#ransomware

[ follow ]
#cyberattack
fromSFGATE
1 day ago
Privacy professionals

Bay Area city paralyzed by cyberattack

A ransomware attack has paralyzed Foster City's government and potentially compromised public data, prompting officials to declare a state of emergency.
fromTechzine Global
3 weeks ago
Information security

Public Prosecutor's Office launches investigation into Odido hack

The Public Prosecutor's Office launched a criminal investigation into a major cyberattack on telecom provider Odido where millions of customer records were stolen, with hackers demanding a seven-figure ransom by February 26.
Privacy professionals
fromSFGATE
1 day ago

Bay Area city paralyzed by cyberattack

A ransomware attack has paralyzed Foster City's government and potentially compromised public data, prompting officials to declare a state of emergency.
Information security
fromTechzine Global
1 day ago

Cohesity embeds Sophos malware scanning in Data Cloud

Cohesity integrates Sophos malware scanning into Data Cloud to detect hidden threats in backup data, enhancing recovery confidence post-cyberattacks.
fromThe Hacker News
2 days ago

54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security

Ransomware gangs, especially those with ransomware-as-a-service (RaaS) programs, frequently produce new builds of their encryptors, and ensuring that each new build is reliably undetected can be time-consuming. More importantly, encryptors are inherently very noisy (as they inherently need to modify a large number of files in a short period); making such malware undetected is rather challenging.
Information security
#data-breach
Information security
fromMail Online
3 weeks ago

'Largest breach in US history' exposes records of 26 MILLION Americans

A massive breach at Conduent exposed personal data for at least 26 million Americans, with millions in Texas and Oregon most severely affected, including addresses, Social Security numbers, and health information.
Information security
fromDataBreaches.Net
3 weeks ago

Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site - DataBreaches.Net

Wynn Resorts' data listing was removed from ShinyHunters leak site after the company reportedly paid an extortion demand, with the resort confirming deletion of stolen employee data.
Privacy professionals
fromSecurityWeek
2 days ago

Marquis Data Breach Affects 672,000 Individuals

Marquis, a marketing and compliance provider for financial institutions, disclosed a data breach affecting approximately 672,000 individuals, with stolen personal and financial information including SSNs, addresses, and payment card numbers.
Privacy professionals
fromSecurityWeek
1 week ago

238,000 Impacted by Bell Ambulance Data Breach

Bell Ambulance notified 237,830 individuals of a February 2025 data breach exposing personal, financial, medical, and health insurance information after the Medusa ransomware gang claimed responsibility.
Privacy professionals
fromTechzine Global
2 weeks ago

All data from dutch Telco Odido hack now online

ShinyHunters released all stolen data from Odido's 6.5 million customers and 600,000 companies online after the company refused ransom payment, exposing names, addresses, social security numbers, ID documents, and sensitive personal information.
Information security
fromSecurityWeek
2 days ago

Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks

Cisco firewall vulnerability CVE-2026-20131 was exploited as a zero-day by Interlock cybercrime group since January 26, before the March 4 patch announcement.
Information security
fromThe Hacker News
3 days ago

Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access

Interlock ransomware exploits critical Cisco Secure Firewall vulnerability CVE-2026-20131 as zero-day since January 26, 2026, enabling unauthenticated remote code execution with root privileges.
Information security
fromThe Hacker News
1 week ago

Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks

AI-generated malware Slopoly enables threat actors to develop malware frameworks significantly faster, demonstrating the weaponization of AI for cybercriminal purposes.
Information security
fromThe Hacker News
1 week ago

CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited

CISA added three actively exploited vulnerabilities to its KEV catalog, including critical flaws in SolarWinds Web Help Desk, Omnissa Workspace One UEM, and Ivanti Endpoint Manager, with federal agencies required to patch by mid-to-late March 2026.
US news
fromSecurityWeek
2 weeks ago

Russian Ransomware Operator Pleads Guilty in US

Russian national Evgenii Ptitsyn pleaded guilty to wire fraud conspiracy for his role in the Phobos ransomware operation, facing up to 20 years in prison.
Information security
fromThe Hacker News
2 weeks ago

Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations

Threat actors impersonate IT support via email and phone calls to deliver Havoc C2 framework for data exfiltration or ransomware attacks across multiple organizations.
Information security
fromTheregister
3 weeks ago

Double whammy: Steaelite RAT bundles data theft, ransomware

Steaelite, a new remote access trojan sold on cybercrime networks, enables double extortion attacks on Windows machines through ransomware, data theft, credential stealing, and live surveillance controlled via a centralized browser-based dashboard.
Information security
fromDataBreaches.Net
3 weeks ago

Extorting the Extorters? Moscow man accused of posing as FSB officer to extort Conti ransomware gang - DataBreaches.Net

A Moscow resident was accused of extorting money from the Conti ransomware group by impersonating an FSB officer and threatening criminal prosecution.
Information security
fromTechzine Global
3 weeks ago

Why cyberattacks don't require advanced hacking

Poor cyber hygiene, weak identity security, overdue IT maintenance, and incomplete logging make organizations vulnerable to financially motivated attacks such as ransomware and email fraud.
#healthcare-cybersecurity
fromFuturism
3 weeks ago

AI Is Destroying Grocery Supply Chains

Whole Foods shelves sit empty after a data breach shut down its wholesale distributor. Meat packers working for JBS Foods are paralyzed as an $11 million ransomware attack takes out their processing facilities. Some 2.2 million workers at Stop & Shop and Hannaford have their personal data exposed as the result of a cyberattack on parent company Ahold Delhaize USA. These scenarios, straight from a William Gibson novel, are becoming increasingly common in supply chains across the world.
Food & drink
#cve-2026-1731
#cybersecurity
Information security
fromDataBreaches.Net
1 month ago

Oklahoma Cheyenne and Arapaho Tribes say ransomware disrupted tribal systems - DataBreaches.Net

Ransomware attack forced Cheyenne and Arapaho Tribes to shut down tribal networks, disrupting communications and suspending some operations while recovery and investigation proceed.
Information security
fromTechzine Global
1 month ago

Cyber attackers hide their tracks by exploiting firewalls

Firewall vulnerabilities enabled 90% of ransomware incidents in 2025, with some attacks encrypting data within three hours and old CVE exploits still active.
Information security
fromTheregister
1 month ago

Polish cops arrest 47-year-old man in Phobos ransomware raid

Polish police arrested a 47-year-old suspected of ties to Phobos after seizing devices containing credentials, payment data, server IPs, and encrypted communications.
fromSecurityWeek
1 month ago

Man Linked to Phobos Ransomware Arrested in Poland

A 47-year-old man arrested by police in Poland for allegedly being involved in cybercriminal activities has been linked to the Phobos ransomware operation. According to Poland's Central Cybercrime Bureau, officers found hacking tools, credentials, payment card numbers, and server IP addresses on the unnamed suspect's devices during a search. They also discovered that the suspect had exchanged messages with the Phobos ransomware group.
Information security
fromTheregister
1 month ago

Infosec exec sold eight zero-day exploit kits to Russia: DoJ

That changed last week when the US Department of Justice published a sentencing memorandum [PDF] that frames Williams' conduct as a betrayal of his employer and the US government, and the cause of significant harm to US national security. Williams "made it possible for the Russian Broker to arm its clients with powerful cyber exploits that could be used against any manner of victim, civilian or military around the world," the DoJ said.
Information security
Education
fromDataBreaches.Net
1 month ago

Cyber Attacks on Schools Plateaued in 2025, but More Records Exposed - DataBreaches.Net

Ransomware attacks on educational institutions remained steady in 2025 while exposed records increased sharply, driven by third-party software vulnerabilities and large higher-education breaches.
#supply-chain-attacks
Information security
fromTheregister
1 month ago

Ransomware crews abuse bossware to blend into networks

Threat actors are abusing legitimate employee monitoring and RMM software to hide in corporate networks and attempt ransomware deployment.
Information security
fromSecurityWeek
1 month ago

Hacktivists, State Actors, Cybercriminals Target Global Defense Industry, Google Warns

Hacktivists, state-sponsored actors, and cybercriminals are intensifying attacks on the global defense industrial base using espionage, ransomware, and LLM-assisted techniques.
fromThe Hacker News
1 month ago

Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools

Cybersecurity researchers have disclosed details of an emergent ransomware family dubbed Reynolds that comes embedded with a built-in bring your own vulnerable driver (BYOVD) component for defense evasion purposes within the ransomware payload itself. BYOVD refers to an adversarial technique that abuses legitimate but flawed driver software to escalate privileges and disable Endpoint Detection and Response (EDR) solutions so that malicious activities go unnoticed. The strategy has been adopted by many ransomware groups over the years.
Information security
fromThe Hacker News
1 month ago

From Ransomware to Residency: Inside the Rise of the Digital Parasite

To be clear, ransomware isn't going anywhere, and adversaries continue to innovate. But the data shows a clear strategic pivot away from loud, destructive attacks toward techniques designed to evade detection, persist inside environments, and quietly exploit identity and trusted infrastructure. Rather than breaking in and burning systems down, today's attackers increasingly behave like Digital Parasites. They live inside the host, feed on credentials and services, and remain undetected for as long as possible.
Information security
fromZDNET
1 month ago

This new 'sleeperware' doesn't set off alarms or crash your system - it sneaks in and waits

In its annual Red Report, a body of research that analyzes real-world attacker techniques using large-scale attack simulation data, Picus Labs warns cybersecurity professionals that threat actors are rapidly shifting away from ransomware encryption to parasitic "sleeperware" extortion as their means to loot organizations for millions of dollars per attack. Released today and now in its sixth year, the 278-page Red Report gets its name from Picus-organized cybersecurity exercises that take the perspective of the attacker's team, otherwise known as the "red team."
Information security
#smartermail
Information security
fromSecuritymagazine
1 month ago

Understanding Breaches Before and After They Happen: What Every Organization Should Know

Most security breaches result from neglected fundamentalsโ€”human error, unpatched systems, weak authentication, and poor network segmentationโ€”rather than advanced, novel exploits.
Information security
fromSecurityWeek
1 month ago

Ransomware Groups May Pivot Back to Encryption as Data Theft Tactics Falter

Ransomware groups find pure data exfiltration less profitable; attackers are shifting back to encryption to regain leverage as victim payment rates fall.
#cisa
Higher education
fromTechCrunch
1 month ago

One of Europe's largest universities knocked offline for days after cyberattack | TechCrunch

La Sapienza Universityโ€™s computer systems have been offline for three days after an apparent ransomware attack affecting emails and workstations; recovery is underway from backups.
Information security
fromTechCrunch
1 month ago

Data breach at govtech giant Conduent balloons, affecting millions more Americans | TechCrunch

A January 2025 ransomware attack on Conduent may have exposed personal data of potentially tens of millions of US residents across multiple states.
Information security
fromTechzine Global
1 month ago

Western Europe is a hotbed for cybercriminals' servers

Cybercriminals abuse ISPsystem's VMmanager and 'bulletproof' European hosting to run ransomware on recurring Windows hostnames and evade abuse complaints.
Information security
fromTheregister
1 month ago

Nitrogen can't unlock its own ransomware after coding error

Nitrogen's VMware ESXi ransomware corrupts the public key via a stack overlap, making decryption impossible even if victims pay.
Information security
fromComputerWeekly.com
1 month ago

Ransomware gangs focus on winning hearts and minds | Computer Weekly

Ransomware gangs are professionalizing, scaling affiliate models, recruiting insiders and cyber professionals, and offering larger commissions and better OpSec to enable more successful attacks.
Information security
fromSecurityWeek
1 month ago

Over 1,400 MongoDB Databases Ransacked by Threat Actor

1,416 of 3,100 internet-exposed MongoDB databases were compromised and replaced with ransom notes demanding about $500 in Bitcoin per incident.
Information security
fromTechCrunch
1 month ago

Fintech firm Marquis blames hack at firewall provider SonicWall for its data breach | TechCrunch

Marquis attributes an August 2025 ransomware attack to credential exposure from its firewall provider SonicWall's cloud backup breach and plans to seek compensation.
Privacy professionals
fromDataBreaches.Net
1 month ago

