Find notable cyber news and cases, enriched with sources, timelines, and signals.

N0n double-extortion ransomware campaign

Campaign
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

The n0n ransomware campaign is actively extorting organizations across financial services, technology, retail, and education, with a Tor leak site already listing over a dozen victims. The operators use double extortion and threaten to encrypt or destroy backups and shadow copies, raising the risk of operational paralysis if targets refuse to pay. Initial access reportedly begins with compromised credentials sourced from third-party infostealer malware, showing a credential-theft-driven intrusion path. The activity has been observed across the US and multiple other countries, indicating broad geographic reach.

Related Happenings

N0n ransomware crew emergence and backup-destruction extortion model

Threat Actor Meta
H score36 First: 24.09.2026 18:00 Last: 24.09.2026 18:00 Sources 1

How related: Named n0n, the emergence of the ransomware crew has been detailed by cybersecurity researchers at CyberXTron.

About this happening: n0n has emerged as a new ransomware crew, increasing extortion pressure by threatening to destroy backups and shadow copies if victims refuse to pay. The group was first s...

Pink new extortion brand within The Com

Threat Actor Meta
H score31 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

About this happening: Pink is an extortion brand linked to UNC6671 and tied in reporting to Cinder as a likely rebrand or continuation of Pink operations. The activity combines IT hel...

Timeline

  1. 24.09.2026 18:00 1 articles · 1h ago

    n0n begins attacks with compromised credentials

    Exploitation Observed

    n0n attacks begin by exploiting compromised credentials sourced from third-party infostealer malware, which are used to gain initial access to corporate networks before privileges are escalated to stage data for extortion.

    Show sources
  2. 24.09.2026 18:00 1 articles · 1h ago

    n0n leak site lists over a dozen victims across multiple countries

    Campaign Scope Update

    By September 22, n0n’s Tor-hosted leak site had published information about over a dozen victims, data stolen in some attacks had already been released after countdown timers reached zero, and claimed victims included organizations in the US, Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg.

    Show sources
  3. 24.09.2026 18:00 2 articles · 1h ago

    CyberXTron warns n0n is an active double-extortion threat

    Initial Disclosure

    CyberXTron described n0n as a newly formed ransomware group and warned organizations to treat it as an active, credible double-extortion threat requiring prompt attention to credential hygiene, access monitoring and backup isolation.

    Show sources