Skip to main content

Tag: ransomware as a service

34 articles

Hospital corridor with healthcare professionals, laptop, and medical equipment, conveying concern and vigilance.

Medusa Ransomware Gang Targets Over 500 Organizations, Experts Warn

The Medusa Ransomware gang has hit over 500 organizations since June 2021, and experts are sounding the alarm. This active and rapidly expanding Ransomware-as-a-Service campaign has prompted urgent warnings from top US security agencies.

Analyst 207
Empty office with laptop on desk, daylight streaming through window.

Ransomware Affiliate Exploits Trust with Fake Recovery Firm Tactics

Meet the scammers who pose as heroes: after a ransomware attack, a fake recovery firm called Ransom Busters claims to have the decryption key and stolen data - for a hefty fee. They promise to delete stolen data from ransomware servers, but it's all a ruse.

Analyst 207
Person sits at desk, scrutinizing laptop screen with skepticism in a dimly lit home office.

Ransomware Affiliate Exploits Trust with Fake Recovery Service

A new scam is targeting ransomware victims, with a fake recovery service called Ransom Busters offering to provide decryption keys and delete stolen data for a hefty fee of $20,000 to $60,000. The impostors are preying on people's trust, contacting them via email and claiming to have access to sensitive information.

Analyst 207
Hospital corridor with people walking, computer workstation, and door in background.

Medusa Ransomware Expands Reach with New Tactics, Hundreds More Victims

The Medusa ransomware gang is on the loose, exploiting unpatched software to target hundreds of victims across various sectors, with the Healthcare and Public Health industry being a frequent hit. Now, US agencies have issued an updated warning, detailing the group's latest tactics and partnerships.

Analyst 207
City transit platform with disrupted digital screens and halted trains.

US, South Korea Warn of Gunra Ransomware Threat

Meet Gunra, a highly sophisticated ransomware threat that's been wreaking havoc since April 2025, evolving from a Windows-targeting menace to a cross-platform attacker with a thriving commercial ecosystem. This malicious force has rapidly expanded its reach, morphing into a full-fledged ransomware-as-a-service operation by January 2026.

Analyst 207
Modern office setting with idle computers, hinting at disruption or concern.

US, South Korea Warn of Gunra Ransomware Gang's Global Reach

US and South Korean authorities are sounding the alarm on the global threat of the Gunra Ransomware Gang, warning that this malicious group has evolved into a sophisticated ransomware-as-a-service operation. The joint advisory aims to alert network defenders to the gang's growing reach and devastating impact on organizations worldwide.

Analyst 207
Network equipment racks with a SonicWall device in a well-lit office IT room.

INC Ransomware Exploits SonicWall Zero-Days Amid Rising Attacks

INC ransomware is rapidly exploiting recently patched SonicWall zero-days, with researchers warning of a surge in attacks. This ransomware-as-a-service operation is now the most active threat actor taking advantage of the vulnerability chain.

Analyst 207
Dimly lit workspace with a single bright laptop screen surrounded by clutter and papers.

DevMan Ransomware Operation Centralizes Affiliate Payouts, Victim Management

Meet the DevMan Ransomware Operation's game-changing portal, where affiliates can now streamline payouts and victim management in one centralized hub. This all-in-one platform combines build generation, finance, victim chat, and support, making it a one-stop-shop for ransomware attacks.

Analyst 207
Network equipment on a rack in a mid-tone lit IT room with blurred background.

Qilin Ransomware Exploits Palo Alto Networks Flaw for Initial Access

In a recent wave of attacks, hackers exploited a high-severity flaw in Palo Alto Networks' PAN-OS software to gain initial access for Qilin ransomware attacks. This vulnerability, known as CVE-2026-0257, allowed attackers to bypass authentication and establish VPN sessions without valid credentials.

Analyst 207
Dimly lit server closet with cluttered computer equipment and cables.

The Gentlemen Ransomware Expands Reach with Lucrative Affiliate Model

Meet The Gentlemen, a ransomware group that's rapidly risen to notoriety with a game-changing affiliate model that dishes out a whopping 90% payout to its partners. This lucrative approach has helped them scale from a small operation to one of 2026's most active ransomware-as-a-service programs in record time.

Analyst 207
Cramped warehouse storage area with industrial computer equipment and tangled cables.

Ransomware Gang Exploits Supply Chain Attacks in New Partnership

Ransomware gangs are now operating like businesses, forming partnerships to supercharge their attacks - and a new alliance between Vect and TeamPCP is a prime example, combining massive credential theft with devastating ransomware-as-a-service operations. This unprecedented pairing puts organizations directly in the crosshairs.

Analyst 207
Brightly-lit industrial setting shows subtle signs of disruption.

The Gentlemen Ransomware Gang Exposes Advanced Tactics

Meet The Gentlemen, a notorious ransomware gang that's made a name for itself with sophisticated tactics, ranking among the top 10 ransomware actors in just a few months. Since February 2026, they've been wreaking havoc across industries and geographies, with a strong presence in Brazil, China, Indonesia, Taiwan, and Thailand.

