Visualização normal

Antes de ontemStream principal
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, September 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
     

Ransom & Dark Web Issues Week 1, September 2026

Por:ATCP
2 de Setembro de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
     

Ransom & Dark Web Issues Week 4, August 2026

Por:ATCP
26 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
  • ✇ASEC BLOG
  • July 2026 Threat Trend Report on Ransomware ATCP
    Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
     

July 2026 Threat Trend Report on Ransomware

Por:ATCP
23 de Agosto de 2026, 12:00
Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 2, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026.           DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
     

Ransom & Dark Web Issues Week 2, August 2026

Por:ATCP
12 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026.           DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026           South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts and Advanced Materials Manufacturer
     

Ransom & Dark Web Issues Week 1, August 2026

Por:ATCP
5 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026           South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts and Advanced Materials Manufacturer
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 5, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 5, July 2026           Termite Ransomware Attack on a U.S. Nonprofit Healthcare Provider ShinyHunters Claims Data Leak Involving a Global Accounting and Consulting Firm The Gentlemen Ransomware Attack on a South Korean IT Software Distributor and Infrastructure Service Provider
     

Ransom & Dark Web Issues Week 5, July 2026

Por:ATCP
29 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 5, July 2026           Termite Ransomware Attack on a U.S. Nonprofit Healthcare Provider ShinyHunters Claims Data Leak Involving a Global Accounting and Consulting Firm The Gentlemen Ransomware Attack on a South Korean IT Software Distributor and Infrastructure Service Provider
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
     

Ransom & Dark Web Issues Week 4, July 2026

Por:ATCP
22 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 3, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 3, July 2026           DragonForce Ransomware Attack on a Saudi Arabian Chemical Manufacturer AiLock Ransomware Attack on Japan’s Largest Taxi and Limousine Operator Cyberattack on Japan’s Largest Frozen Food Company Disrupts the Wider Food Supply Chain
     

Ransom & Dark Web Issues Week 3, July 2026

Por:ATCP
15 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 3, July 2026           DragonForce Ransomware Attack on a Saudi Arabian Chemical Manufacturer AiLock Ransomware Attack on Japan’s Largest Taxi and Limousine Operator Cyberattack on Japan’s Largest Frozen Food Company Disrupts the Wider Food Supply Chain
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 2, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 2, July 2026           Saudi Arabian Medical Records Breach, For Sale on Cybercrime Forum Irish ICT Company Data Leaked, For Sale on Cybercrime Forum LeakNet Breach Targets US Healthcare Insurer, Shared on Cybercrime Forums
     

Ransom & Dark Web Issues Week 2, July 2026

Por:ATCP
8 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 2, July 2026           Saudi Arabian Medical Records Breach, For Sale on Cybercrime Forum Irish ICT Company Data Leaked, For Sale on Cybercrime Forum LeakNet Breach Targets US Healthcare Insurer, Shared on Cybercrime Forums
  • ✇Security Affairs
  • 430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link Pierluigi Paganini
    FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator with access to FortiBleed’s own infrastructure was found actively logged into the negot
     

430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link

2 de Julho de 2026, 07:37

FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks.

SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator with access to FortiBleed’s own infrastructure was found actively logged into the negotiation panels of both ransomware groups, handling ransom demands in real time.

FortiBleed has been documented since SOCRadar’s first report. The operation uses a custom tool written in Go called FortigateSniffer, which passively intercepts authentication traffic by abusing FortiOS’s own built-in packet diagnostic command across two dozen protocols.

The attacker never sends malicious payloads to the firewall. They just listen to the traffic the device generates itself. It’s a quiet way to collect credentials at scale, and it’s been running across more than 150 countries.

After the initial disclosure, SOCRadar continued mapping the campaign using Shodan, Censys, Validin, and its own scanning. That work turned up roughly 200 additional operational servers beyond the original dataset, a mix of credential sniffers and network scanners that hadn’t appeared in the first investigation. As the SOCRadar report states:

“Across the expanded infrastructure, STRU tracked scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets.” reads the report published by SocRadar. “On 354 of those, the actor completed the full attack chain: VPN compromise, access to the domain controller, and domain admin. STRU has confirmed at least 12 ransomware deployments stemming from this access, with hundreds of endpoints encrypted across affected organizations.”

