search
ransomware
Trends
- 1Keio Group Hit by Ransomware Attack▼Keio Group Ransomware Attack Disrupts Retail Payments and Hotel Services Keio Corporation disclosed a ransomware attack
Keio Corporation, the Japanese railway and hospitality conglomerate, disclosed a ransomware attack that disrupted payment systems, loyalty programs, and hotel reservation services across several group companies. The company isolated the affected networks, notified police, and is investigating the incident. The attack highlights how cyber incidents on transport groups can cascade into retail and hospitality operations.
- 2Clop ransomware gang relocates servers after exploiting Grav CMS flaw▼Clop ransomware gang moves to new server after Grav CMS vulnerability exploited
The Clop ransomware gang has moved to new server infrastructure after exploiting a vulnerability in Grav CMS, the open-source flat-file content management system. The extortion group, known for large-scale data-theft campaigns against corporations and government agencies, is continuing operations despite the disruption. Security teams are being urged to patch Grav CMS installations and review whether their systems were targeted.
- 3Ransomware attack hits Keio Electric Railway payment systems●おお、あ、秋田よ 京王電鉄にランサム攻撃 決済に障害、鉄道影響なし https://www. 47news.jp/14997568.html # 神 # news # bot
Keio Electric Railway, a major private railway operator in Tokyo, has been hit by a ransomware attack that disrupted its payment and settlement systems. The company says train operations themselves were not affected, and services continue to run normally while it deals with the cyberattack. The incident adds to a string of ransomware attacks on Japanese organisations, drawing attention to the vulnerability of critical transport infrastructure.
- 4ShinyHunters Hacks Rival Gang Cl0p, Seizes Leak Site▼ShinyHunters Hacks Rival Ransomware Gang Cl0p and Takes Over its Dark Web Tor Data Leak Site
The hacking group ShinyHunters has compromised Cl0p, a rival ransomware gang, and taken control of its dark web Tor data leak site, according to a report by CPO Magazine. The takeover of one major cybercrime operation by another is drawing attention from security researchers tracking shifting alliances and infighting in the ransomware underworld.
- 5KillSec Ransomware Group Dismantled, Teenage Leader Arrested●International Operation Dismantles KillSec Ransomware Group, Arrests Teen Leader
An international law enforcement operation has dismantled the KillSec ransomware group and arrested its teenage alleged leader. The takedown is drawing attention to the growing role of very young cybercriminals in ransomware operations, and to cross-border police cooperation against hacking groups. Details about the arrests and the scale of the group's attacks have not been fully disclosed.
- 6
Police have arrested a 16-year-old suspected of leading the KillSec ransomware group, according to Help Net Security. The arrest of a minor at the head of a ransomware operation has drawn attention to how young hackers have become involved in organized cybercrime, and to the growing activity of the KillSec group itself.
- 7Storm ransomware group claims attack on US manufacturer▼🚨New ransom group blog posts!🚨 Group name: Storm Post title: Step By Step Sector: Unknown Info: https:// cti.fyi/groups/
A new ransomware group calling itself Storm has published a leak-site post claiming the extortion of Allied Machine & Engineering, a US manufacturing company. A post titled 'Step By Step' with an unknown victim was also listed. The alerts were flagged by cybersecurity threat-intelligence trackers monitoring ransom group blogs.
- 8KillSec Ransomware Group Dismantled, 16-Year-Old Leader Arrested●Global Operation Dismantles KillSec Ransomware Group, Arrests 16-Year-Old Leader
An international law enforcement operation has taken down the KillSec ransomware group, arresting its suspected leader, who is reportedly only 16 years old. The case has drawn attention both to the growing role of teenagers in cybercrime and to cross-border cooperation against ransomware networks that have targeted organisations worldwide.
- 9Warlock ransomware hits SharePoint in water and telecom attacks▼Warlock ransomware breach SharePoint in water, telecom operator attacks
The Warlock ransomware group has breached SharePoint servers in attacks targeting water sector organizations and telecom operators, according to reporting by BleepingComputer. The intrusions exploit Microsoft SharePoint infrastructure, a frequent target in recent campaign waves. Cybersecurity watchers are tracking the incidents closely, as attacks on water utilities and telecoms raise concerns about critical infrastructure resilience and data exposure.
