Tag: ransomware as a service
34 articles

Medusa Ransomware Gang Targets Over 500 Organizations, Experts Warn
The Medusa Ransomware gang has hit over 500 organizations since June 2021, and experts are sounding the alarm. This active and rapidly expanding Ransomware-as-a-Service campaign has prompted urgent warnings from top US security agencies.

Ransomware Affiliate Exploits Trust with Fake Recovery Firm Tactics
Meet the scammers who pose as heroes: after a ransomware attack, a fake recovery firm called Ransom Busters claims to have the decryption key and stolen data - for a hefty fee. They promise to delete stolen data from ransomware servers, but it's all a ruse.

Ransomware Affiliate Exploits Trust with Fake Recovery Service
A new scam is targeting ransomware victims, with a fake recovery service called Ransom Busters offering to provide decryption keys and delete stolen data for a hefty fee of $20,000 to $60,000. The impostors are preying on people's trust, contacting them via email and claiming to have access to sensitive information.

Medusa Ransomware Expands Reach with New Tactics, Hundreds More Victims
The Medusa ransomware gang is on the loose, exploiting unpatched software to target hundreds of victims across various sectors, with the Healthcare and Public Health industry being a frequent hit. Now, US agencies have issued an updated warning, detailing the group's latest tactics and partnerships.

US, South Korea Warn of Gunra Ransomware Threat
Meet Gunra, a highly sophisticated ransomware threat that's been wreaking havoc since April 2025, evolving from a Windows-targeting menace to a cross-platform attacker with a thriving commercial ecosystem. This malicious force has rapidly expanded its reach, morphing into a full-fledged ransomware-as-a-service operation by January 2026.

US, South Korea Warn of Gunra Ransomware Gang's Global Reach
US and South Korean authorities are sounding the alarm on the global threat of the Gunra Ransomware Gang, warning that this malicious group has evolved into a sophisticated ransomware-as-a-service operation. The joint advisory aims to alert network defenders to the gang's growing reach and devastating impact on organizations worldwide.

INC Ransomware Exploits SonicWall Zero-Days Amid Rising Attacks
INC ransomware is rapidly exploiting recently patched SonicWall zero-days, with researchers warning of a surge in attacks. This ransomware-as-a-service operation is now the most active threat actor taking advantage of the vulnerability chain.

DevMan Ransomware Operation Centralizes Affiliate Payouts, Victim Management
Meet the DevMan Ransomware Operation's game-changing portal, where affiliates can now streamline payouts and victim management in one centralized hub. This all-in-one platform combines build generation, finance, victim chat, and support, making it a one-stop-shop for ransomware attacks.

Qilin Ransomware Exploits Palo Alto Networks Flaw for Initial Access
In a recent wave of attacks, hackers exploited a high-severity flaw in Palo Alto Networks' PAN-OS software to gain initial access for Qilin ransomware attacks. This vulnerability, known as CVE-2026-0257, allowed attackers to bypass authentication and establish VPN sessions without valid credentials.

The Gentlemen Ransomware Expands Reach with Lucrative Affiliate Model
Meet The Gentlemen, a ransomware group that's rapidly risen to notoriety with a game-changing affiliate model that dishes out a whopping 90% payout to its partners. This lucrative approach has helped them scale from a small operation to one of 2026's most active ransomware-as-a-service programs in record time.

Ransomware Gang Exploits Supply Chain Attacks in New Partnership
Ransomware gangs are now operating like businesses, forming partnerships to supercharge their attacks - and a new alliance between Vect and TeamPCP is a prime example, combining massive credential theft with devastating ransomware-as-a-service operations. This unprecedented pairing puts organizations directly in the crosshairs.

The Gentlemen Ransomware Gang Exposes Advanced Tactics
Meet The Gentlemen, a notorious ransomware gang that's made a name for itself with sophisticated tactics, ranking among the top 10 ransomware actors in just a few months. Since February 2026, they've been wreaking havoc across industries and geographies, with a strong presence in Brazil, China, Indonesia, Taiwan, and Thailand.