That’s not credential theft sitting in a database waiting to be sold. That’s domain-level control of hundreds of organizations, obtained quietly through their own firewall. SOCRadar has confirmed at least 12 ransomware deployments traced directly to FortiBleed-derived access, with hundreds of endpoints encrypted across the affected organizations.

One of the newly discovered servers gave SOCRadar visibility into the group’s own internal environment. An operational security lapse in how the group managed its infrastructure exposed internal files, logs, and operational documentation. That’s what made the ransomware connection possible to prove rather than just infer.

Inside that environment, SOCRadar found an operator logged into negotiation panels for both INC Ransom and Lynx simultaneously.

INC Ransom has been active since mid-2023 and remains one of the more active ransomware-as-a-service operations by victim count. The INC RANSOM has claimed responsibility for the breach of at tens of organizations to date, including US hospice pharmacy  Xerox CorpOnePoint Patient Care, and Scotland’s National Health Service (NHS) Lynx appeared roughly a year later and is widely assessed as a direct evolution of INC. One operator, two brands, infrastructure traceable back to the credential harvesting campaign. The attribution case is direct.

SOCRadar also found a separately discovered open directory linked to INC Ransom and compared its contents against FortiBleed’s own target records. The victims matched.

“Comparing target and victim data from FortiBleed’s own infrastructure against a separately discovered INC-linked open directory, STRU found matching victims across both datasets, independent confirmation that the same organizations were being tracked by both the credential-harvesting operation and the ransomware group.” states SocRadar.

SOCRadar recovered an internal tracking document the group uses to manage its FortiGate targets, recording which credentials were used, which networks were accessed, and whether ransomware was eventually deployed. Analysis of this document points to a structured operation of roughly 20 people. A small core of primary operators handles the high-impact intrusions. Behind them sit dedicated specialists, and below those, a back-office layer of junior operators and technical support staff. It runs like a small company, with a division of labor that would look familiar on any org chart. (Except the product is ransomware.)

SOCRadar is withholding specific operator aliases, tooling details, and the full indicator set until the complete technical whitepaper publishes. That report will also cover a separate line of investigation into the group’s use of AI tools for vulnerability research, including work toward at least one undisclosed zero-day that SOCRadar is coordinating with the affected vendor through responsible disclosure.

The practical implication is direct.

This campaign isn’t an access broker quietly monetizing stolen credentials through underground markets at arm’s length from the actual attacks. The same infrastructure that collected the credentials is directly connected, through a shared operator, to the groups deploying ransomware on victim networks.

“The same access broker infrastructure that quietly intercepted authentication traffic across hundreds of thousands of firewalls is connected, through a shared operator, to two of the more active ransomware brands operating today.” concludes the report. “For organizations running FortiGate infrastructure, this raises the stakes on an already urgent finding: exposure to FortiBleed is not just a credential exposure risk, it is a potential precursor to ransomware.”

If your organization runs FortiGate infrastructure, the question isn’t whether your credentials were targeted. With 430,000 firewalls in scope and active scanning across 150 countries, the better question is whether your environment showed up in the 409 where admin access was confirmed, or the 354 where full domain compromise was achieved.

SOCRadar says the full indicator set will be in the forthcoming whitepaper. Watch for it.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, July 2026.           Settra cliams data leak at Korean industrial firm’s foreign affiliate The Gentlemen launches ransomware attacks against Spanish defense, aerospace, and IT service firms DragonForce claims data theft targeting a South Korean smart factory and digital twin company
     

Ransom & Dark Web Issues Week 1, July 2026

Por:ATCP
1 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, July 2026.           Settra cliams data leak at Korean industrial firm’s foreign affiliate The Gentlemen launches ransomware attacks against Spanish defense, aerospace, and IT service firms DragonForce claims data theft targeting a South Korean smart factory and digital twin company
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, June 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, June 2026       BreachForums, a cybercrime forum, showing signs of admitting to sales and impersonation of its staff Lapsus$ claims to have leaked data from a bank in Myanmar Qilin launches a ransomware attack targeting a law firm in South Korea
     

