search
ransomware
Trends
- 1
Osaka Metropolitan University has been hit by a suspected ransomware cyberattack, forcing around 500 servers offline and cancelling classes across all faculties until at least the 8th. The university held a press conference on the disruption and is investigating whether personal data belonging to some 130,000 people was leaked, with Japanese media closely tracking the incident.
- 2Teenager suspected of running KillSec ransomware group●Teenager suspected of leading KillSec ransomware group
Law enforcement agencies, working with Europol, have seized servers and the leak site used by the KillSec ransomware group, and suspect the operation was led by a teenager. The takedown disrupts one of the newer ransomware crews active in recent attacks, and the unusually young age of the suspected leader has drawn attention as details of the operation emerge.
- 3ARC Advisory Group Examines Industrial Cyber Resilience Needs●Enhancing Industrial Cyber Resilience in a Rapidly Evolving Threat Environment
ARC Advisory Group has published analysis on how industrial operators can strengthen cyber resilience as threats to critical infrastructure grow in sophistication and frequency. The discussion focuses on protecting industrial control systems in an evolving threat environment, a concern that has intensified following rising ransomware and state-linked attacks targeting manufacturing, energy and utilities worldwide.
- 4Storm Ransomware Group Claims Attack on Canadian Hospital●📰 Storm Ransomware Group Claims Attack on Canadian Hospital New ransomware group 'Storm' claims attack on Nipigon Distri
A newly emerged ransomware group calling itself Storm has claimed responsibility for an attack on Nipigon District Memorial Hospital in Canada. The group announced the breach on its leak site, adding the Ontario hospital to its list of victims. Security observers say the incident underscores the ongoing threat that emerging extortion gangs pose to the healthcare sector, where attacks can disrupt patient care and force facilities onto manual procedures while systems are restored.
- 5
A ransomware group has published the personal data of 3,615 customers of Trump Mobile, the mobile phone service launched by the Trump Organization. The leak reportedly includes customer records exposed after the group claimed a breach of the company's systems. The incident raises fresh questions about the security practices of the recently launched venture and the potential exposure of subscriber information.
- 6
The United States Senate has passed the Health Care Cybersecurity and Resilience Act, legislation aimed at strengthening protections against cyberattacks on hospitals and health systems. The American Hospital Association highlighted the passage. The bill now moves to the House, and supporters say it addresses growing threats to patient data and medical services.
- 7EndZone ransomware group claims attack on Philander Smith University▼🚨New ransom group blog post!🚨 Group name: EndZone Post title: Philander Smith University Location: 🇺🇸 US Sector: Educati
The EndZone ransomware group has listed Philander Smith University, a private historically black college in Little Rock, Arkansas, on its leak site, adding the US education sector institution to its claims of victims. Threat intelligence monitors flagged the post. The university has not publicly confirmed the incident, and it is not yet known what data, if any, was stolen or when the attack took place.
- 8Senate Passes Health Care Cybersecurity and Resilience Act●Senate passes Health Care Cybersecurity and Resilience Act | AHA News
The US Senate has passed the Health Care Cybersecurity and Resilience Act, legislation aimed at strengthening cyber defenses across the health care sector. The American Hospital Association reported the passage, a signal of growing federal concern over ransomware and data breaches targeting hospitals and health systems. The bill now moves to the House for consideration.
- 9Ransomware Attack on Keio Hits Times Car Ride-Sharing Service▼Data Breach Impacts Times Car Ride-Sharing Service as Ransomware Attack Hits Railway Operator Keio
Japanese railway operator Keio has been hit by a ransomware attack, which has caused a data breach affecting its Times Car ride-sharing service. Details on the number of customers affected or the scope of the stolen data have not been disclosed. The incident adds to a string of cyberattacks disrupting major Japanese transport and mobility companies.
- 10Insomnia ransomware group claims breach of US healthcare firm Praxis EMR▼🚨New ransom group blog posts!🚨 Group name: insomnia Post title: Praxis EMR Location: 🇺🇸 US Sector: Healthcare Info: http
The Insomnia ransomware group has listed Praxis EMR, a US healthcare sector victim, on its leak blog, according to cyber threat intelligence monitoring. The same reporting round also noted Qilin claiming a US services company, Global Security Concepts. Ransomware attacks on healthcare providers draw attention because of patient data exposure and potential disruption to care.
