Ransomware — Page 4

Fake Emails Now Beat Software Flaws as the Number-One Way Ransomware Gets In
A Sophos survey of more than 2,000 organisations hit by ransomware finds that phishing and malicious emails now cause half of all attacks, while stolen passwords are defeating even multi-factor authentication at an alarming rate.

US charges three Russians behind 'bulletproof' hosting service used by LockBit and Play ransomware
Federal prosecutors say Media Land and ML.Cloud rented servers to ransomware crews that caused more than $62 million in damage across 21 US states.

US sanctions a VPN, a malware disguiser, and the people behind them for helping ransomware gangs
Treasury targets 1VPNS and a Belarusian 'crypter' seller who together helped ransomware crews hit hospitals, banks and local governments.

Ransomware group claims attack on Els for Autism Foundation
A criminal group called cmdorganization has listed the Florida-based autism charity on a dark-web extortion site. The foundation has not confirmed any incident, and the claim could not be independently verified.

Ryuk ransomware suspect admits role in $15 million hacking spree
Karen Vardanyan pleaded guilty in a US court to breaking into company networks and helping unleash Ryuk ransomware, one of the most damaging extortion tools of 2019 and 2020.

Hackers Are Targeting the Companies Behind Your Hospital, Not Just the Hospital Itself
Attacks on healthcare businesses, the billing firms and IT vendors that keep hospitals running, surged 110% in a year. Experts say criminals have figured out that one breach can unlock hundreds of patients at once.

Security Consultant Who Secretly Fed Intel to BlackCat Ransomware Gang Gets Nearly Six Years
Angelo Martino was hired to help ransomware victims negotiate their way out. Instead, he sold their secrets to the criminals holding them hostage.

Ransomware Negotiator Turned Attacker Gets Nearly Six Years for BlackCat Extortion Scheme
Angelo Martino, a former DigitalMint employee, was paid to help victims recover from ransomware. Instead he ran the attacks himself, leaking insurance details to squeeze bigger payouts.

New 'GodDamn' Ransomware Uses a Rogue Driver to Kill Antivirus Software
Symantec links the May 2026 strain to the older Beast ransomware family, with medium confidence it's a rebrand.

A Microsoft-Approved Driver Is Helping 'GodDamn' Ransomware Gut US Security Tools
A rebranded criminal gang called Hyadina is using a signed Windows driver to kill antivirus software before locking victims' files. The driver carries a legitimate Microsoft stamp, and nobody knows quite how that happened.

The Gentlemen Ransomware Gang Turns Your Own IT Tools Against You
A fast-spreading criminal group is using the software your IT team trusts every day to take over company networks. The real test is not whether they got in. It is what happens next.

When the Learning Platform Goes Dark, There Is No Backup Plan
A finals-week breach of a major university software platform in 2026 left students locked out of coursework and grade books. Higher education has proved twice it will pay ransoms. That changes everything.

A U.S. Government Agency Quietly Paid $1 Million to a Group That May Not Even Be Ransomware
A leaked negotiation chat and blockchain trail suggest Kairos runs pure data-theft extortion — no file-locking, just threats to leak.

Meet Avalon: The Swiss-Army Malware That Ends in Ransomware
A newly documented toolkit called Avalon steals passwords, spreads across networks, and locks up files — all from one phishing email.

FortiBleed's Credential Theft Linked to Ransomware Gangs
Researchers reveal FortiBleed's connections to ransomware groups, posing greater risks for affected organizations.