Ransom & Dark Web Issues Week 4, June 2026

Por:ATCP
24 de Junho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, June 2026       BreachForums, a cybercrime forum, showing signs of admitting to sales and impersonation of its staff Lapsus$ claims to have leaked data from a bank in Myanmar Qilin launches a ransomware attack targeting a law firm in South Korea
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 3, June 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 3, June 2026         Sale of Confidencial Defense Industry Documents in South Korea on Spear Forums Ransomware Attack by Qilin Targeting a South Korean Big Data Solution Company Ransomware Attack by Anubis Targeting a South Korean Semiconductor Equipment Parts Company
     

Ransom & Dark Web Issues Week 3, June 2026

Por:ATCP
17 de Junho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 3, June 2026         Sale of Confidencial Defense Industry Documents in South Korea on Spear Forums Ransomware Attack by Qilin Targeting a South Korean Big Data Solution Company Ransomware Attack by Anubis Targeting a South Korean Semiconductor Equipment Parts Company

Silent Ransom Group: what you need to know

11 de Junho de 2026, 12:43
Most extortion gangs hide behind a keyboard. Silent Ransom Group will phone your staff pretending to be IT support - and if that fails, send someone to your office in person to plug in a USB stick. Read more in my article on the Fortra blog.
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 2, June 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 2, June 2026         Black X Ransomware Attacks on Korean and U.S. Organizations Data from South Korean Education Platform Leaked on BreachForums by Hasan Breach of French Secure Government Messaging Data Discovered on PwnForums
     

Ransom & Dark Web Issues Week 2, June 2026

Por:ATCP
10 de Junho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 2, June 2026         Black X Ransomware Attacks on Korean and U.S. Organizations Data from South Korean Education Platform Leaked on BreachForums by Hasan Breach of French Secure Government Messaging Data Discovered on PwnForums
  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: Arup Group Breached by FulcrumSec BushidoToken
     What Happened:On 10 May 2026, the UK-based firm Arup Group was listed as a victim on the Tor data leak site of FulcrumSec. On their Tor data leak site, FulcrumSec stated that they have exposed 700GB of GitHub repos and 2TB of Azure and AWS S3 cloud, plus database backups.Other types of data the adversary claims to have stolen includes Neuron BMS client databases, Odoo ERP data, A66 landowner files, Apple code-signing certificates with plaintext passwords, a Google Cloud Platform (GCP) project w
     

UK Cybercrime Journal: Arup Group Breached by FulcrumSec

10 de Junho de 2026, 04:00

 


What Happened:

  • On 10 May 2026, the UK-based firm Arup Group was listed as a victim on the Tor data leak site of FulcrumSec. 
  • On their Tor data leak site, FulcrumSec stated that they have exposed 700GB of GitHub repos and 2TB of Azure and AWS S3 cloud, plus database backups.
  • Other types of data the adversary claims to have stolen includes Neuron BMS client databases, Odoo ERP data, A66 landowner files, Apple code-signing certificates with plaintext passwords, a Google Cloud Platform (GCP) project with production payment gateway credentials, and the source code of ArupCompute and Oasys. 
  • The FulcrumSec operators also claimed to have spent over half a year analysing the data and went through “email correspondence” with the company before publishing the stolen data.
  • On the victim post, FulcrumSec wrote a detailed incident breakdown. In it, they stated they gained initial access in September 2025 via a GitHub personal access token found hardcoded in a JavaScript file on a forgotten subdomain, which provided access to over 10,000 private GitHub repositories belonging to Arup Group.
  • From there, they scanned the repositories and found additional hardcoded tokens, API keys, and passwords for AWS, Azure, and databases.
  • The adversary stated that Arup detected the Github and Azure Storage intrusions approximately six weeks after they happened and rotated the credentials, but it was too late as the data had been exfiltrated. 
  • FulcrumSec also stated they pivoted into the AWS infrastructure using keys they had found belonging to Arup’s subsidiary Neuron.
  • FulcrumSec allegedly waited until April 2026 to contact their victim, Arup Group, due to the time it took to analyse the vast amounts of stolen data.
  • Impacted client organisations of Arup Group were also mentioned in the post, such as Disney and several other Hong Kong companies. The adversary reportedly uncovered Amazon data center seismic fragility data, British Petroleum (BP) site selection coordinates, and Queensferry Crossing internal documents as well.
  • Critically for the UK, the breached data exposed up to 62 HS2 related GitHub repositories. This involved Euston Station pile design files, ground movement assessments, over 14,000 sensor monitoring records, 48 archaeological site GPS coordinates (including Jones Hill Wood, a sensitive site for environmentalists), as well as confidential documents.

