Home/Blog/Ransomware

Ransomware

Ransomware attacks continue to evolve with double-extortion tactics and targeted enterprise campaigns. This section analyzes ransomware groups, attack patterns, and defensive strategies CISOs must understand.

62 articles

Thai Seng International Co. Ltd Ransomware: nightspire Encrypts Client Data (July 2026)
ransomware

Thai Seng International Co. Ltd Ransomware: nightspire Encrypts Client Data (July 2026)

Thai Seng International Co. Ltd suffered a ransomware attack by the nightspire group, resulting in the encryption of administration and marketing data. Client information was compromised and business operations were disrupted.

Jul 28, 20265 min read
Read More
iw steelTEC Makine San. ve Tic. A.,Ş. Ransomware: Doommageddon Data Leak (July 2026)
ransomware

iw steelTEC Makine San. ve Tic. A.,Ş. Ransomware: Doommageddon Data Leak (July 2026)

Turkish manufacturer iw steelTEC Makine San. ve Tic. A.,Ş. suffered a ransomware attack by Doommageddon, resulting in a 100 GB data leak. The group set a ransom deadline for March 8, 2026.

Jul 27, 20265 min read
Read More
Jubilee Jobs Ransomware: Qilin Disrupts Nigerian Professional Services (July 2026)
ransomware

Jubilee Jobs Ransomware: Qilin Disrupts Nigerian Professional Services (July 2026)

Jubilee Jobs, a Nigerian professional services firm, suffered a high-severity ransomware attack by the Qilin group. The incident resulted in data encryption and significant disruption to company systems.

Jul 26, 20265 min read
Read More
Bank of Baroda Ransomware: 1TB of Customer Data Exposed (July 2026)
ransomware

Bank of Baroda Ransomware: 1TB of Customer Data Exposed (July 2026)

Bank of Baroda suffered a critical ransomware attack by the Triple X group, exposing up to 1TB of sensitive customer data. The breach includes banking records, netbanking access details, and identity documents, impacting hundreds of thousands of customers.

Jul 25, 20265 min read
Read More
Record Go Alquiler Ransomware Attack: Play Group Disrupts Hospitality Operations (July 2026)
ransomware

Record Go Alquiler Ransomware Attack: Play Group Disrupts Hospitality Operations (July 2026)

Record Go Alquiler, a hospitality company in Argentina, suffered a ransomware attack by the Play group. System access was blocked and data encrypted, causing significant operational disruption.

Jul 24, 20265 min read
Read More
Recsa Ransomware: Qilin Group Claims Attack on Costa Rican Firm (July 2026)
ransomware

Recsa Ransomware: Qilin Group Claims Attack on Costa Rican Firm (July 2026)

Recsa, a Costa Rican organization, was targeted by the Qilin ransomware group, resulting in unauthorized access and file encryption. The incident was publicly claimed by Qilin, though Recsa has not confirmed the breach.

Jul 23, 20265 min read
Read More
Langflow Ransomware: ENCFORGE Targets AI Model Files via RCE (July 2026)
ransomware

Langflow Ransomware: ENCFORGE Targets AI Model Files via RCE (July 2026)

Langflow suffered a critical ransomware attack exploiting CVE-2025-3248, allowing the JADEPUFFER group to deploy ENCFORGE and encrypt AI model files, vector indexes, and training datasets. The attack leveraged a remote code execution flaw to disrupt AI infrastructure with no evidence of data exfiltration.

Jul 22, 20265 min read
Read More
SonicWall Ransomware: Zero-Day Exploitation of SMA1000 Appliances (June 2026)
ransomware

SonicWall Ransomware: Zero-Day Exploitation of SMA1000 Appliances (June 2026)

SonicWall customers experienced ransomware attacks after threat actors exploited two critical zero-day vulnerabilities in SMA1000 appliances. At least seven organizations suffered root compromise and credential theft.

Jul 21, 20265 min read
Read More
Medibank Private Ransomware: Armenia Detains Suspected REvil Operator (June 2026)
ransomware

Medibank Private Ransomware: Armenia Detains Suspected REvil Operator (June 2026)

Medibank Private suffered a ransomware breach attributed to REvil, with Armenia detaining a Russian tourist allegedly linked to the attack. The incident underscores ongoing international law enforcement efforts and potential mistaken identity concerns.

Jul 20, 20265 min read
Read More
Land and Agricultural Development Bank of South Africa Ransomware: Global Government Agencies Targeted (Jan–Jun 2026)
ransomware

Land and Agricultural Development Bank of South Africa Ransomware: Global Government Agencies Targeted (Jan–Jun 2026)

Land and Agricultural Development Bank of South Africa and 186 other government organizations were hit by ransomware, causing widespread service disruption. Notably, attackers demanded $3.1 million from the South African bank.

Jul 19, 20265 min read
Read More
Thyssenkrupp Marine Systems Ransomware: 1TB Data Exfiltrated by The Gentlemen (June 2024)
ransomware

Thyssenkrupp Marine Systems Ransomware: 1TB Data Exfiltrated by The Gentlemen (June 2024)

Thyssenkrupp Marine Systems and its subsidiary Atlas Elektronik suffered a ransomware attack by The Gentlemen, resulting in over 1TB of data exfiltrated. The breach was contained to an isolated North American unit, limiting classified data exposure.

Jul 18, 20265 min read
Read More
Transport for London Ransomware: Scattered Spider Sentencing and Critical Disruption (July 2024)
ransomware

Transport for London Ransomware: Scattered Spider Sentencing and Critical Disruption (July 2024)

Transport for London suffered a critical ransomware attack in 2024, compromising personal and financial data of 5,000 individuals and disrupting 148 systems. Attackers Owen Flowers and Thalha Jubair were sentenced to 5.5 years for their roles.

Jul 17, 20265 min read
Read More