319
Total Incidents
29
Last 30 Days
23
Sources
50
Groups Mentioned
319 incidents
BleepingComputer 2026-03-06T19:50:21+00:00
Cognizant TriZetto breach exposes health data of 3.4 million patients

TriZetto Provider Solutions, a healthcare IT company that develops software and services used by health insurers and healthcare providers, has suffered a data breach that exposed the sensitive informa...

SecurityWeek 2026-03-06T15:35:00+00:00
In Other News: FBI Hacked, US Security Pro Killed in Iran War, Hijacked Cameras Used in Khamenei Strike

<p>Other noteworthy stories that might have slipped under the radar: Avira antivirus vulnerabilities, Transport for London data breach affects 10 million, Gaming cheat exposes North Korean hacker.</p>...

The Record 2026-03-05T18:04:23+00:00
Phobos ransomware leader facing 20 years in prison after pleading guilty to hacking charges

Ptitsyn and several others began using the Phobos ransomware in November 2020, attacking more than 1,000 organizations around the world. He was arrested in South Korea and extradited in November 2024.

SecurityWeek 2026-03-05T12:47:10+00:00
Russian Ransomware Operator Pleads Guilty in US

<p>Evgenii Ptitsyn was extradited to the United States from South Korea in November 2024.</p> <p>The post <a href="https://www.securityweek.com/russian-ransomware-operator-pleads-guilty-in-us/">Russia...

BleepingComputer 2026-03-05T08:34:42+00:00
Phobos ransomware admin pleads guilty to wire fraud conspiracy

A Russian national pleaded guilty to a wire fraud conspiracy charge related to his role in administering the Phobos ransomware operation, which breached hundreds of victims worldwide. [...]

BleepingComputer 2026-03-04T18:44:14+00:00
Hacker mass-mails HungerRush extortion emails to restaurant patrons

Customers of restaurants using the HungerRush point-of-sale (POS) platform say they received emails from a threat actor attempting to extort the company, warning that restaurant and customer data coul...

SecurityWeek 2026-03-04T17:44:14+00:00
New LexisNexis Data Breach Confirmed After Hackers Leak Files

<p>The hackers claim to have stolen 2GB of files, including 400,000 personal information records. </p> <p>The post <a href="https://www.securityweek.com/new-lexisnexis-data-breach-confirmed-after-hack...

BleepingComputer 2026-03-04T15:28:56+00:00
Mississippi medical center reopens clinics hit by ransomware attack

The University of Mississippi Medical Center (UMMC) says it has resumed normal operations, nine days after a ransomware attack blocked access to electronic medical records and took down many of its IT...

The Hacker News 2026-03-03T17:15:00+00:00
Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations

Threat hunters have called attention to a new campaign as part of which bad actors masqueraded as fake IT support to deliver the Havoc command-and-control (C2) framework as a precursor to data exfiltr...

Unit 42 2026-03-03 tomb
Law enforcement disrupts tomb ransomware infrastructure

International law enforcement operation seizes servers and domains used by tomb ransomware group.

Unit 42 2026-02-28 hurricanegroup
hurricanegroup leaks 100GB of data from Acme Corp

The hurricanegroup ransomware group has published 2000GB of stolen data from Acme Corp after ransom negotiations failed.

Dark Reading 2026-02-27T20:48:05+00:00
Life Mirrors Art: Ransomware Hits Hospitals on TV &amp; IRL

HBO's &quot;The Pitt&quot; is showing audiences what a real Mississippi healthcare system is going through this week, thanks to a ransomware attack.

Dark Reading 2026-02-27T16:18:19+00:00
The Case for Why Better Breach Transparency Matters

It's become a standard practice for organizations to disclose the bare minimum about a data breach, or worse — not disclose the incident at all.

The Hacker News 2026-02-26T14:28:00+00:00
ThreatsDay Bulletin: Kali Linux + Claude, Chrome Crash Traps, WinRAR Flaws, LockBit & 15+ Stories

Nothing here looks dramatic at first glance. That’s the point. Many of this week’s threats begin with something ordinary, like an ad, a meeting invite, or a software update. Behind the scenes, the tac...

The Hacker News 2026-02-26T12:06:00+00:00
Expert Recommends: Prepare for PQC Right Now

Introduction: Steal It Today, Break It in a Decade Digital evolution is unstoppable, and though the pace may vary, things tend to fall into place sooner rather than later. That, of course, applies to ...

Dark Reading 2026-02-25T21:14:21+00:00
RAMP Forum Seizure Fractures Ransomware Ecosystem

Researchers suggest defenders monitor how these malicious groups re-form and leverage the useful threat intel to guide their next moves.

Dark Reading 2026-02-24T21:18:04+00:00
Lazarus Group Picks a New Poison: Medusa Ransomware

The North Korean threat group also leveraged Comebacker backdoor, Blindingcan RAT, and info stealer Infohook in its recent attacks.

FBI Flash 2026-02-24 atlas
Major healthcare company Samsung Electronics hit by ransomware attack

Samsung Electronics confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Dark Reading 2026-02-23T19:37:59+00:00
600+ FortiGate Devices Hacked by AI-Armed Amateur

A Russian-speaking hacker used generative AI to compromise the FortiGate firewalls, targeting credentials and backups for possible follow-on ransomware attacks.

Dark Reading 2026-02-23 hornetlock
Law enforcement disrupts hornetlock ransomware infrastructure

International law enforcement operation seizes servers and domains used by hornetlock ransomware group.

BleepingComputer 2026-02-23 ra_world
manufacturing sector targeted in new ra_world campaign

Multiple manufacturing organizations across Japan report being targeted by ra_world ransomware in coordinated attacks.

The Record 2026-02-23 cicada3301
Law enforcement disrupts cicada3301 ransomware infrastructure

International law enforcement operation seizes servers and domains used by cicada3301 ransomware group.

Europol 2026-02-21 hunters_v2
hunters_v2 exploits zero-day vulnerability in PaperCut MF

Security researchers confirm hunters_v2 is actively exploiting a critical vulnerability in Progress WS_FTP to deploy ransomware.

Dark Reading 2026-02-20T14:00:00+00:00
Latin America's Cyber Maturity Lags Threat Landscape

The slower pace of upgrades has the unintended impact of creating a haven for attackers, especially for initial access brokers and ransomware gangs.

Microsoft Security 2026-02-15 wastedlocker
Law enforcement disrupts wastedlocker ransomware infrastructure

International law enforcement operation seizes servers and domains used by wastedlocker ransomware group.

Krebs on Security 2026-02-14 hammer
hammer ransomware group claims attack on Samsung Electronics in Canada

The hammer ransomware gang has claimed responsibility for an attack on Samsung Electronics, a major technology organization in Canada. The group threatens to publish stolen data.

Europol 2026-02-11 daransom
healthcare sector targeted in new daransom campaign

Multiple healthcare organizations across Australia report being targeted by daransom ransomware in coordinated attacks.

Ars Technica 2026-02-08 typhon
typhon ransomware group claims attack on Acme Corp in Netherlands

The typhon ransomware gang has claimed responsibility for an attack on Acme Corp, a major telecommunications organization in Netherlands. The group threatens to publish stolen data.

Kaspersky GReAT 2026-02-05 arcusmedia
arcusmedia ransomware group claims attack on Southwest Airlines in Brazil

The arcusmedia ransomware gang has claimed responsibility for an attack on Southwest Airlines, a major retail organization in Brazil. The group threatens to publish stolen data.

TechCrunch 2026-02-04 castorbreach
Major retail company Southwest Airlines hit by ransomware attack

Southwest Airlines confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Krebs on Security 2026-02-02T16:15:16+00:00
Please Don’t Feed the Scattered Lapsus ShinyHunters

A prolific data ransom gang that calls itself Scattered Lapsus ShinyHunters (SLSH) has a distinctive playbook when it seeks to extort payment from victim firms: Harassing, threatening and even swattin...

