Clover Health disclosed in a July 17 SEC filing that three employee accounts were compromised via social engineering, risking protected health data.
Ransomnews Research Team
ShinyHunters listed Fluke (21M Salesforce records claimed) and Ingram Content on its leak site, extending a 2026 Salesforce extortion campaign now drawing class-action lawyers.
LockBit relaunched as version 5.0 in September 2025 and surged to 7% of June 2026 attacks. A profile of the disrupted brand’s resurgence, new encryptor, and affiliate model.
A ransomware group called Unsafe posted Deutsche Bank employee data samples from a third-party supplier. The bank confirms a supplier breach but denies any internal compromise.
Two Scattered Spider members were jailed 5.5 years each on July 16 over the 2024 Transport for London hack, the UK’s first conviction under Computer Misuse Act Section 3ZA.
Coca-Cola disclosed a ransomware attack on its Fairlife dairy subsidiary in a July 16 SEC filing, suspending all US production. No group has claimed it.
Arctic Wolf found 292+ fake GitHub repositories impersonating security and fintech brands to deliver a BoryptGrab-lineage infostealer, with payloads that rotate every 60 seconds.
In 48 hours the US, UK and EU indicted a bulletproof host and sanctioned VPN and cryptor sellers behind LockBit, Play and BlackSuit ransomware.
Arctic Wolf says Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) and abusing legitimate RMM tools to breach networks, then deploying an irreversible data wiper.
A US government entity paid Kairos about $1 million to keep stolen files offline, a Ransom-ISAC case study shows. Kairos never encrypted a machine, it just threatened to publish.