Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

Akira’s pivot to extortion-only: a 2026 group profile

Ransomnews Research TeamMay 3, 20260

Akira began as a classic encrypt-and-extort operation but has been quietly drifting toward data-theft-only attacks across 2025-2026. A profile of where they came from, where they are now, and why the model is working.

Stealer log forensics: tracing infections back to the user

Jesse William McGrawMay 3, 20260

A practitioner’s forensic playbook for working backwards from a stealer log to the originating infection: what the log file structure tells you, where the malware sits, and how to clean it up properly.

RansomHub explained: the post-LockBit consolidator

Ransomnews Research TeamMay 3, 20260

RansomHub became the largest active RaaS by claim count in 2025 by absorbing experienced affiliates from the LockBit and ALPHV exits. A 2026 profile of the operator, their tooling, and their structural position.

Scattered Spider in 2026: still the SIM-swap kings

Ransomnews Research TeamMay 3, 20260

Scattered Spider (UNC3944, Octo Tempest) survived the 2024 arrests and remains one of the most operationally aggressive English-speaking threat groups. Their 2026 playbook, capabilities, and how they keep getting in.

Why double extortion isn’t enough anymore: the rise of triple and quadruple extortion

Ransomnews Research TeamMay 2, 20260

Encrypt the data, leak the data: that’s not enough leverage anymore. A 2026 look at how operators stack additional extortion vectors when the basic playbook stops getting paid.

Ransomware Q1 2026 leaderboard: who’s claiming the most victims

Ransomnews Research TeamMay 2, 20260

A 2026 Q1 ransomware leaderboard built from leak-site claims, with the structural changes shaping the operator pool: RansomHub at the top, a long mid-tier, and the takedown ripples still propagating through the ecosystem.

Why hospital ransomware attacks keep getting worse

Jesse William McGrawMay 2, 20260

Hospitals have been the worst ransomware targets for half a decade and the attacks keep getting worse, not better. A practitioner’s look at why the sector remains uniquely vulnerable and what’s finally starting to help.

BEC vs ransomware: which is more profitable per attack in 2026?

Ransomnews Research TeamMay 2, 20260

A side-by-side look at the per-attack economics of business email compromise vs ransomware in 2026. Hint: the louder threat isn’t the bigger one.

The pivot from encryption to data theft: pure-extortion gangs in 2026

Ransomnews Research TeamMay 2, 20260

A new generation of operators has dropped encryption entirely: they steal the data and threaten to leak it without ever locking a single file. Here’s why that model is winning.

Bulletproof hosting in 2026: where attackers actually run their infrastructure

Ransomnews Research TeamMay 2, 20260

Bulletproof hosting providers (the ones that ignore abuse complaints and law-enforcement requests) remain a foundation of the cybercrime stack. Here’s where they live in 2026 and how the takedown calculus has shifted.

Previous 1 … 12 13 14 15 16 … 24 Next

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,715 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.