Dedicated exclusively to all things related to ransomware
Recently active
Most ransomware stories end with a payment, an arrest, or another victim.This one starts with a question:What happens when the person negotiating on your behalf is secretly helping the ransomware gang instead?According to the U.S. Department of Justice, that's exactly what happened. Angelo Martino, a Florida ransomware negotiator, was recently sentenced to 70 months in federal prison after pleading guilty to conspiring with members of the BlackCat (ALPHV) ransomware operation.The conspiracy is the headline. The information is the real story. The attacker shouldn't know this...When organizations suffer a ransomware attack, negotiators often become trusted advisors. They're brought into executive calls. They work directly with legal teams, insurance carriers, incident responders, and executive leadership. Very quickly, they gain visibility into some of the organization's most sensitive business decisions.The Information the Attacker Was Never Supposed to HaveThey quickly learn things the
July 16, 2026 By Lawrence Abrams The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States.In a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), Coca-Cola said Fairlife detected unauthorized access to some of its systems, including its production-related systems, in connection with a ransomware attack."After detecting the issue, the Company promptly activated its incident response and business continuity protocols," Coca-Cola said in the filing."The Company's investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisors and cybersecurity experts. The Company has also notified law enforcement."The company said product quality and safety have not been affected by the ransomware attack. >>Full Article<<
July 10, 2026 By Bill Toulas A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems.Karen Serobovich Vardanyan was extradited to the United States after being arrested in Kyiv in April 2025 for providing initial access to corporate networks.According to court documents, Vardanyan helped deploy Ryuk ransomware on the networks of multiple U.S. organizations between November 2019 and April 2020 after illegally accessing their systems.In one attack, Vardanyan and his co-conspirators breached a Michigan company that paid 200 BTC (worth more than $1.1 million at the time). Two other attacks the prosecutors noted include a technology company in Wilsonville, Oregon, and a school in Texas.“Vardanyan and his co-conspirators illegally accessed computer networks of victim companies and deployed ransomware on hundreds of compromised servers and workstations,” the U.S. Department of Justice says.The DoJ says that Va
July 9, 2026Angelo Martino exploited his insider position and fed confidential information to ransomware co-conspirators to extort a combined $75.3 million from five U.S.-based victims. A former ransomware negotiator for DigitalMint was sentenced to 70 months in jail for deceiving his employer’s clients and conspiring with ransomware affiliates to extort a combined $75.3 million from five U.S. companies he was entrusted to aid during their moments of extreme crisis, the Justice Department said Thursday. Angelo John Martino III shared confidential information he gained from his work as a ransomware negotiator, including victim organizations’ negotiating positions and insurance policy limits, to extract the maximum payment for himself and other BlackCat affiliates he colluded with in backchannels.Five of Martino’s victims hired DigitalMint, which assigned the 41-year-old to conduct ransomware negotiations on their clients’ behalf — a rare position he exploited to play both sides, effecti
Ravie Lakshmanan Jul 09, 2026 Malware / Endpoint Security Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy.According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It's assessed to be a rebrand of the Beast ransomware, which, in turn, was an enhanced version of Monster, a Delphi-based ransomware that surfaced in March 2022. Broadcom's cybersecurity arm is tracing the developer behind these ransomware families under the moniker Hyadina.In one attack orchestrated by the ransomware operation in early June 2026, the threat actors are said to have leveraged AnyDesk for remote access and used a NirSoft-based credential harvesting toolkit before deploying the ransomware. The exact initial access vector is unknown. The credential harvester is designed to extract sen
July 3, 2026 By Pierluigi Paganini Sysdig reports an AI agent ran a full ransomware attack end-to-end, exploiting flaws, stealing creds, moving laterally, and encrypting data without humans.Sysdig’s Threat Research Team has documented what it assesses to be the first ransomware operation driven end-to-end by a large language model. The operator, which Sysdig calls JADEPUFFER, broke into a server, harvested credentials, moved to a separate production target, encrypted a database, and destroyed data, all without a human at the keyboard. Ransomware has always needed a skilled person somewhere in the loop. That may no longer be true.“The Sysdig Threat Research Team (TRT) has captured what we assess to be the first documented case of agentic ransomware: a complete extortion operation driven end-to-end by a large language model (LLM).” reads the report published by Sysdig. “This operator, which we have dubbed JADEPUFFER, gained initial access to an internet-facing Langflow instance through C
