Topic: ransomware groups

  • Lynx ransomware linked to FortiBleed credential-theft campaign

    Lynx ransomware linked to FortiBleed credential-theft campaign

    The FortiBleed credential-theft campaign, which compromised over 73,000 Fortinet devices, has been directly linked to the INC and Lynx ransomware operations after researchers found a Windows server where a threat actor accessed both groups' ransomware negotiation panels. The operation, larger tha...

    Read More »
  • Authorities shut down €336M crypto laundering hub for cybercriminals

    Authorities shut down €336M crypto laundering hub for cybercriminals

    An international operation dismantled the cryptocurrency laundering service "AudiA6", which processed over "€336 million" in illegal funds for ransomware groups between 2022 and 2025, and was linked to the dark web forum "Dark2Web". On June 10, two administrators were arrested in Georgia, w...

    Read More »
  • Ransomware Attacks Rebound in July After Slow Q2

    Ransomware Attacks Rebound in July After Slow Q2

    Ransomware attacks surged 19% month-over-month in July 2026 to 799 claimed incidents, the second-highest total of the year, after a quiet April-June period. Finance was the hardest-hit sector with a 71% jump in attacks, followed by technology (62%), healthcare (46%), and education (44%), while US...

    Read More »
  • Ransomware Attacks Surge as Extortion Tactics Evolve

    Ransomware Attacks Surge as Extortion Tactics Evolve

    Ransomware data leaks surged dramatically in late 2025, with victim organizations posted to extortion sites increasing by 50% from the prior quarter, even as the overall number of active ransomware gangs decreased. The threat evolved with attackers now systematically stealing and leaking data to ...

    Read More »
  • U.S. Sanctions Russian Hosting Service for Ransomware Role

    U.S. Sanctions Russian Hosting Service for Ransomware Role

    The U.S., U.K., and Australia have imposed sanctions on Russian bulletproof hosting services for enabling ransomware operations, cybercrimes, and ignoring law enforcement takedown requests. Key targets include Media Land and its affiliates, which supported ransomware groups like LockBit and facil...

    Read More »
  • Ransomware Attacks Surge to Record High in 2025

    Ransomware Attacks Surge to Record High in 2025

    Ransomware attacks reached a record high in 2025, with a 30% surge in publicly named victims and a peak of 124 active criminal groups. Artificial intelligence is fueling the threat by lowering technical barriers, enabling more effective phishing and malware development for both new and establishe...

    Read More »
  • ShadowSyndicate Expands: New Technical Markers Reveal Growth

    ShadowSyndicate Expands: New Technical Markers Reveal Growth

    The ShadowSyndicate cybercrime infrastructure has expanded, with researchers linking dozens of servers through the repeated reuse of specific SSH fingerprints and access keys, revealing continued coordination. The infrastructure supports multiple attack methods, serving as command-and-control nod...

    Read More »
  • UK, US, Australia Sanction Russian Cyber Host Media Land

    UK, US, Australia Sanction Russian Cyber Host Media Land

    The United Kingdom, United States, and Australia have jointly sanctioned three bulletproof hosting providers and four Russian executives for enabling ransomware operators and cybercriminals by supplying critical infrastructure. These services are essential to the cybercrime underworld, allowing t...

    Read More »
  • Ransomware disrupts industry without control system access

    Ransomware disrupts industry without control system access

    Ransomware attacks on industrial organizations rose 12% in Q2 2026 to 1,140 incidents, with manufacturing hardest hit (65% of cases), and attackers increasingly targeting enterprise IT systems like ERP and remote access rather than ICS directly to cause production shutdowns. Data theft has overta...

    Read More »
  • Ransomware Attacks Surge 13% as Leak Sites Target More Victims

    Ransomware Attacks Surge 13% as Leak Sites Target More Victims

    European organizations experienced a 13% surge in ransomware attacks, with the UK, Germany, Italy, France, and Spain being the most targeted, and the manufacturing sector was the most vulnerable. The majority of incidents involved both file encryption and data theft, with groups like Akira and Lo...