Microsoft Security 2026-01-30 thanatos
technology sector targeted in new thanatos campaign

Multiple technology organizations across Germany report being targeted by thanatos ransomware in coordinated attacks.

FBI Flash 2026-01-30 thanatos
thanatos exploits zero-day vulnerability in Cisco ASA

Security researchers confirm thanatos is actively exploiting a critical vulnerability in SonicWall SMA to deploy ransomware.

ESET Research 2026-01-30 kappa
kappa exploits zero-day vulnerability in Cisco ASA

Security researchers confirm kappa is actively exploiting a critical vulnerability in Cisco ASA to deploy ransomware.

BBC News 2026-01-27 castorbreach
castorbreach exploits zero-day vulnerability in Atlassian Confluence

Security researchers confirm castorbreach is actively exploiting a critical vulnerability in Progress WS_FTP to deploy ransomware.

CyberScoop 2026-01-26 siren
siren ransomware: New variant uses safe mode encryption to evade detection

Researchers at BleepingComputer have identified a new siren variant that employs living-off-the-land binaries to bypass security controls.

Unit 42 2026-01-25 tsunami
telecommunications sector targeted in new tsunami campaign

Multiple telecommunications organizations across Netherlands report being targeted by tsunami ransomware in coordinated attacks.

Unit 42 2026-01-22 daransom
transportation sector targeted in new daransom campaign

Multiple transportation organizations across Canada report being targeted by daransom ransomware in coordinated attacks.

Dark Reading 2026-01-19 thorstrike
Ransomware attacks surge 60% in Q1 2024

New report shows ransomware attacks increased 60% compared to the previous quarter. thorstrike remains the most active group.

The Record 2026-01-17 titanium
Nestle SA pays $10M ransom to titanium

Nestle SA reportedly paid $1.5 million to titanium ransomware operators. The attack affected operations for 9 days.

Kaspersky GReAT 2026-01-14 noctis
Major technology company Samsung Electronics hit by ransomware attack

Samsung Electronics confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

ESET Research 2026-01-12 cicada3301
cicada3301 ransomware: New variant uses API unhooking to evade detection

Researchers at Dark Reading have identified a new cicada3301 variant that employs double encryption to bypass security controls.

Kaspersky GReAT 2026-01-10 lichdark
lichdark exploits zero-day vulnerability in Cisco ASA

Security researchers confirm lichdark is actively exploiting a critical vulnerability in MOVEit Transfer to deploy ransomware.

Trend Micro Research 2026-01-08 arcusmedia
Major telecommunications company BMW AG hit by ransomware attack

BMW AG confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

BleepingComputer 2026-01-06 castorbreach
Major healthcare company Metro Systems hit by ransomware attack

Metro Systems confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

ESET Research 2026-01-03 monti
monti ransomware: New variant uses double encryption to evade detection

Researchers at BleepingComputer have identified a new monti variant that employs DLL sideloading to bypass security controls.

Mandiant Blog 2026-01-02 unsafe
unsafe ransomware group claims attack on Nestle SA in Canada

The unsafe ransomware gang has claimed responsibility for an attack on Nestle SA, a major retail organization in Canada. The group threatens to publish stolen data.

Europol 2026-01-02 cicada3301
Ransomware attacks surge 15% in Q2 2024

New report shows ransomware attacks increased 45% compared to the previous quarter. cicada3301 remains the most active group.

Dark Reading 2025-12-31 electra
Ransomware attacks surge 60% in Q2 2026

New report shows ransomware attacks increased 45% compared to the previous quarter. electra remains the most active group.

CrowdStrike Blog 2025-12-29 castorbreach
retail sector targeted in new castorbreach campaign

Multiple retail organizations across United Kingdom report being targeted by castorbreach ransomware in coordinated attacks.

BBC News 2025-12-28 fog_v2
fog_v2 leaks 1000GB of data from Toyota Motor

The fog_v2 ransomware group has published 500GB of stolen data from Toyota Motor after ransom negotiations failed.

Ars Technica 2025-12-22 paradoxgroup
Metro Systems pays $3.5M ransom to paradoxgroup

Metro Systems reportedly paid $10 million to paradoxgroup ransomware operators. The attack affected operations for 7 days.

CISA Alert 2025-12-21 sexi
sexi ransomware group claims attack on European Logistics in Brazil

The sexi ransomware gang has claimed responsibility for an attack on European Logistics, a major financial organization in Brazil. The group threatens to publish stolen data.

Reuters 2025-12-21 sect
transportation sector targeted in new sect campaign

Multiple transportation organizations across Germany report being targeted by sect ransomware in coordinated attacks.

Kaspersky GReAT 2025-12-18 sexi
Law enforcement disrupts sexi ransomware infrastructure

International law enforcement operation seizes servers and domains used by sexi ransomware group.

The Record 2025-12-07 embargo_rust
Major telecommunications company British Steel hit by ransomware attack

British Steel confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

CyberScoop 2025-12-02 scriptleak
scriptleak ransomware: New variant uses fileless execution to evade detection

Researchers at Dark Reading have identified a new scriptleak variant that employs process hollowing to bypass security controls.

The Record 2025-12-01 siren
Deutsche Bank AG pays $1.5M ransom to siren

Deutsche Bank AG reportedly paid $15 million to siren ransomware operators. The attack affected operations for 21 days.

Unit 42 2025-11-30 rhysida_v2
Major education company American Water hit by ransomware attack

American Water confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

BleepingComputer 2025-11-28 everest
everest ransomware group claims attack on Roche Holding in Germany

The everest ransomware gang has claimed responsibility for an attack on Roche Holding, a major financial organization in Germany. The group threatens to publish stolen data.

SecurityWeek 2025-11-23 ransomhouse
ransomhouse leaks 1000GB of data from Deutsche Bank AG

The ransomhouse ransomware group has published 500GB of stolen data from Deutsche Bank AG after ransom negotiations failed.

Reuters 2025-11-22 electra
government sector targeted in new electra campaign

Multiple government organizations across Canada report being targeted by electra ransomware in coordinated attacks.

ESET Research 2025-11-17 hornetlock
Law enforcement disrupts hornetlock ransomware infrastructure

International law enforcement operation seizes servers and domains used by hornetlock ransomware group.

Kaspersky GReAT 2025-11-14 hunters_v2
hunters_v2 leaks 200GB of data from European Logistics

The hunters_v2 ransomware group has published 200GB of stolen data from European Logistics after ransom negotiations failed.

Mandiant Blog 2025-11-13 inc_lynx
CISA warns of active exploitation by inc_lynx ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the inc_lynx ransomware group.

The Record 2025-11-13 donut_leaks
Nordic Telecom pays $10M ransom to donut_leaks

Nordic Telecom reportedly paid $10 million to donut_leaks ransomware operators. The attack affected operations for 11 days.

BBC News 2025-11-06 blackhunt
Major education company BMW AG hit by ransomware attack

BMW AG confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Trend Micro Research 2025-11-01 daransom
Law enforcement disrupts daransom ransomware infrastructure

International law enforcement operation seizes servers and domains used by daransom ransomware group.

Kaspersky GReAT 2025-10-29 ransomhouse
Major financial company Central Hospital Network hit by ransomware attack

Central Hospital Network confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Mandiant Blog 2025-10-29 scriptleak
Ransomware attacks surge 15% in Q4 2025

New report shows ransomware attacks increased 45% compared to the previous quarter. scriptleak remains the most active group.

Krebs on Security 2025-10-27 8base
Law enforcement disrupts 8base ransomware infrastructure

International law enforcement operation seizes servers and domains used by 8base ransomware group.

Ars Technica 2025-10-24 scriptleak
Law enforcement disrupts scriptleak ransomware infrastructure

International law enforcement operation seizes servers and domains used by scriptleak ransomware group.

