Skip to main content

Tag: ransomware

1069 articles

Rows of computer servers and network equipment in a brightly-lit office server room.

PaperCut Zero-Days Exploited in Data Theft Attacks

Hackers are actively exploiting two zero-day vulnerabilities in PaperCut NG and MF, using them to bypass authentication and steal sensitive data from vulnerable print management servers. Attackers have already been spotted chaining these flaws to launch data theft attacks, prompting emergency patches from PaperCut Software.

Analyst 207
Rows of shelved medical supplies in a distribution center with employees checking a laptop.

McKesson Discloses Data Theft After ShinyHunters Extortion Attack

McKesson has confirmed a data theft incident following a cyberattack by ShinyHunters, but has assured customers that its business and distribution centers are up and running with no ongoing unauthorized activity. The company sprang into action, activating incident response protocols and launching an investigation to minimize disruption.

Analyst 207
Hospital staff stand in a dimly lit corridor near a medical device and computer.

Cyberattacks Disrupt Healthcare Firms, Compromise Patient Data

Millions of patient records are at risk and remote monitoring for newly implanted cardiac devices has been crippled after two major healthcare firms, Boston Scientific and McKesson, fell victim to separate cyberattacks. Boston Scientific's hack has left new pacemakers and heart devices unable to transmit vital data remotely, putting patients' health and privacy in immediate jeopardy.

Analyst 207
Federal law enforcement facility interior shows signs of concern and disruption.

ATF Cyber Breach Exposes Investigative Targets

The ATF's response to the Qilin ransomware gang's claim of a breach reveals how prepared - or unprepared - the agency was to tackle the incident. A cyber breach at the ATF potentially puts sensitive investigative targets at risk, but details on the incident remain scarce.

Analyst 207
Airport terminal interior with passengers and blurred check-in counter.

FulcrumSec Hack Exposes 86 GB of Manchester Airports Data

Manchester Airports Group swiftly sprang into action after a hack, reassuring customers that they've taken robust measures to safeguard their info and reaching out to those affected, including those with upcoming bookings, to offer extra support. Meanwhile, hackers FulcrumSec claimed responsibility, boasting of swiping 86 GB of sensitive data.

Analyst 207
Modern airport terminal lounge with laptop and papers on a table.

Manchester Airports Breach Exposes 8.7M Customer Records

A recent data breach at Manchester Airports Group exposed a whopping 8.7 million customer records, including emails, contact info, and vehicle registrations, after hackers demanded a ransom that was wisely refused. The breach is a stark reminder that public networks can put your data at risk, no matter how secure they seem.

Analyst 207
Modern office workspace with laptop, papers, and coding materials on tidy desk.

Ransomware Actors Exploit AI Tool in Sophisticated Attacks

Ransomware attackers are now using AI tools like Claude Sonnet to supercharge their assaults, with one group successfully exploiting the technology to target 10 victims in just a few weeks. By leveraging advanced tools like SpaceX's Cursor Agent, these cybercriminals are refining their tactics and getting bolder.

Analyst 207
A calm office lobby with a blurred digital screen on a reception desk.

CRPx0 Ransomware Service Rapidly Expands, Targets 48 Organizations

CRPx0's ransomware service has exploded onto the scene, rapidly expanding its reach to target a staggering 48 organizations - a number that's skyrocketed from fewer than 10 just a few months ago. This alarming growth follows the group's shift from a basic hacking service to a full-fledged, white-label ransomware operation.

Analyst 207
Federal law enforcement office with computers and desks in daylight.

ATF Probes Ransomware Gang's Claims of Major Cybersecurity Breach

A ransomware gang has claimed responsibility for a major cybersecurity breach, prompting a swift response from the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). The ATF is investigating the incident, but few details have been released so far.

Analyst 207
Blurred laptop on counter in retail setting suggests business data breach.

ShinyHunters Breach Exposes 12.9 Million Carhartt Accounts

A massive data breach at Carhartt has exposed a staggering 12.9 million customer accounts, compromising sensitive information and putting millions of people at risk. The breach, attributed to the ShinyHunters extortion group, included a treasure trove of customer, employee, and corporate data.

Analyst 207
Medical device manufacturing facility with equipment and staff, showing signs of disruption.

Boston Scientific Disrupts Global Operations After Cyber Incident

Boston Scientific's global operations have been significantly disrupted due to a cyber incident, affecting access to key systems and applications, including order processing and shipping. The incident has caused a major network outage, impacting the company's ability to operate normally worldwide.

Analyst 207
Federal law enforcement operations room with agents responding to a cyber incident.

ATF Breach Exposes Federal System to Qilin Ransomware Gang

The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a major breach of a standalone system, which was swiftly isolated to prevent further damage, and is now teaming up with the Department of Justice to investigate the Qilin Ransomware Gang's involvement. The incident appears to be contained, with no impact on the ATF's main enterprise network or other critical systems.

Analyst 207
Medical device manufacturing facility interior with workers and equipment.

