ZCyberNews
中文

Ransomware

58 articles

Recent ransomware, extortion, leak-site, and victim-claim coverage.

Grafana GitHub Token Breach Lets Attacker Download Full CodebaseHIGH
Industry News

Grafana GitHub Token Breach Lets Attacker Download Full Codebase

An attacker used a compromised GitHub token to download Grafana's entire private codebase. The company says no customer data was accessed and the incident involved an extortion...

3 min read
Foxconn Confirms Ransomware Attack on North American FactoriesHIGH
Industry News

Foxconn Confirms Ransomware Attack on North American Factories

Nitrogen ransomware gang claims 8TB of stolen data from Foxconn's North American factories, including technical files from major tech clients.

2 min readNitrogen
The Gentlemen RaaS Internal Leak Exposes Admin, Affiliates, TacticsCRITICAL
Threat Intel

The Gentlemen RaaS Internal Leak Exposes Admin, Affiliates, Tactics

A leaked backend database from The Gentlemen RaaS operation reveals 9 accounts, admin TOX ID, initial access via Fortinet/Cisco edge flaws, and a 190,000 USD ransom payout.

CVE-2024-55591CVE-2025-32433CVE-2025-33073
4 min readThe Gentlemen
Instructure Pays Ransom to ShinyHunters After Canvas BreachCRITICAL
Industry News

Instructure Pays Ransom to ShinyHunters After Canvas Breach

Instructure paid ShinyHunters after two Canvas intrusions stole data from 9,000 institutions. Congress launched an investigation into the ed-tech vendor's incident response.

3 min readShinyHunters
Instructure Pays ShinyHunters to Halt 3.65TB Canvas Data LeakHIGH
Industry News

Instructure Pays ShinyHunters to Halt 3.65TB Canvas Data Leak

ShinyHunters agreed to delete 3.65TB of stolen Canvas data after Instructure paid an undisclosed ransom. The breach affects thousands of schools and universities worldwide.

3 min readShinyHunters
UK Fines South Staffordshire Water $1.3M for 2022 BreachHIGH
Industry News

UK Fines South Staffordshire Water $1.3M for 2022 Breach

ICO fined South Staffordshire Water £963,900 after Cl0p ransomware gang leaked data of 663,887 customers — phishing attack went undetected for 20 months.

3 min readCl0p
West Pharma Hit by Ransomware, Systems Disrupted GloballyHIGH
Industry News

West Pharma Hit by Ransomware, Systems Disrupted Globally

West Pharmaceutical Services took systems offline globally after a May 4 ransomware attack with data exfiltration. Unit 42 is investigating; ransom may have been paid.

2 min readLockBit
ShinyHunters Breaches Vimeo, Leaks 119K User RecordsHIGH
Industry News

ShinyHunters Breaches Vimeo, Leaks 119K User Records

ShinyHunters leaked a 106GB archive of Vimeo data after breaching Anodot, exposing emails and names of 119,200 users. No credentials or payment info compromised.

2 min readShinyHunters
Pro-Orbán Media Firm Mediaworks Breached by Ransomware GroupHIGH
Industry News

Pro-Orbán Media Firm Mediaworks Breached by Ransomware Group

Ransomware group claims breach of Mediaworks, a pro-Orbán Hungarian media conglomerate. The firm confirmed unauthorized access and potential data exfiltration on Friday.

2 min readLockBit
Instructure Data Breach: ShinyHunters Claims TheftHIGH
Industry News

Instructure Data Breach: ShinyHunters Claims Theft

ShinyHunters claims to have stolen data from Instructure, the edtech firm behind Canvas LMS. Instructure confirms a breach involving unauthorized access to certain systems and…

2 min readShinyHunters
Ex-Incident Responders Sentenced to 4 Years for Ransomware AttacksHIGH
Industry News

Ex-Incident Responders Sentenced to 4 Years for Ransomware Attacks

Two cybersecurity incident responders who abused client access to deploy ransomware were sentenced to 4 years in prison — a rare case of responders turning attackers.

2 min read
Ex-Ransomware Negotiators Sentenced to 4 Years for BlackCat AttacksHIGH
Industry News

Ex-Ransomware Negotiators Sentenced to 4 Years for BlackCat Attacks

Two former IR firm employees got 4 years each for laundering $18M+ in BlackCat ransom payments and advising attackers on negotiation tactics.