Trend Micro Research 2025-10-18 hunters_v2
CISA warns of active exploitation by hunters_v2 ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the hunters_v2 ransomware group.

SecurityWeek 2025-10-17 rhysida_apt
Siemens AG pays $5M ransom to rhysida_apt

Siemens AG reportedly paid $2 million to rhysida_apt ransomware operators. The attack affected operations for 8 days.

Reuters 2025-10-16 titanium
Law enforcement disrupts titanium ransomware infrastructure

International law enforcement operation seizes servers and domains used by titanium ransomware group.

CrowdStrike Blog 2025-10-15 ra_world
ra_world leaks 1000GB of data from Nordic Telecom

The ra_world ransomware group has published 500GB of stolen data from Nordic Telecom after ransom negotiations failed.

TechCrunch 2025-10-15 hurricanegroup
Major energy company Atlantic Financial Group hit by ransomware attack

Atlantic Financial Group confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

BleepingComputer 2025-10-12 castorbreach
Major education company Samsung Electronics hit by ransomware attack

Samsung Electronics confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

FBI Flash 2025-10-10 jupiterlock
Law enforcement disrupts jupiterlock ransomware infrastructure

International law enforcement operation seizes servers and domains used by jupiterlock ransomware group.

TechCrunch 2025-10-09 hammer
government sector targeted in new hammer campaign

Multiple government organizations across Germany report being targeted by hammer ransomware in coordinated attacks.

Sophos News 2025-09-30 everest
CISA warns of active exploitation by everest ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the everest ransomware group.

FBI Flash 2025-09-29 siren
CISA warns of active exploitation by siren ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the siren ransomware group.

CISA Alert 2025-09-28 hex
Ransomware attacks surge 60% in Q4 2025

New report shows ransomware attacks increased 25% compared to the previous quarter. hex remains the most active group.

CyberScoop 2025-09-25 rhysida_apt
rhysida_apt exploits zero-day vulnerability in Fortinet FortiGate

Security researchers confirm rhysida_apt is actively exploiting a critical vulnerability in Ivanti Connect Secure to deploy ransomware.

CISA Alert 2025-09-24 blackhunt
blackhunt leaks 200GB of data from BMW AG

The blackhunt ransomware group has published 500GB of stolen data from BMW AG after ransom negotiations failed.

Dark Reading 2025-09-23 rhysida_apt
rhysida_apt exploits zero-day vulnerability in Cisco ASA

Security researchers confirm rhysida_apt is actively exploiting a critical vulnerability in Cisco ASA to deploy ransomware.

Krebs on Security 2025-09-21 electra
Law enforcement disrupts electra ransomware infrastructure

International law enforcement operation seizes servers and domains used by electra ransomware group.

Microsoft Security 2025-09-18 jupiterlock
CISA warns of active exploitation by jupiterlock ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the jupiterlock ransomware group.

CISA Alert 2025-09-18 typhon
typhon ransomware group claims attack on National Health Services in Brazil

The typhon ransomware gang has claimed responsibility for an attack on National Health Services, a major retail organization in Brazil. The group threatens to publish stolen data.

Ars Technica 2025-09-12 typhon
retail sector targeted in new typhon campaign

Multiple retail organizations across Australia report being targeted by typhon ransomware in coordinated attacks.

Trend Micro Research 2025-09-05 tsunami
Global Industries pays $3.5M ransom to tsunami

Global Industries reportedly paid $15 million to tsunami ransomware operators. The attack affected operations for 6 days.

Microsoft Security 2025-09-03 sexi
sexi leaks 2000GB of data from BMW AG

The sexi ransomware group has published 1000GB of stolen data from BMW AG after ransom negotiations failed.

Trend Micro Research 2025-09-01 inc_lynx
inc_lynx leaks 500GB of data from Siemens AG

The inc_lynx ransomware group has published 500GB of stolen data from Siemens AG after ransom negotiations failed.

Reuters 2025-08-31 arcusmedia
arcusmedia exploits zero-day vulnerability in Citrix NetScaler

Security researchers confirm arcusmedia is actively exploiting a critical vulnerability in SonicWall SMA to deploy ransomware.

Dark Reading 2025-08-27 vanir
Ransomware attacks surge 60% in Q4 2026

New report shows ransomware attacks increased 35% compared to the previous quarter. vanir remains the most active group.

Krebs on Security 2025-08-17 rhysida_v2
Deutsche Bank AG pays $2M ransom to rhysida_v2

Deutsche Bank AG reportedly paid $10 million to rhysida_v2 ransomware operators. The attack affected operations for 10 days.

Reuters 2025-08-14 daransom
Roche Holding pays $15M ransom to daransom

Roche Holding reportedly paid $3.5 million to daransom ransomware operators. The attack affected operations for 10 days.

Mandiant Blog 2025-08-13 scriptleak
financial sector targeted in new scriptleak campaign

Multiple financial organizations across Japan report being targeted by scriptleak ransomware in coordinated attacks.

CyberScoop 2025-08-13 storm0501
Ransomware attacks surge 25% in Q1 2026

New report shows ransomware attacks increased 25% compared to the previous quarter. storm0501 remains the most active group.

Unit 42 2025-08-09 trinity
CISA warns of active exploitation by trinity ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the trinity ransomware group.

Unit 42 2025-08-08 8base
8base leaks 100GB of data from Continental Energy

The 8base ransomware group has published 500GB of stolen data from Continental Energy after ransom negotiations failed.

Dark Reading 2025-08-08 metaencryptor
Central Hospital Network pays $8M ransom to metaencryptor

Central Hospital Network reportedly paid $10 million to metaencryptor ransomware operators. The attack affected operations for 3 days.

Europol 2025-08-07 arcusmedia
Major transportation company Global Industries hit by ransomware attack

Global Industries confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

CrowdStrike Blog 2025-08-05 jupiterlock
jupiterlock ransomware: New variant uses double encryption to evade detection

Researchers at The Hacker News have identified a new jupiterlock variant that employs fileless execution to bypass security controls.

ESET Research 2025-08-04 8base
8base exploits zero-day vulnerability in Microsoft Exchange

Security researchers confirm 8base is actively exploiting a critical vulnerability in Citrix NetScaler to deploy ransomware.

The Record 2025-08-02 storm0501
Samsung Electronics pays $5M ransom to storm0501

Samsung Electronics reportedly paid $2 million to storm0501 ransomware operators. The attack affected operations for 28 days.

Krebs on Security 2025-08-01 8base
Major technology company Atlantic Financial Group hit by ransomware attack

Atlantic Financial Group confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Europol 2025-07-31 hex
hex ransomware: New variant uses API unhooking to evade detection

Researchers at BBC News have identified a new hex variant that employs double encryption to bypass security controls.

Europol 2025-07-28 noctis
Major manufacturing company European Logistics hit by ransomware attack

European Logistics confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Mandiant Blog 2025-07-27 scriptleak
Major financial company National Health Services hit by ransomware attack

National Health Services confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

FBI Flash 2025-07-25 sect
CISA warns of active exploitation by sect ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the sect ransomware group.

Unit 42 2025-07-23 rhysida_v2
technology sector targeted in new rhysida_v2 campaign

Multiple technology organizations across Japan report being targeted by rhysida_v2 ransomware in coordinated attacks.

SecurityWeek 2025-07-21 rhysida_v2
Ransomware attacks surge 60% in Q3 2026

New report shows ransomware attacks increased 15% compared to the previous quarter. rhysida_v2 remains the most active group.

Unit 42 2025-07-18 scriptleak
scriptleak exploits zero-day vulnerability in Barracuda ESG

Security researchers confirm scriptleak is actively exploiting a critical vulnerability in MOVEit Transfer to deploy ransomware.

