Skip to main content

Tag: ransomware attacks

25 articles

Hospital corridor with staff, medical device, and laptop, well-lit with daylight.

Medusa Ransomware Targets Over 500 Infrastructure Orgs, Expands Tactics

Medusa ransomware has hit a staggering 500+ critical infrastructure organizations, with healthcare being a prime target, as reported in a recent FBI advisory. The attacks are happening at an alarming rate, with exploitation windows as short as 24 hours or even less.

Analyst 207
Hospital corridor with staff, equipment, and furniture, conveying disruption and concern.

Medusa Ransomware Targets Over 500 US Critical Infrastructure Orgs

The Medusa ransomware gang has struck a staggering 500+ US critical infrastructure organizations across multiple sectors, including healthcare, defense, and finance, since June 2021. This alarming surge in attacks has prompted a joint warning from top US agencies, highlighting the urgent need for heightened cybersecurity measures.

Analyst 207
Server room with computer equipment and a monitor displaying lines of code in the foreground.

Clop Ransomware Gang Crafts Custom Web Shell for Windchill Attacks

The Clop ransomware gang has taken its attacks to the next level by crafting a custom Java web shell that specifically targets PTC Windchill and FlexPLM servers, allowing them to harvest sensitive data with ease. This tailored tool is a significant evolution of their mass-exploitation tactics, making it a major concern for businesses using these applications.

Analyst 207
Empty office interior with cubicles, private offices, and scattered papers, lit by soft daylight through windows.

Ransomware Attacks Singly Target Mid-Market Firms

Ransomware attacks are hitting mid-market firms with alarming frequency, and the threat is only escalating as AI-powered tools rapidly uncover new vulnerabilities at an overwhelming pace. Mid-market companies, with revenues between $10m and $1bn, now account for nearly three-quarters of ransomware attack victims.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center with concerned businesspeople in the background.

Clop Ransomware Targets GE, Philips in Data Theft Attacks

Major companies like Philips, General Electric, and Shell are investigating claims by the Clop ransomware gang that their systems were breached, with Philips confirming a contained breach of an internal server that didn't affect customers. The incidents are a stark reminder of the growing threat of ransomware attacks on businesses.

Analyst 207
Blurred laptop on reception desk in brightly-lit office lobby with large window.

Ransomware Attacks Pivot to Identity-Based Exploits

Ransomware attacks are taking a new and more personal approach, with a whopping 80% now targeting identities rather than software flaws. Malicious emails, phishing, and compromised credentials are the top entry points, making identity-based exploits the new favorite tactic of ransomware operators.

Analyst 207
Hospital reception area with concerned staff and a locked computer screen.

Ransomware Attacks Surge 20% as New Gangs Target Finance, Healthcare

Ransomware attacks are on the rise, surging 20% in July with a staggering 799 incidents reported, with finance, healthcare, and tech industries becoming prime targets for new gangs. The alarming increase marks the second-busiest month of the year so far, with the US leading the list of targeted countries.

Analyst 207
Hospital IT room with scattered papers, locked cabinet, and medical equipment in background, hinting at disruption.

Ransomware Attacks Spike 19% in July, Targeting Finance, Tech, and Healthcare

Ransomware attacks surged 19% in July, with 799 claimed incidents targeting key sectors like finance, tech, and healthcare. To stay safe, experts stress the importance of regular backups - and backups of those backups - to quickly restore systems and data in case of an attack.

Analyst 207
Industrial facility interior with computer workstations, machinery, and a laptop screen, with daylight through large windows.

Clop Ransomware Targets PTC Windchill in Data Theft Attacks

A critical vulnerability, CVE-2026-12569, with a near-perfect CVSS score of 9.3 is being exploited by Clop ransomware attackers to breach PTC Windchill and FlexPLM systems, putting sensitive data at risk. Security patches are available, but urgent action is needed to prevent data theft.

Analyst 207
Blurred computer screen amidst ordinary office equipment and decor suggests disruption.

Ransomware Attacks Exploited Compromised Identities in 79% of Incidents

Ransomware attacks are often sparked by something surprisingly simple: 79% of incidents start with compromised identities, highlighting the vulnerability of legitimate user logins and credentials. This means that in nearly 8 out of 10 cases, attackers gain a foothold using stolen or hijacked identities rather than complex hacking techniques.

Analyst 207
IT staff work in a network operations room with rows of equipment and technology.

Qilin Ransomware Gang Exploits Palo Alto VPN Bug in Ongoing Attacks

The Qilin ransomware gang is actively exploiting a critical vulnerability in Palo Alto Networks' VPN software, CVE-2026-0257, to breach security and launch attacks, despite a patch being released on May 13. This alarming development follows reports of multiple intrusions by Qilin in June, highlighting the urgent need for updates.

Analyst 207
Office worker sits at desk with laptop, showing subtle concern on face.

Ransomware Attacks Surge Through Compromised Logins

Ransomware attacks are surging, with a staggering 79% of incidents linked to compromised identities and legitimate user logins, making it the most common entry point for hackers. This marks a significant shift away from traditional software flaw exploitation, now accounting for just 18% of initial attacks.

Analyst 207
Rows of computer servers and storage equipment with warning lights on front panels in a brightly-lit data center.

