< ciso
brief />
Tag Banner

All news with #ransomware tag

541 articles · page 4 of 28

Anubis Claims Responsibility for Fairlife Cyberattack

🛡️ The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, alleging it stole approximately 1 TB of corporate data and encrypted Nutanix systems. Coca-Cola disclosed the incident on July 16 after production at U.S. facilities was suspended; the company said product safety was unaffected and declined to comment on Anubis' claims. Anubis, a RaaS group active since December 2024, has combined data theft, encryption, and destructive wiping in prior attacks.
read more →

Ransomware Landscape Expands with New Groups Weekly

🛡️ The Black Kite Ransomware Report 2026 finds 146 active ransomware groups as of June 2026, up from 105 a year earlier, with 61 new groups emerging in 2026 alone. The study highlights a fragmented ecosystem where groups often have short lifespans—averaging 4.9 months—and a small number of operators still account for a large share of disclosed victims. Black Kite urges organizations to prioritize rapid patching of critical vulnerabilities and strengthen identity and vendor controls to mitigate attacks.
read more →

Critical GlobalProtect VPN Bug Now Used in Ransomware

🔒 Palo Alto Networks patched a critical PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) on May 13 after Rapid7 observed active exploitation from May 17. Arctic Wolf reports the Qilin ransomware gang is leveraging the flaw to gain unauthorized VPN access and deploy ransomware, with incidents in June resulting in domain-wide encryption. CISA added the vulnerability to its Known Exploited Vulnerability catalog and ordered federal agencies to remediate within three days.
read more →

Ransomware Now Disrupts a Government Every Day

🔒 Analysis from Comparitech finds ransomware attacks on government agencies rose in early 2026, averaging one incident per day. The study recorded 187 attacks from January to June 2026, a 13% increase from late 2025, with just over half publicly confirmed. The US was the most targeted country (31%), mean demands were around $100,000, and groups like The Gentlemen, Qilin and LockBit were prominent. Experts stress timely patching, backups and staff training to reduce risk.
read more →

The Gentlemen Tops Ransomware Incidents in Q2

🛡️ ReliaQuest's July analysis shows The Gentlemen ransomware gang conducted 300 attacks in the three-month period, surpassing Qilin's 289 incidents. Researchers tracked 1,368 victim claims across 99 countries from 11 ransomware groups, with DragonForce, Akira and LockBit also active. ReliaQuest attributes The Gentlemen's rise to aggressive affiliate recruitment, pre-packaged intrusion kits and AI-accelerated tooling.
read more →

Coca‑Cola reports Fairlife ransomware halts US production

📰 Coca‑Cola disclosed a ransomware incident affecting its Fairlife dairy subsidiary that led to temporary suspension of U.S. production. The company reported unauthorized access to production-related systems, activated incident response and engaged outside cybersecurity advisors while notifying law enforcement. Product safety remains unaffected and Canadian operations are not impacted. An investigation is ongoing and no claim of data theft or extortion has been confirmed.
read more →

Weekly roundup: emerging cyber threats and takedowns

🛡️ This week’s roundup highlights a wave of opportunistic attacks where familiar software and weak defaults are abused to escalate damage quickly. Reports include malicious NuGet packages that deliver spyware via game cheats, trojanized installers distributing sophisticated RATs, and a fast-spreading Rust ransomware incident that encrypted a network within 24 hours. Additional items cover actively exploited CVEs added to CISA’s KEV, guidance for coordinated vulnerability disclosure, large-scale fraud and money‑laundering disruptions in Europe, evasive Windows bind-link techniques, fake GitHub repos spreading an infostealer, and misuse of Chrome Sync for covert surveillance.
read more →

Spirals ransomware encrypts corporate networks rapidly

🛡️Researchers report a June intrusion where the new Spirals ransomware actor moved from initial access to data theft and encryption in under 24 hours. After compromising a publicly exposed IIS server and uploading an ASP.NET web shell, the attacker bypassed UAC, enabled RDP, created local accounts, and harvested credentials. They disabled security and backup services, used multiple lateral movement and remote-access tools, and deployed a Rust-based payload named bitsadmin.exe to encrypt files and drop a ransom note.
read more →

Compromised Logins Drive Most Ransomware Intrusions

🛡️ New Sophos analysis shows identity-based attacks and stolen credentials are now the leading initial access vector in ransomware incidents, responsible for 79% of cases. Malicious email and phishing remain significant contributors, while exploitation of known vulnerabilities has decreased. The report urges stronger identity controls, widespread MFA, and adoption of ITDR to reduce risk.
read more →

US Sanctions VPN and Malware Providers Linked to Ransomware

🔒 The U.S. Treasury's OFAC sanctioned virtual private network provider First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and a Belarusian cryptor vendor, Yegeniy Silayev, for enabling ransomware operations. Authorities say 1VPNS marketed no-logs service to cybercriminals and used false identities to obtain infrastructure, while Silayev sold tools to evade malware detection. The action follows a multinational takedown and server seizures tied to widespread cybercrime.
read more →