BleepingComputer 2025-07-16 piranhared
CISA warns of active exploitation by piranhared ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the piranhared ransomware group.

Kaspersky GReAT 2025-07-14 typhon
typhon ransomware: New variant uses process hollowing to evade detection

Researchers at Europol have identified a new typhon variant that employs DLL sideloading to bypass security controls.

Trend Micro Research 2025-07-09 daransom
Major manufacturing company Acme Corp hit by ransomware attack

Acme Corp confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

TechCrunch 2025-07-09 hex
hex exploits zero-day vulnerability in Ivanti Connect Secure

Security researchers confirm hex is actively exploiting a critical vulnerability in PaperCut MF to deploy ransomware.

Trend Micro Research 2025-07-06 hex
hex ransomware: New variant uses DLL sideloading to evade detection

Researchers at Reuters have identified a new hex variant that employs BYOVD attacks to bypass security controls.

BleepingComputer 2025-07-05 scriptleak
Ransomware attacks surge 60% in Q1 2026

New report shows ransomware attacks increased 45% compared to the previous quarter. scriptleak remains the most active group.

FBI Flash 2025-07-02 thanatos
Ransomware attacks surge 60% in Q1 2025

New report shows ransomware attacks increased 15% compared to the previous quarter. thanatos remains the most active group.

Trend Micro Research 2025-07-01 typhon
Major manufacturing company Global Industries hit by ransomware attack

Global Industries confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

CrowdStrike Blog 2025-06-26 everest
BMW AG pays $2M ransom to everest

BMW AG reportedly paid $8 million to everest ransomware operators. The attack affected operations for 28 days.

The Record 2025-06-24 unsafe
Major telecommunications company Johnson & Johnson hit by ransomware attack

Johnson & Johnson confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Unit 42 2025-06-19 hornetlock
manufacturing sector targeted in new hornetlock campaign

Multiple manufacturing organizations across Australia report being targeted by hornetlock ransomware in coordinated attacks.

Sophos News 2025-06-15 piranhared
piranhared ransomware: New variant uses living-off-the-land binaries to evade detection

Researchers at FBI Flash have identified a new piranhared variant that employs API unhooking to bypass security controls.

Ars Technica 2025-06-15 wastedlocker
Ransomware attacks surge 45% in Q4 2025

New report shows ransomware attacks increased 45% compared to the previous quarter. wastedlocker remains the most active group.

Trend Micro Research 2025-06-11 kappa
kappa exploits zero-day vulnerability in Ivanti Connect Secure

Security researchers confirm kappa is actively exploiting a critical vulnerability in Fortinet FortiGate to deploy ransomware.

Ars Technica 2025-06-06 arcusmedia
Ransomware attacks surge 60% in Q2 2025

New report shows ransomware attacks increased 15% compared to the previous quarter. arcusmedia remains the most active group.

Kaspersky GReAT 2025-06-05 daransom
daransom ransomware group claims attack on Southwest Airlines in Canada

The daransom ransomware gang has claimed responsibility for an attack on Southwest Airlines, a major energy organization in Canada. The group threatens to publish stolen data.

Ars Technica 2025-06-03 rhysida_v2
CISA warns of active exploitation by rhysida_v2 ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the rhysida_v2 ransomware group.

SecurityWeek 2025-06-01 tomb
tomb exploits zero-day vulnerability in VMware ESXi

Security researchers confirm tomb is actively exploiting a critical vulnerability in Atlassian Confluence to deploy ransomware.

ESET Research 2025-05-29 storm0501
storm0501 ransomware: New variant uses BYOVD attacks to evade detection

Researchers at Reuters have identified a new storm0501 variant that employs EDR evasion to bypass security controls.

Unit 42 2025-05-25 wastedlocker
Law enforcement disrupts wastedlocker ransomware infrastructure

International law enforcement operation seizes servers and domains used by wastedlocker ransomware group.

CISA Alert 2025-05-22 donut_leaks
Law enforcement disrupts donut_leaks ransomware infrastructure

International law enforcement operation seizes servers and domains used by donut_leaks ransomware group.

BBC News 2025-05-21 thorstrike
Major government company Vodafone Group hit by ransomware attack

Vodafone Group confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

CrowdStrike Blog 2025-05-18 wastedlocker
Major education company Samsung Electronics hit by ransomware attack

Samsung Electronics confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Trend Micro Research 2025-05-12 paradoxgroup
paradoxgroup ransomware group claims attack on European Logistics in Germany

The paradoxgroup ransomware gang has claimed responsibility for an attack on European Logistics, a major government organization in Germany. The group threatens to publish stolen data.

Dark Reading 2025-05-01 thorstrike
Law enforcement disrupts thorstrike ransomware infrastructure

International law enforcement operation seizes servers and domains used by thorstrike ransomware group.

CyberScoop 2025-04-28 hex
Major retail company Nestle SA hit by ransomware attack

Nestle SA confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

CISA Alert 2025-04-27 unsafe
Major technology company Metro Systems hit by ransomware attack

Metro Systems confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

BleepingComputer 2025-04-23 xollam
Law enforcement disrupts xollam ransomware infrastructure

International law enforcement operation seizes servers and domains used by xollam ransomware group.

CrowdStrike Blog 2025-04-23 wastedlocker
wastedlocker exploits zero-day vulnerability in Ivanti Connect Secure

Security researchers confirm wastedlocker is actively exploiting a critical vulnerability in VMware ESXi to deploy ransomware.

Microsoft Security 2025-04-22 thorstrike
Major healthcare company British Steel hit by ransomware attack

British Steel confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Trend Micro Research 2025-04-22 daransom
daransom ransomware group claims attack on Samsung Electronics in France

The daransom ransomware gang has claimed responsibility for an attack on Samsung Electronics, a major healthcare organization in France. The group threatens to publish stolen data.

BleepingComputer 2025-04-21 daransom
Deutsche Bank AG pays $10M ransom to daransom

Deutsche Bank AG reportedly paid $5 million to daransom ransomware operators. The attack affected operations for 5 days.

Mandiant Blog 2025-04-15 hex
Ransomware attacks surge 45% in Q3 2026

New report shows ransomware attacks increased 60% compared to the previous quarter. hex remains the most active group.

Microsoft Security 2025-04-14 famine
famine ransomware group claims attack on Nestle SA in France

The famine ransomware gang has claimed responsibility for an attack on Nestle SA, a major education organization in France. The group threatens to publish stolen data.

CISA Alert 2025-04-14 paradoxgroup
paradoxgroup leaks 100GB of data from BMW AG

The paradoxgroup ransomware group has published 50GB of stolen data from BMW AG after ransom negotiations failed.

CrowdStrike Blog 2025-04-04 hurricanegroup
Nestle SA pays $22M ransom to hurricanegroup

Nestle SA reportedly paid $15 million to hurricanegroup ransomware operators. The attack affected operations for 28 days.

Unit 42 2025-03-28 inc_lynx
Major financial company Central Hospital Network hit by ransomware attack

Central Hospital Network confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

TechCrunch 2025-03-27 sect
Major financial company Roche Holding hit by ransomware attack

Roche Holding confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

SecurityWeek 2025-03-22 monti
monti ransomware: New variant uses safe mode encryption to evade detection

Researchers at FBI Flash have identified a new monti variant that employs process hollowing to bypass security controls.

CISA Alert 2025-03-22 noctis
retail sector targeted in new noctis campaign

Multiple retail organizations across France report being targeted by noctis ransomware in coordinated attacks.

Kaspersky GReAT 2025-03-20 paradoxgroup
CISA warns of active exploitation by paradoxgroup ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the paradoxgroup ransomware group.

BleepingComputer 2025-03-19 noctis
retail sector targeted in new noctis campaign

Multiple retail organizations across Germany report being targeted by noctis ransomware in coordinated attacks.

