search
ransomware
Trends
- 1Keio Group Hit by Ransomware Attack▼Keio Group Ransomware Attack Disrupts Retail Payments and Hotel Services Keio Corporation disclosed a ransomware attack
Keio Corporation, the Japanese railway and hospitality conglomerate, disclosed a ransomware attack that disrupted payment systems, loyalty programs, and hotel reservation services across several group companies. The company isolated the affected networks, notified police, and is investigating the incident. The attack highlights how cyber incidents on transport groups can cascade into retail and hospitality operations.
- 2Clop ransomware gang relocates servers after exploiting Grav CMS flaw▼Clop ransomware gang moves to new server after Grav CMS vulnerability exploited
The Clop ransomware gang has moved to new server infrastructure after exploiting a vulnerability in Grav CMS, the open-source flat-file content management system. The extortion group, known for large-scale data-theft campaigns against corporations and government agencies, is continuing operations despite the disruption. Security teams are being urged to patch Grav CMS installations and review whether their systems were targeted.
- 3Ransomware attack hits Keio Electric Railway payment systems●おお、あ、秋田よ 京王電鉄にランサム攻撃 決済に障害、鉄道影響なし https://www. 47news.jp/14997568.html # 神 # news # bot
Keio Electric Railway, a major private railway operator in Tokyo, has been hit by a ransomware attack that disrupted its payment and settlement systems. The company says train operations themselves were not affected, and services continue to run normally while it deals with the cyberattack. The incident adds to a string of ransomware attacks on Japanese organisations, drawing attention to the vulnerability of critical transport infrastructure.
- 4ShinyHunters Hacks Rival Gang Cl0p, Seizes Leak Site▼ShinyHunters Hacks Rival Ransomware Gang Cl0p and Takes Over its Dark Web Tor Data Leak Site
The hacking group ShinyHunters has compromised Cl0p, a rival ransomware gang, and taken control of its dark web Tor data leak site, according to a report by CPO Magazine. The takeover of one major cybercrime operation by another is drawing attention from security researchers tracking shifting alliances and infighting in the ransomware underworld.
- 5
Police have arrested a 16-year-old suspected of leading the KillSec ransomware group, according to Help Net Security. The arrest of a minor at the head of a ransomware operation has drawn attention to how young hackers have become involved in organized cybercrime, and to the growing activity of the KillSec group itself.
- 6RansomHouse claims cyberattack on Peruvian hospital▼🚨New ransom group blog post!🚨 Group name: ransomhouse Post title: Hospital Hermilio Valdizán Location: 🇵🇪 PE Sector: Hea
The ransomware group RansomHouse has listed Hospital Hermilio Valdizán in Peru as a new victim on its leak site, adding the healthcare facility to its portfolio of claimed attacks. If confirmed, patient data and hospital systems could be at risk. The claim is circulating among cybersecurity researchers tracking ransomware activity in Latin America's health sector.
- 7Ransomware group Storm claims Gardeners' Guild and West County Health Centers attacks▼🚨New ransom group blog posts!🚨 Group name: Storm Post title: Gardeners' Guild Info: https:// cti.fyi/groups/Storm.html G
The ransomware group known as Storm has published new posts on its leak site naming the Gardeners' Guild and West County Health Centers as claimed victims. Cybersecurity analysts tracking the group flagged the updates, adding the two organisations to the growing list of companies and healthcare providers hit by ransomware extortion attempts.
- 8Scattered Spider's MGM hack retold with low-poly potatoes▼How Scattered Spider shut down Las Vegas with one phone call, retold with low-poly potatoes 🥔 LinkedIn recon → help-desk
Scattered Spider's 2023 attack on MGM Resorts is being retold in a quirky animated explainer, with low-poly potato characters. The story shows how a single phone call, LinkedIn research and help-desk impersonation led to a password and MFA reset, ransomware across 100+ MGM servers and the shutdown of Las Vegas operations. The campaign later hit Caesars, M&S, Salesforce clients and TfL, where two members were arrested.
- 9
An international police operation has reportedly dismantled the KillSec ransomware group, whose alleged leader is a 16-year-old. The operation targeted members of the cybercrime gang, which is associated with ransomware attacks and data extortion. Discussion is focused on the involvement of teenage hackers in major ransomware operations and what the arrests mean for the group's activity.