Citrix Bleed 2 Exploit Fuels Ransomware Attacks

Ransomware attacks are on the rise, fueled by a new exploit that has already made a significant impact, and now a major software company has ordered its customers to take critical systems offline due to a credible security threat. Progress has urged customers to shut down vulnerable Windows servers to prevent potential breaches.

Analyst 207
Server room with equipment racks and monitors, a lone blank laptop screen in foreground.

Ransomware Operators Leverage AI for Autonomous Attacks

Meet JADEPUFFER, a pioneering threat actor that's harnessing AI to launch autonomous ransomware attacks - and adapting in real-time to get the job done. This groundbreaking tactic has been observed by researchers, who spotted JADEPUFFER's lightning-fast 31-second pivot from a failed login to a successful exploit.

Analyst 207
Person at desk looks concerned while staring at laptop in a brightly-lit office setting with blurred law enforcement logo…

Ransomware Attacks Targeted via Fake Interpol Emails

Beware of fake Interpol emails that could be ransomware traps! Cybercriminals are impersonating the law enforcement agency, sending unsolicited emails with suspicious links and password-protected files, trying to trick organizations into compromising their security.

Analyst 207
Empty hospital corridor with people in distance, blurred laptop screen on nearby desk, conveying concern and unease.

Ransomware Attacks Surge Across Europe

Ransomware attacks are surging across Europe, with a staggering 55.1% year-over-year increase in just the first four months of 2026, averaging 171 incidents per month. Five key countries - Germany, the UK, France, Italy, and Spain - are bearing the brunt, accounting for 70% of all recorded attacks.

Analyst 207
Modern office space with scattered papers and an open file cabinet, hinting at disruption.

Ransomware Attacks Shift to Data Theft Tactics

Ransomware attacks have taken a sinister turn, with a growing number of hackers ditching decryption keys and instead using stolen data to extort their victims. In fact, a recent report found that a whopping 87% of ransomware claims now involve data theft, with encryption becoming a thing of the past.

Analyst 207
Law enforcement officials stand in front of seized servers in a briefing room.

Law Enforcement Disrupts First VPN Service Tied to Ransomware Attacks

In a major cybercrime crackdown, law enforcement agencies have dismantled a notorious VPN service used by ransomware attackers, seizing 33 servers and taking its domains offline in a coordinated operation across 27 countries. The takedown of First VPN, a so-called "no-logs" provider, has dealt a significant blow to threat actors behind ransomware and data theft campaigns.

Analyst 207
Laptop screen displays Microsoft Teams meeting in modern office setting with blurred cityscape background.

MuddyWater Exploits Microsoft Teams in False Flag Ransomware Attacks

MuddyWater hackers are impersonating Chaos ransomware affiliates, using clever social engineering tactics via Microsoft Teams to steal credentials and gain access to sensitive systems. Their sophisticated campaign involves interactive screen-sharing and manipulation of multi-factor authentication.

Analyst 207
Formal courthouse or government building interior with subtle seal emblem.

Cybersecurity Experts Imprisoned for Ransomware Extortion Scheme

Two American cybersecurity experts, Ryan Goldberg and Kevin Martin, have been sentenced to prison for their roles in a brazen 2023 ransomware campaign that targeted companies across the United States. Their crimes have brought to light the severe consequences of cyberattacks and the importance of protecting businesses from such threats.

Analyst 207
Government building with tall windows, abstract seal, and blurred laptop in foreground.

US Sentences Two Cybersecurity Pros for BlackCat Ransomware Role

Two cybersecurity experts turned to a life of crime, using their specialized knowledge to extort victims through BlackCat ransomware attacks, and have been sentenced to four years in prison for their roles. Ryan Goldberg and Kevin Martin deployed the ransomware against multiple US victims between April and December 2023.

Analyst 207
Cracked laptop screen with eerie glow, snake-like cord morphing into menacing stone face.

Microsoft Uncovers Storm-1175's Medusa Ransomware Link

Microsoft just dropped a crucial report linking Storm-1175, a notorious threat actor, to high-velocity Medusa ransomware attacks that exploit flaws in networked systems. This newly uncovered connection raises the alarm for anyone building, defending, or relying on these systems to stay vigilant against Medusa ransomware attacks.

Analyst 207
China-Linked Storm-1175 Weaponizes Zero-Days to Fuel Medusa Ransomware Blitz

China-Linked Storm-1175 Weaponizes Zero-Days to Fuel Medusa Ransomware Blitz

Medusa ransomware attacks are happening at alarming speed, thanks to a China-linked threat actor called Storm-1175 that is exploiting a potent mix of zero-day and known vulnerabilities to rapidly infect exposed systems. This high-velocity campaign is a stark reminder of the evolving ransomware threat landscape.

Analyst 207
BKA Unmasks REvil Ransomware Leaders Behind 130 German Attacks

BKA Unmasks REvil Ransomware Leaders Behind 130 German Attacks

Germany's Federal Criminal Police Office has made a major breakthrough, unmasking the leaders behind the notorious REvil ransomware operation, responsible for 130 devastating attacks on companies, hospitals, and municipalities across the country. The culprits, once hidden behind aliases, have finally been exposed.

Analyst 207