2 min readBlackCat
Cordial Spider, Snarky Spider Use Vishing, SSO Abuse for SaaSHIGH
Threat Intel

Cordial Spider, Snarky Spider Use Vishing, SSO Abuse for SaaS

Two cybercrime groups — Cordial Spider and Snarky Spider — are conducting rapid SaaS extortion attacks using vishing and SSO abuse to steal data within hours, researchers warn.

3 min readCordial Spider
Inc Ransom Breach at Sandhills Medical Exposes 170K RecordsHIGH
Industry News

Inc Ransom Breach at Sandhills Medical Exposes 170K Records

Inc Ransom group breached Sandhills Medical in 2025; the South Carolina healthcare provider took nearly a year to disclose the incident, affecting 170,000 patients.

2 min readInc Ransom
CISA Details Interlock Ransomware TTPs, IOCs in Joint AdvisoryHIGH
Threat Intel

CISA Details Interlock Ransomware TTPs, IOCs in Joint Advisory

CISA and FBI released a joint advisory on Interlock ransomware, detailing TTPs, IOCs, and a shift from double extortion to data-theft-only attacks targeting healthcare and…

2 min readInterlock
VECT 2.0 Ransomware Wiper Bug Destroys Files Over 131KBCRITICAL
Malware

VECT 2.0 Ransomware Wiper Bug Destroys Files Over 131KB

VECT 2.0 ransomware contains a critical encryption flaw that irreversibly destroys files larger than 131KB on Windows, Linux, and ESXi — no recovery possible even with a…

2 min readVECT
VECT Ransomware Wiper Bug Destroys Data, Not Just EncryptsCRITICAL
Malware

VECT Ransomware Wiper Bug Destroys Data, Not Just Encrypts

Check Point Research found a bug in VECT ransomware's encryption logic that permanently destroys files on Windows systems — no recovery possible even after paying.

3 min readVECT Ransomware
Rival Ransomware Gangs 0APT, KryBit Leak Each Other's DataHIGH
Threat Intel

Rival Ransomware Gangs 0APT, KryBit Leak Each Other's Data

0APT and KryBit ransomware groups leaked each other's infrastructure data after a feud, exposing C2 servers, panel credentials, and victim lists to defenders.

2 min read0APT
US Charges 19-Year-Old Scattered Spider Hacker Arrested in FinlandHIGH
Threat Intel

US Charges 19-Year-Old Scattered Spider Hacker Arrested in Finland

A 19-year-old US-Estonian dual citizen arrested in Finland faces federal charges as a prolific Scattered Spider member linked to ransomware attacks on MGM Resorts and Caesars.

2 min readScattered Spider
ADT Breach: ShinyHunters Steals Data of 5.5 MillionHIGH
Industry News

ADT Breach: ShinyHunters Steals Data of 5.5 Million

ShinyHunters breached ADT, stealing personal data of 5.5 million individuals — names, emails, phone numbers, and addresses — from internal systems. No payment data compromised.

2 min readShinyHunters
ESET: March 2026 Cyber Threats Show Resilience GapsMEDIUM
Industry News

ESET: March 2026 Cyber Threats Show Resilience Gaps

ESET's Tony Anscombe warns that March 2026 attacks — including ransomware, supply chain compromises, and AI-driven phishing — reveal systemic gaps in organizational…

2 min read
TeamPCP Partners with Vect Ransomware in Supply Chain AttacksCRITICAL
Threat Intel

TeamPCP Partners with Vect Ransomware in Supply Chain Attacks

Unit 42 reports TeamPCP has partnered with Vect ransomware group to target security software vendors in multi-stage supply chain attacks, compromising trusted update mechanisms.

2 min readTeamPCP
Germany Identifies REvil, GandCrab Ransomware Leader 'UNKN'HIGH
Threat Intel

Germany Identifies REvil, GandCrab Ransomware Leader 'UNKN'

German authorities name 31-year-old Russian Daniil Maksimovich Shchukin as 'UNKN,' the operator behind REvil and GandCrab ransomware groups linked to 130+ extortion attacks.

2 min readREvil
ADT Confirms Breach as ShinyHunters Leaks Customer DataHIGH
Industry News

ADT Confirms Breach as ShinyHunters Leaks Customer Data

ADT confirmed a data breach after ShinyHunters leaked 30,000+ customer records including names, emails, and account details from a compromised Salesforce instance.

