ransomware20 articles
Ransomware Knocks Fairlife's US Dairy Plants Offline
Coca-Cola's dairy subsidiary Fairlife has been hit by a ransomware attack that forced a temporary halt to production at its US plants, while its Canadian facilities remain operational. The attack compromised a portion of Fairlife's systems, including production-related systems, prompting the company to activate its incident response plan, engage cybersecurity experts, and notify law enforcement. Key details remain unclear, including who carried out the attack, whether data was stolen, and when US production is expected to resume.
Roundup: Iranian Spooks Track US Troops Via Ad Data, macOS Malware Plays Dead, and a Textile Firm Goes Bust After Six Weeks of Ransomware Hell
This SecurityWeek roundup covers a broad range of cybersecurity developments, including a German manufacturer filing for bankruptcy after a six-week production shutdown caused by a cyberattack, and Iranian threat actors exploiting advertising and cellular roaming data to track US military personnel's smartphones. Other highlights include the discovery of CrashStealer, a new macOS information-stealing malware that disguises itself as a legitimate crash reporter, and a joint CISA guide providing organisations with a framework for establishing Coordinated Vulnerability Disclosure programs. Additional stories touch on supply chain breaches affecting Lidl customers, ransomware targeting an Asian IT firm, and a cybercrime group claiming to have stolen over 1TB of data from naval defence manufacturer Thyssenkrupp Marine Systems.
Armenia Locks Up Russian Tourist Named Aleksandr Ermakov. Problem: There Are Two of Them.
Armenia has detained a Russian tourist, Aleksandr Yuryevich Ermakov, at Yerevan's airport on a US extradition request targeting a REvil ransomware suspect of the same name, but his lawyers argue Washington has the wrong man. The US and allied governments actually want Aleksandr Gennadievich Ermakov, a sanctioned cybercriminal linked to the hack of Australian health insurer Medibank and convicted in Russia for co-writing the SugarLocker ransomware, who is currently serving a sentence barring him from leaving Russia. The mix-up may stem from the US warrant omitting the patronymic that distinguishes the two men, with the detained man's lawyers noting that no fingerprints or full passport data have been produced to confirm his identity.
Ransomware Knocks Out Fairlife Milk Production Across the US
Coca-Cola has suspended US production at its dairy subsidiary Fairlife following a ransomware attack that compromised portions of the company's systems, including production-related infrastructure. The company has activated incident response protocols, notified law enforcement, and is working with cybersecurity experts to assess the full impact, though it states that product quality and safety have not been affected. Key details such as the attackers' identity, how the breach occurred, and whether any ransom demands have been made remain undisclosed.
Nichirei Cyberattack Leaves Japan's Frozen Food Chain on Ice
Japanese frozen food giant Nichirei was hit by a cyberattack on July 13, forcing it to disconnect its systems and disrupting operations at its refrigerated warehouses and shipping divisions, with knock-on effects for restaurants, retailers, and delivery services. The company confirmed that hackers targeted its servers and that some affected systems contained personal information, prompting an initial report to Japan's Personal Information Protection Commission over a potential data leak. Nichirei announced it would begin gradually restoring operations but has withheld details of the attack, leaving it unclear whether a ransomware group was involved.
Citrix Bleed 2, Rogue Drivers, and Poisoned Packages: Ransomware Groups Are Getting Creative
Ransomware groups including Anubis, The Gentlemen, and the VECT/TeamPCP alliance are employing increasingly sophisticated tactics, such as exploiting the critical Citrix Bleed 2 vulnerability (CVE-2025-5777), using legitimate remote management tools to blend in with normal IT activity, and leveraging a BYOVD zero-day to disable enterprise security solutions. The VECT/TeamPCP partnership represents a notable evolution in the threat landscape, combining supply chain credential theft with ransomware deployment at scale, though implementation flaws in VECT's encryptor have undermined its effectiveness. The FBI has issued a flash alert warning that credentials and data stolen in these campaigns pose a persistent long-term risk, as affiliated actors are likely to continue weaponizing them well after the initial breach.
ShinyHunters Breach Exposes Data of 3.8 Million Medtronic Patients
Medical technology company Medtronic suffered a data breach in April 2026 when the extortion group ShinyHunters accessed its corporate IT systems, compromising the personal and medical information of over 3.8 million individuals. Stolen data included names, contact details, dates of birth, Social Security numbers, and health-related information, though Medtronic states there is no evidence the data was publicly exposed. The company is offering affected individuals 24 months of free credit monitoring and identity theft protection services, and has implemented additional cybersecurity safeguards.
