Ransomware
Ransomware response designed for business continuity and rapid recovery.
$ 0 m
0 s
0 %
Ransomware attacks interrupt operations, halt critical workflows, and force difficult decisions under pressure. Every hour your systems are offline affects revenue, patient care, production schedules, and regulatory compliance. Response speed determines how much damage sticks.
Reduce the risks of ransomware
Managed Detection & Response
Incident Response
Threat Intelligence & Digital Risk Protection
SOC
Red Teaming
Most Active Ransomware Gangs 2026
Akira
The Akira ransomware group was first identified in March 2023. It primarily targets corporate networks across North America, with attacks reported in sectors such as education, finance, insurance, real estate, manufacturing, recreation, and business consulting. Akira uses double extortion tactics, stealing sensitive data before encrypting systems to pressure victims into paying a ransom.
ALPHV/Blackcat
ALPHV, also known as BlackCat, AlphaV, or AlphaVM, is a ransomware-as-a-service (RaaS) operation active since November 2021. It is recognized as the first ransomware group to use the Rust programming language, enabling faster, more adaptable malware. ALPHV is infamous for its triple extortion tactics: encrypting files, exfiltrating sensitive data, and launching DDoS attacks to pressure victims.
Dragonforce
First detected in November 2023, DragonForce is a rapidly emerging ransomware group whose origins remain unverified. Despite being a relatively new player, DragonForce has quickly risen to prominence and is now ranked among the top 20 global ransomware groups in operation. The group is known for launching highly disruptive attacks using double extortion techniques, stealing data before encrypting systems to pressure victims into paying ransoms. DragonForce targets organizations across various sectors, and its activity shows a high level of coordination and technical capability.
Qilin
Qilin, also known as Agenda, is a RaaS group that has targeted organizations across a wide range of sectors worldwide. This cyber threat actor is operated by a user known as “Qilin” on underground cybercriminal forums. The group provides customized ransomware variants to affiliates in return for a share of any ransom payments collected. Qilin’s malware is tailored to specific targets, making its attacks more effective and harder to detect. Active on the global stage, the group has become known for its adaptability and growing list of victims.
Clop
Clop is a sophisticated ransomware group first identified in February 2019, known for targeting large enterprises across multiple sectors worldwide. The group carries out data extortion and ransomware attacks, often exploiting zero-day vulnerabilities to gain access to corporate networks. Clop has been linked to several high-impact campaigns, most notably the MOVEit Transfer attacks, which resulted in the theft of sensitive data and millions in ransom payments. Its technical expertise and aggressive tactics make Clop a significant threat to organizations globally.
Killsec
KillSec began as a hacktivist collective but has since evolved into a RaaS provider, actively supplying customizable ransomware tools to affiliates for cyber extortion. Now operating as a financially motivated threat actor, KillSec has demonstrated its growing capabilities by targeting organizations across a wide range of industries worldwide.
Lockbit
LockBit is one of the most notorious ransomware operations of the modern cybercrime era, evolving from a criminal group into what many viewed as a highly organized underground enterprise. Through its ransomware-as-a-service model, affiliates carried out attacks across the globe while the core operators focused on maintaining the malware, infrastructure and extortion platform. At its height, LockBit was linked to an enormous volume of incidents and was widely regarded as one of the most active and prolific ransomware strains in operation worldwide.
Lynx Ransomware
Lynx Ransomware is a RaaS group first observed in July 2024. Financially motivated, the group uses both single and double extortion tactics, encrypting data and threatening to leak it unless a ransom is paid. On 24 July 2024, Lynx issued a public statement claiming it avoids targeting government institutions, hospitals, and non-profit organizations. Once a system is compromised, the group drops a "readme.txt" file containing a unique ID and a link to its Tor-based portal. Like many RaaS operators, Lynx maintains a data leak site (DLS) to list victims and pressure them into paying.
Medusa
Medusa is a RaaS platform first identified in 2021, operated by a financially motivated cybercriminal group. The threat actors behind Medusa primarily exploit unpatched vulnerabilities to gain access to corporate networks. Once inside, they deploy ransomware to encrypt data and demand payment for its release. Medusa has launched attacks across a wide range of industries, including technology, education, manufacturing, healthcare, and retail, making it a broad and persistent threat.
Play
The Play ransomware group, also known as PlayCrypt, first emerged in June 2022, deploying its own custom ransomware in targeted attacks. Play uses a double extortion model, stealing sensitive data before encrypting files. If victims refuse to pay the ransom, the stolen data is published on the group’s data-leak site to increase pressure. This tactic has made Play a growing concern for organizations worldwide. While initial attacks focused on select industries, Play has since expanded its reach, targeting a broader range of sectors.
Ransomhub
RansomHub is a RaaS group first detected in February 2024, comprising members from across the globe. Known for its structured operations, RansomHub imposes strict rules on its affiliates during attacks; violations can lead to bans from the group. Victim organizations are publicly named on RansomHub’s darknet leak site. The group pledges not to attack targets in CIS countries, Cuba, North Korea, China, and Romania.
SafePay
SafePay is a newly emerged ransomware group first observed in late 2024. It uses a double extortion model, deploying a modified LockBit payload to steal and encrypt sensitive data from critical systems. Once compromised, victims face ransom demands under threat of data exposure. SafePay’s operations involve gaining initial access, conducting post-compromise activity, and moving laterally within networks, often by exploiting vulnerable remote desktop services.
Scattered Spider
Scattered Spider is a financially motivated cybercriminal group that has been active since at least May 2022. Known for its sophisticated extortion and ransomware campaigns, the group has primarily targeted organizations in telecommunications, arts, entertainment, recreation sectors, and, most recently, the retail sector. Scattered Spider is also notable for its focus on compromising software-as-a-service (SaaS) platforms and cloud service provider (CSP) environments to steal sensitive data. The group employs advanced techniques to gain access, move laterally, and exfiltrate valuable information for extortion.
Speak to an expert
Shield your business from ransomware attacks with our managed services. Consult with an expert today to find the best defence solutions tailored to your organization.
Dublin: +353 01 293 4027
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27860 625 673
Johannesburg: +27860 625 673
Find the right solution
I need help with:
- Select
- Ransomware
- Expanding Attack Surface
- Detecting and Responding to Threats
- Securing Cloud Environments
- Securing Endpoints
- Protecting sensitive data
- Defending Identities
- Managing Risk & Compliance
- Securing IoT & OT Environments
- Security Consolidation