Ransomware Negotiator Betrays Victims, Sentenced

🔒 A trusted ransomware negotiator secretly aided the BlackCat/ALPHV gang, sharing victims' insurance limits and negotiation strategies in exchange for cuts of ransom payments. Angelo John Martino III, a DigitalMint negotiator, funneled sensitive negotiation details through a hidden panel to attackers, inflating ransoms and enabling multimillion-dollar payouts. He and accomplices also acted as affiliates, deploying ransomware and siphoning proceeds; authorities seized assets and secured convictions and prison sentences.
read more →

Japan’s largest taxi operator halts systems after attack

🚨 Nihon Kotsu, Japan's largest taxi and chauffeur operator, has shut down parts of its IT infrastructure after detecting unauthorized external access and a malware infection early Saturday. The outage has affected the taxi dispatch system, web booking, reservation management, phone dispatch services, and some internal systems, leaving key services offline while the company investigates. Nihon Kotsu has engaged external cybersecurity experts, warned customers to avoid suspicious attachments and links, and has not yet confirmed any data leakage or any claim of responsibility by ransomware groups.
read more →

Extradited Hacker Pleads Guilty in Ryuk Ransomware Case

🔒 An Armenian national extradited from Ukraine has pleaded guilty in a Portland federal court to conspiracy and computer fraud for his role in deploying Ryuk ransomware between November 2019 and April 2020. The defendant, Karen Serobovich Vardanyan, admitted to compromising multiple US organizations, including a Michigan firm that paid 200 bitcoin and other victims in Oregon and Texas. Under a plea deal he agreed to pay over $1.1m in restitution but faces potential prison terms and fines. The case underscores growing US success in prosecuting ransomware actors who traditionally operated from former Soviet states.
read more →

The Gentlemen ransomware: rise and operational profile

🔒 Unit 42 details the emergence and tactics of The Gentlemen (aka Storm-2697), a Ransomware-as-a-Service active since mid‑2025 and scaling rapidly through 2026. The group uses C and Go variants, offers affiliates a 90% payout, and employs diverse initial access methods including exploited edge devices, brute force, stolen credentials and IAB partnerships. Researchers note custom tooling such as a Go backdoor, an EDR killer called GentleKiller, and likely zero-day exploitation to evade defenses.
read more →

Ryuk Operative Pleads Guilty, Faces 15 Years

🛡️ Karen Serobovich Vardanyan, 34, pleaded guilty to hacking U.S. companies and deploying Ryuk ransomware after being extradited from Kyiv. She provided initial access to corporate networks and helped deploy ransomware between November 2019 and April 2020, leading to large ransom payments including a Michigan firm that paid 200 BTC. Prosecutors say the group collected about 1,610 BTC (≈$15 million then).
read more →

Ransomware family exploits signed drivers to evade

🛡️ Symantec details how the GodDamn ransomware, a 2026 evolution of the Hyadina family, uses Microsoft-signed malicious drivers to disable endpoint defenses. The attackers deployed AnyDesk covertly, dropped a signed kernel driver named PoisonX disguised as a Symantec product, and used credential-stealing tools like Mimikatz to escalate access. After weakening defenses and harvesting credentials, the threat actors executed file encryption and displayed a ransom note, demonstrating continued tactical evolution.
read more →

Former negotiator sentenced in BlackCat ransomware case

🔒 A former DigitalMint incident response employee was sentenced to 70 months for participating in BlackCat (ALPHV) ransomware attacks that targeted U.S. organizations. Prosecutors say the group tied to BlackCat conducted over 60 breaches and collected at least $300 million in ransoms. Two other former negotiators received four-year sentences after pleading guilty to related charges. Victims included large financial and nonprofit organizations that paid multi‑million dollar ransoms.
read more →

GigaWiper: Multipurpose Windows backdoor and wiper

🛡️ Microsoft dissected a destructive Windows backdoor dubbed GigaWiper, which bundles three older wipers into a single Go-based platform offering selectable destructive commands. The implant can wipe entire disks, overwrite the Windows drive, or run fake ransomware that encrypts files without saving keys, and also provides remote control capabilities like screenshots, VNC access, and process management. Microsoft and Binary Defense observed the same file hashes and command servers, with Binary Defense linking the samples to an Iran-linked actor while Microsoft refrains from attributing a country. Defenders should monitor for a OneDrive Update scheduled task, RabbitMQ/Redis traffic from desktops, and suspicious use of takeown/icacls, and apply tamper protection, endpoint blocking, and blocklisted server addresses.
read more →

Weekly ThreatsDay: Emerging cyber risks and trends

🔒 This ThreatsDay roundup highlights a series of recent, pragmatic security incidents and research findings that stem from routine administrative mistakes and small configuration errors. It covers a multinational fraud takedown, malicious typosquatting of payment SDKs, novel code-injection techniques, and a critical unauthenticated ArcGIS Server flaw. The report also outlines ransomware tool overlaps, data-exfiltration concerns in Claude Code, social engineering campaigns abusing Teams and Meta, and multiple kernel and driver vulnerabilities.
read more →

June 2026: Global Cyber Attacks and Ransomware Shift

📈 June 2026 saw a notable rebound in global cyber attacks, with weekly incidents per organization averaging 2,270, up 10% from May and 17% year over year. Education, Government, and Telecommunications were the most targeted industries, while Latin America recorded the largest regional increase. Ransomware incidents surged 33% year over year, and The Gentlemen overtook Qilin as the most active ransomware group.
read more →