extortion7 articles
Berlin Tells Rhysida to Get Lost After 5.7TB Data Heist
Berlin has refused to pay a ransom demanded by the Rhysida ransomware group, which hacked into the city's network between August 7–12 and stole over 5.7 terabytes of data. The stolen data reportedly includes personal information of over 12,000 people, financial documents, passwords, payroll information, and other sensitive files. Rhysida has demanded 30 bitcoin (approximately $2.3 million), but Berlin's governing mayor and interior senator have confirmed the city will not comply.
Meet Ransom Busters: The Ransomware Affiliate Posing as Your Rescuer While Charging $60K for the Privilege
A ransomware affiliate known as **Ransom Busters** is targeting victim organizations with unsolicited emails, claiming to have hacked ransomware groups' servers and offering to delete stolen data in exchange for fees of $20,000–$60,000. Cybersecurity firm GuidePoint found strong technical evidence — including shared tools, identical passwords, and the same attacker hostname across multiple incidents — suggesting the group is itself a ransomware affiliate rather than any legitimate third party, essentially running a secondary extortion scheme against victims already attacked by groups like DragonForce. Experts warn that paying such actors provides no guarantee data will be deleted and should be treated as a scam. The article also highlights the **broader ransomware landscape**, which is growing more fragmented and sophisticated, with 93 active groups recorded in Q2 2026, 2,139 organizations listed on data leak sites, and average ransom payments surging 176% to nearly $1.9 million — driven largely by data exfiltration-focused extortion rather than traditional encryption attacks.
Ransomware Crews Have Done Their Homework: It's the IT Manager They Want
Ransomware attackers are increasingly targeting mid-level managers — particularly those in their mid-40s working in finance, HR, sales, or operations — rather than executives, because these employees hold "business privilege" that gives them influence over payment decisions and access to sensitive data. Research by Zscaler tracking 351 victims found that attackers conduct detailed reconnaissance to map organisational structures and identify the people most likely to accelerate a ransom payment. More broadly, the ransomware landscape is intensifying, with blocked attempts up 146%, public extortion cases up 70%, and stolen data volumes up 92% over the past year.
ShinyHunters Dumps 41GB of Brinks Home Data After Ransom Goes Unpaid
Brinks Home, a Dallas-based home security firm, has suffered a data breach carried out by the ShinyHunters extortion group, who claim to have stolen over 4.9 million records from the company's Salesforce instance. After Brinks Home refused to pay a ransom, the hackers leaked more than 41GB of files online, which allegedly include personally identifiable information (PII). The company has confirmed the breach but stated that its alarm monitoring and core security systems were not affected, and is working to identify impacted individuals.
Paying Ransomware Criminals Doesn't Make Them Go Away. Surprise.
New data from Proofpoint reveals that paying ransomware demands offers no guarantee of safety, with 22% of UK organisations that paid being extorted a second time. Globally, 54% of victim organisations paid ransoms, yet 2% never recovered their files at all, and law enforcement takedowns like Operation Cronos confirmed that criminals routinely retain victim data even after receiving payment. AI is increasingly being used to enhance the phishing and credential-harvesting attacks that precede ransomware, though experts stress that building organisational cyber-resilience remains a far more effective strategy than paying attackers.
Anubis Ransomware Gang Claims Fairlife Hit, Gives Coca-Cola One Week to Pay
The Anubis ransomware group has claimed responsibility for a cyberattack on Fairlife, a Coca-Cola subsidiary, which disrupted production and resulted in the theft of approximately 1 TB of confidential data. The group is threatening to leak the stolen data unless a ransom is paid within one week. Active since December 2024, Anubis employs a double-extortion model and has targeted roughly 100 organisations, and is also notable for a "wiper mode" feature that can permanently delete victims' files.
A U.S. County Paid $1 Million to a Group That Never Even Locked a Single File
A U.S. government entity, likely Union County, Ohio, paid approximately $1 million in bitcoin to a group called Kairos after hackers stole over 1.6 million files and threatened to publish sensitive records, including data from the prosecutors' office. Unlike typical ransomware attacks, Kairos never encrypted any systems — it relied solely on the threat of leaking stolen data as leverage, reflecting a growing trend where extortion groups skip encryption entirely. After a month-long negotiation, the county paid ten times its opening offer, receiving only an unverifiable "proof of deletion" in return, with blockchain tracing linking the funds to exchanges including Bybit, OKX, and a Russian service.