Ransomware — Page 2

DeadLock Ransomware Moves Its Extortion Kit onto the Blockchain
The gang is stitching together Session chat and Polygon smart contracts so takedowns don't stick. Microsoft calls it a resilience play. We'd call it ransomware learning from crypto scams.

Old Medusa Hand, New Locker: Storm-1175 Rolls Out StormEncryptor via N-central Flaw
Microsoft says a China-linked crew is exploiting a critical bug in N-able's remote management tool to plant a fresh ransomware strain, sometimes within days of breaking in.

US and Korean agencies warn about Gunra, a fast-growing ransomware gang built from leaked Conti code
The FBI, CISA and Korea's National Police Agency say Gunra has hit hospitals, utilities, banks and manufacturers across five continents since April 2025.

Ransomware crews are now breaking into SonicWall VPN boxes through two July flaws
CISA says gangs are exploiting a maximum-severity SonicWall SMA1000 bug that has been patched since mid-July. Roughly 380 appliances are still sitting online.

Ransomware group Orion claims attack on Morris Group International
A criminal gang has listed the British professional-services firm on its dark-web pressure site. The company has not confirmed anything, and the claim is unverified.

Ransom Cartel Boss Gets 16 Years After $6.7M Extortion Spree
Belarusian national Maksim Silnikau built and ran the ransomware crew from 2021 to 2023, hitting at least 18 companies before Spanish police caught him and Poland handed him over.

River Bank Paid Hackers to Delete Stolen Data After June Ransomware Attack
Alabama's River Bank & Trust was hit by ransomware in June. The bank appears to have paid the criminals to destroy what they took, but still cannot confirm whether customer data was exposed.

INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward
A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries. The criminals are now also cold-calling victims to pile on the pressure.

Fake IT support calls on Microsoft Teams are ending in ransomware within a day
A gang tracked as STAC4749 is phoning staff on Teams, pretending to be helpdesk, and locking company files with Chaos ransomware in under 17 hours.

Ransomware Group Spacebears Claims Attack on StellarRAD Systems
A criminal group has listed the US telecoms-software firm on its dark-web pressure site, alleging stolen employee data, financial records and client information. The company has not confirmed any incident.

Ransomware gangs are going after VPNs, and an AI just ran its own attack
Ransomware attacks rose for the fourth month in a row in June, with criminals targeting the devices companies use to connect remote workers. A new AI-driven attack completed an entire break-in with no human at the keyboard.

PEAR ransomware crew claims 1.26 million-record breach at Georgia billing firm MCBS
Medical Computer Business Services says attackers roamed its network for four days in September 2025. A ransomware group now claims it stole 3.3 terabytes of patient and business data.

How the FBI Took Down LockBit by Destroying the One Thing Criminals Can't Easily Replace: Trust
Operation Cronos didn't just seize servers. It turned LockBit's own website against its partners, shattered the group's reputation, and cut ransom attacks in the US by nearly 80 percent.

Your ransomware playbook is probably putting the wrong person in charge at 4 a.m.
A growing body of evidence shows that the real damage in ransomware incidents often comes not from the attack itself, but from who gets to decide whether to pull the plug on a business-critical system.

DevMan Ransomware Runs a One-Stop Web Portal for Its Criminal Affiliates
Swiss researchers say the operation, tracked as Funky Mantis, gives partners a single dashboard to build malware, chase payments, and manage victims.