2 min readShinyHunters
BlackFile Extortion Group Targets Retail, Hospitality via VishingHIGH
Threat Intel

BlackFile Extortion Group Targets Retail, Hospitality via Vishing

BlackFile extortion group has hit at least 12 retail and hospitality organizations since Feb 2026, using vishing to steal VPN credentials and exfiltrate data before demanding…

2 min readBlackFile
Trigona Ransomware Deploys Custom Exfil Tool for Faster Data TheftHIGH
Malware

Trigona Ransomware Deploys Custom Exfil Tool for Faster Data Theft

Trigona ransomware attacks now use a custom CLI tool to exfiltrate data from compromised networks faster, targeting backups and cloud storage before encryption.

2 min readTrigona
Kyber Ransomware Deploys Post-Quantum Encryption in AttacksHIGH
Malware

Kyber Ransomware Deploys Post-Quantum Encryption in Attacks

The Kyber ransomware gang is using a variant that implements Kyber1024 post-quantum encryption to target Windows and VMware ESXi systems, according to a BleepingComputer analysis.

2 min readKyber
The Gentlemen Ransomware Deploys Dual Lockers for Windows, Linux, and VMwareHIGH
Malware

The Gentlemen Ransomware Deploys Dual Lockers for Windows, Linux, and VMware

The Gentlemen ransomware-as-a-service operation has infected over 320 victims, deploying separate encryptors for Windows/Linux and VMware ESXi systems to maximize disruption and ransom pressure on enterprise networks.

3 min readThe Gentlemen
Ransomware Attackers Operate Like Businesses, ESET Research RevealsHIGH
Threat Intel

Ransomware Attackers Operate Like Businesses, ESET Research Reveals

ESET analysis of 100+ ransomware attacks shows threat actors run business operations with defined roles, KPIs, and supply chains, not just technical attacks.

3 min readLockBit
Bomgar RMM Exploit Fuels Ransomware and Supply Chain AttacksCRITICAL
Vulnerabilities

Bomgar RMM Exploit Fuels Ransomware and Supply Chain Attacks

CVE-2026-1731, a critical 9.8 CVSS flaw in BeyondTrust's Bomgar RMM, is being actively exploited to deploy ransomware and compromise IT service providers in global supply chain attacks.

CVE-2026-1731
3 min read
Kyber Ransomware Deploys Dual Payloads for Windows and VMware ESXiHIGH
Malware

Kyber Ransomware Deploys Dual Payloads for Windows and VMware ESXi

Kyber ransomware deploys two distinct payloads to encrypt both Windows systems and VMware ESXi servers, using a custom tool to wipe ESXi snapshots and hinder recovery. The attack chain begins with compromised RDP credentials.

3 min readKyber
Former Ransomware Negotiator Pleads Guilty to BlackCat AttacksINFORMATIONAL
Threat Intel

Former Ransomware Negotiator Pleads Guilty to BlackCat Attacks

Angelo Martino, a 41-year-old former employee of cybersecurity firm DigitalMint, pleads guilty to conspiring in BlackCat ransomware attacks against U.S. companies while working as a negotiator.

3 min readBlackCat (ALPHV)
France Titres Data Breach Exposes Citizen Information for SaleHIGH
Threat Intel

France Titres Data Breach Exposes Citizen Information for Sale

France Titres, the French government agency for ID documents, confirms a data breach after a threat actor offers to sell stolen citizen information, including names, addresses, and passport numbers.

3 min read
The Gentlemen Ransomware Botnet Infects 1,570+ Systems via SystemBC ProxyHIGH
Threat Intel

The Gentlemen Ransomware Botnet Infects 1,570+ Systems via SystemBC Proxy

Check Point Research uncovers a 1,570-victim botnet linked to The Gentlemen ransomware, using the SystemBC proxy malware to establish stealthy SOCKS5 tunnels for command and control.

2 min readThe Gentlemen
Datto Warns Traditional Backups Fail to Maintain Business Operations DuringHIGH
Industry News

Datto Warns Traditional Backups Fail to Maintain Business Operations During

Datto's 2026 report reveals 43% of businesses with backups still face over 24 hours of downtime after an attack, highlighting the critical gap between data backup and true business continuity and disaster recovery (BCDR).

