Home/Blog/Ransomware

Ransomware

Ransomware attacks continue to evolve with double-extortion tactics and targeted enterprise campaigns. This section analyzes ransomware groups, attack patterns, and defensive strategies CISOs must understand.

90 articles

Union County Ransomware: $1 Million Paid After 2TB Data Theft (May 2025)
ransomware

Union County Ransomware: $1 Million Paid After 2TB Data Theft (May 2025)

Union County, Ohio suffered a ransomware attack by the Kairos group, resulting in the theft of over 2TB of sensitive data. The county paid $1 million in Bitcoin to prevent public release of information affecting 45,487 individuals.

Jul 8, 20265 min read
Read More
Sysdig Ransomware: First AI-Run Attack Encrypts 1,300+ Records (July 2026)
ransomware

Sysdig Ransomware: First AI-Run Attack Encrypts 1,300+ Records (July 2026)

Sysdig was impacted by JadePuffer, the first AI-driven ransomware attack, which encrypted over 1,300 configuration records and stole credentials. The AI agent autonomously exploited vulnerabilities, raising new concerns about attack scalability.

Jul 7, 20265 min read
Read More
Qilin Ransomware: Market Dominance Amid Cybercrime Consolidation (June 2024)
ransomware

Qilin Ransomware: Market Dominance Amid Cybercrime Consolidation (June 2024)

Qilin, a ransomware-as-a-service operation, has rapidly become the dominant ransomware group, compromising nearly 1,500 organizations over the past year. The group’s mature infrastructure and aggressive tactics have led to significant disruption and increased law enforcement scrutiny.

Jul 6, 20265 min read
Read More
Blackpoint Cyber Ransomware: Avalon Framework Delivers CrownX via Phishing (July 2026)
ransomware

Blackpoint Cyber Ransomware: Avalon Framework Delivers CrownX via Phishing (July 2026)

Blackpoint Cyber was targeted by the Avalon malware framework, which deployed CrownX ransomware via multi-stage phishing. Attackers exfiltrated credentials and cryptocurrency wallets, disrupted recovery, and demanded escalating ransom.

Jul 5, 20265 min read
Read More
Luxury Jewelry Retailer Ransomware: Scattered Spider Extradition Sheds Light on $2M Disruption (May 2025)
ransomware

Luxury Jewelry Retailer Ransomware: Scattered Spider Extradition Sheds Light on $2M Disruption (May 2025)

A luxury jewelry retailer suffered a ransomware attack by Scattered Spider in May 2025, resulting in $2 million in losses from business disruption. The group demanded an $8 million ransom, which was not paid.

Jul 4, 20265 min read
Read More
Fortinet Ransomware: FortiBleed Credential Theft Enables INC and Lynx Deployments (July 2026)
ransomware

Fortinet Ransomware: FortiBleed Credential Theft Enables INC and Lynx Deployments (July 2026)

Fortinet suffered a critical breach as the FortiBleed campaign enabled large-scale credential theft from FortiGate firewalls. Stolen credentials were weaponized by INC and Lynx ransomware groups, resulting in widespread endpoint encryption.

Jul 3, 20265 min read
Read More
Check Point Research Ransomware: AI-Generated InfernoGrabber Abuses Chromium API (July 2026)
ransomware

Check Point Research Ransomware: AI-Generated InfernoGrabber Abuses Chromium API (July 2026)

Check Point Research identified InfernoGrabber v9.0, an AI-generated browser ransomware abusing Chromium APIs to encrypt and steal data. The attack leverages the File System Access API on Windows and Android, exposing a new browser-native ransomware vector.

Jul 2, 20265 min read
Read More
UK Ransomware Attacks: Over 300 Firms Targeted in Coordinated Campaign (April 2025–March 2026)
ransomware

UK Ransomware Attacks: Over 300 Firms Targeted in Coordinated Campaign (April 2025–March 2026)

Marks & Spencer, Co-op Group, and Jaguar Land Rover were among over 300 UK firms hit by ransomware between April 2025 and March 2026. Manufacturing, scientific, and education sectors saw significant operational and financial disruption.

Jul 1, 20265 min read
Read More
Mexican Government Ransomware: Multi-Agency Breaches Expose National Vulnerabilities (2022–2025)
ransomware

Mexican Government Ransomware: Multi-Agency Breaches Expose National Vulnerabilities (2022–2025)

Multiple Mexican government agencies, including SEDENA and SICT, suffered ransomware attacks and data breaches between 2022 and 2025, resulting in sensitive data leaks and operational disruptions.

Jun 30, 20265 min read
Read More
KongTuke Ransomware: Mistic Backdoor Enables Stealthy Access Broker Operations (June 2024)
ransomware

KongTuke Ransomware: Mistic Backdoor Enables Stealthy Access Broker Operations (June 2024)

KongTuke leveraged the Mistic backdoor to compromise organizations in insurance, education, IT, and professional services. The attack enabled persistent, covert access for ransomware deployment.

Jun 29, 20265 min read
Read More
KongTuke Ransomware: Mistic Backdoor Enables Stealthy Access in Global Campaigns (April 2026)
ransomware

KongTuke Ransomware: Mistic Backdoor Enables Stealthy Access in Global Campaigns (April 2026)

KongTuke-affiliated threat actors deployed the Mistic backdoor in ransomware campaigns targeting insurance, education, IT, and professional services sectors, enabling memory-resident code execution and stealthy long-term access.

Jun 28, 20265 min read
Read More
European Manufacturing & IT Services Ransomware: Qilin Group Orchestrates Supply Chain Attacks (Jan 2025–Apr 2026)
ransomware

European Manufacturing & IT Services Ransomware: Qilin Group Orchestrates Supply Chain Attacks (Jan 2025–Apr 2026)

Over 2,000 organizations in European manufacturing and IT services suffered ransomware attacks via third-party suppliers, with Qilin group exploiting supply chains to expose personal data of over one million individuals.

Jun 27, 20265 min read
Read More