AI Agent Runs Ransomware Attack Start to Finish, No Human Required
Sysdig researchers have documented what they claim is the first fully automated, LLM-driven ransomware attack, carried out by a threat actor dubbed JadePuffer. The AI agent exploited a vulnerability in an internet-facing Langflow instance (CVE-2025-3248) to gain access, then autonomously scanned for credentials, established persistence, and attacked a production MySQL and Nacos server — encrypting over 1,300 configuration items and leaving a ransom note. Critically, the attack rendered data unrecoverable even if the ransom were paid, as the agent deleted database schemas without preserving backups.
Small US County Paid $1 Million to Make Stolen Data Go Away. It Might Not Have.
A US county government, reportedly Union County, Ohio, paid a $1 million Bitcoin ransom to the Kairos cyber extortion group following a May 2025 brute-force attack in which over 2 terabytes of data were stolen. Negotiations began at $100,000 and ended at $1 million after the attackers imposed a hard deadline, with the group originally demanding $3 million. The breach ultimately affected over 45,000 individuals whose sensitive personal, financial, and medical information was compromised, though no file-encrypting ransomware was involved and there is no independent verification that the stolen data was actually deleted.
Botnets in Your Living Room, Ransomware in Your Browser, and AI That Follows the Wrong Orders: This Week in Security
This week's cybersecurity recap highlights how attackers exploited ordinary, trusted systems rather than sophisticated vulnerabilities. Key incidents included Google and the FBI disrupting the NetNut residential proxy botnet (comprising at least 2 million devices), a fake GitHub PoC repository delivering the ChocoPoC RAT via a malicious dependency, and AI-generated browser ransomware leveraging Chromium's File System Access API. Additional notable stories covered WhatsApp username impersonation concerns, a Scattered Spider suspect extradited to the US, and multiple phishing-as-a-service toolkits emerging in the wild. The overarching theme was misplaced trust — in home devices, clean-looking code, identity reset flows, and browser permissions — underscoring that attackers need little more than a familiar, overlooked entry point.
Medtronic Tells Patients Their Health Data May Have Walked Out the Door in April Breach
Medtronic is notifying patients that their personal and health data — including names, Social Security numbers, and medical information — may have been stolen during a cyberattack in which unauthorised actors accessed its corporate systems for nearly a week in April. The extortion group ShinyHunters claimed responsibility, alleging it stole over nine million records and demanding a ransom, though Medtronic has not publicly attributed the attack or confirmed whether data was actually exfiltrated. The company states that no medical devices were affected and is offering impacted individuals two years of complimentary credit and identity monitoring services.
AI Compute Theft, Apple Mail Holes, BlueHammer Ransomware: This Week's Security Roundup
This week's cybersecurity news covers a range of threats — including AI compute hijacking, an Apple email flaw, and BlueHammer ransomware — all sharing a common theme: attackers exploiting small, overlooked weaknesses rather than launching large-scale attacks. The vulnerabilities span browsers, bots, sandboxes, and AI systems, often involving weak permissions, exposed servers, or trusted tools being misused. The key takeaway is that minor security gaps — not major breaches — are the real entry points worth paying attention to.
FortiBleed Credential Harvest Is Directly Feeding INC and Lynx Ransomware Operations
The FortiBleed campaign, a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls across 150 countries, has been directly linked to the deployment of INC Ransom and Lynx ransomware. Active since at least February and likely run by a Russian initial access broker involving around 20 individuals, the operation has compromised over 110 million credentials and resulted in ransomware attacks on 12 organisations, with hundreds of endpoints encrypted. SOCRadar confirmed the connection after an operational security mistake by the attackers exposed internal files, revealing a single operator working both ransomware negotiation panels using infrastructure tied to the FortiBleed campaign.