INC Ransomware Targets 830+ Victims, Expands as Major RaaS Threat
The INC ransomware group has rapidly grown into a major threat, claiming over 830 victims since August 2023, with US organizations making up more than 65% of those affected. Sectors such as legal services, manufacturing, and healthcare are among the most targeted, as INC expands its reach as a prominent Ransomware as a Service (RaaS) operation.

Ransomware Attacks Shift to Data Theft Tactics
Ransomware attacks have taken a sinister turn, with a growing number of hackers ditching decryption keys and instead using stolen data to extort their victims. In fact, a recent report found that a whopping 87% of ransomware claims now involve data theft, with encryption becoming a thing of the past.

Ransomware Gang 'The Gentlemen' Traced to Suspected Russian Operator
Meet The Gentlemen, a notorious ransomware gang that's rapidly growing in power thanks to its unusually generous 90/10 affiliate revenue split, outshining the industry standard 80/20 and attracting top talent from rival groups. This bold move has catapulted them to become the second most active ransomware group, with over 332 reported victims since mid-2025.

Gentlemen Ransomware Spreads Rapidly Through Affiliate Network
Gentlemen Ransomware is spreading rapidly through its affiliate network, fueling a surge in multi-platform attacks and infections linked to the malicious tool SystemBC. This ransomware-as-a-service operation is making it alarmingly easy for cybercriminals to join the fray and wreak havoc.

Anubis Ransomware Gang Targets Signature Healthcare in 2TB Data Heist
In a chilling 2TB data heist, the Anubis ransomware gang has struck Signature Healthcare in Massachusetts, stealing sensitive patient information despite claiming they didn't encrypt the hospital's systems. As the healthcare system scrambles to cope, patients are feeling the impact, with ambulance patients being diverted and clinicians forced to go old-school with paper records.

Ransomware Evolves with AI-Fueled Mutation Tactics
The game-changing threat of AI-fueled ransomware is here: hackers can now wield polymorphic malware that mutates on the fly, making it exponentially harder to detect and stop. This emerging menace is made possible by ransomware-as-a-service platforms supercharged with artificial intelligence.

BKA Unmasks REvil Ransomware Leaders Behind 130 German Attacks
Germany's Federal Criminal Police Office has made a major breakthrough, unmasking the leaders behind the notorious REvil ransomware operation, responsible for 130 devastating attacks on companies, hospitals, and municipalities across the country. The culprits, once hidden behind aliases, have finally been exposed.

Akira Ransomware Executes Attacks in Under 60 Minutes
Akira ransomware has become alarmingly efficient, capable of executing a full-scale attack in under 60 minutes - leaving organizations with an incredibly tight window to detect and respond to threats. This lightning-fast strike highlights the urgent need for robust security measures to counter the rapidly evolving ransomware landscape.

University of Mississippi Medical Center Offline: Shocking
When a ransomware attack knocked the University of Mississippi Medical Center offline, clinicians were reduced to paper charts and radios while appointments and critical systems stalled. Its a stark reminder that cybercrime now threatens not just data and dollars, but patient care and safety.

Ransomware Exclusive: Stunning Worst Surge of 2025
Think ransomware was fading? The 2025 ransomware surge proves otherwise—smarter, faster attacks (retail incidents jumped 58% in Q2) are crippling stores, exposing data and stretching insurers and regulators to the breaking point.

Security Leaders Exclusive: Alarming Marquis Breach Insight
The Marquis data breach forces a simple but urgent question: when a trusted provider is compromised, who pays — the vendor, its customers, or the wider ecosystem? With attackers evolving faster than defenders, security leaders say it’s time to rethink third‑party and supply‑chain risk.

Cyber-Insurance Payouts Soar 230% UK Stunning Costly Spike
Think cyber insurance is a safety net? With UK payouts up 230% in 2024, rising ransoms and recovery bills are forcing businesses and regulators to rethink who will shoulder the real cost of cyber attacks.