Index live· 1,284 files · 148 editions
ForensicPost

Search the index

91 results
Try
Results for “Ransomware”Newest first
26-0810
File

Six Agencies Warn Gunra Ransomware Runs on Leaked Conti Source Code

Conti’s leaked source is still producing operations four years on, and this one gets in through patched CVEs.

GunraCVE-2024-55591, CVE-2025-24472MultipleMethod
Sev 4TargetMultiple critical infrastructure sectorsActorGunraUSA
26-0802b
File

Colombia’s Justice Ministry Hit by Ransomware Five Days Before Presidential Handover

Encrypted five days before a change of government, a day after the national CERT warned about ransomware.

UnattributedGovernmentPublic sector
Sev 4TargetMinistry of Justice, ColombiaActorUnattributedColombia
26-0731
File

Conduent Breach Affected More Than 62 Million People, Final Count Shows

The final count on the Conduent intrusion landed above 62 million people — third-largest in US healthcare history, at a processor most of them have never heard of.

SafePayRansomwareHealthcareThird party
Sev 5TargetConduent Business SolutionsActorSafePayUSA
26-0622
File

World Leaks Claims 630GB of Records From Tata Electronics

A claimed 630 GB from a contract manufacturer — mostly documents belonging to customers who were never attacked and may never be notified.

World LeaksRansomwareManufacturingManufacturing
Sev 4TargetTata ElectronicsActorWorld Leaks
26-0612b
File

Thirty Bitcoin, Ten Terabytes, One University

A demand denominated in bitcoin changes value while the victim decides. Neither the price nor the volume is verified.

CMD OrganizationRansomwareEducationEducation
Sev 3TargetMount Royal UniversityActorCMD Organization
26-0607b
File

The School Closed, and so Did Everything Families Had Arranged Around It

Two days closed, summer programmes cancelled. A school that cannot confirm who may collect a child cannot responsibly open.

UnattributedRansomwareEducationEducation
Sev 3TargetEvanston Township High SchoolActorUnattributed
26-0603
File

Ransom Payments Fell 44%, and Claims Rose 40%

Payments down 44%, claims up 40%. An ecosystem earning less per victim has an obvious incentive to increase volume.

MultipleRansomwareFinanceInsurance
Sev 3TargetCyber insurance marketActorMultiple
26-0522
File

Operation Saffron Seizes First VPN, Shared by 25 Ransomware Groups

One anonymity service shared by 25 ransomware groups, watched for three years before seizure. The observation window has victims in it.

MultipleEnforcement actionMultipleEnforcement
Sev 3TargetFirst VPN serviceActorMultiple
26-0513
File

The Attack Was in May and the Claim Arrived in June

A month between attack and claim. Leak-site listings record negotiation failures, not attacks — and that biases everyone’s data.

LockBitRansomwareEducationEducation
Sev 3TargetDelano Public SchoolsActorLockBit
26-0512
File

Eight Terabytes, Claimed, From the Factory Floor of Everything

The group claimed 8 TB and named customers. Nothing beyond the claim is established, and we are not reprinting the customer list.

NitrogenRansomwareManufacturingManufacturing
Sev 4TargetFoxconnActorNitrogen
26-0511
File

A Quarter of the Claims, Half the Money

Ransomware is 28% of claims and 52% of the money. BEC is the most frequent and among the cheapest. They need separate budgets.

MultipleVariousFinanceInsurance
Sev 3TargetCyber insurance claimantsActorMultiple
26-0507
File

West Pharmaceutical Took Global Systems Offline After Intrusion

A global shutdown days after detection. From outside it reads as catastrophe; inside an incident it is often the correct call.

UnattributedRansomwareManufacturingManufacturing
Sev 4TargetWest Pharmaceutical ServicesActorUnattributed
26-0426
File

Healthcare Ransomware Rose 14% in Early 2026, Concentrated on Suppliers

Hospitals flat, their suppliers up ~35%. Hardening one class of victim redistributes attacks rather than preventing them.

