Topic: double extortion

  • Multi-Extortion Ransomware: The New Attack Evolution

    Multi-Extortion Ransomware: The New Attack Evolution

    Ransomware attacks are a pervasive daily reality, severely disrupting operations across critical sectors like healthcare, finance, and manufacturing, as evidenced by a 49% increase in publicly reported attacks in 2025. The threat has escalated due to a shift from simple encryption to aggressive "...

    Read More »
  • CISA warns Medusa ransomware hit 500+ organizations

    CISA warns Medusa ransomware hit 500+ organizations

    Medusa ransomware has compromised over 500 organizations since June 2021, targeting critical infrastructure sectors including healthcare, defense, manufacturing, and government services, according to a joint FBI, CISA, and HHS advisory updated with FBI casework through April 2026. The operation e...

    Read More »
  • The Psychology of Ransomware: How Hackers Turn Data Into Fear

    The Psychology of Ransomware: How Hackers Turn Data Into Fear

    Modern ransomware has evolved into a sophisticated extortion model that weaponizes psychological pressure, legal fears, and reputational damage, moving beyond simple file encryption to target organizational trust and compliance. The threat landscape is now a decentralized network of affiliates us...

    Read More »
  • Kraken Ransomware Evolves With Advanced Benchmarking

    Kraken Ransomware Evolves With Advanced Benchmarking

    In August 2025, the Kraken ransomware group emerged as a sophisticated threat, using SMB vulnerabilities for initial access, Cloudflare for persistence, and SSHFS for data exfiltration before deploying cross-platform malware. Kraken's ransomware features an advanced benchmarking process to optimi...

    Read More »
  • Qilin Ransomware Exposes 40+ Victims Monthly

    Qilin Ransomware Exposes 40+ Victims Monthly

    The Qilin ransomware group has intensified global attacks, listing over 40 new victims monthly and primarily targeting the manufacturing industry, along with professional services and wholesale trade. Qilin uses a double-extortion tactic, encrypting victims' data and stealing sensitive informatio...

    Read More »
  • Two Cybersecurity Workers Jailed for BlackCat Ransomware Attacks

    Two Cybersecurity Workers Jailed for BlackCat Ransomware Attacks

    Two U.S. cybersecurity professionals, Ryan Goldberg and Kevin Martin, were each sentenced to four years in federal prison for facilitating BlackCat ransomware attacks, having pleaded guilty in December 2025. The men helped launch attacks, funneled 20% of ransom payments to BlackCat administrators...

    Read More »
  • Ransomware Profits Plummet as Victims Refuse to Pay

    Ransomware Profits Plummet as Victims Refuse to Pay

    Ransomware payment rates have hit a record low of 23%, driven by improved corporate defenses and pressure from authorities not to pay cybercriminals. Attackers are increasingly using "double extortion" tactics, with data theft involved in over 76% of incidents, though payment rates for such attac...

    Read More »
  • Akira Ransomware Crashes After Failed EDR Evasion

    Akira Ransomware Crashes After Failed EDR Evasion

    An Akira ransomware affiliate breached a corporate network via credential spraying against a SonicWall SSL VPN lacking MFA, then moved laterally via RDP, enumerated Active Directory, and exfiltrated files to cloud storage using s5cmd in a classic double extortion scheme. The attacker attempted to...

    Read More »
  • Gunra Ransomware Targets Critical Infrastructure via Fortinet Flaws

    Gunra Ransomware Targets Critical Infrastructure via Fortinet Flaws

    Gunra ransomware operators are exploiting two legacy Fortinet vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to breach government and critical infrastructure networks, using a ransomware-as-a-service model and targeting internet-facing devices like firewalls and VPNs. The group employs steal...

    Read More »
  • Qilin ransomware exploits critical Palo Alto VPN bug

    Qilin ransomware exploits critical Palo Alto VPN bug

    The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect VPN to breach corporate networks, with Arctic Wolf investigating multiple intrusions in June 2026 involving domain-wide ransomware deployment...