    Read More »
  • Yanluowang Ransomware Broker Pleads Guilty in Landmark Case

    Yanluowang Ransomware Broker Pleads Guilty in Landmark Case

    Aleksey Volkov, a Russian national, admitted to providing initial network access for Yanluowang ransomware attacks on at least eight U.S. companies from 2021 to 2022, facilitating ransom demands ranging from $300,000 to $15 million. The FBI identified Volkov through his Apple iCloud, cryptocurren...

    Read More »
  • AI Slashes Attacker Breakout Time to 4 Minutes

    AI Slashes Attacker Breakout Time to 4 Minutes

    AI is dramatically accelerating cyberattacks, with threat actors using automation to reduce the average breakout time to just 34 minutes, enabling lateral movement in as little as four minutes. Attackers are using AI to enhance reconnaissance and social engineering, while defenders struggle due t...

    Read More »
  • UK Firms Hit by Cyber-Attacks 4x Faster Than Global Average

    UK Firms Hit by Cyber-Attacks 4x Faster Than Global Average

    The UK saw a sharp 36% year-on-year increase in cyber-attacks in February, nearly four times the global rate, despite having a lower overall volume than many regions. Ransomware remains a critical threat, with the UK ranking third globally for corporate victims, while sectors like education and g...

    Read More »
  • Global Crackdown Intensifies on Cybercrime Networks

    Global Crackdown Intensifies on Cybercrime Networks

    Global law enforcement is achieving unprecedented coordination, with major international operations dismantling cybercrime networks and seizing billions in illicit assets like Bitcoin. Southeast Asia and Africa are key hotspots, with operations targeting forced-labor scam compounds and large-scal...

    Read More »
  • Iran-Linked MuddyWater Masks Espionage as Ransomware Attacks

    Iran-Linked MuddyWater Masks Espionage as Ransomware Attacks

    Iranian state-sponsored group MuddyWater is now masking espionage operations as ransomware attacks using commercially available malware to confuse defenders. The group's true objective remains intelligence gathering and network compromise, not financial gain, despite deploying ransomware-like enc...

    Read More »
  • Ransomware Payouts Hit Record $3.6M as Attacks Evolve

    Ransomware Payouts Hit Record $3.6M as Attacks Evolve

    The average ransom payment surged 44% to a record $3.6 million, even as the number of ransomware incidents decreased, indicating a shift toward more targeted attacks. Despite fewer attacks, 70% of victimized organizations paid ransoms, with critical sectors like healthcare and government facing a...

    Read More »
  • UK & US Charge Alleged Scattered Spider Hackers

    UK & US Charge Alleged Scattered Spider Hackers

    Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have been arrested and charged in the U.S. and U.K. for their roles in numerous damaging cyber intrusions, including attacks on critical infrastructure and corporate networks. The suspects are accused of usi...

    Read More »
  • Microsoft Defender Stops Email Bombing Attacks in Office 365

    Microsoft Defender Stops Email Bombing Attacks in Office 365

    Microsoft Defender for Office 365 now includes automatic detection and blocking of email bombing attacks, protecting organizational inboxes without requiring manual setup. The new 'Mail Bombing' feature, fully deployed by July 2025, diverts suspicious emails to Junk and allows monitoring via Thre...

    Read More »
  • Middle East Brute-Force Attacks Surge in 2026

    Middle East Brute-Force Attacks Surge in 2026

    A sharp rise in brute-force attacks targeting network security appliances like firewalls and VPNs was observed in early 2026, with a dominant share of malicious traffic originating from the Middle East. These attacks highlight the critical targeting of internet-exposed edge devices, with over hal...

    Read More »
  • Akira Ransomware Crashes After Failed EDR Evasion

    Akira Ransomware Crashes After Failed EDR Evasion

    An Akira ransomware affiliate breached a corporate network via credential spraying against a SonicWall SSL VPN lacking MFA, then moved laterally via RDP, enumerated Active Directory, and exfiltrated files to cloud storage using s5cmd in a classic double extortion scheme. The attacker attempted to...

    Read More »