Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads

Ransomnews

  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

Home

Tracking the criminal infrastructure of the internet.

Ransomware operators, breach economics, threat-actor profiles, and the open-source investigation toolkit that makes it all visible. Updated daily.

Latest stories

  • 36,769 exposed AI endpoints and only 2% behind authentication, ransomnews.com
    36,769 exposed AI endpoints, only 2% ask for a loginSeptember 11, 2026
    Mysterium VPN counted 36,769 self-hosted AI endpoints reachable on the public internet. Only 2.02% return an authentication challenge, and that is a floor.
  • Telegram 120M leak: we counted 63M, most from 2020September 8, 2026
    A forum listing advertises 120 million Telegram records. Ransomnews parsed the 3.7GB file: 63.1 million rows, 74% Iranian, and most of it dates to 2020.
  • Slopsquatting card showing a terminal where an AI assistant suggests importing a package that does not exist until an attacker registers it, with the stat that 19.7% of AI-generated code named a non-existent package
    What is slopsquatting? AI package hallucinations, explainedSeptember 7, 2026
    Slopsquatting is a supply-chain attack that weaponises the package names AI coding assistants invent. How it works, what the research measured, the real 2026 incidents, and how to defend an AI-assisted pipeline.
  • Card asking is paying a ransom illegal, with a jurisdiction table: United States no ban but sanctions strict liability, United Kingdom ban proposed for public sector and CNI, Australia legal but report within 72 hours, European Union no ban but NIS2 reporting
    Is it illegal to pay a ransomware ransom in 2026?September 7, 2026
    Paying a ransomware ransom is usually legal, but sanctions can make it a crime, and 2026 rules are tightening fast. The law in the US, UK, EU and Australia, and what paying still does not buy.
Most Popular
  1. FortiBleed: 1.16 billion attacks on FortiGate, neon investigation cover1.16 billion attacks: how the FortiBleed crew broke FortiGate
  2. Ransomnews cover: Żabka data up for sale, a leak forum listing offering 541,000 Jira tickets and 89 Git repositories for 5,000 euroŻabka confirms breach via supplier account, data for sale
  3. Ransomware office hours: 16,699 leak posts, 200 groups, 84 percent weekday, peak hour 16:00 UTCRansomware runs office hours: what 16,699 leak posts reveal
  4. Database ransom census dashboard: 62% of 514 traced wallets received zero BTC, 30,515 databases ransomed, 9.78 BTC moved ($753K), top 10 wallets captured 43% - Ransomnews Research62% of database ransom wallets were never paid
  5. Neon poster of the Novo Nordisk charging bull logo cracked and leaking data, title Novo Nordisk Breached, 1.3 TB stolen by FulcrumSec, 25M refusedNovo Nordisk hit by FulcrumSec: the stealer logs saw it coming
  6. Ransomware encryption-less extortion shift May 2026Ransomware ditched encryption in May 2026 — here’s why
  7. The Gentlemen ransomware 2026: 483 victims, infostealer-fed RaaS access pipelineThe Gentlemen ransomware: 483 victims and a leaked playbook
  8. Neon world map of exposed FortiGate firewalls with a cracked firewall shield leaking dataFortiBleed: exposed firewalls are a ransomware early warning

// FOCUS

Ransomware

The defining cybercrime of the decade. How it works, who runs it, and where the money goes.

  • Card asking is paying a ransom illegal, with a jurisdiction table: United States no ban but sanctions strict liability, United Kingdom ban proposed for public sector and CNI, Australia legal but report within 72 hours, European Union no ban but NIS2 reporting
    Is it illegal to pay a ransomware ransom in 2026?September 7, 2026
    Paying a ransomware ransom is usually legal, but sanctions can make it a crime, and 2026 rules are tightening fast. The law in the US, UK, EU and Australia, and what paying still does not buy.
  • 51 confirmed ransomware attacks in August 2026 so far, with a bar chart of confirmed attacks per month from August 2025 to August 2026
    Confirmed ransomware attacks, August 2026: 51 verified so far, Qilin leadsSeptember 7, 2026
    Ransomnews confirmed 51 ransomware attacks in August 2026, down from 62 in July and 136 a year earlier. Qilin led with nine victims and government was the most affected sector.
  • ESXi ransomware synthwave cover, one hypervisor one datacenter, ransomnews.com
    ESXi ransomware in 2026: one host, the whole datacenterJune 24, 2026
    ESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.

// PROFILES

Threat Groups

From LockBit and Conti to Akira and Cl0p, anatomies of the operations behind the headlines.

  • Medusa ransomware group profile card with a bar chart of confirmed Medusa incidents per year: 44 in 2023, 72 in 2024, 37 in 2025 and 8 so far in 2026
    Medusa ransomware: victims, tactics, and how to defend in 2026September 7, 2026
    Medusa is a ransomware-as-a-service crew active since 2021, with 300+ claimed victims and 161 confirmed by Ransomnews. Its targets, tactics, biggest breaches and the defences that stop it.
  • Interlock: the drive-by ransomware crew CISA flagged, ransomnews.com
    Interlock: the drive-by ransomware crew CISA flaggedJuly 20, 2026
    Interlock breaks the ransomware playbook, entering through compromised websites and fake CAPTCHAs. A joint CISA-FBI advisory mapped its TTPs. Here is the profile.
  • SafePay: the centralised crew that skipped affiliates, ransomnews.com
    SafePay: the centralised crew that skipped affiliatesJuly 20, 2026
    SafePay went from unknown to one of the busiest ransomware crews in under a year by ditching affiliates and hammering RDP and VPN gateways. Here is how it works.