June 30, 2026, By Bill Toulas The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications.Nidec is a leader in producing motors of all sizes, from micro-precision ones used in phones and hard drives to heavy-duty motors for robotics, elevators, and large HVAC systems.The company also designs motors for electric vehicles, electric power steering systems, and advanced driver-assistance systems.With annual revenue of $17.2 billion, 100,000 employees, and operations in over 40 countries through manufacturing facilities and subsidiaries, Nidec is a global leader in electric motor manufacturing.In a statement last week, Nidec said that its Taiwanese subsidiary, Nidec Chaun Choung Technology, was compromised in a ransomware attack.“On Monday, June 22, 2026, ransomware-originated damage was confirmed in part of Nidec Chaun Choung Technology’s server,” Nidec says. >&
After a global lull, ransomware gangs are setting sights on a rich new arena: attacking EU organizations and their suppliers. June 25, 2026, By Nate Nelson Source: imaginima via Getty Images A specter is haunting Europe — the specter of ransomware.After a global lull in 2024 and 2025, the ransomware-as-a-service (RaaS) ecosystem appears to be back to form, at least in Europe. Researchers from Black Kite tracked 684 ransomware attacks across the continent through the first four months of 2026. That's 55% more than the 441 recorded in the first four months of 2025, even more than the 643 recorded through the first half of 2025."Globally, the US absorbs almost half of all ransomware victims. Canada and the UK have traded second place. Europe was a step behind. Now that’s shifting," Ferhat Dikbiyik, chief research and intelligence officer at Black Kite, tells Dark Reading. He believes that at least a couple of factors are at play. First, an oversaturation of ransomware activity in the US
June 24, 2026, By Bill Toulas A new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors.The malware is believed to be linked to KongTuke/Woodgnat, an initial access broker active since at least 2024 that specializes in compromising corporate networks and selling that access to ransomware groups, including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.Researchers at cybersecurity company Symantec say that Mistic has been used in intrusions since April.In at least one incident, it was deployed shortly after ModeloRAT, a backdoor attributed to KongTuke and delivered via social engineering attacks over Microsoft Teams.Symantec believes that Mistic is a newly developed, stealthy backdoor designed for long-term persistence in compromised networks. >>Full Article<<
June 19, 2026, By Ravie Lakshmanan The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor.This mature portfolio of EDR-terminating tools is centered around a framework that's known as GentleKiller."They also incorporate third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller," ESET security researcher Jakub Souček said in a report shared with The Hacker News. "These tools are standardized through a shared defense-evasion layer, impersonating predominantly security vendors using fake version information, and copied legitimate certificates and icons."The Slovakian cybersecurity company also called out the ransomware crew for its ability to "unusually quickly operationalize" newly disclosed proof-of-concept (PoC) exploits related to an attack technique called the bring your own vul
June 11, 2026, By Bill Toulas Seizure bannerSource: Europol Law enforcement has dismantled the “AudiA6” cryptocurrency service allegedly used by ransomware actors and other cybercriminals to launder more than $380 million.Europol says that the service has been linked to more than 15 distinct international investigations of ransomware attacks.It is believed that the platform acted as a central money laundering hub between 2022 and 2025.“Investigators uncovered what they describe as an industrial-scale cryptocurrency laundering operation built around thousands of fraudulent exchange accounts opened using stolen or purchased identities,” describes Europol says.“Analysis conducted by Europol linked the criminal service to more than 15 investigations worldwide involving ransomware attacks and large-scale cryptocurrency theft.”The service was marketed as a “professional cryptocurrency mixing service,” but all it did was accept cybercrime proceeds, move the money around through complex transa
June 10, 2026, By Brian Krebs A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.A graphic created and shared by The Gentlemen ransomware group administrator Hastalamuerte on Breachforums in May 2026. Credit: ke-la.com.Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.“A 90/10 affiliate revenue split — compared to the industry standard 80/20 — is accelerating the group’s growth by attracting experienced operators from competing programs,” the researchers wrote in April.Check Point found T
June 8, 2026, By Stefanie Schappert The Qilin ransomware gang on Monday claims to have hacked the Shipping Association of New York/New Jersey (SANYNJ), a major maritime industry group responsible for cargo movements at one of North America’s busiest ports. Key takeaways: Qilin claims it hacked the Shipping Association of New York/New Jersey, a major maritime industry organization tied to one of North America’s busiest ports. A major maritime cyberattack could delay shipments, disrupt cargo tracking, and create supply chain backups across the US. The alleged breach adds to growing cybersecurity concerns surrounding critical transportation and logistics infrastructure. Key Takeaways by nexos.ai, reviewed by Cybernews staff.The notorious ransomware group posted the maritime membership organization on its dark leak site Monday morning.Although Qilin provided few details in the victim entry, the Russian-speaking cybercriminal cartel posted a link claiming to have already “publicated” wh
