Storm-1175 and StormEncryptor: Ransomware Deployed the Same Day the CVE Was Disclosed
Microsoft Threat Intelligence attributed a new ransomware strain, StormEncryptor, to Storm-1175 beginning 2 August 2026 โ the same day CVE-2026-18577 ...
29 articles on ransomware โ privacy laws, security frameworks, and regulatory compliance.
Microsoft Threat Intelligence attributed a new ransomware strain, StormEncryptor, to Storm-1175 beginning 2 August 2026 โ the same day CVE-2026-18577 ...
INC Ransomware has become the dominant actor exploiting CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA 1000 appliances, with 885 victims claimed a...
Attackers were inside Medical Computer Business Services of Augusta, Georgia between 22 and 26 September 2025. The investigation concluded on 28 May 2...
Attackers used compromised credentials to reach a data-exchange platform shared between Stadler Rail and one of its suppliers. Everest demanded $12.3 ...
A 13 July 2026 ransomware attack on Nichirei disrupted roughly 140 distribution centres across Japan, affecting food manufacturers, supermarkets, and ...
Conduent Business Solutions told federal regulators on June 4, 2026 that 62,224,658 people had data exposed in a SafePay ransomware intrusion โ the th...
On July 16, 2026, The Coca-Cola Company disclosed a ransomware event at its dairy subsidiary fairlife, LLC, that forced a temporary suspension of US p...
Angelo Martino, a professional ransomware negotiator at incident response firm DigitalMint, was sentenced to 70 months in prison for secretly working ...
GuidePoint Security's GRIT Q2 2026 report counts 2,279 ransomware victims โ up 7% quarter-over-quarter and 43% year-over-year โ spread across a record...
Sysdig says JADEPUFFER is the first documented ransomware operation run end-to-end by an LLM agent โ it broke into a Langflow instance via CVE-2025-32...
The latest Unified Agenda shows CISA expects to finalize the CIRCIA incident reporting rule in September 2026 โ the second slip after the October 2025...
Mount Royal University confirmed that attackers who breached its network on June 17, 2026 stole data from its student and employee file storage, then ...
On July 4, 2026, the resurgent 'Unsafe' ransomware group listed Deutsche Bank on its dark-web leak site, posting alleged database extracts containing ...
In June 2026, the cybercrime group ShinyHunters breached Madison Square Garden Sports and affiliated MSG entities, claiming more than 26 million custo...
ShinyHunters breached Instructure's Canvas learning platform, exposing data tied to hundreds of millions of users across roughly 8,800 institutions an...
HHS' Office for Civil Rights resolved four ransomware-related HIPAA investigations affecting roughly 427,000 individuals and imposed $1,165,000 in pen...
HHS's Office for Civil Rights has now brought a dozen enforcement actions under its HIPAA Risk Analysis Initiative, and the agency has signaled the pr...
OCR's four ransomware settlements announced in April 2026 โ totaling $1.165 million across breaches affecting 427,000 individuals โ share one root cau...
May 2026 saw 95 publicly disclosed ransomware attacks across 17 countries, with Qilin and ShinyHunters leading a campaign that increasingly skips encr...
HHS OCR announced a $245,000 HIPAA settlement in April 2026 against a self-funded employer-sponsored group health plan following a 2021 ransomware att...
The 2026 Verizon Data Breach Investigations Report analyzed more than 22,000 confirmed breaches and found that vulnerability exploitation now accounts...
West Pharmaceutical Services detected a ransomware attack on May 4, 2026, disclosing via SEC 8-K that attackers exfiltrated data and encrypted systems...
The UK Information Commissioner's Office fined South Staffordshire Water's parent company ยฃ963,900 in May 2026 for security failings exposed by the Cl...
The average ransom demand across confirmed healthcare incidents has surged to $16.9 million in 2026, up from under $600,000 the prior quarter. With 77...
CISA's final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) is expected in May 2026, though federal a...
In late April and early May 2026, Cushman & Wakefield confirmed a cyberattack originating from a voice phishing operation that gave ShinyHunters acces...
ShinyHunters breached Instructure's Canvas learning management system twice in May 2026, stealing an estimated 275 million records โ names, email addr...
The Trump administration's March 2026 cyber strategy and executive order on cyber-enabled crime signal a fundamental policy pivot: less regulatory fri...
In 2025, ransomware groups launched 1,174 publicly disclosed attacksโa 49% year-over-year increaseโand healthcare bore the heaviest burden with 22% of...