3 min read
The Gentlemen Ransomware Deploys SystemBC Proxy for C2 EvasionHIGH
Malware

The Gentlemen Ransomware Deploys SystemBC Proxy for C2 Evasion

The Gentlemen ransomware-as-a-service group uses the SystemBC SOCKS5 proxy tool to hide command-and-control traffic, according to a Check Point DFIR report analyzing a recent affiliate attack.

3 min readThe Gentlemen
Seiko USA Website Defaced, Customer Data Stolen in Ransom AttackHIGH
Threat Intel

Seiko USA Website Defaced, Customer Data Stolen in Ransom Attack

Seiko USA's website was defaced by a hacker claiming theft of its Shopify customer database, including names, emails, and order details for 30,000 individuals, with a ransom demand to prevent public leak.

3 min readRansomHub
Interlock Ransomware Exploits Cisco FMC Zero-Day in Global AttacksCRITICAL
Threat Intel

Interlock Ransomware Exploits Cisco FMC Zero-Day in Global Attacks

The Interlock ransomware group is actively exploiting a zero-day vulnerability in Cisco Firepower Management Center to breach networks. Recorded Future identified 31 high-impact flaws in March 2026, a 139% monthly increase.

3 min readInterlock
TeamPCP Supply Chain Attack Fuels Payroll Fraud and RansomwareHIGH
Threat Intel

TeamPCP Supply Chain Attack Fuels Payroll Fraud and Ransomware

TeamPCP threat actors compromised trusted software tools to steal credentials from over 100 organizations, enabling $1.5M in payroll fraud, logistics theft, and ransomware extortion.

3 min readTeamPCP
NAKIVO Backup & Replication v11.2 Adds Ransomware Defense and Proxmox SupportINFORMATIONAL
Tools & Techniques

NAKIVO Backup & Replication v11.2 Adds Ransomware Defense and Proxmox Support

NAKIVO Inc. has released version 11.2 of its Backup & Replication platform, introducing a ransomware defense module, support for Proxmox VE 9.0, and performance enhancements for VMware vSphere 9 environments.

3 min read
Apache ActiveMQ Vulnerability Exploited, Added to CISA KEV CatalogHIGH
Vulnerabilities

Apache ActiveMQ Vulnerability Exploited, Added to CISA KEV Catalog

A high-severity flaw in Apache ActiveMQ Classic, CVE-2026-34197 (CVSS 8.8), is under active exploitation, prompting CISA to add it to its Known Exploited Vulnerabilities catalog and mandate patching for federal agencies.

CVE-2026-34197
3 min read
Payouts King Ransomware Deploys QEMU VMs as Stealthy Reverse SSH BackdoorsHIGH
Malware

Payouts King Ransomware Deploys QEMU VMs as Stealthy Reverse SSH Backdoors

The Payouts King ransomware group is deploying the open-source QEMU emulator to create hidden virtual machines on compromised hosts, establishing a persistent reverse SSH backdoor that evades conventional endpoint detection.

4 min readPayouts King
DHL-Themed Phishing Campaign Delivers Remote Access SoftwareHIGH
Threat Intel

DHL-Themed Phishing Campaign Delivers Remote Access Software

A new phishing campaign impersonates DHL to trick recipients into installing legitimate remote access software, which attackers then use as a foothold to deploy additional malware, including ransomware.

4 min read
Payouts King Ransomware Emerges from BlackBasta's ShadowHIGH
Threat Intel

Payouts King Ransomware Emerges from BlackBasta's Shadow

The Payouts King ransomware group, linked to former BlackBasta affiliates, has conducted targeted attacks since April 2025, combining data theft with selective encryption to pressure victims.

4 min readPayouts King
McGraw Hill Breach: ShinyHunters Leaks 13.5M User RecordsHIGH
Threat Intel

McGraw Hill Breach: ShinyHunters Leaks 13.5M User Records

ShinyHunters published data from 13.5 million McGraw Hill accounts — names, emails, institutional affiliations — stolen from a misconfigured Salesforce instance.

3 min readShinyHunters
JanaWare Ransomware Campaign Targets Turkish Homes and SMBs for Six YearsHIGH
Malware

JanaWare Ransomware Campaign Targets Turkish Homes and SMBs for Six Years

A ransomware campaign dubbed 'JanaWare' has been targeting Turkish homes and small-to-medium businesses since at least 2018, deploying a custom variant of the Adwind RAT to steal credentials before encryption.