- 11Unreleased Wolverine PS5 game ported to PC using leaked source code▼Wolverine PS5 exclusive ported to PC in buggy solo project using AI — source code was taken from Sony 2023 ransomware attack
A solo developer has produced a buggy PC port of Marvel's Wolverine, the unreleased Insomniac Games PlayStation 5 exclusive, reportedly using AI tools and source code obtained from the 2023 ransomware attack on Sony that exposed stolen internal files. The project is drawing attention because it uses materials from a major security breach and involves an official title that Sony never released publicly.
- 12Interlock ransomware group claims attack on H&L Manufacturing▼🚨New ransom group blog post!🚨 Group name: interlock Post title: H&L Manufacturing Sector: Manufacturing Info: https:// c
The Interlock ransomware group has added H&L Manufacturing to its leak site, listing the company as a new victim in the manufacturing sector. The claim was flagged by cyber threat intelligence monitors tracking new posts from ransomware operations. Manufacturing firms remain a frequent target for ransomware crews seeking leverage through data leaks and production disruption.
- 13Experts call for broader Cybersecurity Awareness Month message▼Cybersecurity Awareness Month 2026 shouldn’t be reduced to “don’t click suspicious links.” Modern attacks now span the e
Cybersecurity professionals are arguing that Cybersecurity Awareness Month 2026 should not be reduced to the familiar advice of avoiding suspicious links. They say modern attacks now cover the full kill chain, including reconnaissance, credential theft, lateral movement, ransomware and data exfiltration, alongside AI-powered social engineering and software supply chain threats. The discussion is prompting calls for security education that reflects how sophisticated today's attack techniques have become.
- 14Europol dismantles KillSec ransomware gang allegedly led by a 16-year-old●Operazione KillSwitch: Europol smantella KillSec, la gang ransomware guidata da un sedicenne Un blitz in quattro paesi e
Europol and Eurojust coordinated raids in four European countries that dismantled KillSec, a ransomware-as-a-service group that began as a hacktivist collective in 2023. Reports say the operation, dubbed KillSwitch, targeted the group's leadership, which allegedly included a teenager. The arrests highlight how young actors are running increasingly professional cybercrime operations.
- 15Ransomware group BYOD lists Franklin Empire and Royal Selangor as victims●🚨New ransom group blog posts!🚨 Group name: BYOD Post title: Franklin Empire Sector: Unknown Info: https:// cti.fyi/group
Cybersecurity trackers report that a ransomware group calling itself BYOD has added new victim posts to its leak site, naming Franklin Empire and Malaysia's Royal Selangor, with the latter listed in the manufacturing sector. Analysts monitoring ransom leak sites flag these listings to warn potential targets and track which sectors and regions the group is hitting.
- 16New ransomware gangs claim Trump Mobile and dental firm as targets●There's a new gang in today's ransomware mix. But the first target. claimed by another new threat actor, takes the cake:
Cybersecurity watchers are tracking two newly emerged ransomware groups announcing their first victims. One group listed Trump Mobile Wireless, the mobile phone venture backed by Donald Trump, as its target, while another new actor claimed O2 Dental Group in the United States. Researchers are monitoring ransomware tracking sites to verify the claims, noting the unusual prominence of a brand tied to the US president among the first claimed victims.
- 17AI troll bot turns Marcus Hutchins' trolls in circles●AI troll bot turns Marcus Hutchins’ trolls in circles
Security researcher Marcus Hutchins, best known for stopping the WannaCry ransomware outbreak in 2017, is reportedly using an AI bot to respond to trolls who target him online. The bot keeps his harassers engaged in circular conversations, tying them up without Hutchins having to reply himself. The story is circulating among tech and cybersecurity audiences as a novel use of AI against online abuse.
- 18Qilin ransomware group lists Asia Era One as new victim●🚨New ransom group blog post!🚨 Group name: qilin Post title: Asia Era One Sector: Unknown Info: https:// cti.fyi/groups/q
The Qilin ransomware group has added a new entry to its leak site, naming Asia Era One as its latest claimed victim. The sector of the targeted organisation was not specified in the listing. Security researchers monitoring ransomware activity flagged the post, adding Qilin to the ongoing tally of active extortion operations targeting companies across regions.
- 19Sovcali ransomware group claims India tech firm Warp9●🚨New ransom group blog post!🚨 Group name: Sovcali Post title: Warp9 Microsolutions Location: 🇮🇳 IN Sector: Technology In
The Sovcali ransomware group has listed Warp9 Microsolutions, an Indian technology company, as a new victim on its leak site, a common tactic used to pressure companies into paying. The claim was flagged by cyber threat intelligence monitors tracking ransomware activity. No details on the scale of the alleged breach or the company's response have been confirmed.