- 10English schools recovering faster from cyber incidents●England's schools are getting better at mopping up cyber incidents Two-thirds report immediate recovery, although teache
Two-thirds of schools in England now report recovering immediately from cyber incidents, suggesting improved resilience to attacks such as ransomware and phishing. Despite the progress, teachers remain divided over who bears responsibility for security and whose job security is at risk when breaches occur, with staff often left handling technical problems outside their expertise.
- 11Flashpoint Unveils Patented Ransomware Risk Scoring Model●Ransomware Risk Model: Flashpoint's Patented Scoring Method to Inform Vulnerability Prioritization
Flashpoint has announced a patented ransomware risk model designed to help organizations prioritize vulnerability patching. The scoring method assesses which vulnerabilities are most likely to be exploited in ransomware attacks, allowing security teams to focus remediation efforts where the threat of encryption-based extortion is highest. The announcement is drawing attention within the cybersecurity community as defenders seek better ways to manage growing vulnerability backlogs.
- 12Security Firm Stresses Ransomware Preparedness for Businesses●What would happen to your business if ransomware hit tomorrow? Would you know what to do? Black Cat White Hat Security i
Black Cat White Hat Security is asking businesses a blunt question: if ransomware struck tomorrow, would they know what to do? The firm says its Defend & Respond platform now includes a Ransomware Assessment, arguing that cybersecurity is not only about prevention but also about being prepared to respond when an attack happens.
- 13FTAPI confirms data breach after ransomware claim▼FTAPI data breach confirmed after The Gentlemen ransomware claim
German secure file-transfer provider FTAPI has confirmed a data breach following a ransomware claim by a group calling itself The Gentlemen. The company acknowledged that data was affected, though details on scope and the number of customers or records involved remain limited. Security outlets are tracking the incident as the group's claim draws scrutiny.
- 14Police dismantle KillSec extortion gang, arrest three●Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
International law enforcement has seized the infrastructure of the KillSec extortion group and arrested three alleged members of the hacking crew. The takedown reportedly disrupts the group's ability to conduct extortion operations. The action highlights continued police pressure on ransomware and extortion networks, and details about the arrested suspects and the scale of the seized infrastructure have not yet been made public.
- 15Storm ransomware group lists new alleged victims▼🚨New ransom group blog posts!🚨 Group name: Storm Post title: The Money Store Info: https:// cti.fyi/groups/Storm.html Gr
The Storm ransomware group has added new entries to its leak site, naming The Money Store, Silvercup Studios and Century Management Services among its latest claimed victims. The listings were flagged by threat intelligence monitors who track ransomware group blogs. Ransomware crews routinely publish victim names to pressure companies into paying, and each new post typically prompts checks by security researchers and affected firms.
- 16Netrunner ransomware group claims breach of Main Place Mall●🚨New ransom group blog posts!🚨 Group name: netrunner Post title: Main Place Mall Sector: Retail Info: https:// cti.fyi/g
A ransomware group calling itself Netrunner has listed Main Place Mall as a new victim on its leak site, tagging the target in the retail sector. The claim surfaced alongside fresh postings from other extortion groups, including Booba Project, in a routinely monitored feed of ransomware activity. Security researchers track these listings as an early indicator of breaches, though the mall operator has not publicly confirmed any incident.
- 17Ransomware data theft surged 275% in 2026●Reward: You've received the Fossil Record Badge — a commemorative exhibit of everything that used to be private. https:/
New reporting from Security Boulevard says ransomware-related data theft jumped 275% in 2026, with schools, hospitals and government agencies filing some of the largest claims. Attackers increasingly exfiltrate sensitive records before encrypting systems, exposing formerly private data. Security commentators are using the figures to warn institutions that a breach now means public disclosure of everything stored, not just downtime.