    Read More »
  • US, South Korea warn of Gunra ransomware hitting govt agencies

    US, South Korea warn of Gunra ransomware hitting govt agencies

    U.S. and South Korean agencies issued a joint advisory urging global critical infrastructure to defend against Gunra, a double-extortion ransomware built on leaked Conti source code, first appearing in April 2025 and targeting healthcare, finance, and government sectors. Gunra exploits Fortinet f...

    Read More »
  • GentleKiller disables 400+ security processes across 48 products

    GentleKiller disables 400+ security processes across 48 products

    The ransomware gang Gentlemen uniquely develops and maintains an in-house framework called GentleKiller, a suite of EDR-killer tools directly supplied to affiliates, rather than delegating this task as other groups do. Gentlemen practices double extortion, targets a wider geographic spread beyond...

    Read More »
  • Adriatic Port Cyberattack Raises Maritime Security Alarms

    Adriatic Port Cyberattack Raises Maritime Security Alarms

    The Anubis ransomware group breached Italy's Adriatic Port Authority in December 2025, compromising 2% of its data including port safety plans and employee records, and demanding a $10 million Bitcoin ransom. The attackers gained initial access through a spear-phishing email, then exploited IT we...

    Read More »
  • Trigona ransomware deploys custom tool to steal data

    Trigona ransomware deploys custom tool to steal data

    Trigona ransomware attackers are using a custom command-line data theft tool called "uploader_client.exe" to accelerate file exfiltration while evading detection, replacing commonly used public tools like Rclone and MegaSync. The tool features parallel uploads with up to five simultaneous connect...

    Read More »
  • Chaos ransomware msaRAT hides C2 channel in legitimate browser process

    Chaos ransomware msaRAT hides C2 channel in legitimate browser process

    A new Rust-based remote access trojan called msaRAT, linked to the Chaos ransomware group, hijacks legitimate Chrome or Edge browsers using Chrome DevTools Protocol and routes command-and-control traffic through WebRTC channels to hide malicious activity. The malware is delivered as an MSI disgui...

    Read More »
  • Ingram Micro Ransomware Attack Impacts 42,000 People

    Ingram Micro Ransomware Attack Impacts 42,000 People

    A ransomware attack on Ingram Micro in July 2025 compromised the personal data of over 42,000 people, including sensitive identification and employment records. The breach, claimed by the SafePay ransomware gang, caused major operational disruption and involved the theft of approximately 3.5 tera...

    Read More »
  • Kraken Ransomware Scans Systems for Fastest Encryption

    Kraken Ransomware Scans Systems for Fastest Encryption

    Kraken ransomware uniquely tests a machine's performance to choose the most efficient encryption method, allowing it to encrypt data quickly without triggering system alerts by using temporary files to decide between full or partial encryption. It targets high-value organizations globally through...

    Read More »
  • Ransomware Surge Intensifies the Battle for Cyber Defenders

    Ransomware Surge Intensifies the Battle for Cyber Defenders

    Ransomware attacks have surged dramatically, with a 20% increase in victims in the first half of the year, driven by the widespread Ransomware-as-a-Service model. The threat landscape is increasingly volatile, with 88 active groups and 35 new entities, making it difficult to track threats as atta...

    Read More »
  • Ransomware Attack Hits SmarterMail via Critical Flaw

    Ransomware Attack Hits SmarterMail via Critical Flaw

    A ransomware attack on SmarterTools began via an unpatched, employee-created virtual machine running outdated SmarterMail software, which allowed lateral movement into office and data center networks. The breach, attributed to the Warlock group exploiting a known vulnerability, led the company to...

    Read More »
  • New "Vect" RaaS Variant Poses Critical Threat, Researchers Warn

    New "Vect" RaaS Variant Poses Critical Threat, Researchers Warn

    A new, highly sophisticated ransomware-as-a-service operation named **Vect** is rapidly emerging, posing a critical threat by targeting organizations and actively recruiting affiliates for expansion. Vect distinguishes itself with custom-built malware using fast encryption techniques and advanced...

    Read More »