#ransomware
131 stories taggedransomware.

Ransomware group Helix claims attack on US energy testing firm AmSpec
A criminal gang called Helix has listed AmSpec on its dark-web leak site, claiming to have broken into the company. AmSpec has not confirmed any incident, and the claim remains unverified.

Medusa ransomware has hit 500 critical infrastructure targets, US agencies warn
A fresh CISA advisory says the gang's victim count has jumped from 300 to over 500 since March 2025, with hospitals, defence suppliers and banks all in the firing line.

The Ransomware Scavengers: 'Ransom Busters' Emails Victims Demanding Up to $60,000
A new outfit is contacting companies already hit by ransomware and offering, for a fee, to wipe their stolen files from the attackers' servers.

Fake 'Ransom Busters' Service Is Actually a Ransomware Insider Running a Side Scam
A criminal pretending to rescue hack victims is really a ransomware affiliate trying to pocket ransom money before his own gang gets it.

Ransomware crews jump on a Windows Task Host bug that hands over full control of the PC
CISA says criminals are now using CVE-2025-60710, a Windows privilege escalation flaw Microsoft patched in November, to seize SYSTEM-level access on unpatched Windows 11 and Server 2025 machines.

Microsoft pulls a 30-year-old Windows tool that hackers loved
WMIC, a command-line utility abused by ransomware crews to wipe backups and disable antivirus, is gone from fresh installs of Windows 11 24H2 and 25H2.

Ransomware group Interlock claims attack on Connell Enterprises LLC
A criminal group has listed a US business on its dark-web pressure site. The company has not confirmed anything, and the claim cannot be independently verified.

Shell probes possible data theft as Clop ransomware crew names it in engineering software raid
The gang claims 89GB of drawings and project files, part of a wider spree hitting PTC Windchill and FlexPLM systems.

ShinyHunters Claims 1.6 Million Records Stolen from RingCentral
The extortion group published 280 gigabytes of alleged RingCentral data after the company refused to pay. Names, addresses, phone numbers and email addresses are now circulating freely.

Nearly One in Three UK Manufacturers Hit by a Cyber Attack, Survey Finds
A new survey paints a stark picture of hacking risk across British industry, and reveals that half of affected companies had no plan ready when trouble arrived.

Ransomware Hit Colombia's Justice Ministry Five Days Before a New President Took Office
Files were encrypted, services went down, and ColCERT had warned about exactly this kind of attack the day before. Here is what happened, and why Colombia keeps ending up in the crosshairs.

DeadLock Ransomware Moves Its Extortion Kit onto the Blockchain
The gang is stitching together Session chat and Polygon smart contracts so takedowns don't stick. Microsoft calls it a resilience play. We'd call it ransomware learning from crypto scams.

Ransomware crews are now breaking into SharePoint servers through a May flaw
CISA says criminals are using CVE-2026-45659 to plant ransomware on unpatched Microsoft SharePoint servers. Over 200 remain exposed online.

Marcus Hutchins: The Accidental Hero Who Once Wrote the Code He Later Helped Stop
The man who halted one of history's most damaging cyberattacks spent years on the wrong side of the line first. His story is worth understanding.

Old Medusa Hand, New Locker: Storm-1175 Rolls Out StormEncryptor via N-central Flaw
Microsoft says a China-linked crew is exploiting a critical bug in N-able's remote management tool to plant a fresh ransomware strain, sometimes within days of breaking in.