Analyst 207
Hospital corridor with blurred patient room doors and a lone computer workstation.

INC Ransomware Targets 830+ Victims, Expands as Major RaaS Threat

The INC ransomware group has rapidly grown into a major threat, claiming over 830 victims since August 2023, with US organizations making up more than 65% of those affected. Sectors such as legal services, manufacturing, and healthcare are among the most targeted, as INC expands its reach as a prominent Ransomware as a Service (RaaS) operation.

Analyst 207
Modern office space with scattered papers and an open file cabinet, hinting at disruption.

Ransomware Attacks Shift to Data Theft Tactics

Ransomware attacks have taken a sinister turn, with a growing number of hackers ditching decryption keys and instead using stolen data to extort their victims. In fact, a recent report found that a whopping 87% of ransomware claims now involve data theft, with encryption becoming a thing of the past.

Analyst 207
Dimly lit server room with rows of computer servers, one device highlighted in brighter light.

Ransomware Gang 'The Gentlemen' Traced to Suspected Russian Operator

Meet The Gentlemen, a notorious ransomware gang that's rapidly growing in power thanks to its unusually generous 90/10 affiliate revenue split, outshining the industry standard 80/20 and attracting top talent from rival groups. This bold move has catapulted them to become the second most active ransomware group, with over 332 reported victims since mid-2025.

Analyst 207
Suited figure in shadows surrounded by devices with encrypted screens.

Gentlemen Ransomware Spreads Rapidly Through Affiliate Network

Gentlemen Ransomware is spreading rapidly through its affiliate network, fueling a surge in multi-platform attacks and infections linked to the malicious tool SystemBC. This ransomware-as-a-service operation is making it alarmingly easy for cybercriminals to join the fray and wreak havoc.

Analyst 207
Ancient jackal head sculpture looms over darkened tech HQ, with shattered laptop in foreground.

Anubis Ransomware Gang Targets Signature Healthcare in 2TB Data Heist

In a chilling 2TB data heist, the Anubis ransomware gang has struck Signature Healthcare in Massachusetts, stealing sensitive patient information despite claiming they didn't encrypt the hospital's systems. As the healthcare system scrambles to cope, patients are feeling the impact, with ambulance patients being diverted and clinicians forced to go old-school with paper records.

Analyst 207
Glowing snake coils around skyscraper, morphing into code-like circuitry, with a lone figure in a hoodie working on a…

Ransomware Evolves with AI-Fueled Mutation Tactics

The game-changing threat of AI-fueled ransomware is here: hackers can now wield polymorphic malware that mutates on the fly, making it exponentially harder to detect and stop. This emerging menace is made possible by ransomware-as-a-service platforms supercharged with artificial intelligence.

Analyst 207
BKA Unmasks REvil Ransomware Leaders Behind 130 German Attacks

BKA Unmasks REvil Ransomware Leaders Behind 130 German Attacks

Germany's Federal Criminal Police Office has made a major breakthrough, unmasking the leaders behind the notorious REvil ransomware operation, responsible for 130 devastating attacks on companies, hospitals, and municipalities across the country. The culprits, once hidden behind aliases, have finally been exposed.

Analyst 207
Akira Ransomware Executes Attacks in Under 60 Minutes

Akira Ransomware Executes Attacks in Under 60 Minutes

Akira ransomware has become alarmingly efficient, capable of executing a full-scale attack in under 60 minutes - leaving organizations with an incredibly tight window to detect and respond to threats. This lightning-fast strike highlights the urgent need for robust security measures to counter the rapidly evolving ransomware landscape.

Analyst 207
University of Mississippi Medical Center Offline: Shocking

University of Mississippi Medical Center Offline: Shocking

When a ransomware attack knocked the University of Mississippi Medical Center offline, clinicians were reduced to paper charts and radios while appointments and critical systems stalled. Its a stark reminder that cybercrime now threatens not just data and dollars, but patient care and safety.

Analyst 207
Ransomware Exclusive: Stunning Worst Surge of 2025

Ransomware Exclusive: Stunning Worst Surge of 2025

Think ransomware was fading? The 2025 ransomware surge proves otherwise—smarter, faster attacks (retail incidents jumped 58% in Q2) are crippling stores, exposing data and stretching insurers and regulators to the breaking point.

Analyst 207
Security Leaders Exclusive: Alarming Marquis Breach Insight

Security Leaders Exclusive: Alarming Marquis Breach Insight

The Marquis data breach forces a simple but urgent question: when a trusted provider is compromised, who pays — the vendor, its customers, or the wider ecosystem? With attackers evolving faster than defenders, security leaders say it’s time to rethink third‑party and supply‑chain risk.

Analyst 207
Cyber-Insurance Payouts Soar 230% UK Stunning Costly Spike

Cyber-Insurance Payouts Soar 230% UK Stunning Costly Spike

Think cyber insurance is a safety net? With UK payouts up 230% in 2024, rising ransoms and recovery bills are forcing businesses and regulators to rethink who will shoulder the real cost of cyber attacks.

Analyst 207