Shell has launched a cybersecurity investigation following claims by the Cl0p ransomware operation that it stole 89GB of corporate information from the…
Tag: ransomware
Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says…
Shell Investigating Data Breach Following Cl0p Ransomware Group Claim
Multinational energy giant Shell has launched an active investigation after the notorious Cl0p ransomware syndicate claimed responsibility for…
The Department of Know: Ransomware gangs, Copilot apps, and drones phone home
Read the full stories at CISOSeries.com This week’s Department of Know is hosted by Sarah Lane, with guests Peter Gregory , author of over 50 books on…
Ransomware Attacks Fall as Business Defenses Improve
Ransomware has long been one of the biggest cyber threats to businesses, often forcing victims into costly downtime and data loss. Recently, analysts have…
New Ransomware Targets AI Model Weights but Fails to Collect Ransom
An updated ransomware campaign is targeting an important but often overlooked asset in artificial intelligence environments: trained AI models and their…
AnMed Health Ransomware Attack Highlights Growing Patient Safety Risks in Healthcare
AnMed Health is the latest healthcare organization to be disrupted by a ransomware-related cybersecurity incident after having to cancel procedures and…
Ransomware Attack Explained: How It Works and How to Defend Against It (2026)
By HOC Team | Last updated: August 2026 | Read time: ~23 min At 2:07 AM on a…
US, South Korea Warn of Growing Gunra Ransomware Threat
U.S. and South Korean authorities warn about the growing Gunra ransomware threat as the operation expands its capabilities and affiliate network.
Storm-1175 Deploys StormEncryptor Ransomware
Microsoft Threat Intelligence has identified a significant shift in tactics by Storm-1175, a China-based financially motivated threat actor, which has…
Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned
July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens
Key takeaways Weekly cyber attacks reached 2,336 per organization in July 2026, up 3% from June and 16% year over year Education remained the most…
Hackers Linked to China Install StormEncryptor Ransomware
Threat actor links to China Microsoft has revealed that a financially motivated hacker linked to China, called Storm-1175 has installed an earlier…
Akira ransomware scum blocked victim’s security tools – and broke their own encryptor
Gives a whole new meaning to Safe Mode
Hackers Using New Blackhat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
A newly surfaced criminal AI service called MessiahGPT is being openly marketed on BreachForums as a purpose-built offensive model that writes ransomware,…
Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
A newly surfaced criminal AI service called MessiahGPT is being openly marketed on BreachForums as a purpose-built offensive model that writes ransomware,…
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations…
Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White
Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.