Topic: ransomware groups
-
Akira Ransomware Crashes After Failed EDR Evasion
An Akira ransomware affiliate breached a corporate network via credential spraying against a SonicWall SSL VPN lacking MFA, then moved laterally via RDP, enumerated Active Directory, and exfiltrated files to cloud storage using s5cmd in a classic double extortion scheme. The attacker attempted to...
Read More » -
Ransomware disrupts industry without control system access
Ransomware attacks on industrial organizations rose 12% in Q2 2026 to 1,140 incidents, with manufacturing hardest hit (65% of cases), and attackers increasingly targeting enterprise IT systems like ERP and remote access rather than ICS directly to cause production shutdowns. Data theft has overta...
Read More » -
Ransomware Attacks Rebound in July After Slow Q2
Ransomware attacks surged 19% month-over-month in July 2026 to 799 claimed incidents, the second-highest total of the year, after a quiet April-June period. Finance was the hardest-hit sector with a 71% jump in attacks, followed by technology (62%), healthcare (46%), and education (44%), while US...
Read More » -
Lynx ransomware linked to FortiBleed credential-theft campaign
The FortiBleed credential-theft campaign, which compromised over 73,000 Fortinet devices, has been directly linked to the INC and Lynx ransomware operations after researchers found a Windows server where a threat actor accessed both groups' ransomware negotiation panels. The operation, larger tha...
Read More » -
Iran-Linked MuddyWater Masks Espionage as Ransomware Attacks
Iranian state-sponsored group MuddyWater is now masking espionage operations as ransomware attacks using commercially available malware to confuse defenders. The group's true objective remains intelligence gathering and network compromise, not financial gain, despite deploying ransomware-like enc...
Read More » -
Authorities shut down €336M crypto laundering hub for cybercriminals
An international operation dismantled the cryptocurrency laundering service "AudiA6", which processed over "€336 million" in illegal funds for ransomware groups between 2022 and 2025, and was linked to the dark web forum "Dark2Web". On June 10, two administrators were arrested in Georgia, w...
Read More » -
Middle East Brute-Force Attacks Surge in 2026
A sharp rise in brute-force attacks targeting network security appliances like firewalls and VPNs was observed in early 2026, with a dominant share of malicious traffic originating from the Middle East. These attacks highlight the critical targeting of internet-exposed edge devices, with over hal...
Read More » -
Navia Data Breach Exposes 2.7 Million People's Information
A data breach at Navia Benefit Solutions compromised the personal information of approximately 2.7 million individuals, with unauthorized access occurring between December 2025 and January 2026. The exposed data includes highly sensitive identifiers like names, Social Security numbers, and benefi...
Read More » -
UK Firms Hit by Cyber-Attacks 4x Faster Than Global Average
The UK saw a sharp 36% year-on-year increase in cyber-attacks in February, nearly four times the global rate, despite having a lower overall volume than many regions. Ransomware remains a critical threat, with the UK ranking third globally for corporate victims, while sectors like education and g...
Read More » -
Microsoft Teams now flags third-party bots in meetings
Microsoft Teams will introduce a feature in May 2026 to automatically identify and label third-party bots in the meeting lobby, requiring explicit host approval for their entry. This security measure is designed to prevent both malicious and legitimate automated participants from joining meetings...
Read More » -
AI Slashes Attacker Breakout Time to 4 Minutes
AI is dramatically accelerating cyberattacks, with threat actors using automation to reduce the average breakout time to just 34 minutes, enabling lateral movement in as little as four minutes. Attackers are using AI to enhance reconnaissance and social engineering, while defenders struggle due t...
Read More » -
Ransomware Attacks Surge to Record High in 2025
Ransomware attacks reached a record high in 2025, with a 30% surge in publicly named victims and a peak of 124 active criminal groups. Artificial intelligence is fueling the threat by lowering technical barriers, enabling more effective phishing and malware development for both new and establishe...
Read More » -
BridgePay Outage Caused by Ransomware Attack
A ransomware attack on BridgePay Network Solutions, a major U.S. payment gateway, caused a nationwide disruption to payment processing, forcing key systems offline and impacting numerous merchants and organizations. While the attack encrypted files, BridgePay's preliminary investigation indicates...
Read More » -
ShadowSyndicate Expands: New Technical Markers Reveal Growth
The ShadowSyndicate cybercrime infrastructure has expanded, with researchers linking dozens of servers through the repeated reuse of specific SSH fingerprints and access keys, revealing continued coordination. The infrastructure supports multiple attack methods, serving as command-and-control nod...
Read More » -
FBI Shuts Down Major Ransomware Hub: RAMP Forum
U.S. authorities seized the Russian Anonymous Marketplace (RAMP), a major dark web forum central to ransomware tool trading and discussion, dealing a significant blow to the cybercrime ecosystem. The forum, which emerged in 2021 and was linked to the Babuk ransomware group, became a primary hub f...
Read More » -
Ransomware Attacks Surge as Extortion Tactics Evolve
Ransomware data leaks surged dramatically in late 2025, with victim organizations posted to extortion sites increasing by 50% from the prior quarter, even as the overall number of active ransomware gangs decreased. The threat evolved with attackers now systematically stealing and leaking data to ...
Read More » -
Ingram Micro Ransomware Attack Impacts 42,000 People
A ransomware attack on Ingram Micro in July 2025 compromised the personal data of over 42,000 people, including sensitive identification and employment records. The breach, claimed by the SafePay ransomware gang, caused major operational disruption and involved the theft of approximately 3.5 tera...
Read More » -
Kyowon Hit by Ransomware Attack, Data Stolen
The Kyowon Group, a major South Korean conglomerate, suffered a ransomware attack in January that disrupted services and led to confirmed data theft from its servers. While the full scope is under investigation, the breach potentially affects millions of customers, but the company has not yet con...
Read More » -
5.8M Customers Hit in 700Credit Dealership Data Breach
A data breach at 700Credit exposed sensitive personal information of approximately 5.8 million individuals, stemming from a security failure at an integration partner that was not promptly reported. The vulnerability was a poorly designed API that allowed unauthorized access and exfiltration of d...
Read More » -
Global Crackdown Intensifies on Cybercrime Networks
Global law enforcement is achieving unprecedented coordination, with major international operations dismantling cybercrime networks and seizing billions in illicit assets like Bitcoin. Southeast Asia and Africa are key hotspots, with operations targeting forced-labor scam compounds and large-scal...
Read More »