Sophos News 2025-03-19 hornetlock
hornetlock ransomware: New variant uses fileless execution to evade detection

Researchers at Sophos News have identified a new hornetlock variant that employs intermittent encryption to bypass security controls.

Sophos News 2025-03-19 xollam
Ransomware attacks surge 60% in Q1 2026

New report shows ransomware attacks increased 60% compared to the previous quarter. xollam remains the most active group.

FBI Flash 2025-03-18 thanatos
Law enforcement disrupts thanatos ransomware infrastructure

International law enforcement operation seizes servers and domains used by thanatos ransomware group.

Krebs on Security 2025-03-12 funklocker
Nordic Telecom pays $5M ransom to funklocker

Nordic Telecom reportedly paid $1.5 million to funklocker ransomware operators. The attack affected operations for 15 days.

BBC News 2025-03-11 trinity
trinity ransomware: New variant uses EDR evasion to evade detection

Researchers at The Hacker News have identified a new trinity variant that employs BYOVD attacks to bypass security controls.

Europol 2025-03-11 8base
8base ransomware group claims attack on European Logistics in United Kingdom

The 8base ransomware gang has claimed responsibility for an attack on European Logistics, a major healthcare organization in United Kingdom. The group threatens to publish stolen data.

SecurityWeek 2025-03-10 rhysida_apt
transportation sector targeted in new rhysida_apt campaign

Multiple transportation organizations across Netherlands report being targeted by rhysida_apt ransomware in coordinated attacks.

Krebs on Security 2025-03-10 unsafe
unsafe exploits zero-day vulnerability in Barracuda ESG

Security researchers confirm unsafe is actively exploiting a critical vulnerability in VMware ESXi to deploy ransomware.

TechCrunch 2025-03-05 kappa
kappa ransomware group claims attack on Toyota Motor in Netherlands

The kappa ransomware gang has claimed responsibility for an attack on Toyota Motor, a major government organization in Netherlands. The group threatens to publish stolen data.

FBI Flash 2025-03-05 lichdark
Major technology company Shell PLC hit by ransomware attack

Shell PLC confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Mandiant Blog 2025-03-03 embargo_rust
Ransomware attacks surge 35% in Q4 2025

New report shows ransomware attacks increased 60% compared to the previous quarter. embargo_rust remains the most active group.

SecurityWeek 2025-03-03 lambdateam
Law enforcement disrupts lambdateam ransomware infrastructure

International law enforcement operation seizes servers and domains used by lambdateam ransomware group.

Unit 42 2025-03-02 embargo_rust
manufacturing sector targeted in new embargo_rust campaign

Multiple manufacturing organizations across United Kingdom report being targeted by embargo_rust ransomware in coordinated attacks.

Kaspersky GReAT 2025-03-01 castorbreach
Ransomware attacks surge 25% in Q2 2024

New report shows ransomware attacks increased 25% compared to the previous quarter. castorbreach remains the most active group.

Microsoft Security 2025-02-25 8base
8base exploits zero-day vulnerability in VMware ESXi

Security researchers confirm 8base is actively exploiting a critical vulnerability in Citrix NetScaler to deploy ransomware.

Ars Technica 2025-02-22 monti
Ransomware attacks surge 35% in Q2 2025

New report shows ransomware attacks increased 60% compared to the previous quarter. monti remains the most active group.

CyberScoop 2025-02-22 funklocker
Law enforcement disrupts funklocker ransomware infrastructure

International law enforcement operation seizes servers and domains used by funklocker ransomware group.

CyberScoop 2025-02-21 thorstrike
Ransomware attacks surge 60% in Q2 2026

New report shows ransomware attacks increased 35% compared to the previous quarter. thorstrike remains the most active group.

The Record 2025-02-20 sexi
Pacific Manufacturing pays $1.5M ransom to sexi

Pacific Manufacturing reportedly paid $15 million to sexi ransomware operators. The attack affected operations for 17 days.

Reuters 2025-02-15 kappa
energy sector targeted in new kappa campaign

Multiple energy organizations across Germany report being targeted by kappa ransomware in coordinated attacks.

Kaspersky GReAT 2025-02-13 blackhunt
CISA warns of active exploitation by blackhunt ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the blackhunt ransomware group.

Krebs on Security 2025-02-12 monti
monti ransomware group claims attack on European Logistics in United States

The monti ransomware gang has claimed responsibility for an attack on European Logistics, a major government organization in United States. The group threatens to publish stolen data.

Microsoft Security 2025-02-10 trinity
Deutsche Bank AG pays $5M ransom to trinity

Deutsche Bank AG reportedly paid $3.5 million to trinity ransomware operators. The attack affected operations for 17 days.

Mandiant Blog 2025-02-06 hunters_v2
Siemens AG pays $5M ransom to hunters_v2

Siemens AG reportedly paid $3.5 million to hunters_v2 ransomware operators. The attack affected operations for 15 days.

Reuters 2025-02-01 ra_world
ra_world exploits zero-day vulnerability in SonicWall SMA

Security researchers confirm ra_world is actively exploiting a critical vulnerability in VMware ESXi to deploy ransomware.

Europol 2025-02-01 siren
siren leaks 2000GB of data from Siemens AG

The siren ransomware group has published 1000GB of stolen data from Siemens AG after ransom negotiations failed.

Microsoft Security 2025-01-31 hex
Major technology company BASF SE hit by ransomware attack

BASF SE confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Reuters 2025-01-22 storm0501
storm0501 ransomware group claims attack on Nordic Telecom in Japan

The storm0501 ransomware gang has claimed responsibility for an attack on Nordic Telecom, a major government organization in Japan. The group threatens to publish stolen data.

FBI Flash 2025-01-18 storm0501
storm0501 exploits zero-day vulnerability in MOVEit Transfer

Security researchers confirm storm0501 is actively exploiting a critical vulnerability in Progress WS_FTP to deploy ransomware.

Mandiant Blog 2025-01-17 hex
hex leaks 500GB of data from Central Hospital Network

The hex ransomware group has published 1000GB of stolen data from Central Hospital Network after ransom negotiations failed.

CrowdStrike Blog 2025-01-15 hammer
Ransomware attacks surge 60% in Q3 2026

New report shows ransomware attacks increased 45% compared to the previous quarter. hammer remains the most active group.

SecurityWeek 2025-01-10 monti
CISA warns of active exploitation by monti ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the monti ransomware group.

Mandiant Blog 2025-01-06 storm0501
CISA warns of active exploitation by storm0501 ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the storm0501 ransomware group.

Sophos News 2025-01-04 sect
Ransomware attacks surge 45% in Q2 2026

New report shows ransomware attacks increased 25% compared to the previous quarter. sect remains the most active group.

Krebs on Security 2025-01-03 hammer
hammer exploits zero-day vulnerability in MOVEit Transfer

Security researchers confirm hammer is actively exploiting a critical vulnerability in Ivanti Connect Secure to deploy ransomware.

BBC News 2024-12-30 famine
famine exploits zero-day vulnerability in MOVEit Transfer

Security researchers confirm famine is actively exploiting a critical vulnerability in Barracuda ESG to deploy ransomware.

CyberScoop 2024-12-23 donut_leaks
CISA warns of active exploitation by donut_leaks ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the donut_leaks ransomware group.

Trend Micro Research 2024-12-21 metaencryptor
education sector targeted in new metaencryptor campaign

Multiple education organizations across Australia report being targeted by metaencryptor ransomware in coordinated attacks.

Sophos News 2024-12-19 hurricanegroup
hurricanegroup exploits zero-day vulnerability in Citrix NetScaler

Security researchers confirm hurricanegroup is actively exploiting a critical vulnerability in Atlassian Confluence to deploy ransomware.

