US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks

US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks

A 36-year-old Yemeni national, who is believed to be the developer and primary operator of ‘Black Kingdom’ ransomware, has been indicted by the United States for conducting 1,500 attacks on Microsoft Exchange servers. The suspect, Rami Khaled Ahmed, is accused of deploying the Black Kingdom malware on roughly 1,500 computers in the United States and abroad, … Read more

Ukrainian extradited to US for Nefilim ransomware attacks

Ukrainian extradited to US for Nefilim ransomware attacks

A Ukrainian national has been extradited from Spain to the United States to face charges over allegedly conducting Nefilim ransomware attacks against companies. The suspect, Artem Aleksandrovych Stryzhak, 35, was arrested in Spain in June 2024 and extradited to the U.S. on April 30, 2025. According to the U.S. Department of Justice, Stryzhak allegedly participated … Read more

Marks & Spencer breach linked to Scattered Spider ransomware attack

Marks & Spencer breach linked to Scattered Spider ransomware attack

Ongoing outages at British retail giant Marks & Spencer are caused by a ransomware attack believed to be conducted by a hacking collective known as “Scattered Spider” BleepingComputer has learned from multiple sources. Marks & Spencer (M&S) is a British multinational retailer that employs 64,000 employees and sells various products, including clothing, food, and home goods … Read more

Hitachi Vantara takes servers offline after Akira ransomware attack

Hitachi Vantara takes servers offline after Akira ransomware attack

Hitachi Vantara, a subsidiary of Japanese multinational conglomerate Hitachi, was forced to take servers offline over the weekend to contain an Akira ransomware attack. The company provides data storage, infrastructure systems, cloud management, and ransomware recovery services to government entities and some of the world’s biggest brands, including BMW, Telefónica, T-Mobile, and China Telecom. In … Read more

DragonForce expands ransomware model with white-label branding scheme

DragonForce expands ransomware model with white-label branding scheme

The ransomware scene is re-organizing, with one gang known as DragonForce working to gather other operations under a cartel-like structure. DragonForce is now incentivizing ransomware actors with a distributed affiliate branding model, providing other ransomware-as-a-service (RaaS) operations a means to carry out their business without dealing with infrastructure maintenance cost and effort. A group’s representative … Read more

Interlock ransomware claims DaVita attack, leaks stolen data

Interlock ransomware claims DaVita attack, leaks stolen data

The Interlock ransomware gang has claimed the cyberattack on DaVita kidney dialysis firm and leaked data allegedly stolen from the organization. DaVita is a Fortune 500 kidney care provider with more than 2,600 U.S. dialysis centers, 76,000 employees in 12 countries, and an annual revenue exceeding $12.8 billion. The healthcare company disclosed to the U.S. … Read more

Ransomware Targeting Personal Devices | by Eina Schroeder | Apr, 2025

Ransomware Targeting Personal Devices | by Eina Schroeder | Apr, 2025

CYBERSECURITY How to Protect Yourself in 2025 and Beyond In today’s over and ever hyper-connected world, our personal devices have become extensions of ourselves — storing our memories, managing our finances, and connecting us to loved ones. Behind all the goodness this digital intimacy brings, it also comes with a dark side: the rising threat … Read more

Interlock ransomware gang pushes fake IT tools in ClickFix attacks

Interlock ransomware gang pushes fake IT tools in ClickFix attacks

The Interlock ransomware gang now uses ClickFix attacks that impersonate IT tools to breach corporate networks and deploy file-encrypting malware on devices. ClickFix is a social engineering tactic where victims are tricked into executing dangerous PowerShell commands on their systems to supposedly fix an error or verify themselves, resulting in the installation of malware. Though this … Read more

Ahold Delhaize confirms data theft after INC ransomware claims attack

Ahold Delhaize confirms data theft after INC ransomware claims attack

Food retail giant Ahold Delhaize confirms that data was stolen from its U.S. business systems during a November 2024 cyberattack. “Based on our investigation to date, certain files were taken from some of our internal U.S. business systems,” a spokesperson confirmed to BleepingComputer. “Since the incident was detected, our teams have been working diligently to determine … Read more

Kidney dialysis firm DaVita hit by weekend ransomware attack

Kidney dialysis firm DaVita hit by weekend ransomware attack

Kidney dialysis firm DaVita disclosed Monday it suffered a weekend ransomware attack that encrypted parts of its network and impacted some of its operations. DaVita is a major provider of kidney care services in the United States, operating over 2,600 outpatient treatment centers that provide dialysis to those suffering from kidney disease. It is a … Read more