search
ransomware group
Trends
- 1
Japanese media report that a member of a ransomware group has been detained and handed over to German authorities in connection with a cyberattack on Asahi. Investigators cited the group's statement claiming responsibility for the attack on the Japanese brewer. The case highlights growing international cooperation in tracking ransomware operators.
- 2
Law enforcement, coordinated through Europol, has seized servers and the leak site of the KillSec ransomware group, which is suspected of being led by a teenager. The takedown disrupts one of the more active ransomware operations, and the suspect's young age is drawing attention to how ransomware crews are increasingly run by minors operating from home.
- 3Trump Mobile Allegedly Tells Ransomware Group It Has No Response Team▼Trump Mobile Allegedly Tells Ransomware Group 'We Have No Team to Handle This'
Trump Mobile has allegedly responded to a ransomware group claiming a breach by saying it has no team to handle the incident, according to an International Business Times report referencing a dark web leak. The reported response suggests the Trump-branded phone service may lack a dedicated security function, raising questions about how customer data is protected.
- 4Incransom ransomware group claims City of Cloverdale▼🚨New ransom group blog posts!🚨 Group name: incransom Post title: City of Cloverdale Location: 🇺🇸 US Sector: Government I
The Incransom ransomware group has added the City of Cloverdale, a local government in the United States, to its list of claimed victims on its leak site. The same post also lists the UAE Pro League as a target. Security researchers tracking ransomware activity flagged the new claims.
- 5
A ransomware group has published the personal data of 3,615 customers of Trump Mobile, the mobile phone service launched by the Trump Organization. The leak reportedly includes customer records exposed after the group claimed a breach of the company's systems. The incident raises fresh questions about the security practices of the recently launched venture and the potential exposure of subscriber information.
- 6
Japanese authorities have detained a Russian man identified as a core member of the international hacking group Qilin, and are proceeding with his extradition. The group has been linked to major ransomware attacks worldwide, and the arrest marks a notable step in international cooperation against cybercrime.
- 7Storm Ransomware Group Claims Attack on Canadian Hospital●📰 Storm Ransomware Group Claims Attack on Canadian Hospital New ransomware group 'Storm' claims attack on Nipigon Distri
A newly emerged ransomware group calling itself Storm has claimed an attack on Nipigon District Memorial Hospital in Canada. Security observers say the claim, if confirmed, would add to a string of extortion attempts against healthcare providers, a sector repeatedly targeted because of its dependence on continuous access to patient records and the sensitivity of medical data.
- 8
The ransomware group known as BYOD has claimed responsibility for a data breach affecting Trump Mobile, the mobile phone service launched by the Trump Organization. The claim was reported by cybersecurity outlet SC Media, which covers ransomware operations and their victims. Details about the volume or sensitivity of any stolen data have not yet been confirmed by the company.
- 9
A core member of the hacker group Qilin has been arrested in Japan, according to a report by TV Asahi's ANN news. The ransomware group is said to have hit victims in more than 100 countries, including Asahi Group Holdings. The arrest of a central figure in one of the world's most active cybercrime groups is drawing wide attention in Japanese media.
- 10Termite Group Ransomware Attack on Aon Exploited Cleo Software Flaw●Aon Ransomware Attack Analysis: Termite Group Exploits CVE-2024-50623 in Cleo Software
Aon has published an analysis of a ransomware attack attributed to the Termite group, which exploited CVE-2024-50623, a vulnerability in Cleo file-transfer software. The flaw allowed attackers to gain unauthorised access to systems before deploying ransomware. Security teams are being urged to patch Cleo installations and review exposure to the vulnerability.
- 11Ransomware group lists Sutton, Massachusetts schools and town government●🚨New ransom group blog posts!🚨 Group name: global Post title: Sutton Public Schools Location: 🇺🇸 US Sector: Education In
A ransomware group calling itself Global has added claims about Sutton Public Schools and the Town of Sutton in Massachusetts to its leak blog, listing the US education and local government sectors. Cybersecurity trackers monitoring ransom group posts flagged the new listings, though no details on stolen data or demands have been confirmed.
- 12New ransomware group Bavacai publishes post titled Balaqah▼🚨New ransom group blog post!🚨 Group name: Bavacai Post title: BALAQAH Info: https:// cti.fyi/groups/Bavacai.html # ranso
Cybersecurity researchers are tracking a new ransomware group calling itself Bavacai, which has published a blog post titled 'Balaqah' on its leak site. Threat intelligence monitors flagged the activity, and a tracking page with details on the group has been made available to the infosec community. Details about the group's victims and operations remain limited while analysts assess the new threat.