// DEFENCE

Security

EDR, Zero Trust, MFA, patching, IR, what actually works against modern threats.

  • Best VirusTotal alternatives 2026 for threat hunters, ransomnews.com
    Best VirusTotal alternatives 2026: what threat hunters runAugust 9, 2026
    The VirusTotal alternatives threat hunters run in 2026: MetaDefender, ANY.RUN, CAPE, Intezer and MalwareBazaar, compared by job, upload privacy and API.
  • SOAR vs SIEM 2026: SIEM decides what is happening, SOAR decides what to do about it
    SOAR vs SIEM 2026: tune before you automateAugust 6, 2026
    SOAR vs SIEM in 2026: they were never alternatives. Gartner marked standalone SOAR obsolete, and the automation now ships inside your SIEM or XDR.
  • SIEM vs XDR 2026: which platform wins on detection speed, retention, audit reporting and custom analytics
    SIEM vs XDR 2026: retention is the deciding factorAugust 6, 2026
    SIEM vs XDR in 2026: XDR wins on detection speed, SIEM wins on retention and audit. Which one you can drop comes down to your compliance obligations.

// SURVEILLANCE

Privacy

GDPR, data brokers, encryption, fingerprinting, VPNs, the surveillance economy and its limits.

  • Codename Morgan: how Morocco ran Pegasus, a Forbidden Stories investigation, ransomnews.com
    Codename Morgan: inside Morocco’s Pegasus machineJuly 22, 2026
    Forbidden Stories names Morocco as NSO’s client “Morgan”: a 2017 Rabat demo, an Emirati broker, roughly 12,000 targets, and Pegasus traces on seven French ministers’ phones.
  • Inside Pegasus: how NSO Group's own court files expose the spyware system, ransomnews.com
    Inside Pegasus: NSO’s own files reveal the machineJuly 22, 2026
    Unsealed NSO Group court files, analysed by Amnesty’s Security Lab and Forbidden Stories, expose how Pegasus really works: a vendor-run spyware service, not a weapon sold and forgotten.
  • Session Cookie Theft and MFA Bypass 2026 — Ransomnews cover
    Stealer logs bypassing MFA in 2026 [Field Guide]May 16, 2026
    Multi-factor authentication was supposed to end the credential-theft era. In 2026, it hasn’t — because adversaries skip the credential entirely and steal the session cookie that the authentication produced. Here’s how the attack works, why MFA doesn’t stop it, and the four controls that do.

// MACHINE LEARNING

AI

Prompt injection, deepfakes, model theft, the EU AI Act, security and policy at the frontier.

  • 36,769 exposed AI endpoints and only 2% behind authentication, ransomnews.com
    36,769 exposed AI endpoints, only 2% ask for a loginSeptember 11, 2026
    Mysterium VPN counted 36,769 self-hosted AI endpoints reachable on the public internet. Only 2.02% return an authentication challenge, and that is a floor.
  • Slopsquatting card showing a terminal where an AI assistant suggests importing a package that does not exist until an attacker registers it, with the stat that 19.7% of AI-generated code named a non-existent package
    What is slopsquatting? AI package hallucinations, explainedSeptember 7, 2026
    Slopsquatting is a supply-chain attack that weaponises the package names AI coding assistants invent. How it works, what the research measured, the real 2026 incidents, and how to defend an AI-assisted pipeline.
  • Delve is dead, the dash took its place. AI lexical markers peak at 0.853 per 1,000 words in 2024 and fall to 0.384 by 2026, while dash usage rises to 0.877, across 21,442 arXiv abstracts.
    “Delve” is dead: AI writing tells expire in 18 monthsAugust 21, 2026
    The word delve fell 94% from its 2024 peak while dash use doubled. We measured 21,442 arXiv abstracts: AI writing tells expire in about 18 months.

// INVESTIGATIONS

OSINT

Tools, methods, and case studies from the open-source investigation discipline.

  • Best OSINT tools 2026: Maltego, Shodan, SecurityTrails, VirusTotal, theHarvester, DarkOwl, BGPView, Wayback Machine
    Best OSINT tools 2026: what analysts actually runAugust 4, 2026
    The OSINT tools worth your time in 2026: Maltego, Shodan, SecurityTrails, DarkOwl, theHarvester and more, ranked by what they do and what they leak.
  • Maltego tutorial: OSINT link analysis in 2026, ransomnews.com
    Maltego tutorial: OSINT link analysis in 2026July 20, 2026
    A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
  • GraphSense tutorial: open-source crypto tracing in 2026, ransomnews.com
    GraphSense tutorial: open-source crypto tracing in 2026July 20, 2026
    A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.

// PRIMERS

Explainers

Long-form primers on the underlying concepts. Built to be referenced, not skimmed.

  • What is intermittent encryption? A 2026 guide, ransomnews.com
    What is intermittent encryption? A 2026 guideJuly 20, 2026
    Intermittent encryption locks only parts of each file so ransomware runs faster and hides from detection. Here is how partial encryption works and how to catch it.
  • What is RaaS? Ransomware-as-a-service explained, ransomnews.com
    What is RaaS? Ransomware-as-a-service, explainedJuly 20, 2026
    Ransomware-as-a-service splits ransomware into a rented product and an affiliate workforce. Here is how the RaaS model works and why it made attacks scale in 2026.
  • What is BYOVD? Bring your own vulnerable driver explained, ransomnews.com
    What is BYOVD? Bring your own vulnerable driver, explainedJuly 20, 2026
    BYOVD lets attackers load a legitimate but vulnerable signed driver to kill EDR from the kernel. Here is how it works and why ransomware crews rely on it in 2026.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.