๐ข Inside RAMP: What a leaked database reveals about Russiaโs ransomware marketplace
We gained exclusive access to a leaked database, allowing us to analyze 1.7K forum threads, 7.7K registered users & 340K IP records from the notorious cybercrime forum.
bit.ly/4cYUfhH
By: @pabischoff.bsky.social
Posts by Bec Moody
๐ Critical Infrastructure at Risk: 179 ICS Devices Exposed Online
Our scan for internet-facing Modbus devices found:
๐บ179 exposed devices
๐บ๐ธ x57
๐ธ๐ช x22
๐น๐ท x19
๐ x1 device from a national railway network
โก๏ธx2 devices from national power grids
bit.ly/4sq6QPJ
โผ๏ธ Mister Guns ๐บ๐ธ is notifying 21,225 people of a data breach following unauthorized access to its systems in November 2025.
Ransomware gang Securotrop claimed an attack on the Texas gun store at the time, alleging to have stolen 290 GB of data.
bit.ly/4toB5Ho
By: @becmoody.bsky.social
๐ฃ Our March 2026 ransomware roundup is live!
๐บ 780 attacks in total (UP 13% from February)
๐ Attacks on utility companies UP 630%
๐ญ Attacks on manufacturers UP 36%
๐๏ธ Attacks on governments UP 30%
๐ฅ Attacks on healthcare DOWN 15%
bit.ly/4v14NUA
By: @becmoody.bsky.social
โผ๏ธ Humana ๐บ๐ธ is notifying people of a data breach from August 2025. Names, SSNs, medical info & health insurance data affected.
This follows #ransomware gang Clop's exploitation of a zero-day vulnerability in Oracleโs E-Business Suite software.
bit.ly/47lmFzr
By: @pabischoff.bsky.social
๐จ Namibia Airports Company ๐ณ๐ฆ has been added to the data leak site of #ransomware gang INC. 500 GB allegedly stolen.
The government airline confirmed its systems were impacted in an attack on March 6. There was no evidence of a data breach at the time.
bit.ly/4sTL1bJ
By: @pabischoff.bsky.social
โผ๏ธ Insightin Health ๐บ๐ธ is warning 142,000+ people of a September 2025 data breach, which was claimed by #ransomware group Medusa.
Medusa issued the healthcare marketing agency with a $500K ransom demand after allegedly stealing 378 GB of data.
bit.ly/4bCuDph
By: @pabischoff.bsky.social
๐จ The City of Hart, MI ๐บ๐ธ has confirmed it's investigating a Feb '26 cyber attack after #ransomware gang Genesis claimed an attack on the government org this weekend.
Genesis says it's stolen 300 GB of data, giving the city less than 6 days to pay up.
bit.ly/4up9mbc
By: @becmoody.bsky.social
๐ฃ Our February 2026 ransomware roundup is live!
๐ป 685 attacks in total (718 in January)
๐ฅ Attacks on healthcare UP 30%
๐ Attacks on transport companies UP 39%
๐ง๐ท Attacks on Brazilian companies UP 180%
๐บ Qilin continues to dominate (104 attacks)
bit.ly/4rr1xix
By: @becmoody.bsky.social
๐จ The Town of Southold ๐บ๐ธ has been added to the data leak site of #ransomware gang Rhysida. A 10 BTC ransom ($661,400) and a payment deadline of 7 days have been issued.
Southold was hit by an attack that crippled key systems in November 2025.
bit.ly/46wJdwH
By: @pabischoff.bsky.social
โผ๏ธ Insight Hospital & Medical Center in Chicago ๐บ๐ธ is warning patients of a data breach following a cyber attack in Aug '25.
TWO #ransomware gangs have claimed attacks on the healthcare provider.
LockBit - Dec '25 (200 GB)
Termite - Feb '26 (360 GB)
bit.ly/471i9Wv
By: @pabischoff.bsky.social
โผ๏ธ North East Medical Services (NEMS) ๐บ๐ธ is notifying 91,513 patients of an Oct '25 data breach following a cyber attack on its third-party software provider, UnitedLayer.
Ransomware gang RansomHouse claimed the attack on UnitedLayer.
bit.ly/4kIN9QC
By: @becmoody.bsky.social
๐จ Cheyenne and Arapaho Tribes ๐บ๐ธ has been added to the data leak site of #ransomware gang Rhysida with a $700K ransom demand.
The government organization said it suffered an attack in December 2025 which impacted systems but said no data was breached.
bit.ly/4aMzioa
By: @pabischoff.bsky.social
๐จ Ardene ๐จ๐ฆ has been added to the data leak site of #ransomware gang Akira. 58 GB stolen.
This week, the Canadian retailer confirmed a cyber attack had impacted its systems in January. It wasn't aware of any customer data being breached "at this time."
bit.ly/4csrnOY
๐ฃ Our January 2026 ransomware roundup is live!
๐ป 711 attacks in total (8% less than Dec '25)
๐ฐ Attacks on finance companies UP 26%
๐ป Attacks on tech companies UP 12%
๐ฌ๐ง Attacks on UK companies UP 83%
๐บ Qilin continues to dominate (108 attacks)
bit.ly/4r7V78p
By: @becmoody.bsky.social
๐จ Jefferson Blount St. Claire Mental Health Authority ๐บ๐ธ is notifying 30,400+ people of a November 2025 data breach. SSNs & medical info affected.