- 18Aurora ransomware group lists Buford-Thompson Company as victim●🚨New ransom group blog post!🚨 Group name: aurora Post title: Buford-Thompson Company, LTD Info: https:// cti.fyi/groups/
The Aurora ransomware group has published a new post on its leak site naming Buford-Thompson Company, LTD as its latest claimed victim. The listing appeared in threat intelligence tracking of ransomware group blogs. Security researchers monitor these posts to identify newly attacked organisations and track the activity of emerging ransomware operations like Aurora.
- 19Ransomware group Lamashtu claims breach tied to Dr Damiel Pugliese●🛡 THREAT INTEL | Dr Damiel Pugliese 🔴 Actor "lamashtu" claims Undisclosed ⚠️ Unverified claim https://www. yazoul.net/in
Threat intelligence feeds are reporting a claim by the ransomware actor known as "lamashtu" involving Dr Damiel Pugliese, dated September 2026 and tracked by the monitoring service Yazoul. The claim is explicitly flagged as unverified and the scope of any breach is undisclosed. Cybersecurity observers are circulating it while awaiting confirmation.
- 20Rhysida ransomware group lists Clicks Digital GmbH as new victim▼🚨New ransom group blog post!🚨 Group name: rhysida Post title: clicks digital GmbH Information Organization: Clicks Digit
The Rhysida ransomware group has added Clicks Digital GmbH, a digital marketing company based in Germany, to its leak site, claiming to have stolen the firm's data. The listing was flagged by threat intelligence monitors tracking ransomware activity. It marks the latest addition to the group's victims and puts the German firm in the public spotlight.
- 21ThreeAM ransomware group claims attack on Newman Tractor●🚨New ransom group blog post!🚨 Group name: threeam Post title: newmantractor.com Organization: Newman Tractor Location: 🇺
The ThreeAM ransomware group has added US heavy equipment dealer Newman Tractor to its leak site, listing the company as a new victim in the manufacturing sector. The claim suggests the group may have exfiltrated company data and could publish it unless a ransom is paid. Security researchers monitoring ransomware activity are flagging the listing as part of ongoing tracking of the group's attacks against US businesses.
- 22New ransomware group 'm3rx' lists Polish company intense.pl as victim▼🚨New ransom group blog post!🚨 Group name: m3rx Post title: intense.pl Info: https:// cti.fyi/groups/m3rx.html # ransomwa
Threat intelligence trackers report a newly surfaced ransomware group calling itself m3rx has published a blog post naming intense.pl, a Polish company, as its latest victim. The claim is being circulated among cybersecurity researchers monitoring ransomware leak sites, with details on the group still sparse. Analysts will be watching for confirmation from the targeted firm and for signs of further activity by the gang.
- 23Interlock ransomware group lists Tekko Enterprises as new victim▼🚨New ransom group blog posts!🚨 Group name: interlock Post title: Tekko Enterprises, Inc Info: https:// cti.fyi/groups/in
Cybersecurity trackers report that the Interlock ransomware group has posted Tekko Enterprises, Inc. on its leak blog, claiming a new breach. A separate post by the Wallstreet ransomware group lists Gibson Area Hospital & Health Services as a victim. Ransomware leak-site monitoring is widely shared among threat intelligence watchers, who use such listings to warn potential targets and track which criminal groups are actively extorting organisations.
- 24West County Health Centers Listed as Ransomware Victim●Another day, another ransomware crook. US: West County Health Centers https:// ransomware.live/id/V2VzdCBDb3V udHkgSGVhb
West County Health Centers, a California-based nonprofit healthcare provider, has been listed as a victim of a ransomware attack on a public ransomware tracking service. Two other US organisations, Gardeners' Guild and Datacomm Services, appear on the same list. The listings suggest the Storm ransomware group claims responsibility, though the extent of any data theft or service disruption is not yet confirmed.
- 25Ransomware group m3rx lists new alleged victims●🚨New ransom group blog posts!🚨 Group name: m3rx Post title: iccsi.com Info: https:// cti.fyi/groups/m3rx.html Group name
The ransomware group m3rx has published new entries on its leak blog, naming iccsi.com, noonsugar.com and somasolucoes.com among its latest alleged victims. Cybersecurity threat-intelligence monitors flagged the posts, adding the group to tracked victim feeds. The listings imply the affected organisations now face data extortion demands, though the extent of the breaches and the companies' responses are not yet known.