#Ransomware

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-21

Anubis ransomware gang claims data breach at Disneyland Paris

The Anubis ransomware gang has claimed responsibility for compromising Disneyland Paris through a partner company breach, allegedly stealing 64GB of sensitive construction data including detailed engineering plans and blueprints for various park attractions.

****
#cybersecurity #infosec #incident #ransomware
beyondmachines.net/event_detai

2025-06-21

New post from #Handala : Zacharia Levi Ltd Hacked
More at : ransomlook.io/group/Handala #Ransomware

2025-06-21

New post from #Inc Ransom : Oak Park & River Forest High School
More at : ransomlook.io/group/Inc%20Rans #Ransomware

2025-06-21

Qilin ransomware now extorts victims by demanding they call lawyers for higher ransom payouts. #ransomware #cybersecurity #Qilin

More details: thehackernews.com/2025/06/qili - flagthis.com/news/17032

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-21

Tonga Ministry of Health paralyzed by ransomware attack

The Kingdom of Tonga's Ministry of Health was hit by a ransomware attack on June 15, 2025, that completely disabled the National Health Information System and potentially compromised the complete medical records of approximately 100,000 residents. The unnamed ransomware group is demanding millions of dollars. All four national hospitals reverted to manual operations. Tonga has requested and receiuved international cybersecurity assistance from Australia.

****
#cybersecurity #infosec #incident #ransomware
beyondmachines.net/event_detai

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-21

Scattered Spider cybercrime group breaches Aflac Insurance

Aflac reported a cybersecurity incident discovered on June 12, 2025. The breach was achieved via social engineering and is potentially linked to the Scattered Spider cybercrime group as part of a broader campaign against the insurance industry. The breach may have compromised sensitive personal information. The company claims they stopped the intrusion within hours and reported no ransomware deployment.

****
#cybersecurity #infosec #incident #ransomware
beyondmachines.net/event_detai

2025-06-21

New post from #Space Bears : Collision & Classics
More at : ransomlook.io/group/Space%20Be #Ransomware

2025-06-21

New post from #Nightspire : Alfa Testing Equipment (Turkey)
More at : ransomlook.io/group/Nightspire #Ransomware

2025-06-21

New post from #Lynx : Levinzon Cpa
More at : ransomlook.io/group/Lynx #Ransomware

2025-06-20

New post from #Inc Ransom : Doradosoftware.Com
More at : ransomlook.io/group/Inc%20Rans #Ransomware

2025-06-20

Just In: 🚨 Anubis ransomware gang claims Disneyland Paris as its latest victim, calling it β€œthe largest data leak in the history of Disneyland Park.”

More: hackread.com/anubis-ransomware

#CyberSecurity #Anubis #Ransomware #CyberAttack #Disneyland #Paris

2025-06-20

BERT RANSOMWARE - THE RAVEN FILE

BERT Ransomware, active since March 2025, has expanded its operations to target both Windows and Linux environments. The group uses phishing for initial access and communicates via the dark web and Sessions for negotiations. Victims span multiple countries, primarily affecting service and manufacturing sectors. The Windows variant employs multiple file extensions and RSA encryption, while the Linux version shares code with Sodinokibi/REvil ransomware. A weaponized PowerShell script is used to disable security features before payload execution. The ransomware's infrastructure is linked to a Russian firm, suggesting potential ties to the region.

Pulse ID: 6855b5c6da6f1326c8888a58
Pulse Link: otx.alienvault.com/pulse/6855b
Pulse Author: AlienVault
Created: 2025-06-20 19:25:58

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #Encryption #InfoSec #Linux #Manufacturing #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #REvil #RansomWare #Russia #Windows #bot #AlienVault

BeyondMachines :verified:beyondmachines1@infosec.exchange
2025-06-20

Feng Chia University hit by NOVA ransomware gang

Feng Chia University targeted by ransomware, says response taken

****
#cybersecurity #infosec #incident #ransomware
beyondmachines.net/event_detai

Π²ΠΎΠ 0Π½Π° :cascadia:cR0w@infosec.exchange
2025-06-20

Disneyland Paris listed by Anubis.

#ransomware

2025-06-20

New post from #Anubis : Disneyland Paris
More at : ransomlook.io/group/Anubis #Ransomware

Dissent Doe :cupofcoffee:PogoWasRight@infosec.exchange
2025-06-20

"The minister disclosed that hackers encrypted the NHIS and demanded payment, assuring MPs 'the hackers won’t damage the information on the NHIS. ' "

That's from the Tonga Ministry of Health commenting on encryption of its national health information system and ransom demand.

talanoaotonga.to/health-minist

There is no explanation of how she knows that the (unnamed) hackers won't damage the information on the system.

The system is currently offline so I can't even email the ministry to ask.

#databreach #ransomware #healthsec #Tonga

Defensorumdefensorum
2025-06-20

Five reasons hackers deploy : Financial gain πŸ’° System disruption πŸ”’ Espionage πŸ•΅οΈ IP theft πŸ“Š Resource hijacking ⚑ Understanding motivations strengthens defense strategies πŸ‘‰ defensorum.com/malware/

Why hackers use malware
Defensorumdefensorum
2025-06-20

πŸ“‹ How to report incidents and ? 🚨 COSTS $12.5B+ ANNUALLY but 88% goes unreported! 😱 Reporting malware incidents helps build collective for everyone. Be part of the solution! πŸ‘‰ defensorum.com/malware/

Malware reporting guide
2025-06-20

New post from #Handala : Kibbutz Almog Hacked
More at : ransomlook.io/group/Handala #Ransomware

2025-06-20

New post from #Handala : Sivim It Hacked
More at : ransomlook.io/group/Handala #Ransomware

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst