | CHECKPOINT |
|
19.8.26 |
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 | A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete | Ransom | The Hacker News |
|
18.8.26 |
The Gentlemen ransomware: Inside one of the fastest-growing extortion operations | The Gentlemen grew from affiliate roots into a major ransomware brand. The group's operators appear to have leveraged relationships, expertise, and credibility developed as the ArmCorp affiliate team to accelerate growth after launching their own ransomware-as-a-service (RaaS) operation. | Ransom | BARRACUDA |
|
18.8.26 |
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 | In July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. | Ransom | Zscaler |
|
16.8.26 |
Shell investigates 'potential incident' after Clop data theft claims | Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. | Ransom | BleepingComputer |
|
16.8.26 |
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt | An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. | Ransom | BleepingComputer |
|
16.8.26 |
DeadLock ransomware uses blockchain to resist infrastructure takedown | The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. | Ransom | BleepingComputer |
|
15.8.26 |
US and South Korea warn of Gunra ransomware targeting govt agencies | U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. | Ransom | BleepingComputer |
|
13.8.26 |
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware | Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Stor ... | Ransom | SECURITYAFFAIRS |
|
13.8.26 |
Akira Hits Safe Mode: Ransomware Rebooting Around EDR | After gaining access via an exposed SonicWall VPN, an Akira affiliate rebooted the victim host into Safe Mode with Networking to defeat EDR, a first for this ransomware variant in our telemetry. | Ransom | Huntress |
|
12.8.26 |
INC Ransom Targeted 24 Law Firms, but Only 10 are Listed | INC was on an encryption streak against US law firms in March 2026. SOCRadar identified 24 individualized extortion sites, hosted across two IP addresses, that we assess with high confidence are tied to INC Ransom. Each one is built for a specific US law firm, complete with its own countdown timer and highly likely shared with the victim firm’s customers to increase the pressure. | Ransom | SOCRADAR |
|
11.8.26 |
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt | The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data | Ransom | The Hacker News |
|
11.8.26 |
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks | Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. | Ransom | The Hacker News |
|
9.8.26 |
Ransom Cartel ransomware creator sentenced to 16 years in prison | Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. | Ransom | BleepingComputer |
|
6.8.26 |
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service | A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel , the | Ransom | The Hacker News |
|
3.8.26 |
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws | The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure | Ransom | The Hacker News |
|
2.8.26 |
Microsoft Teams vishing attacks lead to Chaos ransomware attacks | Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. | Ransom | BleepingComputer |
|
30.7.26 |
Toy Ghouls’ new toy: the GenieLocker ransomware | The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian). | Ransom | SECURELIST |
|
30.7.26 |
Coca-Cola confirms data theft in Fairlife ransomware attack | The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. | Ransom | BleepingComputer |
|
27.7.26 |
LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations | A new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. | Ransom | SECURITYAFFAIRS |
|
26.7.26 |
Clop ransomware targets Windchill, FlexPLM in data theft attacks | The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. | Ransom | BleepingComputer |
|
25.7.26 |
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE | Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in | Ransom | The Hacker News |
|
25.7.26 |
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts | The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to | Ransom | The Hacker News |
|
25.7.26 |
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack | Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. | Ransom | BleepingComputer |
|
23.7.26 |
Ransomware in 2026: Same Business, New Rules | The ransomware economy has been rewired. Meet the eight ransomware groups driving the shift, from affiliate breakaways to AI-assisted attacks based on Group-IB Threat Intelligence. | Ransom | GROUP-IB |
|
23.7.26 |
INC Ransomware affiliate targets ESXi & NAS Devices in AD environment | Using the Hunt.io platform, Ctrl-Alt-Intel researchers discovered an exposed operator working directory containing evidence of an active ransomware intrusion against a Chinese technology organisation. | Ransom | Ctrl-Alt-Intel |
|
23.7.26 |
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge | The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT , the Rust | Ransom | The Hacker News |
|
23.7.26 |
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak | The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. | Ransom | BleepingComputer |
|
23.7.26 |
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang | The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. | Ransom | BleepingComputer |
|
21.7.26 |
A new extortion cocktail: office printers, small ransoms, and BitLocker | We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations. | Ransom | SECURELIST |
|
21.7.26 |
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access | Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin | Ransom | The Hacker News |
|
21.7.26 |
JadePuffer agentic attacks now target AI model data with ransomware | The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. | Ransom | BleepingComputer |
|
21.7.26 |
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack | Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER , the AI-agent-driven operator it first documented earlier this month. | Ransom | The Hacker News |
|
19.7.26 |
Coca-Cola says Fairlife ransomware attack halts US dairy production | The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. | Ransom | BleepingComputer |
|
19.7.26 |
New Spirals ransomware encrypts victim network in under 24 hours | A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. | Ransom | BleepingComputer |
| 17.7.26 | US sanctions VPN, malware providers for enabling ransomware attacks | The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. | Ransom | BleepingComputer |
| 14.7.26 | U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support | The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling | Ransom | The Hacker News |
| 12.7.26 | Ryuk ransomware member pleads guilty in the US, faces 15 years in prison | A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. | Ransom | BleepingComputer |
| 12.7.26 | Former ransomware negotiator gets 4 years for BlackCat attacks | A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. | Ransom | BleepingComputer |
| 10.7.26 | Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks | A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to | Ransom | The Hacker News |
| 9.7.26 | GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses | Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security | Ransom | The Hacker News |
| 5.7.26 | JadePuffer ransomware used AI agent to automate entire attack | Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. | Ransom | BleepingComputer |
| 5.7.26 | FortiBleed credential-theft campaign linked to Lynx ransomware | The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. | Ransom | BleepingComputer |
| 4.7.26 | Blackfield ransomware asks Nidec Corporation for $2 million ransom | The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. | Ransom | BleepingComputer |
| 4.7.26 | CISA: Windows BlueHammer flaw now exploited by ransomware gangs | CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. | Ransom | BleepingComputer |
| 4.7.26 | New Avalon Malware Framework Packs CrownX Ransomware Capabilities | Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by | Ransom | The Hacker News |
| 3.7.26 | Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials | Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability | Ransom | The Hacker News |
| 2.7.26 | FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations | The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An | Ransom | The Hacker News |
| 30.6.26 | The Gentlemen are knocking: сustom backdoors and evolving tactics | Kaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant. | Ransom | SECURELIST |
| 27.6.26 | Malicious Edge extension abuses Native Messaging as bridge to malware | A malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. | Ransom | BleepingComputer |
| 21.6.26 | New Prinz Eugen ransomware prioritizes recent files for encryption | A new ransomware operation named 'Prinz Eugen' prioritizes recently modified files for encryption and leaves no ransom note on the system. | Ransom | BleepingComputer |
| 21.6.26 | Gentlemen ransomware uses multiple EDR killers to disable defenses | The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. | Ransom | BleepingComputer |