- 13Nightspire ransomware group lists Royal EGT and Lumabuilt as victims▼🚨New ransom group blog posts!🚨 Group name: nightspire Post title: Royal EGT Location: 🇬🇧 GB Sector: Technology Info: htt
The Nightspire ransomware group has added new victims to its leak site, naming UK technology company Royal EGT and construction firm Lumabuilt. Cybersecurity threat intelligence watchers flagged the listings, which typically follow extortion attempts in which attackers threaten to publish stolen data unless a ransom is paid.
- 14SafePay ransomware group threatens to leak T-Systems data●SafePay ransomware threatens T-Systems leak in breach claim
The SafePay ransomware group has claimed a breach of T-Systems, the IT services arm of Deutsche Telekom, and is threatening to publish stolen data unless its demands are met. The claim appeared on the group's leak site, and no confirmation from T-Systems has been reported yet, leaving the scale and validity of the alleged breach unknown.
- 15APT73 ransom group claims sale of stolen OmeTV data▼🚨New ransom group blog posts!🚨 Group name: apt73 Post title: ome.tv | SOLD Organization: OmeTV Sector: Technology Info:
The ransomware group APT73 has published new posts on its leak blog claiming to have taken data from video chat platform OmeTV, listing the haul as sold. In a separate entry it claims stolen data from Bank Rakyat Indonesia, also marked as sold to a third party. Both organisations are listed on the group's site; the claims have not been independently verified, and neither company has publicly confirmed a breach.
- 16DragonForce ransomware group lists Brazilian fuel company Petrosul●🚨New ransom group blog post!🚨 Group name: dragonforce Post title: Petrosul Distribuidora, Transportadora e Comércio de C
The DragonForce ransomware group has added Petrosul Distribuidora, Transportadora e Comércio de Combustíveis, a Brazilian fuel distribution and transport company, to its leak site, listing it as a new victim in the energy sector. The claim circulated among cyber threat intelligence watchers, who track ransomware group posts for signs of new attacks. No details on stolen data or ransom demands were given in the listing.
- 17RunSomeWares claims ransomware attack on Morton LTC Pharmacy●🚨New ransom group blog post!🚨 Group name: RunSomeWares Post title: Morton LTC Pharmacy Location: 🇺🇸 US Sector: Healthcar
The ransomware group RunSomeWares has listed Morton LTC Pharmacy, a US healthcare provider, as a new victim on its leak site. The claim, flagged by cyber threat intelligence monitors, adds the pharmacy to a growing list of healthcare organisations targeted by ransomware crews. Healthcare attacks are closely watched because of the risk to patient data and care services.
- 18Deadlock ransomware group targets Italian silverware firm Rino Greggio●🏴☠️ gruppo # Deadlock 🧬 Rino Greggio Argenterie S.P.A. | Sarmeola di Rubano (PD) 🎯 settore: C - Manifatturiero 🔗 greggi
The Deadlock ransomware group has listed Rino Greggio Argenterie, a silverware manufacturer based in Sarmeola di Rubano, in the province of Padua, on its leak site. The group claims to have exfiltrated about 500 GB of data and has set an October 14 publication deadline. No data has been published yet, and the company has not publicly commented.
- 19SilentRansomGroup emerges as new ransomware threat▼🚨New ransom group blog post!🚨 Group name: SilentRansomGroup Post title: A...n Sector: Unknown Info: https:// cti.fyi/gro
A new ransomware group calling itself SilentRansomGroup has been profiled in a fresh threat intelligence write-up. The post lists the group's name and activity but leaves its targeted sector unknown, and details remain limited. Cybersecurity researchers are circulating the alert among threat intelligence and infosec communities as they track the group's emergence.
- 20DragonForce ransomware group claims French construction firm RÉSO●🚨New ransom group blog posts!🚨 Group name: dragonforce Post title: RÉSO Location: 🇫🇷 FR Sector: Construction Info: https
The DragonForce ransomware group has added French construction company RÉSO to its leak site, listing the firm as a new victim. The claim was flagged by cyber threat intelligence monitors tracking ransom group posts. DragonForce has been active in recent ransomware campaigns, and listings of new victims across sectors such as construction and finance continue to draw attention from security researchers.
- 21Vexy Ransomware Posts New Claim on Leak Blog●🚨New ransom group blog post!🚨 Group name: Vexy Ransomware Post title: KOOKABARRA JUICE Info: https:// cti.fyi/groups/Vex
The Vexy Ransomware group has published a new blog post titled 'KOOKABARRA JUICE' on its extortion site, typically a sign the gang is claiming a fresh victim or releasing stolen data. Threat intelligence monitors flagged the update to the cybersecurity community, where researchers track such posts to identify targeted organisations and assess the group's activity.
