< ciso
brief />
Tag Banner

All news with #double extortion tag

45 articles

Berlin Rejects Ransom After Major State Network Breach

🔒 Berlin's state government confirmed an extortion attempt after its state administrative network was compromised in August and said it will not pay the attackers. Forensics found further data exfiltration from the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and 12, 2026, and the scope may include personal or non-public records. Authorities, including state police, the public prosecutor and federal security agencies, are investigating while the Senate continues forensic work and coordination with data protection and security bodies.
read more →

Rogue ransomware affiliate posing as recovery firm

🛡️ GuidePoint Security's GRIT warns that a suspected ransomware affiliate calling itself "Ransom Busters" has been contacting victims before attacks are publicly disclosed, offering decryption keys and data deletion for fees. The group claims to exploit vulnerabilities in RaaS admin panels and demanded $20,000–$60,000 to remove stolen data. Evidence from two incidents suggests the entity is likely the affiliate behind the intrusions, using consistent tools, account patterns, and attacker-controlled hostnames across multiple attacks.
read more →

Medusa Ransomware Hits 500+ Critical Infrastructure

🛡️ The FBI, CISA and HHS issued an updated advisory on August 18, 2026, stating Medusa ransomware has affected over 500 critical infrastructure organizations, with healthcare heavily targeted. The advisory notes the operation has accelerated exploitation of unpatched vulnerabilities—sometimes within 24 hours or before public disclosure—and expanded post-exploitation tooling. Medusa uses stealthy PowerShell techniques, legitimate RMM tools, credential theft methods like Mimikatz, and exfiltration tools such as Bandizip and Rclone to support a double-extortion model.
read more →

DeadLock Ransomware Leverages Blockchain to Resist Takedown

🔒 Microsoft researchers detail a new DeadLock ransomware operation that uses blockchain-backed services and decentralized networks to harden its infrastructure. The group, active since mid-2025, employs double-extortion tactics and hosts leak posts and configuration data on the Polygon blockchain. Victims span multiple European industries, while attackers use Session and Wasabi to protect communications and stolen files, complicating takedown efforts.
read more →

DeadLock ransomware leverages blockchain for resilience

🛡️ Microsoft and security vendors observed DeadLock using decentralized services and an interactive HTML recovery chat to maintain extortion and data-leak operations without traditional backend infrastructure. The group, active since July 2025, uses Session messaging, Polygon smart contracts for proxy rotation, and blockchain-hosted leak content while employing selective encryption, hybrid crypto, and anti-forensic measures. Multiple actors have deployed it and it has claimed nearly 100 victims across Europe and the U.S.
read more →

Gunra Ransomware Targets Critical Infrastructure Globally

🔒 Cybersecurity agencies in South Korea and the U.S. have warned of Gunra ransomware campaigns targeting critical infrastructure sectors globally, including healthcare, finance, and government. The actors exploit vulnerabilities in Schneider Electric PowerLogic P5 and Fortinet FortiOS/FortiProxy to gain access, then use double extortion tactics combining data theft and encryption. Victims face data leaks within days if ransoms are not paid.
read more →

Klue Breach Reveals New Third‑Party Identity Risks

🔒 The 2026 Klue compromise began as a SaaS supply‑chain breach and escalated when a second criminal group claimed to have stolen data from the initial extortion crew. Attackers exploited a forgotten service account and harvested OAuth tokens, enabling broad Salesforce API access and extensive data extraction. The incident underscores how identity and delegated application permissions now constitute the primary attack surface, challenging traditional perimeter defenses and ransom decision models.
read more →

DevMan RaaS Portal Centralizes Payloads and Management

🛡️ Swiss firm PRODAFT reports that the DevMan ransomware-as-a-service operation runs a centralized affiliate portal enabling payload builds, victim management, finance tracking, and team coordination. The platform evolved to v3 in January 2026 with structured victim records, deadlines, and shared access, while affiliates follow strict rules and an 80-20 revenue split. The locker targets Windows, ESXi, and Linux and uses ChaCha20-Poly1305 encryption.
read more →

Stadler Refuses 10M CHF Ransom After Data Breach

🚆 Swiss rail manufacturer Stadler Rail says the Everest ransomware gang demanded 10 million Swiss francs (~$12.3M) after breaching a shared data exchange platform with a supplier. Stadler declared it will not pay the ransom, filed a criminal complaint with Thurgau cantonal police, and stated that its IT and production operations were unaffected. The company says only non-security-relevant technical supplier data was taken and no personal data or rail systems were compromised.
read more →

Anubis Claims Responsibility for Fairlife Cyberattack

🛡️ The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, alleging it stole approximately 1 TB of corporate data and encrypted Nutanix systems. Coca-Cola disclosed the incident on July 16 after production at U.S. facilities was suspended; the company said product safety was unaffected and declined to comment on Anubis' claims. Anubis, a RaaS group active since December 2024, has combined data theft, encryption, and destructive wiping in prior attacks.
read more →

