< ciso
brief />
Tag Banner

All news with #ransomware gang tag

159 articles

US Sanctions Tren de Aragua Over ATM Jackpotting

πŸ”’ The U.S. Treasury has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for roles in widespread ATM jackpotting campaigns that stole millions from U.S. banks. The designated individuals include alleged Ploutus developer Anibal Alexander Canelon Aguirre ("Prometheus") and six associates, while OFAC cited extensive laundering and international transfers. The Treasury also added seven TRON addresses tied to roughly $6.1 million in inflows to the SDN List.
read more β†’

Police disrupt KillSec ransomware ring after arrests

πŸ”Ž Law enforcement dismantled KillSec, a prolific ransomware-as-a-service group active since 2024, seizing its leak site and at least five servers to prevent exposure of 110TB of stolen data. The operation, led by German police with Europol and Group-IB involvement, identified hundreds of victims β€” primarily in the US and India β€” and revealed KillSec operated both as an encryptor and data broker. Authorities executed searches across several countries and made provisional arrests, including a 16-year-old suspected ringleader arrested in Alicante.
read more β†’

International Operation Dismantles KillSec Ransomware Gang

πŸ”’ An international law enforcement operation called Operation KillSwitch dismantled the KillSec ransomware gang, seizing its data leak site and servers and making three provisional arrests. Authorities from multiple countries, coordinated by Europol and Eurojust with assistance from cybersecurity firms Bitdefender and Group-IB, identified a 16-year-old as the suspected main operator. Investigators seized at least 110 TB of stolen data, shut down five servers, and conducted eight searches across several countries while probing around 1,000 suspected attacks. The investigation began in 2025 and uncovered the group's use of AI and exploitation of vulnerable edge devices to steal and extort victims.
read more β†’

FBI urges ShinyHunters members to surrender now

πŸ›‘οΈ The FBI has publicly urged members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested an alleged leader on September 15. Authorities found extensive data on the suspect's laptop, including details about planned murders, and the suspect remains in pre-trial detention for at least 90 days. The FBI says ShinyHunters has breached over 140 organizations and extorted at least $70 million, often targeting SSO, third-party vendors, and cloud SaaS platforms.
read more β†’

ShinyHunters Claims Hack of Clop Ransomware Group

πŸ›‘οΈ The ShinyHunters gang claims to have breached the Clop ransomware group's dark web leak site, defacing it on 18 September and posting a message stating β€œTHIS SITE HAS BEEN PWN3D BY SHINYHUNTERS”. They say they stole private keys, server data, activity logs and IP addresses that could identify Clop members, and left a ransom demand directing Clop to contact them. The incident appears to be part of a wider feud between the two groups dating to 2025 over claimed ownership of Oracle E-Business Suite exploits, including CVE-2025-61882.
read more β†’

Conti ransomware member jailed for four years

πŸ”’ A Ukrainian national was sentenced to four years in prison after pleading guilty to participating in Conti ransomware attacks that targeted victims in the United States and abroad between 2020 and 2022. 44-year-old Oleksii Lytvynenko was arrested in Ireland in July 2023 and extradited to the U.S., where he admitted to intruding on networks, storing stolen data, sending ransom notes, and developing a malware loader used in the group's double extortion attacks.
read more β†’

US Sanctions Xinbi Guarantee for Global Scam Facilitation

βš–οΈ The US Treasury has sanctioned Xinbi Guarantee, a Chinese-language marketplace linked to large-scale fraud, money laundering and other criminal activity. The marketplace β€” alleged to have processed over $24bn in transactions since 2022 β€” connected scam operators in Southeast Asia with merchants offering financial services, fake IDs, AI deepfake tools and OTC crypto exchanges. OFAC also targeted supporting entities including SafeW Technology and Anwen Technology, while authorities and blockchain firms reported freezing $52.8m in cryptoassets and evidence the marketplace has gone offline.
read more β†’

US Imposes Sanctions Targeting Mabna Cyber Unit

πŸ”’ The US announced Operation Economic Outcast on August 24, targeting nearly 60 individuals and entities to disrupt financial flows sustaining Iran. Five people linked to the Mabna Institute were sanctioned, following a Department of Justice indictment of 17 alleged members for long-running cyber-espionage. OFAC also published 30 crypto addresses tied to four defendants, with blockchain analysis tracing roughly $16.8m of funds. The measures expand sectoral sanctions, increasing compliance burdens for crypto and financial firms.
read more β†’

Rogue ransomware affiliate posing as recovery firm

πŸ›‘οΈ GuidePoint Security's GRIT warns that a suspected ransomware affiliate calling itself "Ransom Busters" has been contacting victims before attacks are publicly disclosed, offering decryption keys and data deletion for fees. The group claims to exploit vulnerabilities in RaaS admin panels and demanded $20,000–$60,000 to remove stolen data. Evidence from two incidents suggests the entity is likely the affiliate behind the intrusions, using consistent tools, account patterns, and attacker-controlled hostnames across multiple attacks.
read more β†’

