Skip to main content

Tag: ransomware

1069 articles

Maksim Silnikau sits in defendant's chair in a federal courthouse with a judge's bench and Department of Justice seal in…

Ransom Cartel Creator Sentenced to 16 Years for Global Cyberattacks

Meet Maksim Silnikau, the mastermind behind the notorious Ransom Cartel, who's now facing 16 years behind bars for masterminding a global cyberattack spree that targeted at least 18 companies and raked in millions for him. The US Department of Justice brought him to justice, sentencing him for conspiracy, wire fraud, and identity theft.

Analyst 207
Brazilian school hallway with outdated computer lab and subtle signs of disruption.

Brazilian Schools Exposed to Cyberattacks via Weak Credentials, Outdated Systems

Brazilian schools are under cyberattack, with weak credentials and outdated systems leaving them vulnerable to hackers. New data reveals a hotbed of incidents in São Paulo, Rio de Janeiro, and Pernambuco, with private institutions bearing the brunt of high-severity ransomware attacks.

Analyst 207
Dimly lit police station interior with scattered papers and files, suggesting disarray.

ExfilSquad Breach Exposes Data of 100,000 UK Police Officers

A massive data breach has hit the UK police force, with a hacking group claiming to have stolen sensitive information from over 100,000 officers, including names, organizations, and email addresses. The breach, attributed to ExfilSquad, has left thousands of police personnel and government partners vulnerable to potential identity theft and harassment.

Analyst 207
Clean home security system control panel on a residential hallway wall.

ShinyHunters Breach Exposes Brinks Home Data

Brinks Home recently disclosed a security breach, with an extortion group claiming to have exposed millions of customer records, prompting the company to activate its incident response procedure and work with leading forensics experts to contain the damage. The breach, identified on July 20, thankfully didn't impact alarm monitoring and system functionality.

Analyst 207
Dairy production facility with stainless steel equipment and milk bottles on a pallet.

Ransomware Breach Exposes Fairlife's Data, Disrupts Production

Fairlife has bounced back from a ransomware attack, with Coca-Cola confirming that the majority of production has resumed at its four US facilities. The breach, which involved unauthorized access and data theft, has had a minimal impact on the retail availability of Fairlife products.

Analyst 207
Dairy production facility with stainless steel equipment and milk bottles on a conveyor belt.

Coca-Cola Discloses Data Theft in Fairlife Ransomware Attack

Coca-Cola has confirmed that its dairy subsidiary, Fairlife, was hit by a ransomware attack, resulting in data theft by hackers. The company is working to restore impacted systems and operations, with most US production now back online.

Analyst 207
Modern computer workstation with security software dashboard and office background.

Ransomware Groups Master EDR Kill Techniques

Ransomware groups have mastered the art of disabling endpoint detection and response (EDR) tools, making it standard practice to shut them down before encryption begins. This sinister tactic has significantly shortened defenders' response time, leaving them with limited opportunities to detect and contain attacks.

Analyst 207
Brightly-lit industrial control system terminal on a factory floor.

Cl0p Ransomware Gang Exploits PTC Windchill Flaw in Data Extortion Drive

PTC Windchill users are under attack, with threat actors actively exploiting a critical flaw (CVE-2026-12569) that allows for remote code execution, prompting PTC to warn customers of heightened threat activity. This vulnerability, with a CVSS score of 9.3, has already been added to the US government's list of known exploited vulnerabilities.

Analyst 207
University building with locked computer screens and concerned students in background.

Ransomware Attacks Intensify Against Universities Worldwide

Universities worldwide are under siege by ransomware attacks, with a single group called The Gentlemen responsible for a staggering 80% of their attacks on the education sector, and a 275% surge in attacks on education in just the first half of 2026. This alarming trend has contributed to a spike in ransomware activity against universities, despite an overall decline in recorded incidents across the broader education sector.

Analyst 207
Train manufacturing facility interior with control panel in foreground.

Swiss Train Maker Thwarts Ransomware Demand

A Swiss train maker, Stadler Rail, recently outsmarted a ransomware attack by refusing to give in to a hefty $123 million extortion demand from hackers. By taking a firm stance, the company protected its operational integrity and public reputation.

Analyst 207
Person sits at desk with laptop, surrounded by empty office space, browser window open.

Chaos Ransomware Gang Exploits Browsers for Stealthy C2 Communications

Cisco Talos researchers have uncovered a sneaky new backdoor, msaRAT, that hijacks Chrome or Microsoft Edge to secretly communicate with its command center, avoiding direct network connections. This stealthy tactic uses the browser's remote debugging interface to inject JavaScript and stay under the radar.

Analyst 207
Concerned office worker holding a smartphone at their desk surrounded by papers and office supplies.

Ransomware Attacks Intensify as AI Enhances Phishing Tactics

Ransomware attacks are getting smarter and more effective, with AI-powered phishing tactics leading to a significant increase in successful breaches. In fact, 65% of organizations hit by ransomware say AI tools made the attack more convincing and effective.

