Skip to content

Topic

Ransomware

Malware that encrypts a victim's files or systems, used by attackers to demand ransom for decryption and often threaten to leak stolen data.

Current stories

security14 publishers

Investigators say a 16-year-old ran KillSec, an extortion crew that exploited weakly secured cloud storage

Eurojust says a 16-year-old is the suspected main operator of KillSec, a group it blames for almost 1,000 data-theft extortion attacks since 2024. Both published accounts say its favoured way in was poorly secured access to victims' cloud storage.

Perspective Coverage

14 publishers
Builder
Builder 16%
Operator
Operator 75%
Investor
Investor 9%

Reality

Evidence78
Adoption
Insufficient
Hype gap+25
Incentives45
Confidence76
security6 publishers

Storm-3168 mapped an Azure tenant for 17 hours before a seven-minute deletion run

Microsoft says Storm-3168, also tracked as JADEPUFFER, used two stolen Azure service principals to try deleting more than 100 storage accounts. The deletions took about seven minutes, so the 17 hours of API reads before them were when anyone watching those identities had time to act.

Perspective Coverage

6 publishers
Builder
Builder 23%
Operator
Operator 70%
Investor
Investor 7%

Reality

Evidence72
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence70
security6 publishers

Warlock ransomware group narrows its targets to large Spanish- and Portuguese-speaking organizations

Warlock, the group Microsoft tracks as Storm-2603, hit four organizations in Spanish- or Portuguese-speaking countries in two months, Symantec says. It works like the Chinese state groups it first appeared beside and extorts like a ransomware crew.

Perspective Coverage

6 publishers
Builder
Builder 32%
Operator
Operator 59%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+15
Incentives30
Confidence68
build1 publisher

Gunra enters through the same VPN appliances the advisory says should front RDP

Gunra affiliates get in through two FortiOS and FortiProxy authentication bypasses, CVE-2024-55591 and CVE-2025-24472, says a 10 August 2026 advisory. Its fix for exposed RDP routes remote access through that same class of appliance, so the gateway has to be secured before RDP moves behind it.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+5
Incentives30
Confidence50
security1 publisher

Ransomware attack disrupts utility payments in Vicksburg, Mississippi

Vicksburg Mayor Willis Thompson says ransomware forced a shutdown of city systems that hit utility payments in the Mississippi city of more than 20,000. The city, still investigating, has not determined whether personal data on customers, employees or vendors was accessed.

Publishers:therecord.media

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence60
security3 publishers

Ransomware tooling turns up in weather OT at South Africa's air traffic operator

South Africa's ATNS, which runs air traffic control for about 10% of the world's airspace, found early-stage ransomware tooling in a weather OT network. The state operator says its team stopped the attack yet is seeking outside forensics to learn how the attackers got in.

Publishers:businessday.co.zadarkreading.comscworld.com

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 60%
Investor
Investor 18%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives35
Confidence58
build1 publisher

How Gunra actors got into a network through a default SSL VPN admin password

Gunra actors entered a victim's network through an SSL VPN admin account still on default credentials, according to a 10 August 2026 advisory. The path used no software flaw, so it tests credential changes, lockout and account reviews on edge devices.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
security2 publishers

Arizona's court system says hackers copied residents' data without deploying ransomware

Arizona's Supreme Court says hackers copied personal data on "many Arizonans," with no ransomware deployed and no ransom demand as of Monday. For the people in those records, the risk now is direct misuse of the data, and no extortion talks are under way to show what the thieves intend.

Publishers:azcourts.govtherecord.media

Reality

Evidence50
Adoption
Insufficient
Hype gap0
Incentives40
Confidence50
security4 publishers

Ransomware at Tokyo rail operator Keio reaches the group's hotel business

Keio Corporation shut down its network after a September 26 ransomware attack that disrupted Keio Group companies, including the Keio Plaza Hotel Tokyo. Trains are running normally while Keio checks whether customer and business data left its network.

Perspective Coverage

4 publishers
Builder
Builder 16%
Operator
Operator 69%
Investor
Investor 15%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence65
build1 publisher

Keio's trains kept running through a ransomware attack on its group servers

Keio Corporation shut its network after ransomware hit its group servers on September 26, disrupting payments and the business behind its 25 hotels. Its trains appear unaffected. Investigators have not yet traced the attack path, so it is still unknown whether a designed boundary kept rail out of reach.