MultipleRansomwareHealthcareAnalysis
Sev 4TargetHealthcare sector suppliersActorMultiple
26-0407
File

Signature Healthcare Diverted Ambulances After Systems Taken Offline

Ambulances diverted, chemotherapy infusions cancelled, a fortnight on paper. The affected people experienced it as a phone call.

UnattributedRansomwareHealthcareHealthcare
Sev 4TargetSignature Healthcare (Brockton)ActorUnattributed
26-0330
File

Government Ransomware Rose 65%, and the Target Profile Explains Why

The calculation is not that a city has money. It is that a city has visible pain and a decision-maker accountable to the people feeling it.

MultipleRansomwarePublic sectorAnalysis
Sev 4TargetState and local governmentActorMultiple
26-0310
File

Ransomware Took Foster City Permits, Licences and Utility Billing Offline

Permits, licences, records and billing offline by morning; 911 untouched. The separation that held is the kind budget reviews question.

UnattributedRansomwarePublic sectorPublic sector
Sev 4TargetFoster City, CaliforniaActorUnattributedUSA
26-0304
File

US Healthcare Downtime Costs Around $900,000 per Day

$900,000 a day against demands in the low millions. Printing those two numbers together constructs the attacker’s argument for them.

MultipleRansomwareHealthcareHealthcare
Sev 4TargetUS healthcare providersActorMultipleUSA
26-0301
File

Education Ransomware Closed Schools and Universities Across Several Countries

Education fails closed while other sectors degrade. The fix is not detection — it is an offline copy of the data needed to open safely.

MultipleRansomwareEducationAnalysis
Sev 4TargetEducation institutionsActorMultiple
26-0222
File

DragonForce Claims Attack on Pharmaceutical Manufacturer Kopran

Generic manufacturing runs at high utilisation with no buffer stock. There is nothing in reserve when a plant stops.

DragonForceRansomwareManufacturingPharma
Sev 3TargetKopran LtdActorDragonForce
26-0218
File

Hospital Caribbean Medical Center Attack Affected About 92,000 People

About 92,000 people at a Puerto Rico hospital. Diversion planning assumes somewhere to divert to.

The GentlemenRansomwareHealthcareHealthcare
Sev 3TargetHospital Caribbean Medical CenterActorThe Gentlemen
26-0214
File

UFP Technologies Warned of Billing and Shipment Delays After Attack

A components maker warning of shipment delays. Qualification rules mean a medical supply chain cannot route around a supplier quickly.

Payouts KingRansomwareManufacturingManufacturing
Sev 3TargetUFP TechnologiesActorPayouts King
26-0213
File

Japanese Hotel Chain Ransomware Hit Business Systems but Not Membership Server

Business systems encrypted; the segmented membership server untouched. Our database is mostly a record of controls that failed.

UnattributedRansomwareRetailHospitality
Sev 2TargetWashington Hotel chain (JP)ActorUnattributedJapan
26-0210
File

NetRunner Demanded $100 Million From Nippon Medical School Hospital

A reported $100 million demand against a Japanese teaching hospital, and about 131,700 people. Only one of those numbers means anything.

NetRunnerRansomwareHealthcareHealthcare
Sev 4TargetNippon Medical School Musashi KosugiActorNetRunnerJapan
26-0209
File

BridgePay Ransomware Disrupted Payments for 70,000 Bryan Texas Utilities Customers

No data taken, no notification owed, 70,000 people unable to pay a bill. Availability fails independently of confidentiality.

UnattributedRansomwarePublic sectorThird party
Sev 2TargetBridgePay / Bryan Texas UtilitiesActorUnattributedUSA
26-0131
File

Emergency Dispatch Survived Both Municipal Ransomware Incidents This Quarter

Two cities, two attacks, dispatch survived both. The cost is annual and questioned; the benefit is a disaster that cannot be evidenced.