4 min read
McGraw-Hill Data Breach Exposes 13.5 Million Users via SalesforceHIGH
Threat Intel

McGraw-Hill Data Breach Exposes 13.5 Million Users via Salesforce

Education publisher McGraw-Hill confirms a data breach exposing 13.5 million users' personal data, linked to a misconfigured Salesforce environment. Over 100GB of stolen data has been publicly distributed online following an extortion attempt.

3 min read
Ransomware Attack Disrupts Automotive Data Giant Autovista GroupHIGH
Threat Intel

Ransomware Attack Disrupts Automotive Data Giant Autovista Group

Autovista Group, a major European automotive data and analytics firm, confirms a ransomware attack disrupting operations. The company is investigating with external experts, but impact on customer data remains unclear.

3 min read
Researchers Map Over 1,250 Active C2 Servers Across Russian Hosting ProvidersHIGH
Threat Intel

Researchers Map Over 1,250 Active C2 Servers Across Russian Hosting Providers

A three-month investigation has identified more than 1,250 active command-and-control servers operating across 165 Russian hosting providers, forming a resilient infrastructure for malware and ransomware operations.

3 min read
Rhysida Ransomware Group Breaches Tennessee Hospital, Exposes 337,000HIGH
Threat Intel

Rhysida Ransomware Group Breaches Tennessee Hospital, Exposes 337,000

Cookeville Regional Medical Center confirms a 2025 ransomware attack by the Rhysida group compromised the data of 337,000 individuals after the theft of 500GB of files.

3 min readRhysida
Bitdefender Unifies Endpoint and Email Security in GravityZone PlatformINFORMATIONAL
Industry News

Bitdefender Unifies Endpoint and Email Security in GravityZone Platform

Bitdefender has integrated continuous email threat protection into its GravityZone platform, combining endpoint detection and response (EDR) with email security to combat phishing, BEC, and ransomware.

3 min read
Kraken Faces Extortion After Insider Breach Exposed Bug Bounty FlawHIGH
Threat Intel

Kraken Faces Extortion After Insider Breach Exposed Bug Bounty Flaw

Kraken's security team discovered an insider breach where a researcher exploited a zero-day flaw to steal $3 million in crypto, then demanded a bug bounty payment.

4 min read
McGraw-Hill Data Breach Linked to Exploited Salesforce MisconfigurationMEDIUM
Threat Intel

McGraw-Hill Data Breach Linked to Exploited Salesforce Misconfiguration

McGraw-Hill breached via a misconfigured Salesforce instance — ShinyHunters claim 13.5M user records exposed. Root cause, scope of access, and what educators and SaaS admins should check now.

3 min read
Triad Nexus Cybercrime Operation Evades Sanctions via Major Cloud ProvidersHIGH
Threat Intel

Triad Nexus Cybercrime Operation Evades Sanctions via Major Cloud Providers

The Triad Nexus cybercrime syndicate leverages major cloud and hosting providers to obscure its infrastructure, evade sanctions, and facilitate ransomware, data theft, and financial fraud.

4 min readTriad Nexus
Basic-Fit Data Breach Exposes 1 Million Member RecordsHIGH
Threat Intel

Basic-Fit Data Breach Exposes 1 Million Member Records

Hackers breached European gym chain Basic-Fit, accessing personal data of approximately one million members, including names, birthdates, and email addresses.

3 min read
ChipSoft Ransomware Attack Disrupts Dutch Healthcare IT ServicesHIGH
Threat Intel

ChipSoft Ransomware Attack Disrupts Dutch Healthcare IT Services

Dutch healthcare IT provider ChipSoft was hit by a ransomware attack, forcing it to take patient and provider portals offline, disrupting critical medical administration across the Netherlands.

3 min read
ShinyHunters Breaches Rockstar Games via Third-Party SaaS PlatformHIGH
Threat Intel

ShinyHunters Breaches Rockstar Games via Third-Party SaaS Platform

ShinyHunters breached Rockstar Games by exploiting the Anodot SaaS platform, accessing the company's Snowflake data environment and threatening to leak stolen data unless a ransom is paid.

3 min readShinyHunters
Ransomware Gangs Evolve EDR Evasion, Adopt New Driver-Based KillersHIGH
Threat Intel

Ransomware Gangs Evolve EDR Evasion, Adopt New Driver-Based Killers

ESET Research reports ransomware operators are expanding their arsenal of EDR-killing tools, moving beyond exploiting vulnerable drivers to using legitimate but maliciously signed drivers for stealth.

4 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.