ZeroHour

Search: “startup”

4 stories in the last 30d

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Cisco Talos reports 90 ransomware incidents hit Japanese organizations in H1 2026, led by The Gentlemen, with Qilin using AI for efficiency.

Cisco Talos observed 90 ransomware incidents against Japanese organizations from January to July 2026, up about 4.7% year over year, with manufacturing accounting for 34% of victims. The Gentlemen was the most active group with 14 incidents; its leak-site listings grew from 48 in January to 105 in July. Qilin and SafePay followed with seven incidents each, and Talos notes Qilin is leveraging AI to improve operational efficiency.

Cisco Talos · 1h agoRansomware in the wild

Berlin investigates new data leak after hackers publish stolen login credentials

Berlin investigates a fresh leak after Rhysida hackers published stolen login credentials; the city refuses to pay the ransom demand.

Berlin confirmed hackers published additional stolen data, including login credentials, from a mid-August cyberattack on two city ministries responsible for urban development/housing and transport/climate. The Rhysida ransomware group claimed the breach in late August, saying it stole 5.79 TB of data including contracts, emails, passwords and classified information; Berlin acknowledged an extortion demand but refused to pay. Berlin's data protection regulator said the leak includes personal data on public employees and possibly residents, such as names, addresses, dates of birth and bank information. Germany's BSI separately linked the campaign to the TerminalFix fake-CAPTCHA technique and the LoremIpsumLoader/AxolotLoader malware tied to financially motivated Rhysida-associated hackers, days before Berlin's Sept. 20 election.

The Record · 10d agoRansomware in the wild1

New pro-Ukraine hacker group targets Russian companies with custom ransomware

F6 links new pro-Ukraine ransomware group VantaCore, likely a Thor rebrand, to seven attacks on Russian firms using custom tooling and multimillion-dollar demands.

Russian cybersecurity firm F6 reports that VantaCore, a ransomware group believed to be a rebrand of pro-Ukrainian group Thor, has targeted at least seven Russian organizations with ransom demands reaching millions of dollars, operating as a ransomware-as-a-service operation with a Tor-based victim chat and a leak site. The group uses custom-built tooling including the VantaCore ransomware that encrypts servers and workstations, VantaCoreLoader for distribution, the VantaCoreRAT backdoor, and SnowKiller, which disables antivirus and security software. Initial access relies on poorly secured VPNs and remote-access tools, flaws in internet-facing applications, and credentials stolen from business partners. F6 notes pro-Ukrainian groups increasingly abandoned stock ransomware like LockBit 3 Black and Babuk in 2025-2026 in favor of custom malware.

The Record · 14d agoRansomware

Berlin says it won’t pay ransom after hackers steal government data

Berlin refuses ransom as Rhysida ransomware group claims theft of 5.79 TB of government data ahead of September 20 elections.

The Rhysida ransomware group claimed responsibility for stealing 5.79 TB of data from Berlin's government network, including 46,500 contracts, emails, phone numbers, passwords and classified information, and listed it for auction starting at 30 bitcoin (~$2.3 million). Berlin discovered the breach in mid-August, disconnected two ministries from the state network on August 14, and refused to pay the ransom; authorities have not officially attributed the attack. Data is believed taken between August 7 and 12, and district services such as housing benefit processing were disrupted. Officials said election infrastructure is protected ahead of the September 20 House of Representatives vote, and state IT provider ITDZ Berlin was unaffected.

The Record · 16d agoRansomware