INC Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
28
occurrences
First Seen
November 4, 2025
Last Seen
September 2, 2026

Related Threat Clusters

  • SonicWall SMA1000 Faces Third Zero-Day Exploitation in 2026

    SonicWall's SMA1000 VPN appliances are under active exploitation due to two newly discovered zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, which were confirmed on September 1, 2026. The first…

    21 articles · Updated September 2, 2026
  • Coordinated Cyberattack Disrupts Water Utilities in Minnesota

    A coordinated cyberattack affected water utilities in over 30 Minnesota communities on July 26 and 27, 2026. Key cities impacted include Plymouth, South St. Paul, Braham, and Maple Plain. The attack targeted…

    325 articles · Updated July 27, 2026
  • Chronus Group Breach Exposes 36 Million Mexican Citizens' Data

    In January 2026, the Chronus Group executed a significant data breach against the Mexican government, compromising 2.3 terabytes of sensitive data from at least 25 agencies. The breach exposed personal information of up…

    2 articles · Updated May 28, 2026
  • Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs

    On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…

    33 articles · Updated May 19, 2026
  • Air Côte d'Ivoire Confirms Cyberattack by INC Ransomware Group

    Air Côte d'Ivoire has confirmed a cyberattack that occurred earlier in February 2026, attributed to the INC ransomware group. The attackers claimed to have stolen 208 GB of data and threatened to leak it by February 24,…

    2 articles · Updated February 25, 2026
  • INC Ransomware Exploits SonicWall Vulnerabilities, Calls Victims Directly

    The INC Ransomware group has exploited two critical vulnerabilities in SonicWall devices, specifically CVE-2026-15409 and CVE-2026-15410, affecting organizations in 71 countries, including Colombia. This campaign began…

    3 articles · Updated August 6, 2026
  • INC Ransomware Group Targets Healthcare in Oceania

    The INC ransomware group has launched a series of attacks against healthcare facilities and government agencies across Australia, New Zealand, and Tonga. The Australian Cyber Security Centre (ACSC), National Cyber…

    2 articles · Updated March 11, 2026
  • Pierce County Library System Data Breach Affects Over 340,000 Individuals

    A cyberattack on the Pierce County Library System in Washington exposed the personal information of over 340,000 individuals. The breach, which occurred between April 15 and 21, 2025, involved unauthorized access to the…

    2 articles · Updated December 16, 2025
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1922 articles · Updated February 12, 2026
  • Rise of AI-Driven Scams Targeting UK SMEs

    UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…

    860 articles · Updated March 12, 2026

Recent Intelligence Reports

  • SonicWall reports two major security holes under active exploit — Csoonline · September 2, 2026
  • Significant Cyber Incidents — www.csis.org · August 13, 2026
  • INC ransomware explotó fallas de SonicWall durante tres semanas antes del parche — Colombia entre los países afectados — Ciberseguridadlatam · August 6, 2026
  • INC ransomware explotó fallas de SonicWall durante tres semanas antes del parche — Colombia entre los países afectados — Ciberseguridadlatam · August 6, 2026
  • Silent Ransom Group Sends Operatives Into Law Firm Offices: 38 Firms Already Leaked — Techtimes · May 28, 2026
  • FBI warns US — Cyberscoop · May 27, 2026
  • Microsoft takes down MSaaS used by ransomware gangs — News.Risky.Biz · May 20, 2026
  • Cybercrime service disrupted for abusing Microsoft platform to sign malware — Bleepingcomputer · May 19, 2026

CVSS v3.1 Breakdown