- 22Japan hands Russia-born Qilin hacker suspect to Germany●👁 Спецоперації. Японія передала Німеччині росіянина з хакерської групи Qilin. Про це повідомив міністр внутрішніх справ
Japan has extradited to Germany a Russian national suspected of a leading role in the Qilin hacking group. North Rhine-Westphalia interior minister Herbert Reul said the 28-year-old, identified as Vladimir K., was transferred after German investigators secretly surveilled him for several months. The case highlights growing international cooperation against ransomware gangs.
- 23Qilin ransomware group claims attack on Delta Marine●🛡 THREAT INTEL | Delta Marine 🟢 Actor "qilin" claims Undisclosed ⚠️ Unverified claim https://www. yazoul.net/intel/claim
Threat intelligence monitoring reports that the Qilin ransomware group has claimed Delta Marine as a victim, though no details of the alleged attack or stolen data have been disclosed and the claim remains unverified. Delta Marine has not publicly confirmed any incident. Security researchers are watching to see whether the claim is substantiated.
- 24Shiba ransomware group claims attack on US finance firm Morgan White Group●🚨New ransom group blog post!🚨 Group name: Shiba Post title: Morgan White Group Location: 🇺🇸 US Sector: Finance Info: htt
The Shiba ransomware group has listed Morgan White Group, a US company in the finance sector, as a new victim on its leak site. The claim is being tracked by cyber threat intelligence observers monitoring ransomware activity. If confirmed, the incident would add to the ongoing wave of extortion attacks targeting financial services firms.
- 25UmBra ransomware group lists Tharisa and Raqib as new victims●🚨New ransom group blog posts!🚨 Group name: UmBra Post title: Tharisa Location: 🇨🇾 CY Sector: Unknown Info: https:// cti.
The UmBra ransomware group has added new victims to its leak site, naming Tharisa, a company based in Cyprus, and Raqib, a technology firm in Saudi Arabia. The claims appeared in a threat-intelligence alert shared among cybersecurity watchers tracking ransom group blogs. The companies' involvement has not been independently confirmed, and the sectors affected remain partly unclear.
- 26Insomnia ransomware group claims breach of US healthcare firm Praxis EMR▼🚨New ransom group blog posts!🚨 Group name: insomnia Post title: Praxis EMR Location: 🇺🇸 US Sector: Healthcare Info: http
The Insomnia ransomware group has listed Praxis EMR, a US healthcare sector victim, on its leak blog, according to cyber threat intelligence monitoring. The same reporting round also noted Qilin claiming a US services company, Global Security Concepts. Ransomware attacks on healthcare providers draw attention because of patient data exposure and potential disruption to care.
- 27UmBra ransomware group lists law firm and Egyptian university victims●🚨New ransom group blog posts!🚨 Group name: UmBra Post title: Four Hands LLC Sector: Legal Info: https:// cti.fyi/groups/
A newly active ransomware group calling itself UmBra has added two victims to its leak site: Four Hands LLC, a US legal services firm, and Beni Suef Technological University in Egypt. Security researchers are tracking the listings, which suggest the group is broadening its operations across both the legal and education sectors.
- 28EndZone ransomware group claims attack on Philander Smith University▼🚨New ransom group blog post!🚨 Group name: EndZone Post title: Philander Smith University Location: 🇺🇸 US Sector: Educati
The EndZone ransomware group has listed Philander Smith University, a private historically black college in Little Rock, Arkansas, on its leak site, adding the US education sector institution to its claims of victims. Threat intelligence monitors flagged the post. The university has not publicly confirmed the incident, and it is not yet known what data, if any, was stolen or when the attack took place.
- 29Interlock ransomware group claims attack on H&L Manufacturing▼🚨New ransom group blog post!🚨 Group name: interlock Post title: H&L Manufacturing Sector: Manufacturing Info: https:// c
The Interlock ransomware group has added H&L Manufacturing to its leak site, listing the company as a new victim in the manufacturing sector. The claim was flagged by cyber threat intelligence monitors tracking new posts from ransomware operations. Manufacturing firms remain a frequent target for ransomware crews seeking leverage through data leaks and production disruption.
- 30Qilin ransomware group claims new victim BNYH●🚨New ransom group blog post!🚨 Group name: qilin Post title: BNYH Info: https:// cti.fyi/groups/qilin.html # ransomware #
The Qilin ransomware group has published a new post on its leak site claiming an attack on BNYH, adding the organisation to its list of alleged victims. The claim was flagged by cyber threat intelligence monitors who track ransom group blogs. No details have been confirmed about the scale of the alleged breach, any stolen data, or a response from the organisation named.