- 10Qilin ransomware group claims attack on German chip firm Inova Semiconductors▼🚨New ransom group blog posts!🚨 Group name: qilin Post title: Inova Semiconductors GmbH Location: 🇩🇪 DE Sector: Manufactu
The Qilin ransomware group has added Inova Semiconductors, a German semiconductor manufacturer, to its leak site, claiming to have compromised the company. The claim was flagged alongside a separate posting by the RansomHouse group naming Indonesian mining company PT Indo Tambangraya Megah. Cybersecurity watchers track such listings as indicators of active attacks on industrial firms.
- 11Teen suspected of running KillSec ransomware group arrested●Teen suspected of running KillSec ransomware group as cops seize servers, arrest three Operation KillSwitch takes over l
Police have arrested three people, including a teenager suspected of running the KillSec ransomware group, in an operation dubbed KillSwitch. Servers were seized and the gang's leak site was taken over, reportedly holding at least 110 TB of stolen data. The takeover marks a major disruption of a group blamed for extensive ransomware attacks.
- 12Rhysida ransomware group claims attack on Sweden's Electro Heat▼🚨New ransom group blog posts!🚨 Group name: rhysida Post title: Electro Heat Sweden AB Location: 🇸🇪 SE Sector: Manufactur
The Rhysida ransomware group has listed Electro Heat Sweden AB, a Swedish manufacturing company, as a new victim on its leak blog. The claim was flagged by threat intelligence watchers tracking ransomware activity. Rhysida is a known ransomware operation that publishes victim names to pressure companies into paying. No details on stolen data or the company's response have been confirmed.
- 13RansomHouse claims cyberattack on Peruvian hospital▼🚨New ransom group blog post!🚨 Group name: ransomhouse Post title: Hospital Hermilio Valdizán Location: 🇵🇪 PE Sector: Hea
The ransomware group RansomHouse has listed Hospital Hermilio Valdizán in Peru as a new victim on its leak site, adding the healthcare facility to its portfolio of claimed attacks. If confirmed, patient data and hospital systems could be at risk. The claim is circulating among cybersecurity researchers tracking ransomware activity in Latin America's health sector.
- 14Ransomware Attack Disrupts City of Vicksburg Systems▼City of Vicksburg Ransomware Attack Disrupts Municipal Systems The City of Vicksburg, Mississippi, disclosed a ransomwar
The City of Vicksburg, Mississippi, disclosed a ransomware attack that forced a temporary shutdown of its municipal computer systems on October 1, 2026. City officials confirmed that critical services, including 911 dispatch, police, and fire departments, remained operational while other services were disrupted. The incident adds to a growing string of ransomware attacks targeting US local governments, prompting calls for stronger municipal cybersecurity defenses.
- 15Ransomware group Storm claims Gardeners' Guild and West County Health Centers attacks▼🚨New ransom group blog posts!🚨 Group name: Storm Post title: Gardeners' Guild Info: https:// cti.fyi/groups/Storm.html G
The ransomware group known as Storm has published new posts on its leak site naming the Gardeners' Guild and West County Health Centers as claimed victims. Cybersecurity analysts tracking the group flagged the updates, adding the two organisations to the growing list of companies and healthcare providers hit by ransomware extortion attempts.
- 16Scattered Spider's MGM hack retold with low-poly potatoes▼How Scattered Spider shut down Las Vegas with one phone call, retold with low-poly potatoes 🥔 LinkedIn recon → help-desk
Scattered Spider's 2023 attack on MGM Resorts is being retold in a quirky animated explainer, with low-poly potato characters. The story shows how a single phone call, LinkedIn research and help-desk impersonation led to a password and MFA reset, ransomware across 100+ MGM servers and the shutdown of Las Vegas operations. The campaign later hit Caesars, M&S, Salesforce clients and TfL, where two members were arrested.
