Coverage
Data Breaches
482 articles on breaches and ransomware
Advertisement
Ryuk Ransomware Affiliate Pleads Guilty to US Hacking Charges
A 34-year-old Armenian national faces 15 years in prison for his role in the Ryuk ransomware operation, which targeted U.S. hospitals and businesses.
Insider Threat: Security Expert Sentenced for BlackCat/ALPHV Aid
Former ransomware negotiator Angelo Martino received a 70-month prison sentence for aiding the BlackCat/Alphv ransomware group, highlighting insider threat risks.
GigaWiper Windows Backdoor Analysis: Disk Wiping & Fake Ransomware
Runtime Rebel analyzes GigaWiper, a destructive Windows backdoor identified by Microsoft, bundling disk wiping, fake ransomware, and spyware capabilities.
GodDamn Ransomware Leverages Signed Driver to Disable EDR
Analysis of GodDamn ransomware's BYOVD technique, utilizing a Microsoft co-signed driver to disable security software, impacting US companies.
Mount Royal University Data Breach: Ransomware Impact & Mitigation
Mount Royal University confirms a ransomware attack led to data theft and deletion, impacting student, employee, and university data. Review critical mitigation steps.
Mount Royal University Data Breach: Network Intrusion, Data Theft, and Deletion
Mount Royal University confirms a significant data breach involving network intrusion, data theft, and subsequent deletion of files from storage systems.
Accenture Data Breach: Source Code Theft Confirmed
Accenture confirms a data breach involving source code theft. Runtime Rebel analyzes the incident, potential impacts, and recommends urgent mitigation steps for similar…
Licking County Pays $1M Ransom to Embargo Group Over Data Theft
Licking County, Ohio, reportedly paid $1 million to the Embargo extortion group to prevent the leak of sensitive data, highlighting risks to local governments.
Accenture Confirms Breach: LockBit 2.0 Ransomware and Stolen Data
Accenture confirmed a security breach involving LockBit 2.0 ransomware, leading to 35 GB of stolen source code and proprietary data. Runtime Rebel analyzes the impact.
JadePuffer: First LLM-Driven Ransomware Leverages Langflow Flaw
Analysis of JadePuffer, the first reported LLM-driven ransomware, which exploited a Langflow vulnerability to exfiltrate database data and encrypt systems.
JadePuffer Ransomware: AI Agents Automate the Full Attack Lifecycle
Researchers have identified JadePuffer, a ransomware operation using LLM-driven AI agents to automate scanning, exploitation, and lateral movement.
Kairos Group Extorts $1M from US Government in Data-Theft Campaign
A US government entity paid $1M to the Kairos group to prevent a data leak, signaling a shift from traditional ransomware to pure data-theft extortion.
Agentic AI Automates Ransomware Attacks via Langflow Exploitation
Agentic AI agents demonstrate automated multi-stage ransomware attacks using Langflow, raising concerns for AI development security and future threat automation.
Peter Stokes Extradition: Impact on Scattered Spider Operations
Technical analysis of the extradition of Peter Stokes and the persistent TTPs of the Scattered Spider threat actor group targeting enterprise networks.
Medtronic Breach: ShinyHunters Exfiltrates 3.8M Patient Records
Medtronic confirms a data breach by ShinyHunters impacting 3.8 million people, exposing personal and protected health information (PHI) from corporate IT systems.
CVE-2025-5777: Anubis Ransomware Exploits Citrix Bleed 2
Anubis ransomware affiliates exploit Citrix Bleed 2 (CVE-2025-5777) and BYOVD techniques to breach networks via RMM tools and supply chain credentials.
AI Compute Hijacking and BlueHammer Ransomware Analysis
Analysis of emerging threats including AI compute hijacking via sandbox escapes, BlueHammer ransomware TTPs, and logic flaws in Apple email services.
Alleged Scattered Spider Hacker Extradited: Mitigating Social Engineering
An alleged Scattered Spider member's extradition highlights ongoing efforts against sophisticated social engineering and identity-based attacks impacting major…
FortiBleed: Credential Theft Fuels INC & Lynx Ransomware Intrusions
Analysis of the FortiBleed campaign, linking mass FortiGate credential theft to INC and Lynx ransomware operations for follow-on intrusions.
JADEPUFFER AI Agent Exploits Langflow RCE for Automated Ransomware
The threat actor JADEPUFFER has pioneered the use of AI agents to automate end-to-end ransomware attacks via Langflow RCE, from initial access to data wiping.
Lynx Ransomware Linked to Massive FortiBleed Credential Theft
Threat actors behind Lynx and INC ransomware leverage FortiBleed campaign to harvest over 440,000 Fortinet VPN credentials via CVE-2023-48788 exploits.
Medtronic Data Breach: ShinyHunters Campaign Exposes Customer PII
Medtronic notifies customers of a data breach linked to ShinyHunters. Learn how cloud credential theft led to the exposure of patient and customer records.
CVE-2026-33825: BlueHammer Zero-Day in Microsoft Defender Exploited by Ransomware
Analysis of the BlueHammer zero-day, CVE-2026-33825, in Microsoft Defender, actively exploited by ransomware groups. Learn detection and mitigation strategies.
Aflac Japan Data Breach Exposes Customer Financial Data
Aflac Japan subsidiary data breach exposed personal and bank account details for an undisclosed number of customers. Review impact and mitigation.