N0n double-extortion ransomware campaign
Campaign
Summary
Hide ▲
Show ▼
The n0n ransomware campaign is actively extorting organizations across financial services, technology, retail, and education, with a Tor leak site already listing over a dozen victims. The operators use double extortion and threaten to encrypt or destroy backups and shadow copies, raising the risk of operational paralysis if targets refuse to pay. Initial access reportedly begins with compromised credentials sourced from third-party infostealer malware, showing a credential-theft-driven intrusion path. The activity has been observed across the US and multiple other countries, indicating broad geographic reach.
Related Happenings
N0n ransomware crew emergence and backup-destruction extortion model
Threat Actor Meta
H score36
First: 24.09.2026 18:00
Last: 24.09.2026 18:00
Sources 1
How related:
Named n0n, the emergence of the ransomware crew has been detailed by cybersecurity researchers at CyberXTron.
About this happening:
n0n has emerged as a new ransomware crew, increasing extortion pressure by threatening to destroy backups and shadow copies if victims refuse to pay. The group was first s...
N0n ransomware crew emergence and backup-destruction extortion model
Threat Actor MetaHow related: Named n0n, the emergence of the ransomware crew has been detailed by cybersecurity researchers at CyberXTron.
About this happening: n0n has emerged as a new ransomware crew, increasing extortion pressure by threatening to destroy backups and shadow copies if victims refuse to pay. The group was first s...
Pink new extortion brand within The Com
Threat Actor Meta
H score31
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
Pink is an extortion brand linked to UNC6671 and tied in reporting to Cinder as a likely rebrand or continuation of Pink operations. The activity combines IT hel...
Pink new extortion brand within The Com
Threat Actor MetaAbout this happening: Pink is an extortion brand linked to UNC6671 and tied in reporting to Cinder as a likely rebrand or continuation of Pink operations. The activity combines IT hel...
Timeline
-
24.09.2026 18:00 1 articles · 1h ago
n0n begins attacks with compromised credentials
Exploitation Observedn0n attacks begin by exploiting compromised credentials sourced from third-party infostealer malware, which are used to gain initial access to corporate networks before privileges are escalated to stage data for extortion.
Show sources
- Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims — www.infosecurity-magazine.com — 24.09.2026 18:00
-
24.09.2026 18:00 1 articles · 1h ago
n0n leak site lists over a dozen victims across multiple countries
Campaign Scope UpdateBy September 22, n0n’s Tor-hosted leak site had published information about over a dozen victims, data stolen in some attacks had already been released after countdown timers reached zero, and claimed victims included organizations in the US, Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg.
Show sources
- Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims — www.infosecurity-magazine.com — 24.09.2026 18:00
-
24.09.2026 18:00 2 articles · 1h ago
CyberXTron warns n0n is an active double-extortion threat
Initial DisclosureCyberXTron described n0n as a newly formed ransomware group and warned organizations to treat it as an active, credible double-extortion threat requiring prompt attention to credential hygiene, access monitoring and backup isolation.
Show sources
- Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims — www.infosecurity-magazine.com — 24.09.2026 18:00
- Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims — www.infosecurity-magazine.com — 24.09.2026 18:00