INC Ransomware Fills the LockBit Vacuum, Racks Up 830+ Victims

Two years after a quiet debut, INC has graduated from boutique RaaS to one of 2026's busiest extortion brands, riding the affiliate exodus from LockBit and BlackCat.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
INC Ransomware Fills the LockBit Vacuum, Racks Up 830+ Victims
Share

Key points - INC ransomware has claimed more than 830 victims since its August 2023 debut. - Affiliate flight from LockBit and BlackCat is the primary engine of INC's growth. - Its technical approach is conventional; the advantage is operational discipline and timing. - Healthcare targets include NHS Dumfries and Galloway; a splinter group called Lynx emerged in mid-2024 using what appeared to be recompiled INC code. - Defenders should prioritise edge-device patching, phishing-resistant MFA, and backup segmentation.

INC was a footnote when it surfaced in August 2023. It is not a footnote anymore.

Researchers now put the victim count at more than 830 organisations posted to its leak site, a trajectory that puts INC in the same conversation as the household-name crews it effectively replaced. The growth curve tracks almost exactly with the law-enforcement disruption of LockBit and the exit-scam collapse of BlackCat/ALPHV in early 2024. As Acronis researchers put it, the disruption of both operations "created opportunities for INC to expand as affiliates migrated to alternative ransomware operations."

Affiliates, it turns out, are loyal to infrastructure, not brands.

Should you worry about INC's technical kit?

Not because it's novel. If you've reverse-engineered any post-Conti spinoff, you've seen most of this. The novelty is operational, not cryptographic.

Initial access follows the ecosystem pattern: phished credentials, exposed Citrix and Fortinet appliances, and IAB-supplied footholds into backup infrastructure. Lateral movement uses AnyDesk and PsExec. Exfil rides MEGA and Rclone. None of this should surprise anyone who has read a Mandiant report in the last three years.

What makes INC different from the groups it replaced?

The targeting mix is the tell. Healthcare has taken an outsized share of the hits, including the 2024 attack on NHS Dumfries and Galloway that leaked patient records. Municipal and manufacturing targets round out the list. A splinter calling itself Lynx appeared in mid-2024 using what looked like recompiled INC source, which is either a rebrand or a franchise dispute. Possibly both.

When Operation Cronos seized LockBit's panels and BlackCat's operators walked off with their own affiliates' commissions, the people actually running intrusions needed somewhere to go. INC was ready. Our 28 May report on Operation Saffron showed how quickly displaced crews find new infrastructure when law enforcement pulls one thread; INC is what that regrouping looks like when it goes well for the attackers.

What should defenders do right now?

Treat INC the way defenders should have treated LockBit in 2022: assume affiliates have your edge-device CVEs bookmarked. Enforce phishing-resistant MFA on VPN and admin portals, segment backup infrastructure off the production domain, and hunt for Rclone binaries anywhere Rclone has no business being.

The RaaS market abhors a vacuum. INC simply walked into one, and it has spent two years making itself comfortable.

© 2026 Threat Vectr