You're not paranoid: lawyers ARE coming to get you. - DataBreaches.Net

Failure of federal regulators to act after patient-data breaches can prompt state attorneys general and class-action lawsuits seeking money and corrective action plans.
#ramp
Information security
fromArs Technica
1 month ago

Site catering to online criminals has been seized by the FBI

The FBI seized RAMP, a major Russian-language ransomware marketplace with over 14,000 vetted users, disrupting a significant cybercrime forum and its operations.
Information security
fromDataBreaches.Net
1 month ago

France's Waltio faces ransom threat from notorious hacker collective - DataBreaches.Net

Waltio faces a ShinyHunters ransom threat claiming nearly 50,000 users' data and threatening to leak 2024 tax reports, while core systems remain secure.
Canada news
fromwww.cbc.ca
1 month ago

More criminals are using AI for ransomware attacks, cybersecurity centre warns | CBC News

Ransomware attacks in Canada are increasing and evolving rapidly, with criminals using AI to identify vulnerabilities, create malware, and automate extortion.
fromComputerWeekly.com
1 month ago

Broken decryptor leaves Sicarii ransomware victims adrift | Computer Weekly

A coding error, possibly introduced thanks to over-reliance on artificial intelligence (AI) vibe coding tools, has rendered an emergent strain of ransomware an acutely dangerous threat, according to researchers at Halcyon's Ransomware Research Center (RRC). The Sicarii ransomware-as-a-service (RaaS) operation emerged from the cyber criminal underground in December 2025, when it started advertising for affiliates on the dark web.
Information security
Information security
fromThe Hacker News
1 month ago

Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware

Multi-stage phishing campaign targets Russian users, using social-engineered documents, cloud-hosted loaders, Defender-disable tricks, and deployments of Amnesia RAT and ransomware.
Information security
fromSecurityWeek
1 month ago

Nike Probing Potential Security Incident as Hackers Threaten to Leak Data

Nike is investigating a potential cybersecurity incident after WorldLeaks listed Nike as a victim and threatened to publish alleged stolen data unless paid.
Information security
fromChannelPro
1 month ago

Ransomware is on the rise. Again

Ransomware is resurging with smarter, AI-augmented attacks that leverage phishing, credential theft, and identity/access exploitation, pressuring defenders and creating MSP opportunities.
Information security
fromTechzine Global
1 month ago

New Windows backdoor emerges in ransomware attack

PDFSider is a stealthy Windows backdoor deployed via social engineering and DLL side-loading to provide persistent, encrypted access and data exfiltration over DNS.
#cybercrime
fromFortune
2 months ago
Information security

Feds are hunting teenage hacking groups like 'Scattered Spider' who have targeted $1 trillion worth of the Fortune 500 since 2022 | Fortune

fromFortune
2 months ago
Information security

Feds are hunting teenage hacking groups like 'Scattered Spider' who have targeted $1 trillion worth of the Fortune 500 since 2022 | Fortune

#black-basta
fromDataBreaches.Net
2 months ago

HHS OCR comments on its 2026 priorities - DataBreaches.Net

OCR continues to execute its enforcement mission under its statutory and regulatory authorities regarding civil rights, exercise of conscience, and health information privacy and security, and breach notification. OCR continues to investigate complaints filed, to conduct compliance reviews, and to review breaches of unsecured protected health information. OCR will be responsive to the HIPAA trends and compliance issues within OCR's jurisdiction that are affecting the public and the regulated industry.
Privacy professionals
Information security
fromTheregister
2 months ago

DeadLock ransomware uses smart contracts to evade defenders

DeadLock ransomware uses Polygon smart contracts and decentralized messaging wrappers to rotate proxy URLs and evade detection while relying on encryption-only extortion.
Public health
fromDataBreaches.Net
2 months ago

University of Hawaii Cancer Center: Hackers Stole Research Files, Encrypted Data - DataBreaches.Net

Ransomware attackers stole data from University of Hawaii Cancer Center studies from the 1990s, and the center paid a ransom for a decryptor key.
fromComputerWeekly.com
2 months ago

Business leaders see AI risks and fraud outpacing ransomware, says WEF | Computer Weekly