MultipleRansomwarePublic sectorPublic sector
Sev 3TargetMunicipal emergency systemsActorMultiple
26-0127
File

Sixty Institutions, One Technology Provider

Sixty institutions down through one provider. Pooling technology is what lets small member-owned banks exist, and it concentrates the risk.

UnattributedRansomwareFinanceThird party
Sev 4TargetCredit union technology providerActorUnattributed
26-0126
File

New Britain City Networks Disrupted for More Than Two Days by Ransomware

Two days on manual processes with essential services maintained. The difference between a continuity document and a capability shows in the first hour.

UnattributedRansomwarePublic sectorPublic sector
Sev 3TargetNew Britain, ConnecticutActorUnattributedUnited Kingdom
25-1226
File

Active Ransomware Groups Reached a Record 124 in 2025

Group-based threat intelligence assumes a manageable set of adversaries. The number of groups is approaching the number of incidents.

MultipleRansomware-as-a-serviceMultipleActors
Sev 4TargetRansomware ecosystemActorMultiple
25-1220b
File

Four Properties Combine in Healthcare That Combine Nowhere Else

A hospital carries the operational-technology problem of a utility alongside the data-protection problem of a bank.

MultipleRansomwareHealthcareAnalysis
Sev 4TargetHealthcare sectorActorMultiple
25-1217b
File

Ransomware Encryption Rate Fell to 50% in 2025 From 70%

A shift from the transaction that sometimes works to the one this corpus has never seen work.

MultipleData extortionMultipleAnalysis
Sev 4TargetRansomware victimsActorMultiple
25-1216b
File

47% of Ransomware Attacks Were Halted Before Encryption in 2025, Vendor Research Says

This figure measures the category every disclosure-based count excludes by construction: the attacks that were stopped.

MultipleVariousMultipleAnalysis
Sev 3TargetRansomware defenceActorMultiple
25-1215b
File

Five Operations Accounted for Most Attacks on US Healthcare in 2025

Five names, five sectors, one explanation. A list of five describes the head of a very long distribution.

MultipleRansomware-as-a-serviceHealthcareActors
Sev 4TargetUS healthcare providersActorMultipleUSA
25-1211b
File

Medical Organisations Absorbed 22% of Disclosed Ransomware Attacks in 2025

The visibility explanation this desk applies elsewhere is much weaker here. A leak site names whoever the attacker chose to name.

MultipleRansomwareHealthcareHealthcare
Sev 4TargetMedical organisationsActorMultiple
25-1210b
File

A Fourth 2025 Ransomware Total Puts Publicly Disclosed Attacks at 1,174

The corpus should be as suspicious of numbers that agree for no visible reason as of numbers that disagree.

MultipleVariousMultipleAnalysis
Sev 3TargetRansomware measurementActorMultiple
25-1204
File

Manufacturing Absorbed 56% of Ransomware Activity Across 1,929 Industrial Attacks

Blocking more attempts and losing more data are the same finding. A manufacturer can lose its entire engineering position with no duty to tell anyone.

MultipleVariousManufacturingAnalysis
Sev 3TargetIndustrial sectorActorMultiple
25-1201
File

44% of 2025 Breaches Involved Ransomware and 30% a Third-Party Failure

Around 30% of 2025 breaches originated with a third party. The boundary an organisation defends stopped being the boundary that determines its exposure.

MultipleVariousMultipleAnalysis
Sev 4TargetGlobal breach landscapeActorMultiple
25-1128b
File

Six Sectors, One Operation, One Year

Knowing this operation is active tells a defender nothing, because it is active everywhere. Naming it is naming the weather.

QilinRansomware-as-a-serviceMultipleActors
Sev 4TargetMultiple sectorsActorQilinCanada
25-1127
File

Nevada Published a $1.5 Million Incident Response Bill

The only reliable incident costs in this corpus come from organisations that had no choice but to publish them.