Boston Scientific Cyberattack Disrupts Global Operations

A delayed shipment of a life-saving cardiac device can have devastating consequences, like a cancelled surgery - and that's exactly what's at risk when a cyberattack hits a medical device manufacturer like Boston Scientific. The recent attack has disrupted the company's global operations, causing order-processing delays that can have a ripple effect on patients' lives.

Analyst 207
Hospital staff stand in a brightly-lit corridor amidst medical equipment with disrupted computer screens and slightly…

Boston Scientific Hit by Global Cyberattack Disruption

Boston Scientific is facing significant disruptions to its operations after a global cyberattack hit its IT systems, limiting access to crucial business applications and hindering its ability to process and ship customer orders. The company is working closely with third-party experts to investigate and restore its systems, but a timeline for full recovery remains uncertain.

Analyst 207
Retail store setting with laptop and papers on counter, shelves and clothing racks in background.

Carhartt Breach Reveals 12.9M Affected, Exposes ShinyHunters' Data Padding Tactics

The Carhartt data breach just got a reality check: an analysis by Troy Hunt revealed that around 12.9 million accounts were genuinely affected, not nearly as many as initially claimed by the hackers. Turns out, you can't always take cybercriminals at their word!

Analyst 207
Hospital supply chain facility with industrial and medical equipment, shipping containers, and paperwork under fluorescent…

Boston Scientific Hit by Cyberattack Disrupting Global Operations

Boston Scientific's global operations have been disrupted by a cyberattack, causing significant hiccups in processing and shipping customer orders due to limited access to key information systems and business applications. The incident was detected on August 25, prompting an immediate response to mitigate the impact.

Analyst 207
Cybersecurity professionals gather around a laptop and whiteboard in a brightly-lit office conference room.

ReliaQuest Exposes ShinyHunters' Social Engineering Tactics

ReliaQuest sets the record straight: claims of a ransomware attack or breach are completely false. The company recently thwarted a social engineering scheme by ShinyHunters, swiftly investigating and publicly rebutting the misinformation.

Analyst 207
Hospital corridor with healthcare professionals, laptop, and medical equipment, conveying concern and vigilance.

Medusa Ransomware Gang Targets Over 500 Organizations, Experts Warn

The Medusa Ransomware gang has hit over 500 organizations since June 2021, and experts are sounding the alarm. This active and rapidly expanding Ransomware-as-a-Service campaign has prompted urgent warnings from top US security agencies.

Analyst 207
Dimly lit, cluttered office with scattered equipment and a lone chair in front of a computer screen.

Ransomware Affiliate Exploits Fellow Extortionists with 'Recovery' Scam

In a shocking twist, a ransomware affiliate is turning the tables on its own gang by posing as a recovery service, offering victims a way out for a fraction of the original ransom demand. The scammer, operating under the guise of "Ransom Busters," claims to have infiltrated the ransomware gangs' infrastructure and recovered stolen data.

Analyst 207
Empty office with laptop on desk, daylight streaming through window.

Ransomware Affiliate Exploits Trust with Fake Recovery Firm Tactics

Meet the scammers who pose as heroes: after a ransomware attack, a fake recovery firm called Ransom Busters claims to have the decryption key and stolen data - for a hefty fee. They promise to delete stolen data from ransomware servers, but it's all a ruse.

Analyst 207
Person sits at desk, scrutinizing laptop screen with skepticism in a dimly lit home office.

Ransomware Affiliate Exploits Trust with Fake Recovery Service

A new scam is targeting ransomware victims, with a fake recovery service called Ransom Busters offering to provide decryption keys and delete stolen data for a hefty fee of $20,000 to $60,000. The impostors are preying on people's trust, contacting them via email and claiming to have access to sensitive information.

Analyst 207
Industrial facility with automated systems, control screens, and logistics area in daylight.

Clop Exploits PTC Zero-Day in Large-Scale Data Theft Spree

Clop's latest large-scale data theft spree exploited a critical PTC zero-day vulnerability, CVE-2026-12569, affecting supply chain systems used by manufacturers, retailers, and industries like aerospace and automotive. This attack continues Clop's trend of targeting SaaS logistics companies with zero-days to carry out mass-exploitation campaigns.

Analyst 207
Compromised server room with interconnected devices and scattered cables.

Hackers Exploit 2,000 WordPress Sites in StopAndProtect Malware Campaign

This sneaky malware campaign, known as StopAndProtect, has already hacked nearly 2,000 WordPress sites, using a powerful toolkit that encrypts files, steals sensitive documents, and even lets attackers chat with their victims in real-time. The damage is widespread, with over 6,000 unique IP addresses affected worldwide.

Analyst 207
Dimly lit server room with laptop screen showing an email inbox.

Ransom Busters Emerges as New Player in Ransomware Extortion Economy

Meet Ransom Busters, a newcomer to the ransomware extortion economy that's shaking things up with its bold approach: offering to delete stolen data from ransomware groups' servers for a fee of $20,000 to $60,000. This third-party player claims to have been infiltrating ransomware-as-a-service operations for over three years.

Analyst 207