June 5, 2026, By Pierluigi Paganini Researchers exposed the Silent Ransom Group ‘s Fast Flux infrastructure as the FBI warns of ongoing attacks targeting U.S. law firms and businesses.Resecurity uncovered the Silent Ransom Group (SRG)’s Fast Flux network infrastructure and shares available intelligence with the cybersecurity community to disrupt their malicious activities and enable ISP/DNS providers to counter this threat.“Resecurity is the first to uncover the SRG’s Fast Flux network infrastructure and is sharing this intelligence with the cybersecurity community to disrupt their malicious activities and enable ISP/DNS providers to counter this threat.” reads the report published by Resecurity.The Silent Ransom Group, also known as Luna Moth, Chatty Spider, and UNC3753, is a cyber extortion group active since 2022 that focuses on stealing sensitive data and extorting victims rather than encrypting files. The group primarily targets organizations in sectors such as legal services, hea
June 4, 2026 A new ransomware group known as Payouts King has quietly been building a reputation since it first appeared in April 2025.While it spent most of last year flying under the radar, early 2026 brought a noticeable spike in activity tied to former affiliates of the now-defunct BlackBasta operation.The group targets organizations through well-worn but effective tactics, stealing large volumes of sensitive data before selectively encrypting files on compromised systems.BlackBasta, which had operated as a successor to the notorious Conti ransomware group since February 2022, collapsed in February 2025 after its internal chat logs were leaked online.That exposure forced the group to disband, but it did not stop the individuals behind the attacks. Many of its former affiliates simply carried on under different banners, deploying other ransomware families like Cactus and, more recently, aligning with Payouts King.Zscaler identified these attacks and published a report shared with Cy
June 1, 2026, By Pierluigi Paganini 16,699 ransomware leak posts over 2 years show 84% drop Monday–Friday, peak at European afternoon hours. October spikes yearly.Someone analyzed 16,699 ransomware leak-site posts across 200 groups over two years and asked the question most threat intelligence reports dance around: when does this actually happen? The answer is mundane and useful. Ransomware runs on a workweek, peaks during European office hours, spikes every October, and the operator population is growing fast. Nobody who defends networks for a living should still be planning around the hooded-hacker-at-3am image.The day-of-week breakdown is unambiguous. Monday absorbed 3,080 posts across the 24-month window. Tuesday came in at 3,073. Sunday posted 1,189.“The mythology around ransomware involves anonymous hooded figures hammering keys at 3am. The data says the opposite.” reads the report published by Ransomnews Research Team. “The operators who post leak-site listings are running this
May 27, 2026, By Sinisa Markovic The Silent Ransom Group (SRG) is targeting law firms using social engineering techniques and an unusual tactic for cybercriminals: showing up at victims’ offices in person while posing as IT staff, the FBI warns.The group, also known as Luna Moth, Chatty Spider, and UNC3753, has been active since at least 2022 and has targeted companies in several sectors, including insurance, finance, and healthcare, though law firms remain its primary target.The FBI said SRG actors use phone calls and phishing emails to pose as employees from a victim’s IT department. The phishing emails direct targets to contact fake IT support, while phone calls pressure employees into opening a remote desktop session and granting access to their systems.If those attempts fail, SRG sends a threat actor to company offices to gain physical access to devices. The person then claims they need to create a backup or image the system because of possible issues linked to the phishing email
May 26, 2026, By Pierluigi Paganini A 5-year study on the Ransomware Economy found that 30,515 exposed databases were hit by ransom attacks, causing massive damage despite victims never paying.Database extortion doesn’t look like the ransomware stories that usually grab headlines. There’s no slick branding, no leak-site countdown, no gang posting memes on Telegram. In most cases, there’s just a text file sitting inside a live database telling the victim to send bitcoin for data that’s already been copied, deleted, or both.The Ransomnews Research Team spent five years tracking exposed databases on the public internet, from May 2021 through 13 May 2026. The dataset covers 65,907 exposed systems across MongoDB, MySQL, Elasticsearch, Kibana, and a long list of HTTP-based admin panels. Of those, 30,515 databases, or 46.3%, already carried a ransom or wipe note when researchers found them.The scale matters because the damage isn’t theoretical. Based on pre-attack row counts, the compromised
May 21, 2026, By Bill Toulas A virtual private network service called 'First VPN,' used in ransomware and data theft attacks, has been taken offline in a joint international law enforcement operation.Authorities have seized dozens of First VPN servers located in 27 countries, arrested the administrator, and conducted a house search in Ukraine.The VPN service was advertised on various cybercrime forums as a privacy-focused VPN that does not log user data and ignores law enforcement requests for user information.VPN tools encrypt users’ traffic and hide their real IP addresses. While they are used legitimately to protect privacy on public WiFi, bypass censorship, reduce tracking, and enable secure remote work, threat actors also rely on them to hide their location and infrastructure.Depending on the region they operate in, VPN providers may be legally required to comply with law enforcement requests and hand over any data they retain for criminal investigations.According to Europol, the
