Cybersecurity News
Filters
Filtered by tag: ransomware × Clear
Defining the MVC: Recover faster from cyberattacks by restoring what matters most
Organizations struggle to recover from cyberattacks not due to missing backups, but from trying to restore everything simultaneously. The Minimum Viable Company (MVC) concept offers a better approach: identifying the minimum people, processes, and technology needed to keep functioning during a crisis. Key recovery capabilities include mapping critical services, establishing a trusted foundational layer, isolating recovery assets, building clean-room recovery environments, and validating plans through realistic rehearsals.
Canadian SickKids hospital hit again by cyberattacks, more data stolen
Canada's SickKids pediatric hospital suffered a cyberattack exploiting a third-party software vulnerability, exposing personal data of current and former employees and job applicants. Clinical systems and patient records were unaffected. Those impacted are being offered 24 months of free credit monitoring. The hospital was previously hit by LockBit ransomware in late 2022, marking this its latest security incident.
The ascent of autonomous attacks and the race to contain them
AI is enabling autonomous cyberattacks that can conduct reconnaissance, breach systems, and adapt without human input. A 2025 Jaguar Land Rover attack cost £485m in losses. Smaller businesses face growing exposure as AI scans for vulnerabilities at scale. Defenses need to shift toward continuous monitoring, strong identity controls, and AI-powered detection, supported by human expertise, to counter threats moving faster than traditional security measures.
Scammers pose as ransomware recovery agents, but just go on to steal more from victims
Cybercriminals are posing as ransomware recovery specialists to defraud victims twice. Groups like "Ransom Busters" pose as legitimate recovery firms, approach ransomware victims, and pocket fees without delivering results. In reality, they are ransomware affiliates exploiting desperate victims. Experts warn organizations to thoroughly vet any recovery service before paying, as the fake recovery industry is growing alongside ransomware itself.
Exclusive: Ransomware newcomers list South Australia’s Ramsey Bros as hacking victim
Matched: Australia
Ransomware group Storm claims to have hacked Ramsey Bros, a South Australian farm machinery supplier. The group says it has published stolen data as proof, including alleged customer information and vehicle inspection records. Ramsey Bros has not yet publicly commented. Storm is considered a newcomer among ransomware groups, which typically steal and threaten to leak data to pressure victims into paying.
CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks
Matched: health
CISA, the FBI, and HHS have jointly issued an updated advisory warning that Medusa ransomware attackers are actively targeting enterprise networks, disabling security tools, stealing sensitive data, and encrypting entire systems. The alert urges organizations to strengthen defenses against the group, which has escalated its activity across critical sectors.
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Researchers at Check Point identified a ransomware operation called StopAndProtect in May 2026. The campaign uses the ClickFix social-engineering technique to trick victims into running a PowerShell command, triggering a multi-stage downloader chain. Thousands of hacked WordPress sites serve as infrastructure for the operation, which researchers have now partially unmasked through analysis of its infection chain and supporting infrastructure.
Exclusive: SIA Medical Centre confirms it is investigating cyber incident involving patient data
Matched: medical
Victorian medical centre SIA Medical Centre is investigating a ransomware attack after the Rhysida cyber extortion group claimed to have obtained thousands of patient records. The centre confirmed it is responding to a cyber incident involving patient data. Rhysida, a known ransomware group, has listed the stolen data and is threatening to release it unless a ransom is paid.
Ransomware gang crashes own attack — with no-one to blame but themselves
Ransomware group Akira accidentally sabotaged its own attack after using a driver exploit to disable endpoint detection software — the same technique also killed their encryption tool. Researchers noted the self-inflicted failure but warned the tactic of using vulnerable drivers to bypass security is increasingly common and remains a serious threat even when, as here, it backfires on the attackers.
17th August – Threat Intelligence Report
Colombia's Ministry of Justice suffered a ransomware attack disrupting technology infrastructure and public services tied to drug monitoring and legal processes, with officials confirming file compromise. Other notable incidents include additional breaches and cyberattacks detailed in Check Point Research's weekly Threat Intelligence Bulletin, covering top attacks, emerging vulnerabilities, and threat actor activity for the week of 17th August.
Exclusive: Australian truck trailer company Midland among dozens of victims listed by Cl0p cyber extortion group
Matched: Australia
Ransomware group Cl0p has listed over 40 victims in a single day, including major companies such as Philips, General Electric, Tristar, Shell, and Australian truck trailer manufacturer Midland. The prolific cyber extortion gang typically publishes victim details when ransom demands go unpaid, using the threat of data exposure as leverage.
Akira Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate attempted to bypass endpoint detection by rebooting a victim's system into Safe Mode, which prevents most security tools from loading. The tactic backfired when Safe Mode also blocked their own ransomware from executing properly. Researchers documented the full attack chain, highlighting how threat actors are adapting techniques against modern EDR solutions, sometimes with self-defeating results.
One in three ANZ organisations still pay ransomware demands, Commvault research says
Matched: Australia
One in three organisations in Australia and New Zealand still pay ransomware demands, according to Commvault research, despite uncertainty about whether data will be recovered or operations restored. The findings highlight ongoing vulnerabilities and suggest many organisations lack confidence in their ability to recover without meeting attackers' demands.
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Matched: health
South Korean and US cybersecurity agencies have warned about Gunra ransomware targeting critical infrastructure globally, including healthcare, financial services, government, and nonprofit sectors. The attacks exploit vulnerabilities in Fortinet and Schneider Electric systems. Gunra follows a ransomware-as-a-service model and represents a continuing trend of sophisticated ransomware variants threatening essential services worldwide.
Exclusive: Kairos ransomware lists Warwick Fabrics NZ as hack victim
Matched: medical
New Zealand textile company Warwick Fabrics has been listed as a victim by the Kairos ransomware group, which claims to have stolen 386 gigabytes of data. The alleged breach includes sensitive employee information such as passports, medical reports, and salary data. The company has not yet publicly responded to the claims.
Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites
Matched: health
A Russian-speaking hacker has been linked to a broad campaign breaching organizations across multiple sectors worldwide, including education, healthcare, finance, and government. The actor exploited exposed security appliances and public applications to harvest credentials and sell network access to ransomware groups. The operation also reportedly included surveillance activity targeting Ukrainian military websites.
Exclusive: Partnered Health responds to Inc Ransom data breach claims
Matched: Australia, health
Australian GP network Partnered Health is responding to claims by cyber extortion group Inc Ransom, which alleges it stole terabytes of data from the organisation. At least 21 clinics may be affected. Partnered Health has not confirmed the breach but is investigating. Inc Ransom typically publishes stolen data if ransom demands go unmet.
27th July – Threat Intelligence Report
Nichirei, a Japanese frozen-food and logistics company, suffered a ransomware attack disrupting shipping operations and affecting around 5,000 customers, with KFC Japan warning of possible shortages. Personal data theft was confirmed. The incident is among several attacks and breaches covered in Check Point Research's Threat Intelligence Bulletin for the week of 27th July.
What Are Initial Access Brokers?
Initial access brokers are cybercriminals who specialize in breaking into corporate networks and selling that access to other attackers, such as ransomware groups, rather than exploiting it themselves. They typically gain entry through stolen credentials, phishing, or unpatched vulnerabilities. This division of labor has made cybercrime more efficient and increased the scale of attacks on businesses.
It’s Not Safe To Pay SafePa
Huntress researchers have observed multiple ransomware groups, including Akira, ReadText34, and INC, deploying attacks through SafePay. The findings highlight how ransomware affiliates are actively leveraging the platform to conduct operations, raising significant security concerns for organizations potentially exposed to these threat actors.