- 17
An international police operation has reportedly dismantled the KillSec ransomware group, whose alleged leader is a 16-year-old. The operation targeted members of the cybercrime gang, which is associated with ransomware attacks and data extortion. Discussion is focused on the involvement of teenage hackers in major ransomware operations and what the arrests mean for the group's activity.
- 18Krybit ransomware group claims ten new victims worldwide●🩸 New ransomware victims claimed — 10 • www.raajratna.com — krybit • www.pierrefeu.fr — krybit • sai.org.in — krybit • w
A fresh batch of ransomware claims has been posted to dark-web leak sites, listing ten new alleged victims. The Krybit group accounts for most of the names, including Indian steel firm Raajratna, French domain pierrefeu.fr and an Indian school organisation, while the Storm and The Gentlemen crews each claim a victim, among them Australia's Mandurah State Emergency Service. Security researchers track these listings to monitor which groups are most active and which sectors are being targeted.
- 19Nightspire ransomware group lists Forma Therapeutics as victim●🚨New ransom group blog posts!🚨 Group name: nightspire Post title: Forma Therapeutics Holdings, Inc. Location: 🇺🇸 US Sect
The Nightspire ransomware group has added Forma Therapeutics Holdings, a US healthcare company, to its leak site, indicating an alleged attack and possible data theft. A separate group, Bavacai, simultaneously claimed a Nigerian logistics firm, BAWABAH. Security researchers track these victim postings as early warnings of new extortion campaigns against companies in the healthcare and logistics sectors.
- 20English schools recovering faster from cyber incidents●England's schools are getting better at mopping up cyber incidents Two-thirds report immediate recovery, although teache
Two-thirds of schools in England now report recovering immediately from cyber incidents, suggesting improved resilience to attacks such as ransomware and phishing. Despite the progress, teachers remain divided over who bears responsibility for security and whose job security is at risk when breaches occur, with staff often left handling technical problems outside their expertise.
- 21Vicksburg shuts down city systems after ransomware attack●The Record: Mississippi mayor says ransomware incident led city to shut down systems https:// therecord.media/vicksburg-
The mayor of Vicksburg, Mississippi, said a ransomware incident forced the city to shut down its computer systems. Officials pulled services offline to contain the attack, the latest in a string of ransomware strikes on US local governments. Cybersecurity observers are highlighting the growing pattern of municipal targets, alongside reported incidents elsewhere, including an architects' association in France.
- 22Booba Project ransomware group lists University of Illinois Chicago as victim●🚨New ransom group blog posts!🚨 Group name: Booba Project Post title: University of Illinois Chicago Location: 🇺🇸 US Sect
The Booba Project ransomware group has posted the University of Illinois Chicago on its leak site, claiming a breach of the US education institution. A healthcare organisation, Soni Medical Centre, was also added to the group's list of alleged victims. The claims appeared in threat-intelligence monitoring feeds that track ransomware leak sites, and follow-on confirmation from either organisation has not yet been reported.
- 23Flashpoint Unveils Patented Ransomware Risk Scoring Model●Ransomware Risk Model: Flashpoint's Patented Scoring Method to Inform Vulnerability Prioritization
Flashpoint has announced a patented ransomware risk model designed to help organizations prioritize vulnerability patching. The scoring method assesses which vulnerabilities are most likely to be exploited in ransomware attacks, allowing security teams to focus remediation efforts where the threat of encryption-based extortion is highest. The announcement is drawing attention within the cybersecurity community as defenders seek better ways to manage growing vulnerability backlogs.
- 24Ransomware group Wallstreet claims Danish firm Tronex A/S●🚨New ransom group blog post!🚨 Group name: Wallstreet Post title: Tronex A/S Sector: Unknown Info: https:// cti.fyi/group
The ransomware group calling itself Wallstreet has published a new victim post naming Tronex A/S on its leak site, a standard tactic used to pressure companies into paying by threatening to release stolen data. The listed sector for the company is unknown, and no further details about the alleged attack or the volume of stolen data have been disclosed. Cybersecurity analysts tracking ransomware activity flagged the claim as part of ongoing monitoring of new extortion posts.