Publishers:dev.to

Reality

Evidence40
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence35
build1 publisher

Qilin ransomware affiliate logged into Cisco firewall management with a credential scored 5.3

Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence55

Earlier coverage

  1. New ransomware crew n0n threatens to destroy the backups of victims who refuse to pay

    Security · September 27, 2026 · 2 publishers

  2. Akira Reboots Into Safe Mode to Blind EDR, and Starves Its Own Encryptor

    Security · August 17, 2026 · 3 publishers

  3. WMIC is gone from Windows 11 24H2 and 25H2, and your wmic.exe rules go with it

    Security · August 18, 2026 · 3 publishers

  4. The extortion layer your IR playbook has no page for: 'Ransom Busters' emails victims mid-incident

    Security · August 18, 2026 · 3 publishers

  5. Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric

    Security · August 18, 2026 · 3 publishers

  6. U.S. Bank's answer to LockBit: the breach happened two tiers out

    Security · August 21, 2026 · 2 publishers

  7. ShinyHunters breached Clop's leak site through an unpatched Grav path traversal flaw

    Security · September 26, 2026 · 1 publisher

  8. AFP sizes the Shai-Hulud syndicate's take at more than 500,000 credentials

    Security · August 28, 2026 · 17 publishers

  9. Aurora operators drove Cursor Agent through ten victim networks over six weeks

    Security · August 28, 2026 · 4 publishers

  10. Extortionists supply the only itemized count of what left Berlin's state network

    Security · August 28, 2026 · 6 publishers

  11. AI agents ran more than 50 ATT&CK techniques through one enterprise in under 10 hours

    Security · September 2, 2026 · 2 publishers

  12. Rhysida gives Berlin seven days before it auctions 5.79TB of city data

    Security · September 5, 2026 · 4 publishers

  13. CISA: Ransomware gangs exploiting WatchGuard Firebox flaw as 9,000 firewalls remain unpatched nine months later

    Security · September 10, 2026 · 2 publishers

  14. Stolen vendor credentials pulled patient SSNs out of Veradigm's API

    Security · September 9, 2026 · 2 publishers

  15. The FBI's first Cyber Strategy makes disruption the measure of a successful case

    Security · September 10, 2026 · 2 publishers

  16. Cisco's own July 23 log indicator predates its August date for FMC exploitation

    Security · September 9, 2026 · 6 publishers

  17. A Conti developer got four years for holding stolen data from 12 of the group's 1,000-plus victims

    Security · September 10, 2026 · 5 publishers

  18. Ransomware gangs move onto the vCenter Syslog bug Broadcom patched on July 29

    Security · September 15, 2026 · 2 publishers

  19. ShinyHunters threatens to name companies that paid Clop after defacing its leak site

    Security · September 25, 2026 · 1 publisher

  20. Manufacturing ransomware victims rose 40% in seven months as European counts grew 85%

    Security · September 17, 2026 · 2 publishers

  21. Settra ransomware operators ran two intrusions through the open-source MeshAgent RMM

    Security · September 18, 2026 · 2 publishers

  22. CISA ties ransomware campaigns to a TeamCity flaw patched in July

    Security · September 25, 2026 · 2 publishers

  23. Karen Vardanyan's 24-month Ryuk sentence is mostly time he has already served

    Security · September 24, 2026 · 5 publishers

  24. 72.7% of SANS hunters who caught nation-state intruders saw them abuse native admin tools

    Security · September 24, 2026 · 1 publisher

  25. Storm-2570 brings the same intrusion toolkit to Qilin, DragonForce, Anubis and BERT attacks

    Security · September 24, 2026 · 1 publisher

  26. Government-portal DDoS accounts for a quarter of ENISA's 8,257 EU incidents in 2025

    Security · September 23, 2026 · 1 publisher

  27. Eclypsium finds the month's exploited infrastructure flaws again in the management consoles

    Security · September 23, 2026 · 1 publisher

  28. Coca-Cola's Fairlife shutdown moves the resilience question from the conveyor to the ERP

    Build · September 23, 2026 · 1 publisher

  29. ShinyHunters claims the private keys to Clop's onion address after defacing the leak site

    Security · September 19, 2026 · 6 publishers

  30. Huntress rebuilt a 175-endpoint INC ransomware case from scheduled tasks and a driver fragment

    Security · September 22, 2026 · 1 publisher

  31. Clop asks ShinyHunters to come online from the leak site ShinyHunters defaced

    Security · September 22, 2026 · 1 publisher

  32. ShinyHunters says it controls the private keys to Cl0p's onion address

    Product · September 21, 2026 · 1 publisher

  33. A single Group Policy Object delivered the whole extortion stage at a Middle East manufacturer

    Security · September 21, 2026 · 1 publisher

  34. ShinyHunters says a Grav upload flaw got it inside Cl0p's leak site

    Product · September 21, 2026 · 1 publisher

  35. A crafted HTTP request runs as root on the console that pushes every Cisco firewall's policy

    Build · September 20, 2026 · 1 publisher

  36. Restoring a SCADA workstation from its OS backup leaves the alarm setpoints behind

    Security · September 19, 2026 · 1 publisher

  37. Three intrusion clusters reached the same Cisco console through one CVSS 10.0 bypass

    Build · September 18, 2026 · 1 publisher

  38. Talos argues defenders are already behind the models they have

    Security · September 17, 2026 · 1 publisher

  39. Aurora put a Cursor agent on the keyboard for its ESXi exploit work

    Build · September 17, 2026 · 1 publisher

  40. An OpenAI evaluation model broke out of its sandbox through a flaw it found in its own package proxy

    Security · September 17, 2026 · 1 publisher