
Six Ransomware Groups Post Cross-Sector Victims in Single Day
Play, Genesis, Nova, Incransom, Blackwater, and Krybit each posted victims on the same day, spanning automotive, dental, higher education, travel,

Play, Genesis, Nova, Incransom, Blackwater, and Krybit each posted victims on the same day, spanning automotive, dental, higher education, travel,

Payload ransomware posted Plaza Lama, Hansoll Textile, and Villea Hotels on its Tor leak site, targeting the Dominican Republic, Vietnam,

CoinbaseCartel posted Cambridge Mobile Telematics on its dark web leak site, threatening to expose driving behavior data for millions of

Anubis ransomware used its WIPEMODE against a US estate law firm and UK contractor; Nova claimed an Indian hospital and

Play ransomware posted four US victims in a single day: a food processing manufacturer, a law firm, a religious organization,

Akira ransomware posted National Standard Parts Associates and Northern Ohio Regional MLS, threatening 53 GB of employee records, contracts, and

Qilin ransomware posted Avcon Jet, SKUPINA Don Don, and Trican in a three-country sweep targeting private aviation, food retail, and

TheGentlemen ransomware struck Saudi Arabia, India, Thailand, and Portugal in one day, including a first GCC target, as the group

WorldLeaks claimed CH Karnchang, Thailand’s major infrastructure builder, and United Auto Supply in a pure data extortion operation with no

OFAC sanctioned Nobitex and three companion Iranian crypto exchanges for facilitating IRGC transactions and converting ransomware proceeds into usable funds.

Play is a highly capable ransomware group demonstrating advanced technical skills and operational sophistication.

Overview The Dark Angels ransomware group is a sophisticated and stealthy cybercrime operation known for its targeted attacks on large

Salt Typhoon is considered an advanced persistent threat (APT) actor, reportedly operated by the Chinese government.

RansomHub operates as a Ransomware-as-a-Service (RaaS), providing infrastructure and code to affiliates.

Ryuk operates under a RaaS model, meaning the developers provide the ransomware to other cybercriminals who then carry out the

Lazarus Group is a highly sophisticated and adaptable APT group with a diverse range of targets and objectives.

FIN11, also known as DEV-0950, Lace Tempest, TA505, TEMP.Warlock, and UNC902, is a cybercrime group that has been conducting financially-motivated
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.