| 20.6.26 | Ransomware gang abuses Microsoft Teams relays to hide malicious traffic | DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure. | Ransom | BleepingComputer |
| 20.6.26 | The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes | The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response | Ransom | The Hacker News |
| 18.6.26 | INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 | Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most | Ransom | The Hacker News |
| 14.6.26 | Ukrainian national pleads guilty to role in Conti ransomware operation | A Ukrainian national extradited from Ireland to the United States last year has pleaded guilty to conspiracy charges tied to the Conti ransomware operation. | Ransom | BleepingComputer |
| 14.6.26 | Authorities dismantle 'AudiA6' ransomware crypto-laundering service | Law enforcement has dismantled the “AudiA6” cryptocurrency service allegedly used by ransomware actors and other cybercriminals to launder more than $380 million. | Ransom | BleepingComputer |
| 13.6.26 | Check Point links VPN zero-day attacks to Qilin ransomware gang | Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks. | Ransom | BleepingComputer |
| 13.6.26 | Silent Ransom Group targets law firms with fake IT support calls | The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant. | Ransom | BleepingComputer |
| 12.6.26 | The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm | A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate | Ransom | The Hacker News |
| 29.5.26 | Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs | Most Akira write-ups focus on the ransom note or the encryption routine. By the time those show up the interesting forensic work is over. The questions that matter to defenders sit earlier. | Ransom | SANS |
| 24.5.26 | Police seize “First VPN” service used in ransomware, data theft attacks | A virtual private network service called 'First VPN,' used in ransomware and data theft attacks, has been taken offline in a joint international law enforcement operation. | Ransom | BleepingComputer |
| 23.5.26 | First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups | Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. | Ransom | The Hacker News |
| 20.5.26 | Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks | Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing | Ransom | The Hacker News |
| 16.5.26 | Foxconn confirms cyberattack claimed by Nitrogen ransomware gang | Foxconn, the world's largest electronics manufacturer, says some of its North American factories are now working to resume normal operations after a cyberattack. | Ransom | BleepingComputer |
| 12.5.26 | Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak | American educational technology company Instructure, the parent company of Canvas, said it reached an "agreement" with a decentralized | Ransom | The Hacker News |
| 10.5.26 | Trellix source code breach claimed by RansomHouse hackers | The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion. | Ransom | BleepingComputer |
| 10.5.26 | Why ransomware attacks succeed even when backups exist | Backups don't fail because they're missing, they fail because attackers destroy them first. Acronis explains how ransomware targets backup systems before encryption, leaving no path to recovery | Ransom | BleepingComputer |
| 6.5.26 | MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack | The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in what has been described as a "false flag" operation. | Ransom | The Hacker News |
| 3.5.26 | Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks | A new disclosed cPanel flaw tracked as CVE-2026-41940 is being mass-exploited to breach websites and encrypt data in "Sorry" ransomware attacks. | Ransom | BleepingComputer |
| 3.5.26 | US ransomware negotiators get 4 years in prison over BlackCat attacks | Two former employees of cybersecurity incident response companies Sygnia and DigitalMint were sentenced to four years in prison each for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. | Ransom | BleepingComputer |
| 2.5.26 | Broken VECT 2.0 ransomware acts as a data wiper for large files | Researchers are warning that the VECT 2.0 ransomware has a problem in the way it handles encryption nonces that leads to permanently destroying larger files rather than encrypt them. | Ransom | BleepingComputer |
| 1.5.26 | Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks | The U.S. Department of Justice (DoJ) on Thursday announced the sentencing of two cybersecurity professionals to four years each in prison for their role in | Ransom | The Hacker News |
| 28.4.26 | VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi | Threat hunters are warning that the cybercriminal operation known as VECT 2.0 acts more like a wiper than a ransomware due to a critical flaw in its | Ransom | The Hacker News |
