UINAT
NewsRankingsCompaniesGuidesBreachesCompliance
TagsAbout
Home/Tags/ransomware

ransomware

25 articles tagged with "ransomware".

Operation Cronos: How Law Enforcement Dismantled LockBit, the World's Largest Ransomware Operation

On February 20, 2024, a 10-country task force seized LockBit's infrastructure, identified 194 affiliates, and froze $112 million in cryptocurrency in the most significant ransomware takedown in history.

February 20, 2026 LockBitransomwarelaw enforcement

Clop Exploits Oracle E-Business Suite Zero-Days in Massive Extortion Campaign

The Clop ransomware group weaponized CVE-2025-61882 and CVE-2025-61884 to breach nearly 100 organizations including Allianz UK, GlobalLogic, Envoy Air, Harvard, and Washington Post, with ransom demands reaching $50 million.

February 5, 2026 ClopransomwareOracle

ShinyHunters Publishes Harvard and UPenn Data: 2 Million Records Exposed

The ShinyHunters cybercriminal group published stolen data from Harvard University and the University of Pennsylvania after ransom demands went unpaid, exposing over 2 million alumni, donor, and student records.

February 4, 2026 ShinyHuntersdata breachHarvard

Ascension Health — Black Basta Ransomware Disrupts 100+ Hospitals

A Black Basta ransomware attack on Ascension Health, one of the largest US Catholic healthcare systems, forced hospitals to divert emergency patients, delay surgeries, and revert to paper records, affecting 5.6 million patients.

February 3, 2026 ransomwareBlack Bastahealthcare

Evolve Bank & Trust — LockBit Ransomware Exposes 7.6 Million via Fintech Partners

A LockBit ransomware attack on Evolve Bank & Trust, a banking-as-a-service provider for major fintechs, exposed data of 7.6 million individuals and rippled through partners including Affirm, Mercury, Wise, and others.

February 3, 2026 ransomwareLockBitfintech

CIRCIA: Federal Cyber Incident Reporting Requirements for Critical Infrastructure

The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) will require critical infrastructure entities to report cyber incidents to CISA within 72 hours and ransomware payments within 24 hours, with the final rule now expected May 2026.

February 2, 2026 CIRCIACISAincident reporting

Automated Extortion Campaign Wipes 1,400 MongoDB Servers, Demands Bitcoin Ransom

A single threat actor is conducting automated attacks against exposed MongoDB instances, wiping databases and demanding 0.005 BTC per server, with 208,500 instances publicly exposed worldwide.

February 1, 2026 extortionMongoDBdatabase security

Qilin Ransomware Gang Claims Tulsa International Airport Breach

The Russian-speaking Qilin ransomware group listed Tulsa International Airport as a victim, leaking financial documents, employee IDs, and executive communications in the aviation sector's first reported attack of 2026.

February 1, 2026 ransomwareQilinaviation

Backup and Disaster Recovery for Cyber Resilience

A comprehensive guide to designing backup strategies, implementing immutable backups, and building disaster recovery capabilities that withstand ransomware and destructive attacks.

February 1, 2026 backupdisaster recoveryransomware

GootLoader Uses 500-1,000 Concatenated ZIP Archives to Evade Detection

The GootLoader malware loader now creates malformed ZIP files containing hundreds of concatenated archives, causing security tools to extract harmless files while Windows extracts malicious JavaScript.

January 30, 2026 GootLoadermalwareevasion

FBI Seizes RAMP Cybercrime Forum Used by Ransomware Gangs

The FBI has seized the notorious RAMP dark web forum in coordination with DOJ. The forum had 14,000+ users and facilitated hundreds of millions in ransomware damages. Leaked database may expose LockBit operator.

January 29, 2026 FBIlaw enforcementransomware

Ransomware Attacks Surge 45% in 2025 with Over 9,200 Cases Recorded

NordStellar research reveals 9,251 ransomware incidents in 2025, with Qilin leading at 1,066 attacks (408% increase). December set a two-year record with 1,004 incidents. 2026 projected to exceed 12,000 attacks.

January 28, 2026 ransomwareresearchstatistics

Ransomware Defense Strategy: Prevention, Detection, and Recovery

A practical guide to defending against ransomware attacks, covering prevention controls, detection techniques, backup strategies, and incident response procedures.