UnattributedRansomwarePublic sectorAnalysis
Sev 3TargetNevada state governmentActorUnattributedUSA
25-1120
File

Automotive Ransomware More Than Doubled, and the Cars Are Next

Corporate IT, a production line, and a connected product you can still reach after sale. Few industries carry all three.

MultipleVariousManufacturingAnalysis
Sev 3TargetAutomotive sectorActorMultiple
25-1116
File

Three Countries Account for Most Latin American Ransomware Victims

Where disclosure is not mandatory, the regional picture is assembled almost entirely from what attackers chose to publish.

MultipleRansomwareMultipleAnalysis
Sev 3TargetLatin American organisationsActorMultipleUSA
25-1109
File

Qilin Led Telecom Ransomware Activity in 2025, Ahead of Akira and Play

An ecosystem-wide long tail alongside sector concentration. Both are true, and it complicates the corpus’s own argument.

QilinRansomware-as-a-serviceTelecomActors
Sev 4TargetTelecommunications sectorActorQilin
25-1108
File

Qilin Named Victims Rose 420% to Lead All Operations in 2025

A fivefold rise is affiliate recruitment, not innovation. Which makes affiliate confidence the scarce asset worth attacking.

QilinRansomware-as-a-serviceMultipleActors
Sev 4TargetRansomware ecosystemActorQilin
25-0925
File

ENISA Confirmed European Airport Disruption as Ransomware Days Later

A regulator saying “this is ransomware, we don’t yet know by whom” on day two serves everybody better than a complete account on day thirty.

UnattributedGovernanceLogisticsMethod
Sev 3TargetCross-border incident classificationActorUnattributed
25-0923c
File

Stopping Research Is a Harm With No Victim to Notify

Real, distributed across people who will never know, and deferred by years. No instrument here can see it.

MultipleRansomwarePharmaAnalysis
Sev 3TargetPharmaceutical researchActorMultiple
25-0922
File

Nevada Systems Stayed Offline for 28 Days Across DMV, Welfare and Payroll

A social services outage means a benefit application does not progress for somebody who applied because they had nothing.

UnattributedRansomwarePublic sectorAvailability
Sev 5TargetNevada state governmentActorUnattributedUSA
25-0921
File

They Refused, and Recovered Ninety per Cent

The variable that predicts the outcome is not the payment decision. It is whether you could recover without them.

UnattributedRansomwarePublic sectorExtortion
Sev 5TargetNevada state governmentActorUnattributedUSA
25-0919
File

Collins Aerospace Ransomware Disrupted Heathrow, Brussels and Berlin

Heathrow, Brussels and Berlin degraded through one supplier none of them was attacked. The 2026 repeat is filed at 26-0406.

UnattributedRansomwareLogisticsAviation
Sev 4TargetCollins Aerospace MUSEActorUnattributed
25-0918
File

US Government Ransomware Incidents Rose 65% in the First Half of 2025

A company can raise prices. A county cannot — more security means visibly less of something a resident can see.

MultipleVariousPublic sectorAnalysis
Sev 4TargetUS public sectorActorMultipleUSA
25-0908
File

LockBit Resurfaced Eighteen Months After Operation Cronos

Removing the largest operator did not reduce the market. It redistributed it into smaller, less trackable operations.

LockBitRansomware-as-a-serviceMultipleActors
Sev 4TargetRansomware ecosystemActorLockBit
25-0824
File

Sixty State Agencies at Once

Sixty agencies at once means something common to all of them fell. Consolidation working as designed, failing all at once.

UnattributedRansomwarePublic sectorPublic sector
Sev 4TargetState of NevadaActorUnattributedUSA
25-0807
File

Pakistan Petroleum Isolated IT Services After Ransomware Intrusion

A corpus assembled from disclosures records failures in detail and successes almost never.

