INC Ransom is a ransomware-as-a-service operation that has claimed more than 800 victims since it surfaced in mid-2023, and it remained one of the most prolific crews through the first half of 2026. Also tracked as GOLD IONIC, INC leans on stolen credentials, edge-device vulnerabilities and disciplined double extortion rather than novel malware. The Ransomnews tracker logged 35 confirmed INC victims in 2026, concentrated in business services, government and healthcare across the United States and Europe.
Who is INC Ransom?
INC Ransom first appeared in July 2023 and quickly built a reputation for competence over flash. The group runs a RaaS model, recruiting affiliates who carry out intrusions and split proceeds with the core operators. Victims get files appended with an .inc extension and a ransom note named INC-README.txt or INC-README.html.
What makes INC durable is not a zero-day arsenal. It is operational patience. Multiple incident-response teams have noted the group succeeds by doing ordinary things well: valid accounts, living-off-the-land tooling, slow lateral movement, and quiet exfiltration before anyone notices. A source-code leak and a for-sale posting in 2024 also spawned Lynx, a group widely assessed as an INC derivative, which is a reminder that codebases in this economy rarely stay contained. It sits alongside its peers in the Ransomnews threat-group catalogue.
How does INC Ransom get in?
INC obtains initial access three ways: spear-phishing, credentials bought from initial access brokers, and exploitation of public-facing appliances. Its exploited-CVE list reads like a tour of edge-device pain: CVE-2023-3519 in Citrix NetScaler, CVE-2023-48788 in Fortinet FortiClient EMS, CVE-2024-57727 in SimpleHelp RMM, and CVE-2025-5777, the Citrix Bleed 2 session-token leak. Many of those credentials originate in infostealer logs, which is why a corporate password in a stealer dump is an early warning, not a footnote.
What does INC do once inside?
Post-access, INC affiliates favour tools already present on the network: legitimate remote-management software such as AnyDesk, PsExec and native RDP for movement, plus common credential-dumping and reconnaissance utilities. Data is staged and pushed to attacker-controlled cloud storage before any encryptor runs. The encryption stage is deliberately late, because the stolen data is the leverage. In 2026 the Ransomnews victim tracker recorded INC hauls such as 1.5 TB from Swiss firm SteelcoBelimed and 1.4 TB from a US medical-services provider, the kind of volumes that make a leak threat credible.
Why healthcare keeps getting hit
Healthcare has been an INC fixation since the 2024 attack on NHS Dumfries and Galloway in Scotland, where the group threatened to release three terabytes of patient data and later published samples on its leak site. The logic is grim but consistent: hospitals combine fragile uptime requirements, deep stores of sensitive records, and cyber-insurance coverage, which together raise the odds of payment. Business services still make up the plurality of INC’s 2026 victims, but healthcare and government remain the sectors where the extortion pressure bites hardest.
What should defenders do?
Because INC wins on fundamentals, the defence is fundamentals too. Patch internet-facing appliances on the day advisories drop, since INC’s CVE list is dominated by known, patchable edge flaws. Enforce phishing-resistant MFA on every VPN, RDP and webmail entry point, and treat any employee credential found in a stealer log as already compromised. Segment the network so a single foothold cannot reach domain controllers, and keep offline, tested backups so encryption is an inconvenience rather than a catastrophe. Business EDR that can catch living-off-the-land behaviour matters more here than signature detection; see our business ransomware protection guide.
Frequently asked questions
Is INC Ransom still active in 2026?
Yes. INC Ransom remained one of the most active ransomware operations through the first half of 2026, with 35 confirmed victims logged by the Ransomnews tracker and fresh listings appearing into June 2026.
What is the difference between INC Ransom and Lynx?
Lynx is widely assessed as a derivative of INC Ransom, built on leaked or sold INC code after a 2024 source-code posting. The two share technical DNA but operate as separate brands with separate leak sites.
How does INC Ransom encrypt files?
INC appends an .inc extension to encrypted files and drops a ransom note named INC-README.txt or INC-README.html. Encryption happens late in the intrusion, after data has already been stolen for double extortion.
What sectors does INC Ransom target most?
Business and professional services form the largest share of INC’s 2026 victims, followed by government and healthcare. Healthcare draws outsized attention because of its uptime sensitivity and record-rich databases.
How do you defend against INC Ransom?
Patch edge appliances promptly, enforce phishing-resistant MFA everywhere, monitor for stolen credentials in stealer logs, segment the network, and maintain offline backups. INC exploits known flaws and valid accounts, so disciplined hygiene removes most of its advantage.