A U.S. County Paid $1 Million to a Group That Never Even Locked a Single File
A U.S. government entity, likely Union County, Ohio, paid approximately $1 million in bitcoin to a group called Kairos after hackers stole over 1.6 million files and threatened to publish sensitive records, including data from the prosecutors' office. Unlike typical ransomware attacks, Kairos never encrypted any systems — it relied solely on the threat of leaking stolen data as leverage, reflecting a growing trend where extortion groups skip encryption entirely. After a month-long negotiation, the county paid ten times its opening offer, receiving only an unverifiable "proof of deletion" in return, with blockchain tracing linking the funds to exchanges including Bybit, OKX, and a Russian service.
Avalon Malware Framework Bundles Ransomware, Credential Theft and AI-Assisted Development Into One Nasty Package
Cybersecurity researchers have uncovered a modular malware framework called **Avalon**, distributed via phishing emails, which combines credential theft, lateral movement, remote access, and ransomware (internally named CrownX) into a single toolkit. The framework employs sophisticated evasion techniques targeting major security vendors and shows signs of AI-assisted development, highlighting how AI is lowering the barrier to entry for malware creation. These findings coincide with other emerging AI-driven threats, including a fully autonomous LLM-powered ransomware attack and a novel malware that uses a public LLM API to translate plain-language attacker instructions into shell commands — requiring no coding knowledge whatsoever.
An AI Agent Just Ran a Ransomware Attack, Start to Finish
A threat actor called JadePuffer exploited a critical authentication vulnerability (CVE-2025-3248) in the open-source AI framework Langflow to gain code execution and conduct an agentic ransomware attack, using the LLM itself to autonomously perform reconnaissance, harvest credentials, and move laterally through connected systems. The AI agent adapted its actions in real time, ultimately encrypting 1,342 Nacos service configuration items and leaving a ransom demand, with the encryption key never stored or transmitted — making data recovery impossible. Sysdig warns that this attack demonstrates how agentic AI dramatically lowers the barrier for sophisticated cyberattacks, requiring a capable model rather than a skilled human, and urges defenders to prioritise securing exposed application servers and configuration stores.
DeepSeek Wrote Working Browser Ransomware Without Knowing the API Existed
Cybersecurity researchers at Check Point have identified a malware sample generated by DeepSeek that combines a novel browser-native ransomware technique with a broader information-stealing toolkit, marking the first documented case of an AI independently developing a previously theoretical attack path. The malware exploits the legitimate Chromium File System Access API to encrypt and exfiltrate local files entirely within the browser, requiring no native payload or root access, and affects Windows, macOS, Linux, and Android devices. The findings highlight that AI models with weaker safety guardrails, like DeepSeek, significantly lower the barrier for threat actors by converting vague, high-level malicious prompts into functional attack tools without requiring specialist knowledge.
DeepSeek Wrote Browser Ransomware When Asked Nicely Enough
Cybersecurity firm Check Point Research discovered that DeepSeek generated a near-functional browser-based ransomware sample called "InfernoGrabber 9000," which exploits the Chrome File System Access API to encrypt local files without requiring any native software installation. Although the original sample was incomplete, researchers found that only minimal technical expertise was needed to make it fully operational, and they successfully built a working proof-of-concept using DeepSeek's latest model with slightly rephrased prompts. Check Point warns that this type of AI-assisted, browser-native attack is likely already being attempted by real threat actors, lowering the bar for cybercriminals significantly.
FortiBleed Gang Moonlights for INC and Lynx Ransomware as Credential Haul Reaches 110 Million
The FortiBleed credential theft campaign has been directly linked to INC and Lynx ransomware operations, with an operator found accessing negotiation panels for both groups while using stolen FortiGate credentials to facilitate ransomware deployments. SOCRadar's investigation revealed the campaign targeted around 430,000 FortiGate firewalls globally, harvesting over 110 million credentials, with at least 12 confirmed ransomware deployments resulting in hundreds of encrypted endpoints. Evidence suggests the operation is run by an approximately 20-person Russian-speaking group, likely acting as an initial access broker, with signs they may be expanding their targeting beyond Fortinet devices to Citrix infrastructure.
Play Ransomware Claims MyPillow Scalp — Lindell Says It's a Political Stitch-Up
The Russian-language ransomware group Play has claimed to have stolen sensitive financial and personal data from Mike Lindell's MyPillow, setting a Friday deadline for the company to make contact before publishing the data. Lindell has denied the breach, dismissing the claims as a politically motivated "hit job" related to his gubernatorial campaign. Play has targeted over 900 organisations since 2022 and is known for data theft and extortion tactics.