Tag: ransom
-
Ransom Cartel creator sentenced to 16 years in prison
Maksim Silnikau participated in cybercrime since at least 2005. He ran Ransom Cartel from 2021 until his arrest in 2023. First seen on cyberscoop.com Jump to article: cyberscoop.com/ransom-cartel-creator-sentenced-to-16-years-in-prison/
-
Hacker pleads guilty to stealing data from more than 165 Snowflake customers
Connor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in ransom payments. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/06/hacker-pleads-guilty-to-stealing-data-from-more-than-165-snowflake-customers/
-
Ransom Cartel Leader Sentenced to 16 Years in U.S.
A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka >>J.P. Morgan,<>lansky,<>xxx,<<) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes himself. This week, a federal judge in Virginia […] First seen…
-
Belarusian cybercriminal behind Ransom Cartel gets 16-year prison sentence
A Belarusian national active in the cybercriminal world for decades was sentenced to 16 years in U.S. prison for running the Ransom Cartel ransomware operation. First seen on therecord.media Jump to article: therecord.media/belarus-hacker-ransomware-sentenced
-
Canadian Pleads Guilty to Snowflake Customer Data Extortion
Extortionist Connor Moucka, 26, Helped Breach Over 150 Customers’ Accounts. Canadian national Connor Riley Moucka, 26, pleaded guilty in Seattle federal court holding to ransom data he helped steal from over 150 customers of cloud-based data warehousing platform Snowflake, leading to victims paying millions in cryptocurrency ransoms and incident response costs. First seen on govinfosecurity.com…
-
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021.Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to…
-
Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/
-
Flailing Ransomware Hackers Resorting to Extreme Tactics
Silent Ransom Bucks Trend of Fewer Victims Paying, and Paying Less When They Do. Fewer ransomware victims are choosing to pay a ransom than ever before, bar some big payoffs that largely trace to high-profile law firms that got hit by a group called Silent Ransom, which the FBI says has a penchant for infiltrating…
-
Fake ShinyHunters Emails Give Victims 48 Hours to Pay $2,000 Bitcoin Ransom
Fake ShinyHunters-themed sextortion emails are abusing data from recent ShinyHunters leaks to threaten victims with the release of fabricated “webcam recordings” unless a 2,000 dollar Bitcoin ransom is paid within 48 hours. Despite the technical-sounding claims, there is no evidence of actual device compromise, malware deployment, or recorded content behind these messages. The emails impersonate…
-
Swiss train maker Stadler refuses Everest $12 million ransomware demand
Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier’s file-sharing platform. First seen on therecord.media Jump to article: therecord.media/stadler-refuses-everest-ransom-demand
-
Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack
Cybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/stadler-everest-ransom-demand/
-
New ransomware group uses printers to deliver ransom notes
First seen on scworld.com Jump to article: www.scworld.com/brief/new-ransomware-group-uses-printers-to-deliver-ransom-notes
-
Stadler Rail refuses to pay $12.3 million ransom after ransomware attack
First seen on scworld.com Jump to article: www.scworld.com/brief/stadler-rail-refuses-to-pay-12-3-million-ransom-after-ransomware-attack
-
Anubis Ransomware Halts Fairlife Milk Production in the US
Gang Claims 1TB of Stolen Data and Sets Deadline for Ransom Talks. Anubis claims it encrypted Fairlife’s production systems and stole 1 terabyte of data, forcing the Coca-Cola-owned dairy brand to suspend U.S. milk production while investigators assess the ransomware incident and work to restore operations. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/anubis-ransomware-halts-fairlife-milk-production-in-us-a-32297
-
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/
-
If you pay a hacker’s ransom, chances are that they’ll come back for more
The long-held understanding among security researchers and network defenders is that it’s impossible to negotiate in good faith with an extortion racket because there’s no incentive for the other side to actually walk away. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more/
-
Kenya probes hack of president’s website after bitcoin ransom demand
The website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the ransom was paid. First seen on therecord.media Jump to article: therecord.media/kenya-probes-hack-of-presidents-website-after-ransom-demand
-
Pay up or not? Ransomware surge has victims facing tough choices.
Governments look at banning ransom payments in face of increasingly sophisticated threats. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices/
-
Pay up or not? Ransomware surge has victims facing tough choices
Governments look at banning ransom payments in face of increasingly sophisticated threats. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices/
-
Savi’s app aims to protect consumers from realistic AI scams like kidnappers demanding ransom
The company just raised $7 million in seed funding, and is launching its app for iPhone and Android on Tuesday. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/07/savis-app-aims-to-protect-consumers-from-realistic-ai-scams-like-kidnappers-demanding-ransom/
-
U.S. Government Agency Paid $1M to Data Extortion Group Kairos
Tags: blockchain, data, data-breach, extortion, government, group, ransom, ransomware, theft, threatA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked negotiation transcript and blockchain tracing of the ransom payment.…
-
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
Tags: blockchain, breach, data, data-breach, extortion, government, group, ransom, ransomware, theftA U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left.The odd part: the group that took the money calls itself Kairos, but it may not be…
-
FortiBleed Hacks Tied to INC Ransom and Lynx Operation
Theat Actor Accessed INC and Lynx Ransom Negotiation Panels. SOCRadar linked the FortiBleed credential-harvesting operation to ransomware groups INC Ransom and Lynx, citing evidence that a sophisticated initial access broker compromised more than 430,000 FortiGate firewalls, prioritized high-value organizations and enabled ransomware attacks against governments, critical infrastructure and major enterprises. First seen on govinfosecurity.com Jump…
-
FortiBleed Credential Theft Connected to INC and Lynx Ransomware
FortiBleed, the Fortinet credential theft campaign, is now connected to INC Ransom and Lynx, with a Nextcloud zero-day vulnerability also under investigation. First seen on hackread.com Jump to article: hackread.com/fortibleed-credential-theft-in-lynx-ransomware/
-
Scattered Spider suspect extradited over $8 million ransom scheme
A suspected Scattered Spider member has been extradited to the United States to face charges linked to cyberattacks against U.S. companies, including the breach of a luxury … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/02/scattered-spider-criminal-group-suspect-extradited/
-
430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link
FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator…
-
430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link
FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator…
-
FortiBleed Campaign Linked to INC and Lynx Ransomware Operations
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes, significantly increasing the threat posed by exposed firewall infrastructure. FortiBleed Campaign Linked to INC and…
-
Blackfield ransomware asks Nidec Corporation for $2 million ransom
The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/blackfield-ransomware-asks-nidec-corporation-for-2-million-ransom/
-
New Prinz Eugen ransomware targets recent files, avoids ransom notes
First seen on scworld.com Jump to article: www.scworld.com/brief/new-prinz-eugen-ransomware-targets-recent-files-avoids-ransom-notes