UnattributedRansomwareEnergyEnergy
Sev 2TargetPakistan Petroleum LimitedActorUnattributedPakistan
25-0731
File

Sustained Campaigns Against Energy, Aerospace and Government

A state-linked group running ransomware collapses the distinction the corpus is organised around — and from a defender’s position it is unresolvable in the moment.

Iranian state-linked setsVariousEnergyEspionage
Sev 4TargetGulf energy and governmentActorIranian state-linked sets
25-0728
File

A Seventy-Five Million Dollar Payment, and What It Tells the Market

Payments become known; refusals do not. The observable signal is biased towards paying, and it is the observable signal that sets expectations.

MultipleRansomwareFinanceAnalysis
Sev 4TargetFinancial sectorActorMultiple
25-0722
File

Interlock and Rhysida Worked Healthcare Without the Older Claimed Limits

The published “we don’t hit hospitals” rules were positioning. An operation whose affiliates pick the victims cannot implement a sector exclusion.

MultipleRansomwareHealthcareActors
Sev 4TargetHealthcare sectorActorMultiple
25-0714
File

Ransomware Against Telecoms Rose Fourfold Between 2022 and 2025

A sector whose failure would degrade the response to every other incident in this database.

MultipleRansomwareTelecomTelecom
Sev 4TargetTelecommunications sectorActorMultiple
25-0713
File

Gulf Financial Institutions Reported Ransomware Disruptions Through 2025

The sector best measured in one jurisdiction is thinly recorded in another — a statement about supervisory publication, not about the banks.

MultipleRansomwareFinanceFinance
Sev 3TargetGulf financial institutionsActorMultiple
25-0605
File

Episource Ransomware Exposed Data on 5.4 Million People

5.4 million through a subsidiary of the group that had already produced the largest healthcare breach on record.

UnattributedRansomwareHealthcareThird party
Sev 4TargetEpisourceActorUnattributedUSA
25-0528
File

A Southeast Asian Energy Provider, and a Group Nobody Had Heard Of

An energy provider serving a population had an incident. The public record contains a group name and a month.

NightSpireRansomwareEnergyEnergy
Sev 3TargetSoutheast Asian energy providerActorNightSpire
25-0527
File

Two Leaked Ransomware Operations Disagree on Pricing, Geography and Scale

A second sample that confirmed the first would have been more satisfying and much less informative.

MultipleMultipleMethod
Sev 2TargetNot applicableActorMultiple
25-0525
File

The Leaked LockBit Tier Shows Ransomware-as-a-Service Has an Entry Level

Somebody looked at the population of people who wanted to run ransomware, decided it was larger than the population who could, and built a product for the difference.

LockBitCriminalEconomics
Sev 3TargetNot applicableActorLockBit
25-0520
File

Kettering Health Shut 600 Applications After Attack Affecting 1.7 Million

600 applications withdrawn in a live hospital. Most people guess a few dozen; nobody can say what each one would break.

UnattributedRansomwareHealthcareHealthcare
Sev 4TargetKettering HealthActorUnattributedUSA
25-0515
File

Health IT Vendor Ransomware Exposed Data on 442,000 Patients

One vendor incident becomes many provider notifications on different dates. Anyone counting breaches sees several small ones.

UnattributedRansomwareHealthcareThird party
Sev 3TargetHealth IT vendorActorUnattributed
25-0415
File

When the Delayed Shipment Is a Medical Device

Hospitals reorder against expected supply. A delay of weeks means deferred procedures nobody will ever connect to a supplier’s IT incident.

UnattributedRansomware suspectedManufacturingManufacturing
Sev 2TargetMedical device manufacturerActorUnattributed
25-0412
File

Interlock Held DaVita for 19 Days and Took Records on 2.7 Million People

Nineteen days inside a dialysis provider, 2.7 million records taken, and treatment never stopped. The continuity is the underreported part.