- 25Direwolf ransomware group claims attack on US finance firm NorthStar●🚨New ransom group blog post!🚨 Group name: direwolf Post title: 🇺🇸 NorthStar Organization: NorthStar Location: 🇺🇸 US Sect
The Direwolf ransomware group has added a new victim to its leak site, claiming an attack on NorthStar, a US-based organisation in the finance sector. The listing appeared on the group's blog alongside its name, the target's location and sector. Threat intelligence watchers flagged the post shortly after it was published. Details on the volume of data stolen or a demanded ransom have not yet been made public.
- 26Security Firm Stresses Ransomware Preparedness for Businesses●What would happen to your business if ransomware hit tomorrow? Would you know what to do? Black Cat White Hat Security i
Black Cat White Hat Security is asking businesses a blunt question: if ransomware struck tomorrow, would they know what to do? The firm says its Defend & Respond platform now includes a Ransomware Assessment, arguing that cybersecurity is not only about prevention but also about being prepared to respond when an attack happens.
- 27New ransomware group calling itself ImNotAVillain posts notices●🚨New ransom group blog posts!🚨 Group name: ImNotAVillain Post title: Notice Sector: Unknown Info: https:// cti.fyi/group
A previously untracked ransomware operation going by the name ImNotAVillain has set up a leak-site presence, publishing brief posts titled 'Notice' and 'Warning' with no stated target sector. Cyberthreat intelligence trackers flagged the new group's blog activity. Its motives, affiliates and victim base are not yet known, and security researchers will be watching for signs of actual extortion activity.
- 28Inc Ransom claims breach of Colorado electric cooperative●🚨New ransom group blog posts!🚨 Group name: incransom Post title: Sangre de Cristo Electric Association Location: 🇺🇸 US S
The ransomware group Inc Ransom has listed Sangre de Cristo Electric Association, a US energy provider, on its leak site, claiming to have stolen data from the Colorado-based cooperative. The listing was flagged by cybersecurity researchers tracking new ransom group posts. Energy sector victims draw attention because of potential risks to critical infrastructure, alongside other new claims including a Georgian healthcare organisation posted by a separate group.
- 29FTAPI confirms data breach after ransomware claim▼FTAPI data breach confirmed after The Gentlemen ransomware claim
German secure file-transfer provider FTAPI has confirmed a data breach following a ransomware claim by a group calling itself The Gentlemen. The company acknowledged that data was affected, though details on scope and the number of customers or records involved remain limited. Security outlets are tracking the incident as the group's claim draws scrutiny.
- 30Deadlock ransomware group lists Virginia law firm as new victim●🚨New ransom group blog posts!🚨 Group name: Deadlock Post title: SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA Organiza
The Deadlock ransomware group has published a new post claiming to have compromised Shaheen Law Group, a legal practice based in Richmond, Virginia, in the United States. The listing, reported alongside claims against other organisations by a group tracked as Storm, suggests the firms' data may be leaked unless a ransom is paid. The law firm has not publicly commented, and the extent of any breach remains unclear.
- 31Police dismantle KillSec extortion gang, arrest three●Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
International law enforcement has seized the infrastructure of the KillSec extortion group and arrested three alleged members of the hacking crew. The takedown reportedly disrupts the group's ability to conduct extortion operations. The action highlights continued police pressure on ransomware and extortion networks, and details about the arrested suspects and the scale of the seized infrastructure have not yet been made public.
- 32Barracuda ransomware group claims Ecuador motoring club ANETA●🚨New ransom group blog post!🚨 Group name: Barracuda Post title: Automovil Club del Ecuador ANETA Location: 🇪🇨 EC Sector:
The ransomware group Barracuda has added Automovil Club del Ecuador ANETA to its leak site, listing the Ecuadorian motoring organisation in the services sector. The claim was flagged by a cyber threat intelligence feed that tracks new posts from ransomware gangs. No details have been released about the volume of data allegedly taken or any ransom demand.
