Home/Blog/Ransomware

Ransomware

Ransomware attacks continue to evolve with double-extortion tactics and targeted enterprise campaigns. This section analyzes ransomware groups, attack patterns, and defensive strategies CISOs must understand.

76 articles

Akira Ransomware Attack: SonicWall VPN Exploitation and EDR Evasion (August 2026)
ransomware

Akira Ransomware Attack: SonicWall VPN Exploitation and EDR Evasion (August 2026)

An unnamed organization suffered a high-severity Akira ransomware attack in August 2026, involving credential-spraying against a SonicWall SSL VPN and Safe Mode EDR evasion. Data was exfiltrated and ransomware deployed, but encryption failed due to system constraints.

Aug 15, 20265 min read
Read More
Unknown Organization Ransomware: Akira Affiliate Disables EDR, Data Stolen but No Encryption (June 2024)
ransomware

Unknown Organization Ransomware: Akira Affiliate Disables EDR, Data Stolen but No Encryption (June 2024)

An unknown organization suffered a ransomware attack by an Akira affiliate, resulting in data and credential theft after EDR was disabled via Safe Mode, though encryption failed.

Aug 14, 20265 min read
Read More
DeadLock Ransomware: Blockchain-Powered Double Extortion Hits 80 European Organizations (July 2026)
ransomware

DeadLock Ransomware: Blockchain-Powered Double Extortion Hits 80 European Organizations (July 2026)

DeadLock ransomware compromised 80 organizations across Europe, stealing and encrypting sensitive data. The group leveraged blockchain and decentralized networks to evade takedown.

Aug 13, 20265 min read
Read More
San Diego Hospitals Ransomware: Critical Patient Care Disruptions (2021)
ransomware

San Diego Hospitals Ransomware: Critical Patient Care Disruptions (2021)

Four San Diego hospitals suffered a ransomware attack in 2021, crippling operations and causing severe patient care disruptions. The incident led to a 48% increase in wait times and a 128% rise in patients leaving without care.

Aug 8, 20265 min read
Read More
Signature Services Ransomware: Play Group Claims File Encryption (August 2026)
ransomware

Signature Services Ransomware: Play Group Claims File Encryption (August 2026)

Signature Services, a US-based professional services provider, suffered a ransomware attack attributed to the Play group, resulting in file encryption and operational disruption. The incident was publicly claimed by the attackers, though the organization has not confirmed details.

Aug 7, 20265 min read
Read More
Preferred Financial Group Ransomware: Play Actor Disrupts Operations (August 2026)
ransomware

Preferred Financial Group Ransomware: Play Actor Disrupts Operations (August 2026)

Preferred Financial Group suffered a ransomware attack attributed to the Play group, resulting in unauthorized access and operational disruption. The incident was publicly claimed by the threat actor, though the organization has not confirmed the breach.

Aug 6, 20265 min read
Read More
Centro Universitário CESMAC Ransomware: Krybit Group Claims Attack (August 2026)
ransomware

Centro Universitário CESMAC Ransomware: Krybit Group Claims Attack (August 2026)

Centro Universitário CESMAC in Brazil suffered a ransomware attack attributed to the krybit group, resulting in potential IT system encryption and service disruption. The incident was publicly claimed by the threat actor on their darknet blog.

Aug 5, 20265 min read
Read More
naskdoorinc.com Ransomware Attack: safepay Group Disrupts Manufacturing Operations (August 2026)
ransomware

naskdoorinc.com Ransomware Attack: safepay Group Disrupts Manufacturing Operations (August 2026)

naskdoorinc.com, a US-based manufacturing company, suffered a ransomware attack by the safepay group, causing operational disruption across southeastern Pennsylvania and northern Delaware. The incident may involve data encryption or theft, though technical specifics remain unconfirmed.

Aug 4, 20265 min read
Read More
Minnesota Water Utilities Ransomware: Coordinated OT Disruption (July 2026)
ransomware

Minnesota Water Utilities Ransomware: Coordinated OT Disruption (July 2026)

Minnesota water utilities suffered a coordinated ransomware attack impacting over 30 organizations, including Braham and Plymouth Water Utilities. Attackers exploited exposed PLCs, resulting in operational outages and boil water notices.

Aug 3, 20265 min read
Read More
Vernon & Waldrep Ransomware Attack: 274 GB of Sensitive Data Compromised (August 2026)
ransomware

Vernon & Waldrep Ransomware Attack: 274 GB of Sensitive Data Compromised (August 2026)

Vernon & Waldrep, a Texas-based healthcare organization, suffered a ransomware attack by Global Secret Group, resulting in the compromise of 274 GB of data. Over 56,000 files, including sensitive healthcare and mental health specialist information, were exposed.

Aug 2, 20265 min read
Read More
MBM Law Ransomware Attack: Disruption by Dragonforce (July 2026)
ransomware

MBM Law Ransomware Attack: Disruption by Dragonforce (July 2026)

MBM Law, a South Carolina-based law firm, suffered a ransomware attack attributed to the threat actor dragonforce. The incident resulted in operational disruption and a ransomware claim against the firm.

Aug 1, 20265 min read
Read More
L3Harris Ransomware Attack: Kyber Group Disrupts US Operations (July 2026)
ransomware

L3Harris Ransomware Attack: Kyber Group Disrupts US Operations (July 2026)

L3Harris, a US-based aerospace and defense technology company, suffered operational disruption following a ransomware attack attributed to Kyber Group. The incident targeted US operations and was publicly claimed by the threat actor.

Jul 31, 20265 min read
Read More