InterlockRansomwareHealthcareHealthcare
Sev 4TargetDaVitaActorInterlockUSA
25-0402
File

Akira, PLAY and RansomHub Absorbed the Disrupted Leader's Affiliates

In a lawful market, removing the dominant supplier reduces volume because capacity is expensive to replace. Here the capacity is software.

MultipleRansomware-as-a-serviceMultipleAnalysis
Sev 4TargetRansomware ecosystemActorMultiple
25-0222
File

A Researcher Named Him. This Desk Will Not

Applying the rule to a ransomware leader is the case that tests whether it is a rule or a preference. If it only holds for sympathetic subjects it is not a rule.

Black BastaCriminalMethod
Sev 2TargetNot applicableActorBlack Basta
25-0210
File

Nearly Three Million, Disclosed the Following Year

Not “nearly three million” — 2,947,264. Healthcare produces exact counts because every affected person must be notified.

UnattributedRansomwareHealthcareHealthcare
Sev 4TargetPIH HealthActorUnattributed
25-0127b
File

Frederick Health Attack Forced Ambulance Diversion and Delayed Care

EMS already records diversion status and transport time. What does not exist is any mechanism connecting it to a cyber incident.

UnattributedRansomwareHealthcareHealthcare
Sev 5TargetFrederick HealthActorUnattributed
25-0127
File

Frederick Health Ransomware Took Data on More Than 934,000 Patients

934,000 patients, a closed laboratory, and an internal emergency posture that already had a name for this.

UnattributedRansomwareHealthcareHealthcare
Sev 4TargetFrederick Health Medical GroupActorUnattributedUSA
24-1008
File

Casio Ransomware Exposed Partner and Employee Data but Not Card Details

Invoice records describe who supplies whom, on what terms — useful to a competitor and to a fraudster.

UnattributedManufacturingManufacturing
Sev 3TargetCasioActorUnattributedJapan
24-0505
File

Wichita Shut Down City Systems After 5 May Ransomware Attack

A resident who needs to pay a water bill has one counterparty and no alternative.

UnattributedGovernmentPublic sector
Sev 3TargetCity of WichitaActorUnattributedUSA
24-0322
File

Panera Bread Ransomware Took Tills and Ordering Down for a Week

A restaurant chain without tills is not a degraded restaurant chain.

UnattributedRetailAvailability
Sev 3TargetPanera BreadActorUnattributedUSA
24-0317
File

Fujitsu Found Malware That Copied Files and Was Not Ransomware

Ransomware has to announce itself. Malware that only copies succeeds by staying unremarkable.

UnattributedTechnologyMethod
Sev 3TargetFujitsuActorUnattributedJapan
24-0221
File

The Change Healthcare Theft and the Ransomware Were a Week Apart

Encryption is the moment the attacker chooses to be seen. It happens after the theft, because the theft is the leverage.

ALPHVValid credentials, no MFAHealthcareDwell
Sev 5TargetChange HealthcareActorALPHVUSA
23-1123
File

Ardent Health Took 30 Hospitals Offline After Thanksgiving Ransomware

Diversion is the rare availability harm that produces a number — in minutes, measured by the ambulance service.

UnattributedHealthcareAvailability
Sev 5TargetArdent Health ServicesActorUnattributedUSA
23-1108
File

ICBC’s US Unit Could Not Clear Treasury Trades After LockBit Attack

Settlement data proposed by USB stick, between two of the largest financial institutions on earth.

LockBitRansomwareFinanceFinance
Sev 5TargetICBC Financial ServicesActorLockBitUSA
23-0923
File

Johnson Controls Put Its Ransomware Response at $27 Million in an SEC Filing

One number was filed with a securities regulator. The other two were published by the people doing the extorting.

Dark AngelsRansomwareManufacturingManufacturing
Sev 4TargetJohnson Controls InternationalActorDark AngelsUSA
23-0616
File

St Margaret's Health Closed, Citing a 2021 Ransomware Attack Among the Causes

The fatal injury was to cash flow, and it took two years to prove fatal.