- 31KillSec Ransomware Group Dismantled, Teenage Leader Arrested●International Operation Dismantles KillSec Ransomware Group, Arrests Teen Leader
An international law enforcement operation has dismantled the KillSec ransomware group and arrested its teenage alleged leader. The takedown is drawing attention to the growing role of very young cybercriminals in ransomware operations, and to cross-border police cooperation against hacking groups. Details about the arrests and the scale of the group's attacks have not been fully disclosed.
- 32
Police have arrested a 16-year-old suspected of leading the KillSec ransomware group, according to Help Net Security. The arrest of a minor at the head of a ransomware operation has drawn attention to how young hackers have become involved in organized cybercrime, and to the growing activity of the KillSec group itself.
- 33Storm ransomware group claims attack on US manufacturer▼🚨New ransom group blog posts!🚨 Group name: Storm Post title: Step By Step Sector: Unknown Info: https:// cti.fyi/groups/
A new ransomware group calling itself Storm has published a leak-site post claiming the extortion of Allied Machine & Engineering, a US manufacturing company. A post titled 'Step By Step' with an unknown victim was also listed. The alerts were flagged by cybersecurity threat-intelligence trackers monitoring ransom group blogs.
- 34Europol dismantles KillSec ransomware gang allegedly led by a 16-year-old●Operazione KillSwitch: Europol smantella KillSec, la gang ransomware guidata da un sedicenne Un blitz in quattro paesi e
Europol and Eurojust coordinated raids in four European countries that dismantled KillSec, a ransomware-as-a-service group that began as a hacktivist collective in 2023. Reports say the operation, dubbed KillSwitch, targeted the group's leadership, which allegedly included a teenager. The arrests highlight how young actors are running increasingly professional cybercrime operations.
- 35KillSec Ransomware Group Dismantled, 16-Year-Old Leader Arrested●Global Operation Dismantles KillSec Ransomware Group, Arrests 16-Year-Old Leader
An international law enforcement operation has taken down the KillSec ransomware group, arresting its suspected leader, who is reportedly only 16 years old. The case has drawn attention both to the growing role of teenagers in cybercrime and to cross-border cooperation against ransomware networks that have targeted organisations worldwide.
- 36Ransomware group BYOD lists Franklin Empire and Royal Selangor as victims●🚨New ransom group blog posts!🚨 Group name: BYOD Post title: Franklin Empire Sector: Unknown Info: https:// cti.fyi/group
Cybersecurity trackers report that a ransomware group calling itself BYOD has added new victim posts to its leak site, naming Franklin Empire and Malaysia's Royal Selangor, with the latter listed in the manufacturing sector. Analysts monitoring ransom leak sites flag these listings to warn potential targets and track which sectors and regions the group is hitting.
- 37New ransomware gangs claim Trump Mobile and dental firm as targets●There's a new gang in today's ransomware mix. But the first target. claimed by another new threat actor, takes the cake:
Cybersecurity watchers are tracking two newly emerged ransomware groups announcing their first victims. One group listed Trump Mobile Wireless, the mobile phone venture backed by Donald Trump, as its target, while another new actor claimed O2 Dental Group in the United States. Researchers are monitoring ransomware tracking sites to verify the claims, noting the unusual prominence of a brand tied to the US president among the first claimed victims.
- 38Aurora ransomware group lists US law firm as victim●🚨New ransom group blog posts!🚨 Group name: aurora Post title: Thomas Y. Pickett & Co., Inc. Location: 🇺🇸 US Sector: Lega
The Aurora ransomware group has posted Thomas Y. Pickett & Co., Inc., a US legal sector firm, on its leak site, indicating an alleged extortion attack. The same tracking also flagged a new post by the Lamashtu group naming Grupo Industrial Tauro, a Mexican manufacturing company. Security researchers monitor these listings as early indicators of breaches affecting professional services and industrial firms.
- 39Qilin ransomware group lists Asia Era One as new victim●🚨New ransom group blog post!🚨 Group name: qilin Post title: Asia Era One Sector: Unknown Info: https:// cti.fyi/groups/q
The Qilin ransomware group has added a new entry to its leak site, naming Asia Era One as its latest claimed victim. The sector of the targeted organisation was not specified in the listing. Security researchers monitoring ransomware activity flagged the post, adding Qilin to the ongoing tally of active extortion operations targeting companies across regions.
- 40Tower investigates unverified ransomware claim▼Tower investigates unverified ransomware claim after being named on leak site
Insurer Tower has launched an investigation after being named on a ransomware group's leak site, according to Insurance Business. The claim remains unverified, and Tower has not confirmed whether any of its systems or customer data have been compromised. Companies listed on such sites are typically given deadlines to pay extortion demands before data is published.