Akira began as a classic encrypt-and-extort operation but has been quietly drifting toward data-theft-only attacks across 2025-2026. A profile of where they came from, where they are now, and why the model is working.
A practitioner’s forensic playbook for working backwards from a stealer log to the originating infection: what the log file structure tells you, where the malware sits, and how to clean it up properly.
RansomHub became the largest active RaaS by claim count in 2025 by absorbing experienced affiliates from the LockBit and ALPHV exits. A 2026 profile of the operator, their tooling, and their structural position.
Scattered Spider (UNC3944, Octo Tempest) survived the 2024 arrests and remains one of the most operationally aggressive English-speaking threat groups. Their 2026 playbook, capabilities, and how they keep getting in.
Encrypt the data, leak the data: that’s not enough leverage anymore. A 2026 look at how operators stack additional extortion vectors when the basic playbook stops getting paid.
A 2026 Q1 ransomware leaderboard built from leak-site claims, with the structural changes shaping the operator pool: RansomHub at the top, a long mid-tier, and the takedown ripples still propagating through the ecosystem.
Hospitals have been the worst ransomware targets for half a decade and the attacks keep getting worse, not better. A practitioner’s look at why the sector remains uniquely vulnerable and what’s finally starting to help.
A side-by-side look at the per-attack economics of business email compromise vs ransomware in 2026. Hint: the louder threat isn’t the bigger one.
A new generation of operators has dropped encryption entirely: they steal the data and threaten to leak it without ever locking a single file. Here’s why that model is winning.
Bulletproof hosting providers (the ones that ignore abuse complaints and law-enforcement requests) remain a foundation of the cybercrime stack. Here’s where they live in 2026 and how the takedown calculus has shifted.