| 26.4.26 | Trigona ransomware attacks use custom exfiltration tool to steal data | Recently observed Trigona ransomware attacks are using a custom, command-line tool to steal data from compromised environments faster and more efficiently. | Ransom | BleepingComputer |
| 26.4.26 | Kyber ransomware gang toys with post-quantum encryption on Windows | A new Kyber ransomware operation is targeting Windows systems and VMware ESXi endpoints in recent attacks, with one variant implementing Kyber1024 post-quantum encryption. | Ransom | |
| 25.4.26 | Former ransomware negotiator pleads guilty to BlackCat attacks | 41-year-old Angelo Martino, a former employee of cybersecurity incident response company DigitalMint, has pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023. | Ransom | |
| 23.4.26 | The Gentlemen ransomware now uses SystemBC for bot-powered attacks | A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack carried out by a gang affiliate. | Ransom | |
| 22.4.26 | SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation | Threat actors associated with The Gentlemen ransomware‑as‑a‑service (RaaS) operation have been observed attempting to deploy a known proxy | Ransom | The Hacker News |
| 22.4.26 | Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023 | A third individual who was employed as a ransomware negotiator has pleaded guilty to conducting ransomware attacks against U.S. companies in 2023. | Ransom | The Hacker News |
| 19.4.26 | NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support | NAKIVO Inc. announced the general availability of NAKIVO Backup & Replication v11.2, focused on fast, reliable, and proactive data protection. | Ransom | |
| 19.4.26 | Payouts King ransomware uses QEMU VMs to bypass endpoint security | The Payouts King ransomware is using the QEMU emulator as a reverse SSH backdoor to run hidden virtual machines on compromised systems and bypass endpoint security. | Ransom | |
| 12.4.26 | Healthcare IT solutions provider ChipSoft hit by ransomware attack | Dutch healthcare software vendor ChipSoft has been impacted by a ransomware attack that forced the company to take offline its website and digital services for patients and healthcare providers. | Ransom | |
| 11.4.26 | Microsoft links Medusa ransomware affiliate to zero-day attacks | Microsoft says that Storm-1175, a China-based financially motivated cybercriminal group known for deploying Medusa ransomware payloads, has been deploying n-day and zero-day exploits in high-velocity attacks. | Ransom | |
| 8.4.26 | Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools | Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver ( BYOVD ) technique | Ransom | The Hacker News |
| 6.4.26 | Die Linke German political party confirms data stolen by Qilin ransomware | The Qilin ransomware group has claimed responsibility for an attack against Die Linke ('The Left'), forcing an IT systems outage at the political party, and threatening sensitive data leak. | Ransom | |
| 6.4.26 | Evolution of Ransomware: Multi-Extortion Ransomware Attacks | Multi-extortion ransomware relies on stolen data to pressure victims with public leaks. Penta Security explains how its D.AMO platform keeps exfiltrated files encrypted and useless to attackers. | Ransom | |
| 5.4.26 | Google Drive ransomware detection now on by default for paying users | Google announced that the AI-powered Google Drive ransomware detection feature has reached general availability and is now enabled by default for all paying users. | Ransom | BleepingComputer |
| 28.3.26 | Yanluowang ransomware access broker gets 81 months in prison | A Russian national was sentenced to nearly 7 years in prison after pleading guilty to acting as an initial access broker (IAB) for Yanluowang ransomware attacks. | Ransom | |
| 27.3.26 | Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware | A pro-Ukrainian group called Bearlyfy has been attributed to more than 70 cyber attacks targeting Russian companies since it first surfaced in the threat | Ransom | The Hacker News |
| 24.3.26 | U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage | A 26-year-old Russian citizen has been sentenced in the U.S. to 6.75 years (81 months) in prison for his role in assisting major cybercrime groups, including the Yanluowang ransomware crew, in conducting numerous attacks against | Ransom | The Hacker News |
| 21.3.26 | Ransomware gang exploits Cisco flaw in zero-day attacks since January | The Interlock ransomware gang has been exploiting a maximum severity remote code execution (RCE) vulnerability in Cisco's Secure Firewall Management Center (FMC) software in zero-day attacks since late January. | Ransom | BleepingComputer |
