Related Threat Clusters
-
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics
Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their…
2 articles · Updated August 17, 2026 -
Foxconn Cyberattack: Nitrogen Ransomware Claims 8TB of Data Theft
Foxconn confirmed a cyberattack on its North American facilities, attributed to the Nitrogen ransomware group, which claims to have stolen 8 terabytes of data, including over 11 million files. The attack reportedly…
54 articles · Updated May 12, 2026 -
DigiCert Hacked via Malicious Screensaver File, EV Certificates Stolen
In April 2026, DigiCert experienced a breach due to a social engineering attack that compromised its tech support team. An attacker tricked two employees into executing a malicious screensaver file, leading to the theft…
6 articles · Updated May 4, 2026 -
WantToCry Ransomware Campaign Targets Exposed SMB Services for Remote Encryption
The WantToCry ransomware campaign exploits exposed Server Message Block (SMB) services to remotely encrypt files without deploying malware on victim systems. Attackers scan for open SMB ports and use brute-force methods…
6 articles · Updated May 20, 2026 -
Telehealth Security Risks: Data Breaches and Ransomware Threaten Patient Privacy
On World Health Day 2026, Kaspersky reported significant cybersecurity risks associated with telehealth services. Medical data breaches are increasingly common, with sensitive records being leaked and traded on the dark…
2 articles · Updated April 9, 2026 -
Scattered Spider Reclassified as Decentralized Cybercrime Collective
Scattered Spider, a cybercrime entity linked to various high-profile attacks since 2022, has been reclassified as a decentralized collective rather than a unified group. Group-IB's analysis indicates that it consists of…
2 articles · Updated July 7, 2026 -
Ransomware Dominates Financial Losses in Manufacturing Cyberattacks
A new report from Resilience reveals that the manufacturing sector is the most targeted industry for cyberattacks, with ransomware accounting for 90% of financial losses despite only 12% of claims. The analysis, based…
2 articles · Updated April 29, 2026 -
DigitalMint Negotiator Charged for $75 Million Ransomware Scheme
Angelo John Martino III, a former ransomware negotiator for DigitalMint, has been charged with conspiracy to interfere with interstate commerce by extortion. He allegedly conducted at least 10 ransomware attacks between…
4 articles · Updated March 12, 2026 -
Florida Ransomware Negotiator Pleads Guilty to Conspiracy with BlackCat Gang
Angelo Martino, a 41-year-old former ransomware negotiator from Florida, pleaded guilty to conspiracy charges related to assisting the BlackCat/ALPHV ransomware gang in extorting U.S. companies. Martino, along with…
33 articles · Updated April 21, 2026 -
Latvian Ransomware Negotiator Sentenced for $56 Million Cyber Extortion Scheme
Deniss Zolotarjovs, a 35-year-old Latvian national, was sentenced to 8.5 years in federal prison for his role in a ransomware organization linked to over 54 cyberattacks on various companies from June 2021 to August…
12 articles · Updated May 5, 2026
Recent Intelligence Reports
- Storm-0501 — attack.mitre.org · August 18, 2026
- U.S. Court Seizes $8.37 Million in Crypto Assets from BlackCat/ALPHV Ransomware Collaborator — Kucoin · July 20, 2026
- U.S. Court Seizes $8.37M in Crypto Assets, Including BTC and XRP, in Ransomware Case — Kucoin · July 19, 2026
- US court seizes $8.37 million in crypto from executive tied to ransomware group — Bitget · July 19, 2026
- Connecting Scattered Spider — www.group-ib.com · July 8, 2026
- Ukrainian national pleads guilty to role in Conti ransomware operation — Bleepingcomputer · June 12, 2026
- Ukrainian national pleads guilty to role in Conti ransomware operation — Bleepingcomputer · June 12, 2026
- WantToCry ransomware remotely encrypts files — News.Sophos · May 19, 2026