Find notable cyber news and cases, enriched with sources, timelines, and signals.

N0n ransomware crew emergence and backup-destruction extortion model

Threat Actor Meta
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

n0n has emerged as a new ransomware crew, increasing extortion pressure by threatening to destroy backups and shadow copies if victims refuse to pay. The group was first seen on September 18 and had already listed over a dozen victims by September 22, showing rapid early activity. Its use of double extortion and credential-based initial access raises the risk of full operational disruption across affected organizations.

Related Happenings

N0n double-extortion ransomware campaign

Campaign
H score35 First: 24.09.2026 18:00 Last: 24.09.2026 18:00 Sources 1

How related: In a blog post published on September 23, researchers said activity by n0n was first spotted on September 18 and by September 22 the group’s Tor-hosted leak site had published information about over a dozen victims.

About this happening: The n0n ransomware campaign is actively extorting organizations across financial services, technology, retail, and education, with a Tor leak site already listing over a...

Timeline

  1. 24.09.2026 03:00 1 articles · 16h ago

    n0n begins ransomware activity using stolen credentials

    Exploitation Observed

    On September 18, n0n activity was first observed as attackers used compromised credentials sourced from third-party infostealer malware to gain initial access to corporate networks and start privilege escalation.

    Show sources
  2. 24.09.2026 03:00 1 articles · 16h ago

    n0n leak site lists more than a dozen victims and releases stolen data

    Victim Impact Update

    By September 22, n0n's Tor-hosted leak site had published information on over a dozen victims, claims spanned targets in the US and in Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg, and some countdown timers had reached zero as stolen data was released.

    Show sources
  3. 24.09.2026 03:00 2 articles · 16h ago

    CyberXTron details n0n's backup-destruction extortion model

    Initial Disclosure

    On September 23, CyberXTron described n0n as a newly formed ransomware group using double extortion, including threats to encrypt or destroy backups and shadow copies, said financial services accounted for 23% of confirmed victims, and urged organizations to prioritize credential hygiene, access monitoring and backup isolation.

    Show sources