| 21.3.26 | Marquis: Ransomware gang stole data of 672K people in cyberattack | Marquis, a Texas-based financial services provider, revealed this week that a ransomware gang stole the data of over 670,000 individuals in an August 2025 cyberattack that also disrupted operations at 74 banks across the United States. | Ransom | |
| 20.3.26 | LeakNet ransomware uses ClickFix, Deno runtime in stealthy attacks | The LeakNet ransomware gang is now using the ClickFix technique for initial access into corporate environments and deploys a malware loader based on the open-source Deno runtime for JavaScript and TypeScript. | Ransom | BleepingComputer |
| 18.3.26 | Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access | Amazon Threat Intelligence is warning of an active Interlock ransomware campaign that's exploiting a recently disclosed critical security flaw in Cisco | Ransom | The Hacker News |
| 18.3.26 | LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader | The ransomware operation known as LeakNet has adopted the ClickFix social engineering tactic delivered through compromised websites as an initial | Ransom | The Hacker News |
| 15.3.26 | US charges another ransomware negotiator linked to BlackCat attacks | The U.S. Department of Justice charged another former DigitalMint employee for his involvement in an insider scheme in which ransomware negotiators secretly partnered with the BlackCat (ALPHV) ransomware operation. | Ransom | BleepingComputer |
| 8.3.26 | Termite ransomware breaches linked to ClickFix CastleRAT attacks | Ransomware threat actors tracked as Velvet Tempest are using the ClickFix technique and legitimate Windows utilities to deploy the DonutLoader malware and the CastleRAT backdoor. | Ransom | |
| 7.3.26 | Phobos ransomware admin pleads guilty to wire fraud conspiracy | A Russian national pleaded guilty to a wire fraud conspiracy charge related to his role in administering the Phobos ransomware operation, which breached hundreds of victims worldwide. | Ransom | |
| 7.3.26 | Mississippi medical center reopens clinics hit by ransomware attack | The University of Mississippi Medical Center (UMMC) says it has resumed normal operations, nine days after a ransomware attack blocked access to electronic medical records and took down many of its IT systems. | Ransom | |
| 1.3.26 | Ransomware payment rate drops to record low as attacks surge | The number of ransomware victims paying threat actors has dropped to 28% last year, an all-time low, despite a significant increase in the number of claimed attacks. | Ransom | |
| 1.3.26 | Marquis sues SonicWall over backup breach that led to ransomware attack | Marquis Software Solutions has filed a lawsuit against SonicWall, accusing the cybersecurity company of gross negligence and misrepresentation that allegedly led to a ransomware attack disrupting operations at 74 U.S. banks. | Ransom | |
| 24.2.26 | Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks | The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed | Ransom | The Hacker News |
| 22.2.26 | Japanese tech giant Advantest hit by ransomware attack | Advantest Corporation disclosed that its corporate network has been targeted in a ransomware attack that may have affected customer or employee data. | Ransom | |
| 22.2.26 | CISA: BeyondTrust RCE flaw now exploited in ransomware attacks | Hackers are actively exploiting the CVE-2026-1731 vulnerability in the BeyondTrust Remote Support product, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns. | Ransom | |
| 22.2.26 | Mississippi medical center closes all clinics after ransomware attack | The University of Mississippi Medical Center (UMMC) closed all its clinic locations statewide on Thursday following a ransomware attack. | Ransom | |
| 21.2.26 | Poland arrests suspect linked to Phobos ransomware operation | Polish police have detained a 47-year-old man suspected of ties to the Phobos ransomware group and seized computers and mobile phones containing stolen credentials, credit card numbers, and server access data. | Ransom | |
| 21.2.26 | Washington Hotel in Japan discloses ransomware infection incident | The Washington Hotel brand in Japan has announced that that its servers were compromised in a ransomware attack, exposing various business data. | Ransom | BleepingComputer |
| 14.2.26 | Crazy ransomware gang abuses employee monitoring tool in attacks | A member of the Crazy ransomware gang is abusing legitimate employee monitoring software and the SimpleHelp remote support tool to maintain persistence in corporate networks, evade detection, and prepare for ransomware deployment. | Ransom | |
