Ransomware
66 articoliQWERTYmag ricostruisce gli incidenti con attenzione a fatti verificati, misure di difesa e decisioni successive all’attacco: isolamento, backup, ripristino, comunicazione e gestione dei dati sottratti. Le guide spiegano come ridurre l’impatto prima di un incidente e quali rischi comporta il pagamento. Il focus è l’estorsione ransomware e il recupero operativo, distinto dal malware generico e dalle violazioni di dati prive di cifratura.
Nova ransomware traced to real identity after global victim surge
Nova ransomware, born from the RALord group, has spread fast and hit victims worldwide. Investigators have now tied the operation to a specific person using digital clues and breach data, revealing the real face behind the attacks.
Storm-2570 breaks into global networks using remote access tools
Storm-2570 isn't tied to just one ransomware group. It moves between Qilin, DragonForce, Anubis, and BERT, always using the same set of remote access and data theft tools. Microsoft shows how this affiliate keeps breaking in-and what defenders need to do to stop them.
PAYLOAD ransomware turns Active Directory into a weapon
The PAYLOAD ransomware group has flipped the script, using Microsoft Active Directory Group Policy to freeze Windows systems and steal data-without dropping classic ransomware.
Ransomware locks company network using Windows tools and stolen accounts
A manufacturing firm in the Middle East was crippled by ransomware that never used encryption. Instead, attackers hijacked privileged accounts and standard Windows features to lock workstations, display ransom notes, and leak stolen data online.
Ransomware attack shuts down Nepal Stock Exchange
A ransomware hit on Data Hub has stopped trading for 72 stockbrokers, forcing NEPSE to freeze the market and raising urgent questions about the safety of Nepal's financial data systems.
Ransomware recovery in South Africa now costs over one million dollars
South African organisations now face an average recovery bill of R17 million after ransomware attacks. Most incidents end with encrypted data and chaos, even as costs dip slightly from last year.
Ransomware recovery fails without real-world proof
Backup plans and recovery playbooks mean nothing if they are not tested under the same hostile conditions ransomware creates. Only clean-room restoration and rigorous validation can prove a system is truly recoverable and trustworthy.
Storm-2570 exposes ransomware playbook before encryption hits
Microsoft has identified Storm-2570 as a ransomware affiliate using identical attack methods across multiple ransomware families, allowing defenders to spot intrusions before systems are encrypted.
NFM Lending hit by huge data breach claim after Interlock ransomware attack
A ransomware group says it stole over 2.5 terabytes of data from NFM Lending, including Social Security numbers and financial records. The breach has triggered a class action lawsuit and urgent questions about the lender's cybersecurity.
Galago ransomware rivendica legami con Panzer: nel mirino la sanità islandese
Galago, gruppo ransomware appena emerso, dichiara una collaborazione con Panzer e punta la sanità islandese. Ma dietro i proclami, mancano prove di attacchi concreti e di una vera partnership.
Ransomware recovery costs surge for schools and universities
Schools and universities now face average recovery bills of $2.26 million after ransomware attacks. Identity breaches and long downtimes are exposing deep weaknesses across the education sector.
Ransomware hits new highs as cybercriminals ramp up attacks in 2026
August 2026 set a new record for ransomware attacks, with more than 1,000 organizations worldwide hit. Factories, hospitals, and IT companies took the brunt as groups like Qilin and The Gentlemen stepped up their campaigns.
Nepal Stock Exchange reopens after ransomware halts trading
Trading at NEPSE came roaring back after a ransomware attack forced a rare shutdown. With systems restored, turnover hit NRs 7.05 billion as regulators pressed for answers on the breach.
Ransomware gangs turn on each other in dark web sabotage
ShinyHunters hijacked Clop's leak site, setting off a fierce cyber feud that lays bare the cutthroat rivalries and shaky alliances inside the ransomware world. The fallout is hitting not just criminals, but also companies caught in the middle.
ShinyHunters hijacks Clop ransomware leak site in cybercriminal turf war
ShinyHunters has breached and defaced the Clop ransomware gang's dark-web leak site, claiming to have stolen sensitive server data and threatening to extort its rival. The attack exposes vulnerabilities even among top cybercrime groups.
Namibian Defence Force listed in ransomware claim, but evidence is missing
RansomHouse has named the Namibian Defence Force as a victim on its dark web site, but so far, no proof of a breach or stolen data has surfaced. Security researchers say the claim remains unverified and lacks technical evidence.
Ransomware blocca i sistemi della contea di Ellis
Un attacco ransomware ha colpito la contea di Ellis, bloccando i servizi digitali locali e sollevando dubbi sulla sicurezza informatica delle amministrazioni pubbliche.
