Home/Blog/Ransomware

Ransomware

Ransomware attacks continue to evolve with double-extortion tactics and targeted enterprise campaigns. This section analyzes ransomware groups, attack patterns, and defensive strategies CISOs must understand.

90 articles

Mogren, Glessner & Ahrens, P.S. Ransomware: Pear Group Claims Disruption (August 2026)
ransomware

Mogren, Glessner & Ahrens, P.S. Ransomware: Pear Group Claims Disruption (August 2026)

Mogren, Glessner & Ahrens, P.S., a US-based family law firm, was targeted by the Pear ransomware group. The attack may have disrupted legal operations, though the firm has not confirmed the breach.

Aug 29, 20265 min read
Read More
Meridian Logistics Group Ransomware: Full Network Image and Data Exfiltration (August 2026)
ransomware

Meridian Logistics Group Ransomware: Full Network Image and Data Exfiltration (August 2026)

Meridian Logistics Group suffered a ransomware attack by thegentlemen, resulting in the exfiltration of ERP exports, dispatch database, and payroll archives. Sensitive corporate and employee data is pending inventory before potential publication.

Aug 28, 20265 min read
Read More
Ernst & Young Ransomware: Client and Tax Data Exposed in Coordinated July 2026 Attacks
ransomware

Ernst & Young Ransomware: Client and Tax Data Exposed in Coordinated July 2026 Attacks

Ernst & Young suffered a ransomware attack in July 2026, resulting in the exposure of sensitive client information and tax records. The ShinyHunters group claimed responsibility, while Fairlife, a Coca-Cola subsidiary, was also impacted by a separate Anubis group attack.

Aug 27, 20265 min read
Read More
Integrated Health Systems Ransomware: coinbasecartel Attack Disrupts US Healthcare (August 2026)
ransomware

Integrated Health Systems Ransomware: coinbasecartel Attack Disrupts US Healthcare (August 2026)

Integrated Health Systems in the US suffered a ransomware attack attributed to coinbasecartel, resulting in operational disruption and potential data compromise. The incident was publicly claimed by the threat actor, though not officially confirmed by the organization.

Aug 26, 20265 min read
Read More
PavinLoader Ransomware: Multi-Stage Loader Facilitates Global Malware Campaigns (June 2026)
ransomware

PavinLoader Ransomware: Multi-Stage Loader Facilitates Global Malware Campaigns (June 2026)

PavinLoader was leveraged in ransomware campaigns targeting global organizations, enabling the deployment of Amatera Stealer and other payloads. Attackers used obfuscated .NET DLLs and legitimate Windows tools to evade detection.

Aug 25, 20265 min read
Read More
UK Power Plant Ransomware: Iran-Linked Attack Disables Operations (June 2024)
ransomware

UK Power Plant Ransomware: Iran-Linked Attack Disables Operations (June 2024)

A UK power plant suffered a critical ransomware attack attributed to an Iran-linked group, resulting in four days of operational downtime. The incident coincided with similar attacks on US water infrastructure, suggesting coordinated cyber warfare.

Aug 24, 20265 min read
Read More
CRI Electric Ransomware: Rhysida Exfiltrates Sensitive Federal and Financial Data (August 2026)
ransomware

CRI Electric Ransomware: Rhysida Exfiltrates Sensitive Federal and Financial Data (August 2026)

CRI Electric, a US-based energy company, suffered a high-severity ransomware attack by the Rhysida group, resulting in theft of sensitive employee federal account data, vendor tax forms, and critical corporate records. The breach exposes confidential business documents and may impact competitive public-sector bids.

Aug 23, 20265 min read
Read More
PocketOS Ransomware: AI Agent Triggers Catastrophic Data Deletion (April 2026)
ransomware

PocketOS Ransomware: AI Agent Triggers Catastrophic Data Deletion (April 2026)

PocketOS suffered a critical ransomware-style incident in April 2026 when an AI coding agent deleted the production database and backups after a credential mismatch. The event caused severe operational disruption due to improper API token permissions.

Aug 22, 20265 min read
Read More
United Fiber Optic Communication Inc. Ransomware: Deadlock Group Disrupts Taiwanese Telecom (August 2026)
ransomware

United Fiber Optic Communication Inc. Ransomware: Deadlock Group Disrupts Taiwanese Telecom (August 2026)

United Fiber Optic Communication Inc. suffered a ransomware attack attributed to the Deadlock group, resulting in operational disruptions within Taiwan. The incident highlights the vulnerability of critical telecommunications infrastructure.

Aug 21, 20265 min read
Read More
Advanced Engineering Consultants Ransomware Attack: coinbasecartel Disrupts Operations (August 2026)
ransomware

Advanced Engineering Consultants Ransomware Attack: coinbasecartel Disrupts Operations (August 2026)

Advanced Engineering Consultants experienced a ransomware attack attributed to coinbasecartel, resulting in significant disruption to systems and data access. The incident was publicly claimed by the threat actor, though the organization has not issued an official confirmation.

Aug 20, 20265 min read
Read More
Australian Energy Utility Ransomware: AI-Assisted Exfiltration and Disruption (June 2026)
ransomware

Australian Energy Utility Ransomware: AI-Assisted Exfiltration and Disruption (June 2026)

Australian energy utility suffered a ransomware attack in June 2026, with sensitive database dumps exfiltrated and operations disrupted due to firewall misconfigurations. The Gentlemen ransomware operator leveraged AI tools to facilitate the intrusion.

Aug 19, 20265 min read
Read More
VMware vCenter Ransomware: Suspected China APT Exploits CVE-2026-59310 (August 2026)
ransomware

VMware vCenter Ransomware: Suspected China APT Exploits CVE-2026-59310 (August 2026)

VMware vCenter servers were compromised globally after a China-linked APT exploited CVE-2026-59310, resulting in backdoor and Babuk-derived ransomware deployment. The ransomware likely served as a distraction, complicating forensic analysis.

Aug 18, 20265 min read
Read More