Midway through a decade that is coming to be defined by the runaway acceleration of technological change, the threat of ransomware attacks seems to be dropping down the agenda in boardrooms around the world, with C-suite executives more concerned about growing risks arising from artificial intelligence (AI) vulnerabilities, cyber-enabled fraud and phishing attacks, disruption to supply chains, and exploitation of software vulnerabilities.
Information security
Information security
fromDataBreaches.Net
2 months ago

CrazyHunter ransomware escalates with advanced intrusion tactics, six Taiwan healthcare victims confirmed - DataBreaches.Net

CrazyHunter ransomware, a Go-based Prince fork, has rapidly evolved with advanced intrusion and evasion capabilities, targeting Taiwanese healthcare providers and leaking stolen data.
France news
fromDataBreaches.Net
2 months ago

Basketball player arrested for alleged ransomware ties freed in Russia-France prisoner swap - DataBreaches.Net

Daniil Kasatkin, a Russian basketball player accused of negotiating for a ransomware gang, was freed in a prisoner exchange between Russia and France.
World news
fromTheregister
2 months ago

France swaps alleged ransomware crook for conflict researche

France exchanged an alleged US-wanted ransomware suspect for pardoned French researcher Laurent Vinatier, who was released from a Russian prison.
Information security
fromThe Hacker News
2 months ago

Cybersecurity Predictions 2026: The Hype We Can Ignore (And the Risks We Can't)

Organizations must prioritize evidence-based cybersecurity predictions focusing on targeted ransomware, internal AI-related risks, and skepticism about AI-orchestrated attacks.
fromTheregister
2 months ago

Ransomware attacks kept climbing in 2025

Trackers keeping an eye on ransomware leak sites logged more than 8,000 claimed victims worldwide in 2025, a rise of more than 50 percent compared to 2023. The counts come from outfits watching dark web shaming pages such as Ransomware.live and RansomLook.io, so they only include cases where crooks decided to post receipts. Plenty of victims, Emsisoft says, will have paid up, recovered, or kept quiet without ever appearing on a leak site.
Information security
fromSecuritymagazine
2 months ago

Communication Criticized in Handling of Recent Healthcare Hack

Manage My Health, a portal enabling connection between individuals and their healthcare providers, experienced a cyberattack identified on Dec. 30. The New Zealand-based organization published a statement to its website the following day, and as of Jan. 5, has continued to post subsequent updates as information has come available. Following the forensic investigations, the organization believes around 7% of 1.8 million registered patients may have been impacted.
Privacy professionals
fromTheregister
2 months ago

King Charles gives award to LockBit takedown architect

The National Crime Agency's (NCA) Gavin Webb was among the names on the King's most recent New Year Honours list for 2026. Webb was given an Officer of the Order of the British Empire (OBE) award.
Miscellaneous
Information security
fromComputerworld
2 months ago

US cybersecurity experts plead guilty to attacking US companies with ransomware

Two cybersecurity professionals pleaded guilty to conspiring to use BlackCat ransomware to extort multiple U.S. victims and will be sentenced March 12, 2026.
#alphv-blackcat
fromDataBreaches.Net
2 months ago
US news

Two Cybersecurity Professionals Plead Guilty to Targeting Multiple U.S. Victims Using ALPHV BlackCat Ransomware - DataBreaches.Net

fromDataBreaches.Net
2 months ago
US news

Two Cybersecurity Professionals Plead Guilty to Targeting Multiple U.S. Victims Using ALPHV BlackCat Ransomware - DataBreaches.Net

Information security
fromTechzine Global
2 months ago

Security experts themselves carried out ransomware attacks

Two U.S. cybersecurity employees pleaded guilty to using BlackCat/ALPHV ransomware to extort victims, launder proceeds, and face up to 20 years in prison.
Information security
fromSocial Media Explorer
2 months ago

Is Your Bank Prepared for the Next Big Cybersecurity Threat? - Social Media Explorer

Preparedness through managed IT services and proactive security is essential for banks to counter evolving cyber threats like ransomware and spear-phishing.
Information security
fromThe Verge
2 months ago

Two cybersecurity employees plead guilty to carrying out ransomware attacks

Two former cybersecurity employees pleaded guilty to using ALPHV/BlackCat ransomware to extort $1.2 million and target multiple U.S. companies in 2023.
[ Load more ]