Halcyon blocca la cifratura ransomware con File Resilience
Halcyon introduce File Resilience, una funzione che impedisce la cifratura ransomware prima che inizi. Il sistema ora protegge anche macOS e si integra più a fondo con gli strumenti Microsoft, rafforzando la sicurezza aziendale contro le minacce digitali.
Settra ransomware colpisce aziende tramite VPN compromesse
Il ransomware Settra prende di mira organizzazioni sfruttando credenziali VPN rubate e strumenti di monitoraggio remoto. Gli attacchi hanno interessato aziende dei settori retail e manifatturiero, con tecniche pensate per eludere le difese e cancellare le tracce.
Ransomware agentico: il primo attacco AI senza operatori umani
Per la prima volta, un ransomware gestito da agenti AI autonomi ha condotto un'intera campagna di estorsione senza intervento umano, accelerando le intrusioni e rendendo il crimine informatico più accessibile e scalabile.
Ransomware paralyses South African organisations as recovery costs climb
South African organisations are under constant attack from ransomware, with most incidents traced to stolen credentials and poor security. Even as more companies use backups, recovery is slow and expensive, according to the 2026 Sophos report.
Boardrooms face critical blind spot in ransomware defense
Ransomware is no longer a technical glitch but a board-level crisis. Most boards remain dangerously underinformed about the criminal economy driving attacks, leaving organizations exposed to escalating operational and financial threats.
MUIS: No mass data leak after ransomware hits mosque payroll system
Singapore's Islamic Religious Council says no large-scale data theft occurred after a ransomware attack on the SmartHRMS payroll system. Data was recovered, operations continued, and no ransom was paid.
Ransomware surges in the Middle East as AI gives hackers new power
Ransomware attacks have jumped twenty-fold in the Middle East, with AI-driven hacking tools now targeting critical infrastructure and major economies. Both criminal and state-backed groups are reshaping the region's cyber threat landscape.
Druva uses AI to counter AI-powered ransomware
Druva is using its own AI to analyze suspicious identity behavior and validate threats through backup data, giving security teams concrete evidence for rapid containment and recovery.
Cartrack sotto indagine dopo un attacco ransomware che espone i dati dei clienti
Ad agosto, un attacco ransomware ha colpito Cartrack, esponendo dati personali e bancari dei clienti. L'Information Regulator ha aperto un'indagine per chiarire la portata della fuga di informazioni e le responsabilità dell'azienda.
Russian Enterprises Targeted by Coordinated Cyberattacks Using Custom Malware
Three threat groups-NightEagle, Hacking Cat, and Toy Ghouls-are systematically breaching Russian companies with advanced backdoors, ransomware, and wiper malware, according to new research from Kaspersky.
Ransomware blocca i servizi al Nipigon District Memorial Hospital
Un attacco ransomware ha colpito il Nipigon District Memorial Hospital, bloccando i sistemi informatici e costringendo la struttura a sospendere alcuni servizi essenziali. I pazienti si trovano ad affrontare attese più lunghe e incertezza sulla sicurezza dei dati personali.
DaVita Inc. stock jumps after ransomware settlement clarifies legal risk
DaVita Inc. shares rose 4.4% to $189.32 after a preliminary settlement in a ransomware class action, helping the stock recover from its 52-week low and restoring some investor confidence despite ongoing challenges in the healthcare sector.
Ransomware gangs escalate attacks on Gulf infrastructure
A wave of ransomware attacks is battering Gulf businesses and critical infrastructure, as criminal groups shift focus to the Middle East and leverage AI to amplify their reach. New data reveals a dramatic spike in incidents and exposes the vulnerabilities putting entire sectors at risk.
Ransomware exploits VMware vCenter flaw before patches are applied
Ransomware groups are taking advantage of a critical VMware vCenter vulnerability just days after a patch was released, encrypting ESXi virtual machines and highlighting how little time defenders have to respond.
Ransomware attack halts payroll for Singapore mosques
A ransomware attack has shut down the payroll and HR system used by Singapore's Islamic Religious Council, exposing staff data but leaving public services running. Authorities and provider Avelogic are investigating and working to restore security.
Ransomware recovery plans fail to restore business operations
A Fenix24 report reveals that most organizations hit by ransomware cannot fully recover operations even if they refuse to pay, exposing critical gaps in identity and infrastructure recovery planning.
Ransomware recovery targets collapse for nearly all companies
Fenix24's new report reveals that almost every company fails to meet its own ransomware recovery targets, with identity management and backup systems routinely sabotaging efforts to restore operations within days.
Zero trust blocks ransomware threats for older adults and critical systems
Ransomware attacks now threaten hospitals and critical infrastructure, putting lives at risk. Experts explain why zero trust is essential for older adults, families, and organizations facing constant digital threats.
Pagina 1 di 3