Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

Cybercrime

CRIMINAL ECONOMY

Cybercrime

Ransomware operations, threat-actor profiles, breach economics, and the criminal markets that fund all of it.

The business of cybercrime: the initial-access brokers who sell the way in, the infostealer economy that feeds them, the dark-web markets where data is sold, and our own desk that tests leak claims before they become headlines. See how initial-access brokers fuel ransomware and the breach verification desk.

For live exposure data, look up any domain with Stealercheck and track active operators on the Ransomtracker.

Start here

  • Initial access brokers: ransomware’s supply chain
  • Breach verification desk: is the leak real?
  • Bulletproof hosting: where attackers run infrastructure
  • The Telegram stealer-log economy
  • Exploit.in: inside a Russian hacker forum, 2005 to 2008

Latest cybercrime coverage

  • Novo Nordisk data breach lawsuits cover: two lawsuits, one footnote. A terminal panel shows both complaints cite ransomnews.com for the 1.3 terabyte figure, plead a class of over one hundred members against a claimed 163,000 employee records, and leave the attack vector unpleaded. ransomnews.com
    Novo Nordisk breach lawsuits: what the complaints get wrongOctober 3, 2026
    Two class actions over the Novo Nordisk data breach cite our FulcrumSec reporting for its scale, then skip how the attackers got in and what data was exposed.
  • Ransomnews cover: Conti was hiring, showing the group's affiliate entrance exam questions in a terminal panel
    Conti was hiring: the ransomware crew’s entrance examSeptember 17, 2026
    Germany named Vitaly Kovalev as Conti’s boss in 2025. RAMP forum messages show the other end: a recruiter, a written hacking exam, and when the hiring stopped.
  • Exploit.in forum database 2005 to 2008, 9,647 members, ransomnews.com
    Exploit.in: inside a Russian hacker forum, 2005 to 2008September 17, 2026
    Inside the Exploit.in database, 2005 to 2008: 9,647 members of the Russian hacker forum, 60% who never posted, and 205 handles still on the boards today.
  • Telegram 120M leak: we counted 63M, most from 2020September 8, 2026
    A forum listing advertises 120 million Telegram records. Ransomnews parsed the 3.7GB file: 63.1 million rows, 74% Iranian, and most of it dates to 2020.
  • 32.8 million Condé Nast user records for sale: bar chart of what the records contain, email in every row, names in 32%, postal addresses in 22%, gender 18%, date of birth 13%, phone 2.9%
    Condé Nast: 32.8M user records for sale, sample verifiedSeptember 7, 2026
    A 32.8M-record Condé Nast user database is on sale for $15,000 on a Russian-language hacker forum. We tested the sample: genuine account data, and the rest of the December WIRED hack.
  • Ticket-stub graphic showing The Town 2025 sold via Ticketmaster Brasil, 412,192 records offered at $10,000, marked source unverified and stamped claimed
    The Town 2025 ticketing data sold as a Ticketmaster breachSeptember 3, 2026
    A seller is offering 412,192 Latin American ticket-buyer records from The Town 2025, including 250,000 Brazilian CPFs, at about four cents a head. We tested the sample.
  • Ransomnews cover: one day apart, two water attacks, not one campaign. 1 of 244 confirmed utility ransomware attacks recorded a paid ransom
    Micro-Comm hack is separate from the US water attacksSeptember 1, 2026
    The FBI water-sector PLC alert and the Barracuda ransomware breach at supplier Micro-Comm landed a day apart. The evidence says they are not the same story.
  • Diagram of a UK driving licence number showing surname, date of birth and initial segments, with match rates of 98.1, 78.7 and 97.2 percent against the leaked records
    Love Electric driver data for sale: NI, licence numbersAugust 28, 2026
    A seller is offering 877,000 driver records from UK EV salary sacrifice broker Love Electric, including National Insurance and driving licence numbers. We checked the sample.
  • Typographic cover reading Stripe was not breached, 659 of its merchants were, with a band of 659 ticks of which 519 are highlighted
    Live Stripe keys for 659 merchants, published for freeAugust 18, 2026
    Stripe was not breached. A forum dataset holds live API keys for 659 of its merchants, plus 35GB pulled from them. We told Stripe before publishing this.
  • Grid of 4,867 marks, one per disciplinary notice issued on the Verified forum, coloured by reason
    Verified.ru: inside the archive of a cybercrime bureaucracyAugust 17, 2026
    A 152,973-message archive of the Verified forum shows how Russian-speaking cybercrime governed itself between 2005 and 2010, using rules, penalty points and bans.
  • Golden arches rendered out of rows of directory records, over the headline Employee directory, listed for sale
    McDonald’s employee data listed for sale in wider Entra campaignAugust 16, 2026