Analyst 207
Swiss industrial facility with machinery and subtle tech setup in background.

Stadler Rail Rebuffs $12.3M Ransom Demand by Everest Gang

Stadler Rail is taking a firm stance against ransomware extortion, boldly refusing to pay the $12.3 million demanded by the Everest gang after a mid-July data breach. The company has instead filed a criminal complaint, making it clear that it will never give in to such threats.

Analyst 207
Corporate office interior with employees working, featuring a large blank whiteboard in the foreground.

Ransomware Risk Amplified by Enterprise GenAI Deployments

With enterprise GenAI deployments on the rise, the ransomware risk is skyrocketing - after all, Microsoft alone detects over 38 million identity risk signals daily, a stark reminder that AI-enabled attacks can strike at any moment. As attackers supercharge their ops with AI, businesses are unwittingly increasing their vulnerability by deploying AI systems that can be exploited.

Analyst 207
Businessperson looks concerned while staring at laptop screen in office setting.

Ransomware gangs exploit victims' payments, extort again

Paying ransomware attackers doesn't always guarantee relief, with many victims being extorted again. A recent survey found 54% of organizations globally paid a ransom, yet it often doesn't end the attack.

Analyst 207
Damaged server equipment in a data center with concerned technicians in the background.

JADEPUFFER Evolves to Target AI Models with Ransomware

JADEPUFFER's latest move is a game-changer: they're now using ransomware to destroy AI models, leaving encrypted artifacts irretrievable. This devastating attack can cost victims up to $500,000 or more in training and computing losses.

Analyst 207
Rows of computer equipment in a dimly lit server room lie in disarray, cables scattered and screens flickering with error…

AI Emerges as Force Multiplier in Cyberattacks

As AI continues to evolve, it's crucial to treat AI-driven threats as a top priority, as they can significantly accelerate and scale attacks. By leveraging AI, cyber attackers can speed up their operations, but their tactics remain familiar, including credential theft, phishing, and ransomware.

Analyst 207
Ransom note emerges from printer paper tray on cluttered office desk.

BitLocker Extortion Tactics Target Firms via Printer Ransom Notes

Cybercriminals are using a clever and intimidating tactic to extort money from companies, deploying BitLocker to lock down files and leaving ransom notes printed out on physical printers. The attackers guarantee their promises will be kept, boasting a flawless online reputation to back up their threats.

Analyst 207
Control room with industrial and technological elements, emphasizing security and access control.

Zero Trust Bolsters Critical Infrastructure Against Identity Threats

A single compromised account, like the inactive VPN login used to breach Colonial Pipeline in 2021, can have devastating ripple effects - just imagine a national crisis triggered by a simple vulnerability. The Colonial Pipeline ransomware attack is a stark reminder of the catastrophic consequences that can unfold when critical infrastructure is compromised.

Analyst 207
City street with busy storefronts and office buildings, hinting at disruption.

Ransomware Landscape Fractures as New Groups Proliferate

The ransomware landscape is shattering into more factions than ever, with over one new group emerging every week in 2026, according to the Black Kite Ransomware Report. This explosion of new players has led to a surge in attacks, with 61 new groups appearing in just one year alone.

Analyst 207
Cluttered tech lab with AI equipment, laptop screen shows AI model file access.

ENCFORGE Ransomware Targets AI Model Files in Langflow Attack

A new ransomware called ENCFORGE is targeting AI model files, exploiting a high-severity flaw in Langflow to deploy a custom-built payload that threatens machine learning systems. This highly specialized attack focuses on encrypting critical AI data, including PyTorch, TensorFlow, and Hugging Face files.

Analyst 207
Server room with rows of computer servers and a lone laptop with a blank screen.

JadePuffer Unleashes AI-Targeted Ransomware with Data Wiping Capabilities

In a chilling display of cyber sophistication, JadePuffer unleashed a devastating ransomware attack that not only locked up data but also boasted data-wiping capabilities, leaving a trail of destruction in its wake. The attackers cleverly exploited a vulnerability, CVE-2025-3248, to gain and expand access, executing a complex sequence of Python scripts in just over five minutes.

Analyst 207
Handcuffed young men escorted by a stern-looking officer outside a UK courthouse.

UK Sentences Scattered Spider Members to 66 Months for Cyberattacks

In a major cybercrime crackdown, two young men have been sentenced to 66 months in jail for their role in a 2024 cyberattack that crippled Transport for London's network operations. Thalha Jubair and Owen Flowers were arrested and pleaded guilty, marking a significant win for the UK's National Crime Agency after nearly two years of investigation.

Analyst 207
Government office with a barricaded door and encrypted computer screen.

Ransomware Targets Government Agencies Daily, Study Reveals

Government agencies are under attack, with ransomware hitting a staggering 187 organizations in just six months - that's one body disrupted every single day, on average. This alarming trend is up 13% from the previous half-year, leaving public services vulnerable and citizens at risk.

Analyst 207