Analyst Comment:

Arup Group is a large multinational architectural design and engineering firm based in London who has been involved in constructing the Wembley Football Stadium in London, the HS1 Channel Tunnel Rail Link network, and the Eden Project in Cornwall, among other significant international construction projects.


Active since September 2025, FulcrumSec is a financially motivated data-theft-extortion group that specialises in rapid exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions.


This attack was noteworthy due to its highly targeted nature. FulcrumSec claimed they had access to Arup Group’s data for seven months and they clearly invested significant time to analyse the documents and spent weeks negotiating over email. Plus, to find initial access they also would have had to spend time checking Arup’s domains and Internet-facing assets to eventually find a single leaked credential to exploit. These types of targeted intrusions often only happen to large companies. This is because for it to be worth the cybercriminal’s time, effort, and risk to their freedom they will want a large ransom payment that only rich companies can typically afford.


FulcrumSec is an adversary worth monitoring due to the effort they put into their intrusions compared to other smash-and-grab ransomware campaigns. In October 2025, in a case documented by VX-Underground, FulcrumSec emailed detailed information about the breach they conducted with the aim of those details getting published and exert additional pressure on the victim.


Interestingly, FulcrumSec said the ransom they demanded was less than 1% of Arup’s annual revenue and was less than how much Arup lost to the deepfake fraudsters. This is a reference to Arup reportedly lost over £20 million pounds in 2024 after one of their Hong Kong employees was duped into sending cash to cybercriminals using an AI-generated video call. The fact Arup became publicly known for falling victim to a large scam potentially contributed to the adversary’s decision to select and focus them for this attack.


Defensive Takeaways:

  • Asset Inventory and Shadow IT Audits: Identifying the outdated unused domains with hardcoded credentials is standard best practices. All organisations must have processes in place to catalog and retire systems to avoid incidents like this. 
  • Hardcoded Credentials in Code: They way FulcrumSec gained access demonstrates the importance of using secret environment variables and features like GitHub Secret Scanning.
  • Implement Incident Response Procedures: Importantly, Arup detect the activity too late and it took them a staggering six weeks to rotate credentials (according to the adversary), which shows why having automated systems to check for unauthorised usage and reset tokens and all accounts is crucial to respond to such attacks.
  • GitHub Activity Monitoring: The adversary claimed they were able to clone thousands of GitHub repositories containing sensitive data without being detected. These types of activities are available to monitor and detect in GitHub Audit Logs. It’s also important to have a plan in place when suspicious activities are detected.
  • Third-Party Risk Management Programs: This incident also had some notable downstream impact. It shows why client organisations of another company’s services need to know what data and how much data is stored by third-parties for when such breaches occur. Knowing what’s potentially exposed will streamline the response to the incident.
  • Deception Tech: Arup could have implemented a boobytraps for the adversary such as the use of CanaryTokens inside sensitive documents. As the adversary spent time analysing the Arup’s documents before contacting them, if they open a boobytrapped document, then the incident could been detected much earlier and the damages could have been reduced.


Relevant Sources:

  1. https://x.com/darkwebinformer/status/2053281385582891437 
  2. https://www.ransomware.live/id/QXJ1cCBHcm91cEBmdWxjcnVtc2Vj 
  3. https://en.wikipedia.org/wiki/Arup_Group
  4. https://www.theguardian.com/technology/article/2024/may/17/uk-engineering-arup-deepfake-scam-hong-kong-ai-video


Relevant CTI Resources:

  1. https://www.ransomware.live/group/fulcrumsec
  2. https://x.com/vxunderground/status/1975629199323853027 
  3. https://www.reddit.com/r/Scams/s/wfZ3Wp94mY
  4. https://www.bleepingcomputer.com/news/security/lexisnexis-confirms-data-breach-as-hackers-leak-stolen-files/

  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, June 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, June 2026           Qilin Ransomware Attack Targets South Korean Automation Equipment Company New Data Extortion Group Black X Claims Leak of Internal Data from South Korean Plastic Surgery Clinic Nova Ransomware Attack Targets Department of AI at University in Daegu, South […]
     

Ransom & Dark Web Issues Week 1, June 2026

Por:ATCP
3 de Junho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, June 2026           Qilin Ransomware Attack Targets South Korean Automation Equipment Company New Data Extortion Group Black X Claims Leak of Internal Data from South Korean Plastic Surgery Clinic Nova Ransomware Attack Targets Department of AI at University in Daegu, South […]

Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations

Qilin

Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets.