#Ransomware gang Medsua claimed the attack on the healthcare org with a $200K ransom for 168.6 GB of data.
bit.ly/4rziTdc
By: @pabischoff.bsky.social
๐ข Our 2025 education ransomware roundup is live!
Attacks on the education sector plateaued in 2025 (when compared to 2024), but the number of records involved in these data breaches increased significantly (up to 3.96M from 3.11M).
Read the report here: bit.ly/3ZfacsD
By: @becmoody.bsky.social
๐จ Ransomware gang Lynx has claimed the attack on Lakelands Public Health ๐จ๐ฆ
The Canadian health authority has been dealing with an attack since January 29, 2026. System restoration and data breach investigations are ongoing.
bit.ly/49Z375I
By: @pabischoff.bsky.social
โผ๏ธ Alpine Ear, Nose & Throat, P.L.L.C. ๐บ๐ธ is issuing data breach notifications to 65,648 people following a cyber attack in November 2024. SSNs, medical info & credit card data affected.
#Ransomware gang BianLian claimed the attack.
bit.ly/45NHuTo
By: @pabischoff.bsky.social
โผ๏ธ 30,797 people are confirmed to have been impacted in a data breach on Appalachian Community Federal Credit Union ๐บ๐ธ following a cyber attack in October 2025.
Names, SSNs & financial account info affected.
#Ransomware gang Qilin claimed the attack.
bit.ly/49S2rPg
By: @pabischoff.bsky.social
๐ฃ Worldwide ransomware roundup: 2025 end-of-year report
๐บ 7,419 attacks in total - UP 32% from 2024
๐บ 374 attacks on government entities โ UP 27%
๐บ 444 attacks on healthcare companies โ UP 2%
๐บ 252 attacks on educational institutions โ UP 2%
bit.ly/4ql9DcL
By: @becmoody.bsky.social
โผ๏ธMoney Mart ๐บ๐ธ๐จ๐ฆ is issuing data breach letters to US residents following a cyber attack in November 2025. SSNs affected.
#Ransomware gang Everest claimed the attack and alleged theft of 80K files from the finance company's US and Canadian offices.
bit.ly/3NeWxPw
By: @pabischoff.bsky.social
โผ๏ธ Clackamas Community College ๐บ๐ธ is notifying 33K people of a data breach that leaked SSNs, student records & more.
#Ransomware gang Medusa claimed the attack, demanding $300K to delete 1.2 TB of data.
NB: Clackamas was also hit by LockBit in Jan '24.
bit.ly/4szdeVO
By: @pabischoff.bsky.social
โผ๏ธ Chesapeake Bay Maritime Museum ๐บ๐ธ is notifying 5K+ people of 17-month-old data breach from August 2024. SSNs and financial info affected.
#Ransomware group Helldown claimed the attack at the time, allegedly stealing 65 GB of data.
bit.ly/4qahz0n
By: @pabischoff.bsky.social
โผ๏ธPulse Urgent Care Center ๐บ๐ธ is issuing data breach letters following a cyber attack in March 2025. SSNs & medical info among the data affected.
#Ransomware gang Medusa claimed the attack, issuing a $120K ransom for 60.7 GB of data allegedly stolen.
bit.ly/4qz9Ybb
By: @pabischoff.bsky.social
๐จ Kelsey School Division ๐จ๐ฆ has been added to the data leak site of Ransomware Blog/MedusaLocker. A ransom of $40K is being demanded for the stolen data.
The Canadian school district confirmed a cyber attack had impacted systems on November 13, 2025.
bit.ly/3MYlXAH
By: @pabischoff.bsky.social
๐ข Akira ransomware: stats on attacks, ransoms & data breaches
2025 key findings:
๐บ 683 victims - double 2024's total (272)
๐บ 182 attacks on manufacturers - triple 2024's total (52)
๐บ 32 TB of data stolen
๐บ๐ธ The US accounts for the most attacks (455)
bit.ly/493bMTY
By: @becmoody.bsky.social
๐จ Ransomware gang DragonForce has taken credit for an October cyber attack on the city of La Vergne, Tennessee ๐บ๐ธ It alleges to have stolen 382 GB of data.
The group has given the city a week to pay its ransom before the data is leaked.
bit.ly/4rL0mM5
By: @pabischoff.bsky.social
๐ข Our #ransomware roundup for November 2025 is live!
๐ป 659 attacks in total (DOWN 5% from October)
๐ป Attacks on healthcare (DOWN 44%)
๐บ Attacks on manufacturers (UP 35%)
๐บ Attacks on education (UP 24%)
๐บ Top strain - Qilin (107 attacks)
bit.ly/446vpI6
By: @becmoody.bsky.social
๐จ #Ransomware gang Devman is demanding $400K for 500 GB of data from the Georgia Superior Court Clerksโ Cooperative Authority ๐บ๐ธ
GSCCCA's systems are currently down while it deals with a "credible and ongoing cybersecurity threat."
bit.ly/4pOP87F
By: @pabischoff.bsky.social