Skip to content

Tag: ransomware

Ransomware Extortion at UK Department for Education

Ransomware extortionists claim they accessed data from the UK Department for Education, including customer service contact fields. The government says the risk to individuals is not high and no ransom payments are made.

Focus Keyphrase: Vishing via Microsoft Teams

Attackers used vishing via Microsoft Teams to impersonate IT support staff, trick employees into granting remote access, and then deploy Chaos ransomware. Sophos observed fast intrusions, sometimes within 17 hours.

BitLocker extortion through printers: what changed

Two recent incidents in Latin America show a new extortion pattern: attackers encrypt disks with BitLocker and trigger ransom notes via office printers. The cases also reveal recurring misuse of RDP, MSSQL misconfigurations, and RMM tools.

INC ransomware: SonicWall SMA 1000 vulnerabilities

Resecurity reports that INC ransomware has been claiming victims faster since the beginning of August 2026 via SonicWall SMA 1000. The chain appears to be driven by zero-days that, among other things, abuse MFA seeds and credentials.

SonicWall SMA1000: patched flaws behind ransomware

Two newly reported SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410) have been exploited in ransomware incidents. Security teams urge rapid patching and active threat hunting.