| 11.2.26 | Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools | Cybersecurity researchers have disclosed details of an emergent ransomware family dubbed Reynolds that comes embedded with a built-in bring your own | Ransom | The Hacker News |
| 10.2.26 | Reynolds: Defense Evasion Capability Embedded in Ransomware Payload | BYOVD component included in ransomware payload itself, rather than as a separate tool. | Ransom | SECURITY.COM |
| 10.2.26 | Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools | Cybersecurity researchers have disclosed details of an emergent ransomware family dubbed Reynolds that comes embedded with a built-in bring your own | Ransom | The Hacker News |
| 10.2.26 | Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server | SmarterTools confirmed last week that the Warlock (aka Storm-2603) ransomware gang breached its network by exploiting an unpatched | Ransom | The Hacker News |
| 8.2.26 | Payments platform BridgePay confirms ransomware attack behind outage | A major U.S. payment gateway and solutions provider says a ransomware attack has knocked key systems offline, triggering a widespread outage affecting multiple services. The incident began on Friday and quickly escalated into a nationwide disruption across BridgePay's platform. | Ransom | |
| 8.2.26 | Ransomware gang uses ISPsystem VMs for stealthy payload delivery | Ransomware operators are hosting and delivering malicious payloads at scale by abusing virtual machines (VMs) provisioned by ISPsystem, a legitimate virtual infrastructure management provider | Ransom | |
| 3.2.26 | Marquis blames ransomware breach on SonicWall cloud backup hack | Marquis Software Solutions, a Texas-based financial services provider, is blaming a ransomware attack that impacted its systems and affected dozens of U.S. banks and credit unions in August 2025 on a security breach reported by SonicWall a month later. | Ransom | |
| 3.2.26 | Initial access hackers switch to Tsundere Bot for ransomware attacks | A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access trojan to gain network access that could lead to ransomware attacks. | Ransom | |
| 3.2.26 | FBI seizes RAMP cybercrime forum used by ransomware gangs | The FBI has seized the notorious RAMP cybercrime forum, a platform used to advertise a wide range of malware and hacking services, and one of the few remaining forums that openly allowed the promotion of ransomware operations. | Ransom | |
| 25.1.26 | INC ransomware opsec fail allowed data recovery for 12 US orgs | An operational security failure allowed researchers to recover data that the INC ransomware gang stole from a dozen U.S. organizations. | Ransom | |
| 25.1.26 | Ingram Micro says ransomware attack affected 42,000 people | Information technology giant Ingram Micro has revealed that a ransomware attack on its systems in July 2025 led to a data breach affecting over 42,000 individuals. | Ransom | |
| 23.1.26 | New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack | Cybersecurity researchers have disclosed details of a new ransomware family called Osiris that targeted a major food service franchisee operator in | Ransom | The Hacker News |
| 18.1.26 | Black Basta boss makes it onto Interpol's 'Red Notice' list | The identity of the Black Basta ransomware gang leader has been confirmed by law enforcement in Ukraine and Germany, and the individual has been added to the wanted list of Europol and Interpol. | Ransom | |
| 18.1.26 | South Korean giant Kyowon confirms data theft in ransomware attack | The Kyowon Group (Kyowon), a South Korean conglomerate, disclosed that a cyberattack has disrupted its operations and customer information may have been exposed in the incident. | Ransom | |
| 18.1.26 | Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice | Ukrainian and German law enforcement authorities have identified two Ukrainians suspected of working for the Russia-linked ransomware-as-a-service | Ransom | The Hacker News |
| 17.1.26 | University of Hawaii Cancer Center hit by ransomware attack | University of Hawaii says a ransomware gang breached its Cancer Center in August 2025, stealing data of study participants, including documents from the 1990s containing Social Security numbers. | Ransom | |
| 3.1.26 | US cybersecurity experts plead guilty to BlackCat ransomware attacks | Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023 | Ransom | |
| 3.1.26 | Romanian energy provider hit by Gentlemen ransomware attack | A ransomware attack hit Oltenia Energy Complex (Complexul Energetic Oltenia), Romania's largest coal-based energy producer, on the second day of Christmas, taking down its IT infrastructure. | Ransom |