Confirmed ransomware attack statistics, updated monthly: attacks per year, month, country, industry and group, from a human-verified dataset going back to 2018.
Ransomnews Research Team
Inside XSS.is, the Russian cybercrime forum seized in 2025. A data-led profile from 123,241 leaked messages: what it traded, who ran it, its place in the ransomware kill chain, and a searchable country IoC table.
ESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.
Inside the FortiBleed operation: 1.16 billion FortiGate brute-force attempts, a 45-GPU cracking cluster, and the full attack chain, mapped step by step.
We cross-checked 73,932 exposed FortiGate firewalls against stealer-log and ransomware-leak data. The overlap is a measurable early warning for breaches.
FortiBleed exposed cracked admin passwords for around 75,000 Fortinet firewalls across 194 countries, roughly half the internet-facing fleet. There is no new zero-day. It is config exports, weak hashing, and recycled credentials, packaged as a sales catalog.
FulcrumSec says it stole 1.3 TB from Novo Nordisk, including internal AI models and clinical-trial data, and wants $25M. We pulled the leak-site listing and the stealer logs. The credentials were leaking for months.
The Gentlemen RaaS has listed 483 victims across 66 countries since 2025. A leaked chat log, live tracker data, and infostealer records show how the crew scaled.
Lumma now leads the infostealer ecosystem in 2026, after Operation Magnus took out RedLine and META in late 2024. RedLine’s legacy footprint still surfaces in older logs, Vidar remains stubbornly durable, StealC has gained share, Atomic dominates the macOS side, and ACR Stealer and Meduza are the rising Russian-language contenders. The top six families together produce the overwhelming majority of all stealer logs traded in 2026. Here is who is in your stealer log and why each one matters. Ransomnews Research Team. Window: post-Operation Magnus through May 2026.
A stealer log is the data dump that an infostealer malware produces after it compromises a device. It typically contains every saved browser password, every active session cookie, autofill data, system details, and in some families, screenshots and clipboard history. Stealer logs feed account takeover, ransomware initial access, and corporate breach pipelines. This explainer covers what a 2026 stealer log actually holds, how devices end up in one, how the logs are sold, and how anyone can check whether their data is in the ecosystem. Ransomnews Research Team. Updated June 2026.