Ars Technica 2024-12-13 everest
Major retail company Nordic Telecom hit by ransomware attack

Nordic Telecom confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

The Hacker News 2024-12-08 fog_v2
fog_v2 ransomware: New variant uses living-off-the-land binaries to evade detection

Researchers at FBI Flash have identified a new fog_v2 variant that employs safe mode encryption to bypass security controls.

The Hacker News 2024-12-08 arcusmedia
arcusmedia exploits zero-day vulnerability in PaperCut MF

Security researchers confirm arcusmedia is actively exploiting a critical vulnerability in VMware ESXi to deploy ransomware.

The Record 2024-12-07 storm0501
storm0501 leaks 100GB of data from BASF SE

The storm0501 ransomware group has published 100GB of stolen data from BASF SE after ransom negotiations failed.

CyberScoop 2024-12-05 hammer
hammer ransomware group claims attack on BASF SE in Netherlands

The hammer ransomware gang has claimed responsibility for an attack on BASF SE, a major telecommunications organization in Netherlands. The group threatens to publish stolen data.

Krebs on Security 2024-12-03 ra_world
CISA warns of active exploitation by ra_world ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the ra_world ransomware group.

CrowdStrike Blog 2024-12-03 castorbreach
government sector targeted in new castorbreach campaign

Multiple government organizations across France report being targeted by castorbreach ransomware in coordinated attacks.

Trend Micro Research 2024-11-29 cicada3301
cicada3301 exploits zero-day vulnerability in Citrix NetScaler

Security researchers confirm cicada3301 is actively exploiting a critical vulnerability in Atlassian Confluence to deploy ransomware.

Krebs on Security 2024-11-28 famine
Johnson & Johnson pays $15M ransom to famine

Johnson & Johnson reportedly paid $3.5 million to famine ransomware operators. The attack affected operations for 9 days.

Kaspersky GReAT 2024-11-27 ransomhouse
ransomhouse leaks 100GB of data from Siemens AG

The ransomhouse ransomware group has published 50GB of stolen data from Siemens AG after ransom negotiations failed.

TechCrunch 2024-11-22 daransom
Major technology company Metro Systems hit by ransomware attack

Metro Systems confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

BleepingComputer 2024-11-21 funklocker
funklocker exploits zero-day vulnerability in Microsoft Exchange

Security researchers confirm funklocker is actively exploiting a critical vulnerability in MOVEit Transfer to deploy ransomware.

TechCrunch 2024-11-19 thanatos
thanatos leaks 2000GB of data from Pacific Manufacturing

The thanatos ransomware group has published 50GB of stolen data from Pacific Manufacturing after ransom negotiations failed.

BleepingComputer 2024-11-16 donut_leaks
CISA warns of active exploitation by donut_leaks ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the donut_leaks ransomware group.

Krebs on Security 2024-11-06 thorstrike
Ransomware attacks surge 35% in Q4 2025

New report shows ransomware attacks increased 15% compared to the previous quarter. thorstrike remains the most active group.

CrowdStrike Blog 2024-11-05 lambdateam
lambdateam exploits zero-day vulnerability in Fortinet FortiGate

Security researchers confirm lambdateam is actively exploiting a critical vulnerability in Barracuda ESG to deploy ransomware.

Europol 2024-10-28 fog_v2
Major financial company BASF SE hit by ransomware attack

BASF SE confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

CyberScoop 2024-10-24 paradoxgroup
Major energy company British Steel hit by ransomware attack

British Steel confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

BBC News 2024-10-23 xollam
Ransomware attacks surge 60% in Q2 2024

New report shows ransomware attacks increased 25% compared to the previous quarter. xollam remains the most active group.

FBI Flash 2024-10-15 sect
sect ransomware: New variant uses living-off-the-land binaries to evade detection

Researchers at BleepingComputer have identified a new sect variant that employs process hollowing to bypass security controls.

CISA Alert 2024-10-14 sexi
CISA warns of active exploitation by sexi ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the sexi ransomware group.

FBI Flash 2024-10-13 lambdateam
government sector targeted in new lambdateam campaign

Multiple government organizations across Germany report being targeted by lambdateam ransomware in coordinated attacks.

TechCrunch 2024-10-07 rhysida_v2
CISA warns of active exploitation by rhysida_v2 ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the rhysida_v2 ransomware group.

FBI Flash 2024-09-30 hornetlock
hornetlock ransomware group claims attack on Deutsche Bank AG in Brazil

The hornetlock ransomware gang has claimed responsibility for an attack on Deutsche Bank AG, a major manufacturing organization in Brazil. The group threatens to publish stolen data.

CyberScoop 2024-09-30 piranhared
energy sector targeted in new piranhared campaign

Multiple energy organizations across Italy report being targeted by piranhared ransomware in coordinated attacks.

SecurityWeek 2024-09-27 8base
8base ransomware: New variant uses BYOVD attacks to evade detection

Researchers at Microsoft Security have identified a new 8base variant that employs EDR evasion to bypass security controls.

CrowdStrike Blog 2024-09-21 vanir
Ransomware attacks surge 35% in Q4 2025

New report shows ransomware attacks increased 45% compared to the previous quarter. vanir remains the most active group.

The Record 2024-09-20 atlasattack
CISA warns of active exploitation by atlasattack ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the atlasattack ransomware group.

BleepingComputer 2024-09-13 monti
BASF SE pays $8M ransom to monti

BASF SE reportedly paid $22 million to monti ransomware operators. The attack affected operations for 17 days.

Microsoft Security 2024-09-12 atlas
Vodafone Group pays $3.5M ransom to atlas

Vodafone Group reportedly paid $10 million to atlas ransomware operators. The attack affected operations for 17 days.

CrowdStrike Blog 2024-09-12 storm0501
telecommunications sector targeted in new storm0501 campaign

Multiple telecommunications organizations across Netherlands report being targeted by storm0501 ransomware in coordinated attacks.

Unit 42 2024-09-08 rhysida_v2
Central Hospital Network pays $3.5M ransom to rhysida_v2

Central Hospital Network reportedly paid $3.5 million to rhysida_v2 ransomware operators. The attack affected operations for 30 days.

Mandiant Blog 2024-09-07 sexi
sexi ransomware: New variant uses process hollowing to evade detection

Researchers at Unit 42 have identified a new sexi variant that employs double encryption to bypass security controls.

Mandiant Blog 2024-09-03 inc_lynx
energy sector targeted in new inc_lynx campaign

Multiple energy organizations across United Kingdom report being targeted by inc_lynx ransomware in coordinated attacks.

Unit 42 2024-08-28 hex
Siemens AG pays $22M ransom to hex

Siemens AG reportedly paid $22 million to hex ransomware operators. The attack affected operations for 6 days.

The Record 2024-08-26 lichdark
lichdark leaks 1000GB of data from Nestle SA

The lichdark ransomware group has published 50GB of stolen data from Nestle SA after ransom negotiations failed.

Kaspersky GReAT 2024-08-21 siren
Ransomware attacks surge 25% in Q1 2026

New report shows ransomware attacks increased 15% compared to the previous quarter. siren remains the most active group.

Microsoft Security 2024-08-21 funklocker
funklocker ransomware: New variant uses process hollowing to evade detection

Researchers at CyberScoop have identified a new funklocker variant that employs API unhooking to bypass security controls.

Kaspersky GReAT 2024-08-18 lichdark
American Water pays $1.5M ransom to lichdark

American Water reportedly paid $15 million to lichdark ransomware operators. The attack affected operations for 27 days.

TechCrunch 2024-08-08 lichdark
lichdark leaks 200GB of data from Deutsche Bank AG

The lichdark ransomware group has published 1000GB of stolen data from Deutsche Bank AG after ransom negotiations failed.

CrowdStrike Blog 2024-08-05 castorbreach
government sector targeted in new castorbreach campaign

Multiple government organizations across Australia report being targeted by castorbreach ransomware in coordinated attacks.