Qilin: The Dominant Force

Qilin — also known as Agenda — is a ransomware group that entered 2026 accelerating, not slowing down. By early 2026, Qilin had already posted 55 confirmed victims, placing it ahead of its own 2025 pace. By June 2026, tracking data, Qilin had accumulated 168 confirmed victims in the healthcare sector alone, behind only manufacturing (291) and business services (245) in overall victim count. Qilin operates as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates who conduct attacks using Qilin's ransomware builder and infrastructure in exchange for a percentage of ransom proceeds. This model allows the core group to expand operational throughput without directly executing every attack. The group's double extortion model — encrypting victim data while simultaneously exfiltrating it and threatening public release on their leak site — has proven effective at pressuring victims into paying ransom demands even when robust backups exist. Public exposure of sensitive patient records creates regulatory, legal, and reputational pressure that many healthcare organisations find more immediately damaging than operational downtime. A notable recent case involves Covenant Health, which suffered a Qilin ransomware breach that exposed 478,188 patient records. The Covenant Health incident highlights Qilin's willingness to attack hospitals and health systems regardless of the direct patient safety implications.

INC Ransom: Targeting Critical Sectors

INC Ransom is another highly active operator that was among the top ransomware groups by victim count in January 2026, with 47 known attacks that month. The group targets organisations across multiple sectors, including healthcare, legal services, and public administration. INC Ransom gained significant attention in 2025 for its attack on NHS Scotland, which exposed 3 terabytes of patient data. The group continues to operate aggressively in 2026, targeting entities including healthcare practices, municipal agencies, and regional service providers. Recent INC Ransom victims include healthcare organisations such as Lymphedema Therapy Specialists, Inc. (February 2026, affecting 378 Texas patients) and various municipal and public sector entities, including Champaign-Urbana Public Health District.

The 2026 Ransomware Landscape

Beyond Qilin and INC Ransom, the broader 2026 ransomware ecosystem is characterised by:
  • AI-assisted operations: Multiple ransomware groups are now using AI tools to accelerate phishing campaign creation, target research, and initial access operations, reducing the operational cost of launching attacks.
  • Healthcare as a premium target: Patient records sell for up to 10 times as much as financial records on darknet markets, making it a persistently attractive target. Operational disruption of healthcare services also creates patient-safety leverage that can pressure organisations to make faster payment decisions.
  • The Play and SafePay operators were also confirmed in recent June 2026 attack disclosures, targeting organisations including Clínica Maitenes and various regional businesses.

Why It Matters

The 30% year-over-year increase in ransomware incidents confirms that neither law enforcement action nor improved defensive capabilities has materially reduced the operational tempo of ransomware criminal enterprises. The professionalisation of RaaS platforms, combined with AI-assisted tooling and shortened attack timelines, is creating conditions in which even well-defended organisations face materially elevated risk. For healthcare specifically, the combination of operational sensitivity, high data value, and historically underfunded security programmes creates a structural vulnerability that the industry has not yet resolved despite years of high-profile attacks.
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 3, May 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 3, May 2026         Nova Ransomware Attack on South Korean Cosmetics and Chemical Firm CoinbaseCartel, Data Leak Claim Against Open-Source Visualization Platform TeamPCP Claimed Source Code Leak and Sale from Major Developer Platform
     

Ransom & Dark Web Issues Week 3, May 2026

Por:ATCP
20 de Maio de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 3, May 2026         Nova Ransomware Attack on South Korean Cosmetics and Chemical Firm CoinbaseCartel, Data Leak Claim Against Open-Source Visualization Platform TeamPCP Claimed Source Code Leak and Sale from Major Developer Platform

Grafana Says It Rejected Ransom Demand After Source Code Theft

Grafana says hackers stole its source code after accessing a GitHub token, but no customer data or systems were affected.
❌
❌