Home/Blog/Ransomware

Ransomware

Ransomware attacks continue to evolve with double-extortion tactics and targeted enterprise campaigns. This section analyzes ransomware groups, attack patterns, and defensive strategies CISOs must understand.

62 articles

Luxury Jewelry Retailer Ransomware: Scattered Spider Extradition Sheds Light on $2M Disruption (May 2025)
ransomware

Luxury Jewelry Retailer Ransomware: Scattered Spider Extradition Sheds Light on $2M Disruption (May 2025)

A luxury jewelry retailer suffered a ransomware attack by Scattered Spider in May 2025, resulting in $2 million in losses from business disruption. The group demanded an $8 million ransom, which was not paid.

Jul 4, 20265 min read
Read More
Fortinet Ransomware: FortiBleed Credential Theft Enables INC and Lynx Deployments (July 2026)
ransomware

Fortinet Ransomware: FortiBleed Credential Theft Enables INC and Lynx Deployments (July 2026)

Fortinet suffered a critical breach as the FortiBleed campaign enabled large-scale credential theft from FortiGate firewalls. Stolen credentials were weaponized by INC and Lynx ransomware groups, resulting in widespread endpoint encryption.

Jul 3, 20265 min read
Read More
Check Point Research Ransomware: AI-Generated InfernoGrabber Abuses Chromium API (July 2026)
ransomware

Check Point Research Ransomware: AI-Generated InfernoGrabber Abuses Chromium API (July 2026)

Check Point Research identified InfernoGrabber v9.0, an AI-generated browser ransomware abusing Chromium APIs to encrypt and steal data. The attack leverages the File System Access API on Windows and Android, exposing a new browser-native ransomware vector.

Jul 2, 20265 min read
Read More
UK Ransomware Attacks: Over 300 Firms Targeted in Coordinated Campaign (April 2025–March 2026)
ransomware

UK Ransomware Attacks: Over 300 Firms Targeted in Coordinated Campaign (April 2025–March 2026)

Marks & Spencer, Co-op Group, and Jaguar Land Rover were among over 300 UK firms hit by ransomware between April 2025 and March 2026. Manufacturing, scientific, and education sectors saw significant operational and financial disruption.

Jul 1, 20265 min read
Read More
Mexican Government Ransomware: Multi-Agency Breaches Expose National Vulnerabilities (2022–2025)
ransomware

Mexican Government Ransomware: Multi-Agency Breaches Expose National Vulnerabilities (2022–2025)

Multiple Mexican government agencies, including SEDENA and SICT, suffered ransomware attacks and data breaches between 2022 and 2025, resulting in sensitive data leaks and operational disruptions.

Jun 30, 20265 min read
Read More
KongTuke Ransomware: Mistic Backdoor Enables Stealthy Access Broker Operations (June 2024)
ransomware

KongTuke Ransomware: Mistic Backdoor Enables Stealthy Access Broker Operations (June 2024)

KongTuke leveraged the Mistic backdoor to compromise organizations in insurance, education, IT, and professional services. The attack enabled persistent, covert access for ransomware deployment.

Jun 29, 20265 min read
Read More
KongTuke Ransomware: Mistic Backdoor Enables Stealthy Access in Global Campaigns (April 2026)
ransomware

KongTuke Ransomware: Mistic Backdoor Enables Stealthy Access in Global Campaigns (April 2026)

KongTuke-affiliated threat actors deployed the Mistic backdoor in ransomware campaigns targeting insurance, education, IT, and professional services sectors, enabling memory-resident code execution and stealthy long-term access.

Jun 28, 20265 min read
Read More
European Manufacturing & IT Services Ransomware: Qilin Group Orchestrates Supply Chain Attacks (Jan 2025–Apr 2026)
ransomware

European Manufacturing & IT Services Ransomware: Qilin Group Orchestrates Supply Chain Attacks (Jan 2025–Apr 2026)

Over 2,000 organizations in European manufacturing and IT services suffered ransomware attacks via third-party suppliers, with Qilin group exploiting supply chains to expose personal data of over one million individuals.

Jun 27, 20265 min read
Read More
Transport for London Ransomware: Scattered Spider Disrupts Services (August 2024)
ransomware

Transport for London Ransomware: Scattered Spider Disrupts Services (August 2024)

Transport for London suffered a high-severity ransomware attack by the Scattered Spider group in August 2024, causing service disruptions and operational compromise. Two men have pleaded guilty in the UK for their roles in the incident.

Jun 26, 20265 min read
Read More
Woodgnat Ransomware: Mistic RAT Enables Multi-Industry Access (April 2026)
ransomware

Woodgnat Ransomware: Mistic RAT Enables Multi-Industry Access (April 2026)

Woodgnat, an initial access broker, leveraged the new Mistic RAT to compromise organizations globally, enabling ransomware groups to infiltrate networks. The campaign targeted education, insurance, IT, and professional services sectors using advanced social engineering and lateral movement.

Jun 25, 20265 min read
Read More
FFmpeg Ransomware: PixelSmash Flaw Enables Remote Code Execution (June 2024)
ransomware

FFmpeg Ransomware: PixelSmash Flaw Enables Remote Code Execution (June 2024)

FFmpeg and downstream projects suffered a critical ransomware incident exploiting CVE-2026-8461, allowing remote code execution via crafted media files. Attackers leveraged the MagicYUV decoder flaw to compromise major media platforms.

Jun 24, 20265 min read
Read More
The Gentlemen Ransomware Operation Ransomware: GentleKiller Framework Disables Security Software (June 2024)
ransomware

The Gentlemen Ransomware Operation Ransomware: GentleKiller Framework Disables Security Software (June 2024)

The Gentlemen Ransomware-as-a-Service group deployed the GentleKiller framework to disable over 400 security products, including Microsoft Defender and CrowdStrike, prior to ransomware deployment. This allowed their attacks to bypass endpoint protection and increase impact across Southeast Asia, South America, and Western Europe.

Jun 23, 20265 min read
Read More