Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Threat Groups

INC Ransom: the RaaS that wins by mastering the basics

Martynas VareikisBy Martynas VareikisJuly 20, 2026Updated:July 20, 2026No Comments5 Mins Read20 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
INC Ransom: the RaaS that wins by mastering the basics, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

INC Ransom is a ransomware-as-a-service operation that has claimed more than 800 victims since it surfaced in mid-2023, and it remained one of the most prolific crews through the first half of 2026. Also tracked as GOLD IONIC, INC leans on stolen credentials, edge-device vulnerabilities and disciplined double extortion rather than novel malware. The Ransomnews tracker logged 35 confirmed INC victims in 2026, concentrated in business services, government and healthcare across the United States and Europe.

Who is INC Ransom?

INC Ransom first appeared in July 2023 and quickly built a reputation for competence over flash. The group runs a RaaS model, recruiting affiliates who carry out intrusions and split proceeds with the core operators. Victims get files appended with an .inc extension and a ransom note named INC-README.txt or INC-README.html.

What makes INC durable is not a zero-day arsenal. It is operational patience. Multiple incident-response teams have noted the group succeeds by doing ordinary things well: valid accounts, living-off-the-land tooling, slow lateral movement, and quiet exfiltration before anyone notices. A source-code leak and a for-sale posting in 2024 also spawned Lynx, a group widely assessed as an INC derivative, which is a reminder that codebases in this economy rarely stay contained. It sits alongside its peers in the Ransomnews threat-group catalogue.

INC Ransom victims by sector, 2026 (n=35) ransomnews.com Business services: 22 Government: 6 Healthcare: 5 Education: 2 Business services is the plurality; healthcare remains a favoured high-pressure target.

How does INC Ransom get in?

INC obtains initial access three ways: spear-phishing, credentials bought from initial access brokers, and exploitation of public-facing appliances. Its exploited-CVE list reads like a tour of edge-device pain: CVE-2023-3519 in Citrix NetScaler, CVE-2023-48788 in Fortinet FortiClient EMS, CVE-2024-57727 in SimpleHelp RMM, and CVE-2025-5777, the Citrix Bleed 2 session-token leak. Many of those credentials originate in infostealer logs, which is why a corporate password in a stealer dump is an early warning, not a footnote.

INC Ransom attack chain ransomnews.com Valid creds /edge CVE Recon,AnyDesk/RDP Domain priv,lateral move Exfiltrate tocloud Encrypt.inc Exfiltration precedes encryption; the leak threat is the real leverage.

What does INC do once inside?

Post-access, INC affiliates favour tools already present on the network: legitimate remote-management software such as AnyDesk, PsExec and native RDP for movement, plus common credential-dumping and reconnaissance utilities. Data is staged and pushed to attacker-controlled cloud storage before any encryptor runs. The encryption stage is deliberately late, because the stolen data is the leverage. In 2026 the Ransomnews victim tracker recorded INC hauls such as 1.5 TB from Swiss firm SteelcoBelimed and 1.4 TB from a US medical-services provider, the kind of volumes that make a leak threat credible.

Why healthcare keeps getting hit

Healthcare has been an INC fixation since the 2024 attack on NHS Dumfries and Galloway in Scotland, where the group threatened to release three terabytes of patient data and later published samples on its leak site. The logic is grim but consistent: hospitals combine fragile uptime requirements, deep stores of sensitive records, and cyber-insurance coverage, which together raise the odds of payment. Business services still make up the plurality of INC’s 2026 victims, but healthcare and government remain the sectors where the extortion pressure bites hardest.

What should defenders do?

Because INC wins on fundamentals, the defence is fundamentals too. Patch internet-facing appliances on the day advisories drop, since INC’s CVE list is dominated by known, patchable edge flaws. Enforce phishing-resistant MFA on every VPN, RDP and webmail entry point, and treat any employee credential found in a stealer log as already compromised. Segment the network so a single foothold cannot reach domain controllers, and keep offline, tested backups so encryption is an inconvenience rather than a catastrophe. Business EDR that can catch living-off-the-land behaviour matters more here than signature detection; see our business ransomware protection guide.

Frequently asked questions

Is INC Ransom still active in 2026?

Yes. INC Ransom remained one of the most active ransomware operations through the first half of 2026, with 35 confirmed victims logged by the Ransomnews tracker and fresh listings appearing into June 2026.

What is the difference between INC Ransom and Lynx?

Lynx is widely assessed as a derivative of INC Ransom, built on leaked or sold INC code after a 2024 source-code posting. The two share technical DNA but operate as separate brands with separate leak sites.

How does INC Ransom encrypt files?

INC appends an .inc extension to encrypted files and drops a ransom note named INC-README.txt or INC-README.html. Encryption happens late in the intrusion, after data has already been stolen for double extortion.

What sectors does INC Ransom target most?

Business and professional services form the largest share of INC’s 2026 victims, followed by government and healthcare. Healthcare draws outsized attention because of its uptime sensitivity and record-rich databases.

How do you defend against INC Ransom?

Patch edge appliances promptly, enforce phishing-resistant MFA everywhere, monitor for stolen credentials in stealer logs, segment the network, and maintain offline backups. INC exploits known flaws and valid accounts, so disciplined hygiene removes most of its advantage.

Sources and further reading

  • CISA #StopRansomware — official ransomware guidance and advisories
  • The Record (Recorded Future News) — INC Ransom leaks stolen Scottish healthcare data
  • BleepingComputer — INC Ransom threatens to leak 3TB of NHS Scotland data
  • Ransomnews live victim tracker
  • Ransomnews — Initial Access Brokers 2026
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous Articlewp2shell: pre-auth RCE in WordPress core (CVE-2026-63030)
Next Article SafePay: the centralised crew that skipped affiliates
Martynas Vareikis

Martynas Vareikis is the AI Editor at Ransomnews. He covers the intersection of artificial intelligence and information security — from machine-learning models in defensive tooling to the adversarial use of LLMs by ransomware operators, deepfake-driven social engineering, and the rise of agentic threats. His reporting focuses on translating fast-moving AI research into practical guidance for defenders, journalists, and the broader security community. Reach Martynas via [email protected].

Related Posts

Interlock: the drive-by ransomware crew CISA flagged

July 20, 2026

SafePay: the centralised crew that skipped affiliates

July 20, 2026

LockBit, 2 years after Operation Cronos: where are they now?

May 11, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.