Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
New ransomware gang n0n threatens to destroy backups and has listed more than a dozen victims.
CyberXTron reported a new ransomware group, n0n, first observed on September 18, 2026, whose Tor leak site listed more than a dozen victims by September 22. The group uses double extortion and explicitly threatens to encrypt or destroy backups and shadow copies if victims do not pay. Financial services made up 23% of confirmed victims, with technology, retail, and education at 15% each; the United States is the top target, with claims also in Vietnam, Uzbekistan, Brazil, Sweden, and Luxembourg. Intrusions begin with credentials taken by third-party infostealers, followed by privilege escalation and data staging, and some stolen data has already been released.