May 19, 2026, By Tushar Subhra Dutta A ransomware group called The Gentlemen has been quietly building one of the most aggressive cybercriminal operations seen in recent years.Emerging publicly in the second half of 2025, the group rapidly scaled its activity to become one of the top two most active ransomware threats globally by early 2026.What makes this group stand out is not just its speed, but the breadth of systems it targets and the scale at which it has grown.The group has demonstrated capability against a wide range of enterprise environments, including Windows, Linux, NAS, BSD, and VMware ESXi systems.Its attacks follow a well-organized workflow, from gaining initial access through stolen credentials or exposed remote services, to deploying ransomware across entire networks.The group also steals data before locking systems, using that stolen information as additional lever to pressure victims into paying.Analysts at LevelBlue said in a report shared with Cyber Security News (
The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation. May 15, 2026, By Eduard Kovacs American Lending Center this week revealed that a data breach discovered last year has impacted more than 123,000 individuals.American Lending Center (ALC) is a California-based non-bank lender that manages a $3 billion portfolio specializing in government-guaranteed small business loans.The organization is notifying individuals affected by the data breach that information such as names, dates of birth, and SSNs may have been stolen in a ransomware attack detected in July 2025. “Through a forensic investigation into this breach, it was discovered that the threat actor compromised internal network, executed a ransomware attack, and accessed certain files that may have contained personal identifying or sensitive information,” ALC said in its notification to impacted customers, a copy of which was submitted to the Maine attorney general’s of
May 12, 2026, By Marko Zivkovic Apple supply chain partner Foxconn suffered a cyberattack at its Wisconsin facility.More than 10 million documents spanning 8 terabytes of data were reportedly stolen from Foxconn's network. Confidential AMD, Google, and Intel projects are at risk of exposure, but Apple's tech appears to be safe.Even with Apple's extensive security measures for pre-production designs, the company's supply chain partners often fall victim to cyberattacks. In December 2025, an Apple assembler in China was targeted by attackers, with the same thing happening to Luxshare in January 2026.Now, Foxconn has become the latest Apple supply chain and assembly partner to suffer a cyberattack. On Tuesday, the company confirmed its facility in Mount Pleasant, Wisconsin, had been impacted by the attack in May 2026.Ransomware group Nitrogen claims to have taken 8TB of data, or over 11 million files. "These include files such as confidential instructions, projects, and drawings from Inte
May 12, 2026, By Jonathan Greig A large Pennsylvania pharmaceutical company said a ransomware attack has impacted critical systems used to ship, receive and manufacture products. West Pharmaceutical Services filed a report with the Securities and Exchange Commission (SEC) on Monday evening warning customers that a hacker breached the company network on May 4, stole data and encrypted systems. “The incident and the Company’s proactive response have temporarily disrupted the Company’s business operations globally,” the company’s general counsel wrote in the 8-K form. “While the Company has restored its core enterprise systems, and critical processes for shipping, receiving, and manufacturing have restarted at some sites with restoration of the remaining sites in process, the timeline for a complete restoration has not yet been finalized.”A spokesperson for the company told Recorded Future News that West Pharmaceutical shut down and isolated on-premise infrastructure that was affected, r
May 12, 2026, By Pierluigi Paganini WannaCry showed how unpatched flaws and leaked cyber tools can cripple global systems, reshaping cybersecurity defenses worldwide.In memory of the day the digital world was shaken, but learned to fight back.The WannaCry ransomware attack represents one of the most significant events in recent cybersecurity history, not only for its global scale but also for the technical and geopolitical implications it raised. Analyzing its history means understanding how known vulnerabilities, advanced tools, and delays in mitigation can converge into an event capable of disrupting critical infrastructure worldwide.WannaCry emerged on May 12, 2017 by exploiting a vulnerability in the SMBv1 protocol of Microsoft Windows (CVE-2017-0144 aka EternalBlue). This vulnerability, which was addressed by the Microsoft security patch MS17-010 in March 2017, allowed remote code execution without authentication. The most critical detail is that the exploit used, known as Eternal
Internal Communications Dumped Online, Revealing Fresh Victims, Repeat Tactics May 11, 2026, By Mathew J. Schwartz Image: Carlo Semlinsky/ShutterstockA ransomware organization is suffering an extreme case of turnabout is fair play through a data breach that splaying internal correspondence across the internet."The Gentlemen" surfaced as a ransomware-as-a-service organization in mid-2025 with - as SOCRadar has noted - little intention of playing nice. Hints that The Gentlemen suffered a data breach first surfaced on May 4, in a post to cybercrime forum Breached with the subject line "The Gentlemen - hacked data for sale," requested $10,000, payable in bitcoin, "for the full data," with samples available on request.Whether or not someone paid isn't clear, but on Friday, the same user listed a link to file-sharing site MediaFire, for downloading the stolen data for free. >>Full Article<<
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.