Qilin ransomware leverages PAN‑OS VPN flaw

🛡️ Arctic Wolf Labs investigated June 2026 intrusions where actors exploited CVE-2026-0257, a patched authentication bypass in Palo Alto Networks PAN-OS, to establish SSL VPN sessions and deploy Qilin (aka Agenda) ransomware. Post-exploitation activity varied from rapid encryption to full double-extortion, but shared tactics included staging payloads in C:\PerfLogs\, using PsExec for lateral movement, harvesting credentials, disabling Defender real-time protection, and clearing event logs.
read more →

Extortion-Only Attacks Rise, Shift Focus to Data Theft

🔍 Insurers report a marked increase in extortion-only incidents where attackers rely on data theft rather than encryption. Resilience found that 65% of extortion claims in H2 2025 did not involve encryption, and data theft accounted for 87% of ransomware claims by year-end. The report warns that paying for data suppression is unreliable, with 30–40% of paid cases still resulting in leaks, and recommends prevention, tabletop exercises, and pre-incident legal and response retainers.
read more →

DentaQuest breach exposed data of 2.6 million accounts

🔒 DentaQuest, a major US dental benefits administrator, disclosed a cybersecurity incident after the extortion group ShinyHunters posted and later leaked over 234 GB of stolen data. The company confirmed limited disruption to services on June 2 and said it engaged external experts to investigate and contain the breach. Analysis by Have I Been Pwned found records for 2.6 million accounts in the leaked dataset, including emails, names, phone numbers, government IDs, insurance details, genders, and dates of birth.
read more →

Data-Only Extortion Rising in the Cyber Threat Economy

🔍 This Unit 42 report examines the growing shift from ransomware encryption to data-theft and extortion-only attacks, profiling threat actors, techniques, and sectors most affected. It highlights drivers such as improved backups, faster exfiltration, and regulatory pressures that make disclosure risk financially coercive. The briefing also warns of AI-accelerated attacks and offers prioritized defensive recommendations for DLP, SaaS posture, identity resilience, supply chain integrity, and AI preparedness.
read more →

FBI Issues Advisory After ShinyHunters Breach of Canvas LMS

⚠️ The FBI's IC3 issued an advisory on 15 May 2026 about the ShinyHunters extortion gang breaching an online learning management system used by US educational institutions. Although the advisory avoided naming the vendor, reporting and Instructure's confirmation made clear Canvas was affected and the company reportedly paid a ransom after receiving alleged 'shred logs'. The FBI warns victims not to engage with extortionists, enable multi‑factor authentication, and remain vigilant against phishing, harassment, and swatting; students and staff should assume their data may be exposed and await official guidance.
read more →

Canvas Breach and Extortion Disrupts US Schools Nationwide

🔒 Instructure's Canvas platform was taken offline on May 7 after the cybercrime group ShinyHunters defaced login pages and posted a ransom demand claiming to hold data on 275 million students and faculty at nearly 9,000 institutions. Instructure had acknowledged a breach on May 6, saying the stolen records include names, email addresses, student ID numbers and user messages but not passwords or financial information. The outage, timed during many institutions' final exams, disrupted coursework while schools and the vendor evaluated exposure and potential extortion responses.
read more →

ShinyHunters Defaces Canvas Login Portals at Scale

🔒 The ShinyHunters extortion group defaced Canvas login portals for roughly 330 colleges and universities, replacing standard pages with an extortion message that demanded payment by May 12, 2026. The same message also appeared in the Canvas app and was visible for about 30 minutes before being taken offline. Instructure has taken Canvas offline while confirming that data was stolen and continuing its investigation. BleepingComputer reports the group claims the theft includes extensive student and staff records.
read more →

ShinyHunters Claims 280M Records Stolen from Instructure

🔒 Instructure says it is investigating a breach after the extortion group ShinyHunters claimed to have stolen 280 million records tied to students, teachers, and staff across 8,809 colleges, school districts, and online education platforms. The actors allege they accessed names, email addresses, private messages and enrollment data by abusing Canvas export features such as DAP queries, provisioning reports and user APIs. Instructure has acknowledged the incident but has not provided detailed public answers; several universities have begun their own inquiries.
read more →

Trigona Ransomware Adopts Custom Tool to Steal Data

🔒 Symantec researchers observed Trigona ransomware affiliates using a custom command-line exfiltration utility, uploader_client.exe, in March to siphon high-value documents to a hardcoded server. The tool supports parallel uploads, TCP rotation after 2GB, selective file-type exclusion, and an authentication key to control access to stolen data. The shift from public utilities like Rclone appears intended to reduce detection during double-extortion operations. Symantec has published IoCs to aid defenders.
read more →

Evolution of Ransomware: Multi-Extortion Threats Rise

🔒 Ransomware's shift to multi-extortion is producing real operational harm across healthcare, finance, and manufacturing, with widespread incidents and patient-care disruptions reported in 2025–2026. Attackers now routinely exfiltrate data before encrypting systems, making backups alone insufficient and increasing regulatory and business risk. The article highlights D.AMO from Penta Security, an integrated platform combining kernel-level folder encryption, process-based access control, and independent recovery to render stolen files unreadable, block unauthorized access, and speed restoration.
read more →