- 33Storm ransomware group lists new alleged victims▼🚨New ransom group blog posts!🚨 Group name: Storm Post title: The Money Store Info: https:// cti.fyi/groups/Storm.html Gr
The Storm ransomware group has added new entries to its leak site, naming The Money Store, Silvercup Studios and Century Management Services among its latest claimed victims. The listings were flagged by threat intelligence monitors who track ransomware group blogs. Ransomware crews routinely publish victim names to pressure companies into paying, and each new post typically prompts checks by security researchers and affected firms.
- 34Netrunner ransomware group claims breach of Main Place Mall●🚨New ransom group blog posts!🚨 Group name: netrunner Post title: Main Place Mall Sector: Retail Info: https:// cti.fyi/g
A ransomware group calling itself Netrunner has listed Main Place Mall as a new victim on its leak site, tagging the target in the retail sector. The claim surfaced alongside fresh postings from other extortion groups, including Booba Project, in a routinely monitored feed of ransomware activity. Security researchers track these listings as an early indicator of breaches, though the mall operator has not publicly confirmed any incident.
- 35Ransomware data theft surged 275% in 2026●Reward: You've received the Fossil Record Badge — a commemorative exhibit of everything that used to be private. https:/
New reporting from Security Boulevard says ransomware-related data theft jumped 275% in 2026, with schools, hospitals and government agencies filing some of the largest claims. Attackers increasingly exfiltrate sensitive records before encrypting systems, exposing formerly private data. Security commentators are using the figures to warn institutions that a breach now means public disclosure of everything stored, not just downtime.
- 36Aurora ransomware group lists Buford-Thompson Company as victim●🚨New ransom group blog post!🚨 Group name: aurora Post title: Buford-Thompson Company, LTD Info: https:// cti.fyi/groups/
The Aurora ransomware group has published a new post on its leak site naming Buford-Thompson Company, LTD as its latest claimed victim. The listing appeared in threat intelligence tracking of ransomware group blogs. Security researchers monitor these posts to identify newly attacked organisations and track the activity of emerging ransomware operations like Aurora.
- 37Ransomware group Lamashtu claims breach tied to Dr Damiel Pugliese●🛡 THREAT INTEL | Dr Damiel Pugliese 🔴 Actor "lamashtu" claims Undisclosed ⚠️ Unverified claim https://www. yazoul.net/in
Threat intelligence feeds are reporting a claim by the ransomware actor known as "lamashtu" involving Dr Damiel Pugliese, dated September 2026 and tracked by the monitoring service Yazoul. The claim is explicitly flagged as unverified and the scope of any breach is undisclosed. Cybersecurity observers are circulating it while awaiting confirmation.
- 38Rhysida ransomware group lists Clicks Digital GmbH as new victim▼🚨New ransom group blog post!🚨 Group name: rhysida Post title: clicks digital GmbH Information Organization: Clicks Digit
The Rhysida ransomware group has added Clicks Digital GmbH, a digital marketing company based in Germany, to its leak site, claiming to have stolen the firm's data. The listing was flagged by threat intelligence monitors tracking ransomware activity. It marks the latest addition to the group's victims and puts the German firm in the public spotlight.
- 39ThreeAM ransomware group claims attack on Newman Tractor●🚨New ransom group blog post!🚨 Group name: threeam Post title: newmantractor.com Organization: Newman Tractor Location: 🇺
The ThreeAM ransomware group has added US heavy equipment dealer Newman Tractor to its leak site, listing the company as a new victim in the manufacturing sector. The claim suggests the group may have exfiltrated company data and could publish it unless a ransom is paid. Security researchers monitoring ransomware activity are flagging the listing as part of ongoing tracking of the group's attacks against US businesses.
- 40New ransomware group 'm3rx' lists Polish company intense.pl as victim▼🚨New ransom group blog post!🚨 Group name: m3rx Post title: intense.pl Info: https:// cti.fyi/groups/m3rx.html # ransomwa
Threat intelligence trackers report a newly surfaced ransomware group calling itself m3rx has published a blog post naming intense.pl, a Polish company, as its latest victim. The claim is being circulated among cybersecurity researchers monitoring ransomware leak sites, with details on the group still sparse. Analysts will be watching for confirmation from the targeted firm and for signs of further activity by the gang.