CrowdStrike Blog 2024-08-03 blackhunt
Toyota Motor pays $22M ransom to blackhunt

Toyota Motor reportedly paid $2 million to blackhunt ransomware operators. The attack affected operations for 27 days.

Reuters 2024-07-31 famine
manufacturing sector targeted in new famine campaign

Multiple manufacturing organizations across France report being targeted by famine ransomware in coordinated attacks.

CISA Alert 2024-07-28 thanatos
thanatos exploits zero-day vulnerability in MOVEit Transfer

Security researchers confirm thanatos is actively exploiting a critical vulnerability in Progress WS_FTP to deploy ransomware.

The Hacker News 2024-07-27 hex
Law enforcement disrupts hex ransomware infrastructure

International law enforcement operation seizes servers and domains used by hex ransomware group.

Reuters 2024-07-24 vanir
CISA warns of active exploitation by vanir ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the vanir ransomware group.

Kaspersky GReAT 2024-07-20 lichdark
Johnson & Johnson pays $2M ransom to lichdark

Johnson & Johnson reportedly paid $5 million to lichdark ransomware operators. The attack affected operations for 16 days.

Kaspersky GReAT 2024-07-18 castorbreach
castorbreach ransomware: New variant uses living-off-the-land binaries to evade detection

Researchers at FBI Flash have identified a new castorbreach variant that employs double encryption to bypass security controls.

Reuters 2024-07-13 atlasattack
Toyota Motor pays $5M ransom to atlasattack

Toyota Motor reportedly paid $2 million to atlasattack ransomware operators. The attack affected operations for 6 days.

BleepingComputer 2024-07-08 kappa
Law enforcement disrupts kappa ransomware infrastructure

International law enforcement operation seizes servers and domains used by kappa ransomware group.

Reuters 2024-07-04 8base
CISA warns of active exploitation by 8base ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the 8base ransomware group.

Dark Reading 2024-07-04 paradoxgroup
CISA warns of active exploitation by paradoxgroup ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the paradoxgroup ransomware group.

Dark Reading 2024-06-30 noctis
retail sector targeted in new noctis campaign

Multiple retail organizations across Brazil report being targeted by noctis ransomware in coordinated attacks.

FBI Flash 2024-06-29 hurricanegroup
hurricanegroup ransomware group claims attack on Pacific Manufacturing in United Kingdom

The hurricanegroup ransomware gang has claimed responsibility for an attack on Pacific Manufacturing, a major education organization in United Kingdom. The group threatens to publish stolen data.

BBC News 2024-06-24 cicada3301
CISA warns of active exploitation by cicada3301 ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the cicada3301 ransomware group.

Dark Reading 2024-06-23 wastedlocker
Law enforcement disrupts wastedlocker ransomware infrastructure

International law enforcement operation seizes servers and domains used by wastedlocker ransomware group.

CyberScoop 2024-06-22 jupiterlock
Major financial company Toyota Motor hit by ransomware attack

Toyota Motor confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Reuters 2024-06-20 hex
CISA warns of active exploitation by hex ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the hex ransomware group.

SecurityWeek 2024-06-17 funklocker
CISA warns of active exploitation by funklocker ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the funklocker ransomware group.

SecurityWeek 2024-06-16 trinity
trinity leaks 200GB of data from Roche Holding

The trinity ransomware group has published 1000GB of stolen data from Roche Holding after ransom negotiations failed.

CrowdStrike Blog 2024-06-15 fog_v2
government sector targeted in new fog_v2 campaign

Multiple government organizations across Australia report being targeted by fog_v2 ransomware in coordinated attacks.

Trend Micro Research 2024-06-14 famine
famine ransomware group claims attack on Toyota Motor in Canada

The famine ransomware gang has claimed responsibility for an attack on Toyota Motor, a major telecommunications organization in Canada. The group threatens to publish stolen data.

Microsoft Security 2024-06-14 rhysida_v2
Major education company National Health Services hit by ransomware attack

National Health Services confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Dark Reading 2024-06-12 lambdateam
Major retail company Global Industries hit by ransomware attack

Global Industries confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

CrowdStrike Blog 2024-06-11 funklocker
funklocker ransomware: New variant uses double encryption to evade detection

Researchers at Unit 42 have identified a new funklocker variant that employs double encryption to bypass security controls.

CISA Alert 2024-06-11 rhysida_v2
BMW AG pays $2M ransom to rhysida_v2

BMW AG reportedly paid $22 million to rhysida_v2 ransomware operators. The attack affected operations for 15 days.

Trend Micro Research 2024-06-04 blackhunt
Major telecommunications company European Logistics hit by ransomware attack

European Logistics confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Europol 2024-06-04 cicada3301
energy sector targeted in new cicada3301 campaign

Multiple energy organizations across Australia report being targeted by cicada3301 ransomware in coordinated attacks.

The Hacker News 2024-06-03 ra_world
CISA warns of active exploitation by ra_world ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the ra_world ransomware group.

The Record 2024-06-01 famine
famine ransomware group claims attack on Continental Energy in Japan

The famine ransomware gang has claimed responsibility for an attack on Continental Energy, a major manufacturing organization in Japan. The group threatens to publish stolen data.

Sophos News 2024-05-30 piranhared
Law enforcement disrupts piranhared ransomware infrastructure

International law enforcement operation seizes servers and domains used by piranhared ransomware group.

Europol 2024-05-29 hornetlock
Ransomware attacks surge 15% in Q1 2024

New report shows ransomware attacks increased 45% compared to the previous quarter. hornetlock remains the most active group.

BBC News 2024-05-29 jupiterlock
jupiterlock ransomware group claims attack on Atlantic Financial Group in France

The jupiterlock ransomware gang has claimed responsibility for an attack on Atlantic Financial Group, a major manufacturing organization in France. The group threatens to publish stolen data.

The Hacker News 2024-05-27 donut_leaks
CISA warns of active exploitation by donut_leaks ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the donut_leaks ransomware group.

ESET Research 2024-05-27 paradoxgroup
paradoxgroup exploits zero-day vulnerability in Atlassian Confluence

Security researchers confirm paradoxgroup is actively exploiting a critical vulnerability in Citrix NetScaler to deploy ransomware.

Krebs on Security 2024-05-25 electra
European Logistics pays $15M ransom to electra

European Logistics reportedly paid $2 million to electra ransomware operators. The attack affected operations for 21 days.

CrowdStrike Blog 2024-05-21 metaencryptor
Major government company Central Hospital Network hit by ransomware attack

Central Hospital Network confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

CISA Alert 2024-05-14 scriptleak
scriptleak ransomware: New variant uses EDR evasion to evade detection

Researchers at TechCrunch have identified a new scriptleak variant that employs safe mode encryption to bypass security controls.

Unit 42 2024-05-09 daransom
daransom exploits zero-day vulnerability in PaperCut MF

Security researchers confirm daransom is actively exploiting a critical vulnerability in Microsoft Exchange to deploy ransomware.

Unit 42 2024-05-05 vanir
Law enforcement disrupts vanir ransomware infrastructure

International law enforcement operation seizes servers and domains used by vanir ransomware group.

SecurityWeek 2024-05-05 kappa
Ransomware attacks surge 35% in Q4 2026

New report shows ransomware attacks increased 25% compared to the previous quarter. kappa remains the most active group.

Trend Micro Research 2024-05-02 sect
Ransomware attacks surge 60% in Q1 2026

New report shows ransomware attacks increased 60% compared to the previous quarter. sect remains the most active group.

Mandiant Blog 2024-04-30 8base
8base ransomware: New variant uses living-off-the-land binaries to evade detection

Researchers at BBC News have identified a new 8base variant that employs fileless execution to bypass security controls.

Microsoft Security 2024-04-28 siren
siren ransomware group claims attack on Acme Corp in Australia

The siren ransomware gang has claimed responsibility for an attack on Acme Corp, a major transportation organization in Australia. The group threatens to publish stolen data.