    A forum seller claims 1.7 million McDonald’s employee records pulled from its Azure tenant. We analysed the sample, and the four other brands listed alongside it.
  • Ransomnews cover: 7.3 million chess.com records leaked, verified real and days old, with a scraped rather than breached data shape
    7.3M chess.com records leaked, and the data is realAugust 12, 2026
    A 15.5 GB file of 7.3 million chess.com user records is circulating free on two leak forums. We verified it: the data is genuine and days old, but the shape points to scraping, not a breach.
  • Attribution chain: the alternate accounts chromium and evilcore share two IPs with Quake3, the XSS.is moderator, who identified himself as morgot on exploit.in, the persona DEF CON 33 placed at REvil source-code development and the man the BKA named in April 2026.
    Quake3 and morgot: tracing REvil’s source-code developerAugust 10, 2026
    Quake3, a moderator on the XSS.is cybercrime forum, is the persona DEF CON 33 research placed at REvil’s source-code development, and the man the German BKA named in April 2026. We trace the forum record that ties the handles together.
  • Ransomnews cover: Swyft vending data marketed as a live 2026 breach, but every record in the sample dates from 2016
    Pokémon Center vending ‘breach’ is old 2016 dataAugust 10, 2026
    A seller is marketing a ‘live’ breach of automated-retail vendor SwyftStore across 28 brands including Pokémon Center. The sample is genuine Zoom/Swyft data, but every record dates from 2016.
  • Ransomnews cover: Israel population registry, 9.2 million records offered for sale, every date in the sample frozen at 2005
    Israeli population registry for sale, but the data is oldAugust 10, 2026
    A vendor is selling what they call Israel’s current 9.22M-record population registry. Our analysis of the 100k sample says the data is genuine, but every date in it stops in 2005.
  • Ransomnews cover: Żabka data up for sale, a leak forum listing offering 541,000 Jira tickets and 89 Git repositories for 5,000 euro
    Żabka confirms breach via supplier account, data for saleAugust 3, 2026
    Żabka has confirmed unauthorized access through an external provider’s account after a dataset was listed for €5,000. We reviewed the sample; the company has not confirmed its scale.
  • 5socks.net: 20 years of proxy crime, 2004 to seizure, ransomnews.com
    5socks.net: 20 years of proxy crime, 2004 to seizureJuly 31, 2026
    5socks.net sold access to hacked residential IPs from 2004 until the FBI seized it in May 2025. Dancho Danchev traces the service back to its Russian origins.
  • Deadlock: ransomware that hides its C2 on the blockchain, ransomnews.com
    Deadlock: ransomware that hides its C2 on the blockchainJuly 18, 2026
    Deadlock ransomware uses Polygon smart contracts for takedown-resistant command and control and a vulnerable driver to kill EDR. A profile of 2026’s most technically novel new group.
  • Clover Health discloses social-engineering breach in 8-K, ransomnews.com
    Clover Health discloses social-engineering breach in 8-KJuly 18, 2026
    Clover Health disclosed in a July 17 SEC filing that three employee accounts were compromised via social engineering, risking protected health data.
  • DragonForce: the cartel that absorbed its rivals, ransomnews.com
    DragonForce: the cartel that absorbed its rivalsJuly 17, 2026
    DragonForce rebranded as a ransomware cartel offering white-label infrastructure, absorbed RansomHub affiliates, and hit UK retail. A profile of its model, decline, and tactics.
  • ShinyHunters' Salesforce extortion wave hits Fluke and Ingram, ransomnews.com
    ShinyHunters’ Salesforce extortion wave hits Fluke, IngramJuly 17, 2026
    ShinyHunters listed Fluke (21M Salesforce records claimed) and Ingram Content on its leak site, extending a 2026 Salesforce extortion campaign now drawing class-action lawyers.
  • LockBit 5.0: the comeback nobody wanted, ransomnews.com
    LockBit 5.0: the comeback nobody wantedJuly 17, 2026
    LockBit relaunched as version 5.0 in September 2025 and surged to 7% of June 2026 attacks. A profile of the disrupted brand’s resurgence, new encryptor, and affiliate model.
  • Deutsche Bank breached via supplier as Unsafe gang leaks data, ransomnews.com
    Deutsche Bank breached via supplier as Unsafe gang leaks dataJuly 17, 2026
    A ransomware group called Unsafe posted Deutsche Bank employee data samples from a third-party supplier. The bank confirms a supplier breach but denies any internal compromise.
  • Scattered Spider duo jailed 5.5 years over TfL hack, ransomnews.com
    Scattered Spider duo jailed 5.5 years over £29M TfL hackJuly 16, 2026
    Two Scattered Spider members were jailed 5.5 years each on July 16 over the 2024 Transport for London hack, the UK’s first conviction under Computer Misuse Act Section 3ZA.

Every cybercrime article

Every article we have published in this section, newest first.

  • Novo Nordisk breach lawsuits: what the complaints get wrong
  • Conti was hiring: the ransomware crew’s entrance exam
  • Exploit.in: inside a Russian hacker forum, 2005 to 2008
  • Telegram 120M leak: we counted 63M, most from 2020
  • Condé Nast: 32.8M user records for sale, sample verified
  • The Town 2025 ticketing data sold as a Ticketmaster breach
  • Micro-Comm hack is separate from the US water attacks
  • Love Electric driver data for sale: NI, licence numbers
  • Live Stripe keys for 659 merchants, published for free
  • Verified.ru: inside the archive of a cybercrime bureaucracy
  • McDonald’s employee data listed for sale in wider Entra campaign
  • 7.3M chess.com records leaked, and the data is real
  • Quake3 and morgot: tracing REvil’s source-code developer
  • Pokémon Center vending ‘breach’ is old 2016 data
  • Israeli population registry for sale, but the data is old
  • Żabka confirms breach via supplier account, data for sale
  • 5socks.net: 20 years of proxy crime, 2004 to seizure
  • Deadlock: ransomware that hides its C2 on the blockchain
  • Clover Health discloses social-engineering breach in 8-K
  • DragonForce: the cartel that absorbed its rivals
  • ShinyHunters’ Salesforce extortion wave hits Fluke, Ingram
  • LockBit 5.0: the comeback nobody wanted
  • Deutsche Bank breached via supplier as Unsafe gang leaks data
  • Scattered Spider duo jailed 5.5 years over £29M TfL hack
  • World Leaks dumps 19,000 files tied to India nuclear plant
  • Akira: the edge-VPN ransomware that never slowed down
  • Coca-Cola’s Fairlife halts US production after ransomware
  • Qilin: the RaaS that ran H1 2026 ransomware
  • The week the West went after ransomware’s plumbing
  • Anubis ransomware is exploiting Citrix Bleed 2 for access
  • Kairos took $1M from a US government body and encrypted nothing
  • XSS forum: from DaMaGeLaB to the 2025 takedown
  • 1.16 billion attacks: how the FortiBleed crew broke FortiGate
  • FortiBleed: exposed firewalls are a ransomware early warning
  • Novo Nordisk hit by FulcrumSec: the stealer logs saw it coming
  • The Gentlemen ransomware: 483 victims and a leaked playbook
  • Ransomware runs office hours: what 16,699 leak posts reveal
  • 62% of database ransom wallets were never paid
  • Ransomware ditched encryption in May 2026: here’s why
  • Initial Access Brokers 2026: ransomware’s supply chain
  • How initial access brokers price corporate access in 2026: an explainer for defenders
  • How to investigate a phishing kit: tutorial with urlscan.io, PhishTank, and Sublime Security
  • Tracing crypto laundering: tutorial with Chainabuse, OXT, Walletexplorer, and Etherscan
  • Why double extortion isn’t enough anymore: the rise of triple and quadruple extortion
  • BEC vs ransomware: which is more profitable per attack in 2026?
  • Bulletproof hosting in 2026: where attackers actually run their infrastructure
  • Inside a money mule recruitment thread on Telegram
  • Crypto laundering pipelines after the 2025 mixer takedowns
  • The 2026 cybercrime economy by the numbers
  • The economics of AI agent jailbreaks: who profits when an LLM goes off-rails
  • The Telegram stealer-log economy: how stolen credentials are sold
  • How stealer logs power modern ransomware attacks
  • Redline, Lumma, Vidar, Raccoon: the major infostealer families of 2026
  • What are stealer logs? A field guide to the credential-theft economy
  • Play: the closed-shop ransomware brand quietly hitting cities, schools, and critical infrastructure
  • Hive: the ransomware operation the FBI spent seven months inside
  • DarkSide: Colonial Pipeline, the pseudo-code-of-conduct, and the rebrand to BlackMatter
  • Akira: the retro-themed ransomware operation quietly eating mid-market enterprise
  • Black Basta: Conti’s most successful successor and its healthcare specialism
  • Ryuk: the big-game hunter that made ransomware a boardroom problem
  • Cl0p: the mass-exploitation specialists behind Accellion, GoAnywhere, and MOVEit
  • BlackCat / ALPHV: the Rust-powered RaaS that ended in an exit scam
  • REvil / Sodinokibi: the big-game hunters who hit Kaseya, JBS, and then disappeared twice
  • Conti: anatomy of a ransomware corporation, and how it imploded
  • LockBit: the ransomware brand that redefined the industry, and got taken down
  • Ransomware-as-a-service (RaaS): how cybercrime got its franchise model
  • A brief history of ransomware: from the AIDS Trojan to the RaaS empires

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,711 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.