January 24, 2026 ransomwareincident responsebackup

LockBit 5.0 Analysis: Upgraded Encryption, Stealbit Integration, and Enhanced Evasion

Security researchers detail LockBit 5.0's capabilities including ChaCha20-Poly1305 encryption, X25519 key exchange, modular two-stage deployment, and advanced anti-analysis techniques.

January 23, 2026 LockBitransomwaremalware analysis

Under Armour Ransomware Breach Exposes 72 Million Customer Records

The Everest ransomware group leaked 72.7 million Under Armour customer records including emails, names, dates of birth, purchase history, and loyalty program details after the company didn't pay.

January 21, 2026 Under Armourransomwaredata breach

Healthcare Ransomware Crisis: Lessons from Ascension and the 2024-2025 Attack Wave

Healthcare ransomware attacks affected 93% of organizations in 2024-2025, with Ascension's $1.8B loss and 5.6M affected patients illustrating the sector's vulnerability. HIPAA Security Rule update pending.

January 20, 2026 ransomwarehealthcarebreach

AZ Monica Hospital — Ransomware Attack Disrupts Patient Care Across Belgian Healthcare

A ransomware attack on AZ Monica hospital in Antwerp forced cancellation of 70+ surgeries, patient transfers, and revealed a broader breach affecting five Belgian hospitals through a shared software supplier.

January 14, 2026 AZ Monicahospitalransomware

Belgian Hospital Shuts Down Systems After Cyberattack, Transfers Critical Patients

AZ Monica hospital in Antwerp shut down all servers at 6:32 AM after detecting ransomware, canceling 70+ operations and transferring 7 critical patients. Belgium pledged €10M for hospital cybersecurity.

January 13, 2026 healthcareransomwareBelgium

CDK Global Ransomware Attack: How One Vendor Crippled 15,000 Auto Dealerships

A BlackSuit ransomware attack on CDK Global, the dominant dealer management system provider, shut down operations at 15,000 auto dealerships for nearly two weeks in June 2024, causing over $1 billion in losses and exposing critical supply chain risks.

January 6, 2026 ransomwareBlackSuitCDK Global

Claims Management Giant Sedgwick Hit by TridentLocker Ransomware

TridentLocker claims to have stolen 3.4GB from Sedgwick Government Solutions, which provides claims services to DHS, ICE, CBP, DOL, and CISA. The attack targeted an isolated file transfer system.

January 4, 2026 ransomwaredata breachinsurance

Sedgwick Government Solutions — TridentLocker Ransomware Breach

The TridentLocker ransomware group breached Sedgwick Government Solutions, a federal contractor subsidiary providing claims management to DHS, ICE, and CISA, exfiltrating 3.39 GB of data.

January 4, 2026 SedgwickTridentLockerransomware

Two US Cybersecurity Professionals Plead Guilty to BlackCat Ransomware Charges

Ryan Goldberg (Sygnia) and Kevin Martin (DigitalMint) admitted to operating as ALPHV/BlackCat affiliates, targeting healthcare organizations and causing $9.5M in losses. They face up to 20 years in prison.

January 2, 2026 ransomwareBlackCatALPHV

Change Healthcare — ALPHV/BlackCat Ransomware Disrupts US Healthcare System

The ALPHV/BlackCat ransomware attack on Change Healthcare caused the most significant disruption to the US healthcare system from a cyberattack, affecting claims processing for months and exposing data of approximately 100 million individuals.

December 15, 2025 ransomwarehealthcareALPHV

Synnovis/NHS — Qilin Ransomware Disrupts London Hospital Blood Services

A Qilin ransomware attack on pathology provider Synnovis disrupted blood testing and transfusion services across major London NHS hospitals for months, forcing cancellation of thousands of operations and appointments.

October 1, 2025 ransomwareQilinNHS

Marks & Spencer Ransomware Attack

Scattered Spider social-engineered a service desk password reset to breach M&S, deploying DragonForce ransomware that encrypted VMware infrastructure, halted online sales for 46 days, and caused £300 million in lost profit.

April 24, 2025 retailransomwareScattered Spider
SYS ONLINE
PAGES 963
UPDATED 2026-02-06
UINAT

Security news, vulnerability alerts, and expert resources for professionals who defend the perimeter.

// Sections

  • › News
  • › Rankings
  • › Companies
  • › Breaches

// Resources

  • › Guides
  • › Compliance
  • › Tags
  • › About

// Feeds

  • › All Content
  • › News Only
  • › Breaches Only

> © 2026 UINAT. All rights reserved.

[ DEFEND THE PERIMETER ]

Search