Microsoft Security 2024-04-26 jupiterlock
Ransomware attacks surge 60% in Q2 2025

New report shows ransomware attacks increased 15% compared to the previous quarter. jupiterlock remains the most active group.

Microsoft Security 2024-04-21 sect
sect exploits zero-day vulnerability in Ivanti Connect Secure

Security researchers confirm sect is actively exploiting a critical vulnerability in Microsoft Exchange to deploy ransomware.

CrowdStrike Blog 2024-04-18 piranhared
telecommunications sector targeted in new piranhared campaign

Multiple telecommunications organizations across United Kingdom report being targeted by piranhared ransomware in coordinated attacks.

Kaspersky GReAT 2024-04-18 sect
Major technology company Southwest Airlines hit by ransomware attack

Southwest Airlines confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

CyberScoop 2024-04-17 monti
Major telecommunications company Acme Corp hit by ransomware attack

Acme Corp confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Europol 2024-04-13 unsafe
unsafe leaks 2000GB of data from European Logistics

The unsafe ransomware group has published 100GB of stolen data from European Logistics after ransom negotiations failed.

BBC News 2024-04-08 electra
electra ransomware: New variant uses intermittent encryption to evade detection

Researchers at Dark Reading have identified a new electra variant that employs API unhooking to bypass security controls.

The Record 2024-03-28 storm0501
Major energy company Southwest Airlines hit by ransomware attack

Southwest Airlines confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Europol 2024-03-27 vanir
Major energy company Samsung Electronics hit by ransomware attack

Samsung Electronics confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Krebs on Security 2024-03-27 unsafe
Ransomware attacks surge 35% in Q3 2025

New report shows ransomware attacks increased 15% compared to the previous quarter. unsafe remains the most active group.

CyberScoop 2024-03-25 embargo_rust
embargo_rust leaks 500GB of data from Continental Energy

The embargo_rust ransomware group has published 500GB of stolen data from Continental Energy after ransom negotiations failed.

Trend Micro Research 2024-03-22 siren
Nordic Telecom pays $3.5M ransom to siren

Nordic Telecom reportedly paid $8 million to siren ransomware operators. The attack affected operations for 28 days.

The Hacker News 2024-03-19 rhysida_v2
CISA warns of active exploitation by rhysida_v2 ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the rhysida_v2 ransomware group.

CrowdStrike Blog 2024-03-16 lambdateam
lambdateam ransomware: New variant uses EDR evasion to evade detection

Researchers at Mandiant Blog have identified a new lambdateam variant that employs BYOVD attacks to bypass security controls.

Krebs on Security 2024-03-15 cicada3301
cicada3301 ransomware group claims attack on Johnson & Johnson in Australia

The cicada3301 ransomware gang has claimed responsibility for an attack on Johnson & Johnson, a major healthcare organization in Australia. The group threatens to publish stolen data.

Reuters 2024-03-13 ra_world
BMW AG pays $1.5M ransom to ra_world

BMW AG reportedly paid $3.5 million to ra_world ransomware operators. The attack affected operations for 6 days.

FBI Flash 2024-03-12 funklocker
financial sector targeted in new funklocker campaign

Multiple financial organizations across Japan report being targeted by funklocker ransomware in coordinated attacks.

Ars Technica 2024-03-11 typhon
typhon ransomware group claims attack on Continental Energy in United Kingdom

The typhon ransomware gang has claimed responsibility for an attack on Continental Energy, a major telecommunications organization in United Kingdom. The group threatens to publish stolen data.

Kaspersky GReAT 2024-03-10 ransomhouse
transportation sector targeted in new ransomhouse campaign

Multiple transportation organizations across France report being targeted by ransomhouse ransomware in coordinated attacks.

ESET Research 2024-03-08 rhysida_v2
American Water pays $1.5M ransom to rhysida_v2

American Water reportedly paid $10 million to rhysida_v2 ransomware operators. The attack affected operations for 3 days.

Unit 42 2024-03-04 lambdateam
Major telecommunications company Samsung Electronics hit by ransomware attack

Samsung Electronics confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Trend Micro Research 2024-03-04 atlasattack
Major financial company Acme Corp hit by ransomware attack

Acme Corp confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

Dark Reading 2024-02-28 ransomhouse
Ransomware attacks surge 25% in Q2 2024

New report shows ransomware attacks increased 60% compared to the previous quarter. ransomhouse remains the most active group.

CyberScoop 2024-02-27 storm0501
CISA warns of active exploitation by storm0501 ransomware

CISA has issued an advisory warning organizations about active exploitation campaigns by the storm0501 ransomware group.

BBC News 2024-02-25 blackhunt
Ransomware attacks surge 45% in Q1 2026

New report shows ransomware attacks increased 60% compared to the previous quarter. blackhunt remains the most active group.

Reuters 2024-02-22 rhysida_v2
rhysida_v2 leaks 500GB of data from Shell PLC

The rhysida_v2 ransomware group has published 2000GB of stolen data from Shell PLC after ransom negotiations failed.

FBI Flash 2024-02-17 typhon
Law enforcement disrupts typhon ransomware infrastructure

International law enforcement operation seizes servers and domains used by typhon ransomware group.

BBC News 2024-02-10 siren
siren ransomware group claims attack on National Health Services in Australia

The siren ransomware gang has claimed responsibility for an attack on National Health Services, a major government organization in Australia. The group threatens to publish stolen data.

SecurityWeek 2024-02-09 unsafe
unsafe leaks 200GB of data from Continental Energy

The unsafe ransomware group has published 500GB of stolen data from Continental Energy after ransom negotiations failed.

BBC News 2024-02-07 arcusmedia
Ransomware attacks surge 25% in Q4 2026

New report shows ransomware attacks increased 25% compared to the previous quarter. arcusmedia remains the most active group.

Kaspersky GReAT 2024-01-30 thorstrike
Law enforcement disrupts thorstrike ransomware infrastructure

International law enforcement operation seizes servers and domains used by thorstrike ransomware group.

Unit 42 2024-01-28 blackhunt
Major financial company Samsung Electronics hit by ransomware attack

Samsung Electronics confirms systems encrypted in sophisticated ransomware attack. Recovery operations underway.

BBC News 2024-01-27 cicada3301
cicada3301 leaks 50GB of data from Shell PLC

The cicada3301 ransomware group has published 500GB of stolen data from Shell PLC after ransom negotiations failed.

Microsoft Security 2024-01-17 rhysida_apt
rhysida_apt ransomware group claims attack on British Steel in Italy

The rhysida_apt ransomware gang has claimed responsibility for an attack on British Steel, a major retail organization in Italy. The group threatens to publish stolen data.

BleepingComputer 2024-01-14 ra_world
telecommunications sector targeted in new ra_world campaign

Multiple telecommunications organizations across France report being targeted by ra_world ransomware in coordinated attacks.

The Record 2024-01-13 xollam
xollam ransomware: New variant uses BYOVD attacks to evade detection

Researchers at BleepingComputer have identified a new xollam variant that employs EDR evasion to bypass security controls.

Dark Reading 2024-01-12 everest
Roche Holding pays $8M ransom to everest

Roche Holding reportedly paid $10 million to everest ransomware operators. The attack affected operations for 20 days.

SecurityWeek 2024-01-10 cicada3301
cicada3301 leaks 1000GB of data from European Logistics

The cicada3301 ransomware group has published 200GB of stolen data from European Logistics after ransom negotiations failed.

ESET Research 2024-01-01 atlasattack
government sector targeted in new atlasattack campaign

Multiple government organizations across Canada report being targeted by atlasattack ransomware in coordinated attacks.

Threatpost 2022-08-26T16:44:27+00:00
Ransomware Attacks are on the Rise

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.