Ransomware

AI-Assisted Ransomware Gang Tore Through a Corporate Network in Under 10 Hours
Researchers at Palo Alto Networks watched attackers use artificial intelligence agents to do in a single working day what normally takes criminal crews two weeks. The case is a signal, not an outlier.

Six things MSPs should actually test before the next ransomware hit
Acronis lays out a practical checklist for managed service providers, moving the conversation past backups and antivirus to the full arc of prevention, detection and recovery.

Rhysida gang claims theft of 5.79TB from Berlin's city government
The ransomware crew says it took 1.44 million files, including water-supply security assessments and plaintext passwords. Berlin's mayor says the city will not pay.

Aurora ransomware crew caught using Cursor AI to break into networks
Researchers at CloudSEK and Gambit Security tie a Russian-speaking gang to at least 10 intrusions built with help from SpaceX's coding assistant.

Ransomware group falcon claims attack on Globus Medical
A criminal group has listed the US medical-device maker on its dark-web extortion site, allegedly claiming nearly 3 terabytes of sensitive company data. Globus Medical has not publicly confirmed any incident.

Cyber attack on Australian book distributor leaves bookshops empty-handed before Christmas
A suspected ransomware attack on Alliance Distribution Services has disrupted book supply across Australia for six weeks, hitting independent bookshops and Hachette authors at the worst possible time.

US firearms agency ATF confirms 'major incident' as Qilin ransomware gang lists it as a victim
The Bureau of Alcohol, Tobacco, Firearms and Explosives says a standalone system was breached. The Qilin ransomware crew added ATF to its dark web leak site the same day.

Ransomware group Helix claims attack on US energy testing firm AmSpec
A criminal gang called Helix has listed AmSpec on its dark-web leak site, claiming to have broken into the company. AmSpec has not confirmed any incident, and the claim remains unverified.

Medusa ransomware has hit 500 critical infrastructure targets, US agencies warn
A fresh CISA advisory says the gang's victim count has jumped from 300 to over 500 since March 2025, with hospitals, defence suppliers and banks all in the firing line.

The Ransomware Scavengers: 'Ransom Busters' Emails Victims Demanding Up to $60,000
A new outfit is contacting companies already hit by ransomware and offering, for a fee, to wipe their stolen files from the attackers' servers.

Fake 'Ransom Busters' Service Is Actually a Ransomware Insider Running a Side Scam
A criminal pretending to rescue hack victims is really a ransomware affiliate trying to pocket ransom money before his own gang gets it.

Ransomware group Interlock claims attack on Connell Enterprises LLC
A criminal group has listed a US business on its dark-web pressure site. The company has not confirmed anything, and the claim cannot be independently verified.

Shell probes possible data theft as Clop ransomware crew names it in engineering software raid
The gang claims 89GB of drawings and project files, part of a wider spree hitting PTC Windchill and FlexPLM systems.

Akira gang reboots into Safe Mode to blind security tools, then fumbles the ransom
The hackers walked in through a SonicWall VPN with no second login step, but their own ransomware ran out of memory before it could lock a single file.

Ransomware Hit Colombia's Justice Ministry Five Days Before a New President Took Office
Files were encrypted, services went down, and ColCERT had warned about exactly this kind of attack the day before. Here is what happened, and why Colombia keeps ending up in the crosshairs.