Home/Blog/Ransomware

Ransomware

Ransomware attacks continue to evolve with double-extortion tactics and targeted enterprise campaigns. This section analyzes ransomware groups, attack patterns, and defensive strategies CISOs must understand.

90 articles

Medibank Private Ransomware: Armenia Detains Suspected REvil Operator (June 2026)
ransomware

Medibank Private Ransomware: Armenia Detains Suspected REvil Operator (June 2026)

Medibank Private suffered a ransomware breach attributed to REvil, with Armenia detaining a Russian tourist allegedly linked to the attack. The incident underscores ongoing international law enforcement efforts and potential mistaken identity concerns.

Jul 20, 20265 min read
Read More
Land and Agricultural Development Bank of South Africa Ransomware: Global Government Agencies Targeted (Jan–Jun 2026)
ransomware

Land and Agricultural Development Bank of South Africa Ransomware: Global Government Agencies Targeted (Jan–Jun 2026)

Land and Agricultural Development Bank of South Africa and 186 other government organizations were hit by ransomware, causing widespread service disruption. Notably, attackers demanded $3.1 million from the South African bank.

Jul 19, 20265 min read
Read More
Thyssenkrupp Marine Systems Ransomware: 1TB Data Exfiltrated by The Gentlemen (June 2024)
ransomware

Thyssenkrupp Marine Systems Ransomware: 1TB Data Exfiltrated by The Gentlemen (June 2024)

Thyssenkrupp Marine Systems and its subsidiary Atlas Elektronik suffered a ransomware attack by The Gentlemen, resulting in over 1TB of data exfiltrated. The breach was contained to an isolated North American unit, limiting classified data exposure.

Jul 18, 20265 min read
Read More
Transport for London Ransomware: Scattered Spider Sentencing and Critical Disruption (July 2024)
ransomware

Transport for London Ransomware: Scattered Spider Sentencing and Critical Disruption (July 2024)

Transport for London suffered a critical ransomware attack in 2024, compromising personal and financial data of 5,000 individuals and disrupting 148 systems. Attackers Owen Flowers and Thalha Jubair were sentenced to 5.5 years for their roles.

Jul 17, 20265 min read
Read More
Progress Ransomware: ShareFile Storage Zone Controllers Disabled Amid Credible Threat (July 2026)
ransomware

Progress Ransomware: ShareFile Storage Zone Controllers Disabled Amid Credible Threat (July 2026)

Progress has directed ShareFile customers to immediately shut down Storage Zone Controllers following a credible ransomware threat. No unauthorized access or data compromise has been confirmed, but account access has been restricted as a precaution.

Jul 16, 20265 min read
Read More
Langflow Ransomware: JadePuffer LLM-Driven Attack Destroys Alibaba Nacos Configurations (June 2025)
ransomware

Langflow Ransomware: JadePuffer LLM-Driven Attack Destroys Alibaba Nacos Configurations (June 2025)

Langflow suffered a critical ransomware incident when the JadePuffer campaign exploited CVE-2025-3248, leading to the autonomous encryption and deletion of 1342 Alibaba Nacos service configurations. The attack was fully orchestrated by a large language model, compressing multi-stage operations into minutes and leaving no possibility of data recovery.

Jul 15, 20265 min read
Read More
DigitalMint Ransomware: Insider Collusion Amplifies BlackCat Extortion (July 2026)
ransomware

DigitalMint Ransomware: Insider Collusion Amplifies BlackCat Extortion (July 2026)

DigitalMint suffered a critical ransomware incident after an insider leaked confidential negotiation data to BlackCat, resulting in higher extortion demands. The breach also implicated Sygnia Cybersecurity Services and led to $1.2 million in losses.

Jul 14, 20265 min read
Read More
Ryuk Ransomware Attacks: U.S. Organizations Targeted in Coordinated Campaign (April 2020)
ransomware

Ryuk Ransomware Attacks: U.S. Organizations Targeted in Coordinated Campaign (April 2020)

Multiple U.S. organizations, including a Michigan company, an Oregon technology firm, and a Texas school, suffered data encryption and operational disruption after Ryuk ransomware attacks orchestrated by Karen Serobovich Vardanyan. Victims paid over $15 million in Bitcoin ransoms.

Jul 13, 20265 min read
Read More
Citrix NetScaler Ransomware: DragonForce Deployed via CitrixBleed 2 Exploit (Early 2026)
ransomware

Citrix NetScaler Ransomware: DragonForce Deployed via CitrixBleed 2 Exploit (Early 2026)

Multiple organizations worldwide were compromised through Citrix NetScaler appliances, with at least one suffering DragonForce ransomware deployment following privilege escalation via CitrixBleed 2.

Jul 12, 20265 min read
Read More
The Gentlemen Ransomware: Global Manufacturing Disruption and Custom Tooling (June 2026)
ransomware

The Gentlemen Ransomware: Global Manufacturing Disruption and Custom Tooling (June 2026)

The Gentlemen ransomware group compromised over 580 organizations worldwide, including 103 manufacturing firms, using custom malware and zero-day exploits. Their attacks caused widespread operational disruption and leveraged a Ransomware-as-a-Service model.

Jul 11, 20265 min read
Read More
GodDamn Ransomware Attack: PoisonX Driver Used for Defense Evasion (June 2026)
ransomware

GodDamn Ransomware Attack: PoisonX Driver Used for Defense Evasion (June 2026)

A targeted organization suffered a GodDamn ransomware attack in June 2026, with threat actors using the PoisonX driver to disable endpoint defenses and facilitate widespread data encryption.

Jul 10, 20265 min read
Read More
Bandai Channel Ransomware: AI-driven JadePuffer Attack and Mass Subscription Cancellations (June 2024)
ransomware

Bandai Channel Ransomware: AI-driven JadePuffer Attack and Mass Subscription Cancellations (June 2024)

Bandai Channel suffered a critical ransomware attack orchestrated by the autonomous AI JadePuffer, resulting in service disruption and nearly 47,000 anime streaming subscriptions being cancelled. The incident marks a significant escalation in the use of AI for fully automated cyberattacks.

Jul 9, 20265 min read
Read More