GE and Philips probe alleged Clop ransomware breach

πŸ” General Electric and Philips are investigating claims that the Clop ransomware gang breached their systems and stole data. Philips confirmed an attempted compromise of an internal enterprise server that has been contained and said there was no impact on customer environments. GE acknowledged awareness of the claim and is assessing the potential issue. The incidents are linked to Clop’s exploitation of a PTC Windchill and FlexPLM vulnerability (CVE-2026-12569) that has prompted emergency advisories and active threat confirmations.
read more β†’

ExfilSquad leaks data from 13 organizations

πŸ” New analysis links the ExfilSquad extortion group to leaked data from 13 victims across government, education, finance and manufacturing. Fortra Intelligence and Research Experts (FIRE) validated that public samples contained sensitive information, with published torrents totaling 382.64 GB and 27 million records. Researchers say misconfigured Microsoft Power Pages and unauthorized read access to Microsoft D365/Dataverse exports appear to be the primary cause, not a D365 vulnerability. FIRE identified numerous exposed Power Pages instances and highlighted the risk of the Anonymous Users web role.
read more β†’

Ransom Cartel founder sentenced to 16 years

πŸ”’ A federal judge sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, a ransomware-as-a-service operation active from 2021 to 2023. The group attacked at least 18 companies across the U.S. and abroad, using stolen credentials from initial access brokers, a hidden affiliate panel, and cryptocurrency mixers to process ransoms. The sentence follows an indictment unsealed in 2024 and a separate unresolved prosecution in New Jersey.
read more β†’

Ransom Cartel founder sentenced to 16 years

πŸ“° Maksim Silnikau, creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison after pleading to conspiracy, wire fraud, and aggravated identity theft. US prosecutors say he recruited affiliates, supplied stolen credentials and encryption tools, and ran a portal to coordinate attacks and split ransom payments. The scheme targeted at least 18 companies worldwide and sought over $5.2 million in extortion.
read more β†’

Fortinet and Crime Stoppers Launch Cybercrime Bounty

πŸ›‘οΈ The Cybercrime Bounty program from Crime Stoppers International and Fortinet has launched its first live bounty, Operation Silent Vector I, to identify individuals behind the INC ransomware group. The program combines anonymous reporting, threat validation by FortiGuard Labs, and established escalation to law enforcement, with potential financial rewards for actionable tips.
read more β†’

DevMan RaaS Portal Centralizes Payloads and Management

πŸ›‘οΈ Swiss firm PRODAFT reports that the DevMan ransomware-as-a-service operation runs a centralized affiliate portal enabling payload builds, victim management, finance tracking, and team coordination. The platform evolved to v3 in January 2026 with structured victim records, deadlines, and shared access, while affiliates follow strict rules and an 80-20 revenue split. The locker targets Windows, ESXi, and Linux and uses ChaCha20-Poly1305 encryption.
read more β†’

Authorities dismantle major Kratos phishing infrastructure

πŸ›‘οΈ German and US law enforcement dismantled the core infrastructure of the Kratos phishing kit and arrested a developer in Indonesia. Investigators disabled over 200 servers; authorities estimate about 1,800 customers ran roughly 15,000 phishing campaigns per month. Kratos stole credentials and session cookies, enabling adversary-in-the-middle bypasses of MFA and persistent access to Microsoft 365 accounts.
read more β†’

Armenia Detains Russian Tourist on U.S. Extradition Warrant

πŸ“° Armenian authorities have detained a Russian tourist, Aleksandr Ermakov, at Yerevan's Zvartnots airport on June 28 after a U.S. extradition request tied to a REvil/Sodinokibi investigation. His lawyers claim Washington has targeted the wrong man, asserting the detained individual is Aleksandr Yuryevich Ermakov of Omsk, not the sanctioned Aleksandr Gennadievich Ermakov. The U.S. charging documents and an Interpol notice allege extensive ransomware activity, but Armenian officials have not commented publicly.
read more β†’

Two Scattered Spider Members Sentenced for TfL Hack

πŸ”’ Two leading members of the Scattered Spider collective were sentenced to five years and six months each for the August 2024 breach of Transport for London (TfL). The attack disrupted internal systems, affected services like Dial-a-Ride and contactless ticketing, and rendered 148 systems inoperable. Investigations led to arrests in September 2024, and authorities credited TfL's cooperation with enabling convictions.
read more β†’

Ryuk Operative Pleads Guilty, Faces 15 Years

πŸ›‘οΈ Karen Serobovich Vardanyan, 34, pleaded guilty to hacking U.S. companies and deploying Ryuk ransomware after being extradited from Kyiv. She provided initial access to corporate networks and helped deploy ransomware between November 2019 and April 2020, leading to large ransom payments including a Michigan firm that paid 200 BTC. Prosecutors say the group collected about 1,610 BTC (β‰ˆ$15 million then).
read more β†’

Former negotiator sentenced in BlackCat ransomware case

πŸ”’ A former DigitalMint incident response employee was sentenced to 70 months for participating in BlackCat (ALPHV) ransomware attacks that targeted U.S. organizations. Prosecutors say the group tied to BlackCat conducted over 60 breaches and collected at least $300 million in ransoms. Two other former negotiators received four-year sentences after pleading guilty to related charges. Victims included large financial and nonprofit organizations that paid multi‑million dollar ransoms.
read more β†’