UnattributedHealthcareAvailability
Sev 5TargetSt Margaret’s HealthActorUnattributedUSA
23-0412
File

Ransomware at One NCR Data Centre Stopped Restaurants Running Their Own Back Office

The unit that matters is not the facility. It is the number of organisations that stop when it does.

ALPHV/BlackCatRansomwareRetailAvailability
Sev 4TargetNCR Aloha customersActorALPHV/BlackCat
23-0407
File

Researchers Found MSI Firmware Signing Keys in Data Leaked After a Ransom Refusal

A signing key burned into shipped hardware cannot be rotated the way a credential can.

Money MessageRansomwareManufacturingSupply chain
Sev 4TargetMicro-Star InternationalActorMoney Message
23-0223
File

Dish Network Customers Spent Days Unable to Reach a Company That Could Not Reach Itself

The mechanism for reaching the company was part of the same incident.

UnattributedRansomwareTelecomAvailability
Sev 4TargetDISH NetworkActorUnattributedUSA
23-0217
File

US Marshals Service Ransomware Reached Investigation Records in a Major Incident

A population the holder cannot notify without defeating the reason it holds the data.

UnattributedGovernmentPublic sector
Sev 4TargetUS Marshals ServiceActorUnattributedUSA
23-0210
File

Dole Halted North American Production After Ransomware

The only instrument anyone had was a shopper noticing an absence.

UnattributedFood and agricultureAvailability
Sev 4TargetDole Food CompanyActorUnattributedUSA
23-0118
File

Yum! Brands Closed 300 UK Restaurants for a Day, Then Found Employee Data Had Gone

The customer headline and the actual victim population were different groups.

UnattributedRansomwareRetailAvailability
Sev 3TargetYum! BrandsActorUnattributedUnited Kingdom
23-0110
File

Royal Mail Could Not Send a Parcel Abroad for Six Weeks After LockBit Attack

No database at the centre of it. A national postal operator simply stopped being able to send a parcel abroad.

LockBitRansomwareLogisticsAvailability
Sev 4TargetRoyal MailActorLockBitUnited Kingdom
22-1220
File

Guardian Ransomware Exposed UK Staff Data and Closed Its London Office for Six Weeks

It held the information, had the means to publish, and every commercial reason not to.

UnattributedPhishing — as reportedMediaAftermath
Sev 3TargetThe GuardianActorUnattributedUnited Kingdom
22-1002
File

CommonSpirit Health Ransomware Forced Paper Records Across More Than 100 Facilities

623,700 had data exposed. The people actually harmed were the ones whose procedure moved.

UnattributedHealthcareAvailability
Sev 5TargetCommonSpirit HealthActorUnattributedUSA
22-0826
File

Montenegro Blamed Russia for August Attack as Cuba Ransomware Claimed It

Two small NATO members, two months apart, two entirely different instruments.

Cuba ransomware (claimed)GovernmentStatecraft
Sev 5TargetGovernment of MontenegroActorCuba ransomware (claimed)Montenegro
22-0525
File

SpiceJet Ransomware Attempt Stranded Passengers and Halted Morning Departures

An attempt that stops a carrier’s morning departures has succeeded at everything but encryption.

UnattributedAviationAvailability
Sev 3TargetSpiceJetActorUnattributedIndia
22-0508
File

A Country Declared a National Emergency Over a Ransomware Attack

Tax collection stopping is fiscal. Customs stopping means the containers do not move.

ContiGovernmentPublic sector
Sev 5TargetGovernment of Costa RicaActorContiCosta Rica
22-0227
File

A Ransomware Group Took a Side, and Its Own Chat Logs Were Published

A backlog, a staffing problem, and trouble encrypting large files. It reads like a company.

ContiAccountability
Sev 2TargetNot applicableActorContiUkraine
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging