N0n ransomware crew emergence and backup-destruction extortion model
Threat Actor Meta
Summary
Hide ▲
Show ▼
n0n has emerged as a new ransomware crew, increasing extortion pressure by threatening to destroy backups and shadow copies if victims refuse to pay. The group was first seen on September 18 and had already listed over a dozen victims by September 22, showing rapid early activity. Its use of double extortion and credential-based initial access raises the risk of full operational disruption across affected organizations.
Related Happenings
N0n double-extortion ransomware campaign
Campaign
H score35
First: 24.09.2026 18:00
Last: 24.09.2026 18:00
Sources 1
How related:
In a blog post published on September 23, researchers said activity by n0n was first spotted on September 18 and by September 22 the group’s Tor-hosted leak site had published information about over a dozen victims.
About this happening:
The n0n ransomware campaign is actively extorting organizations across financial services, technology, retail, and education, with a Tor leak site already listing over a...
N0n double-extortion ransomware campaign
CampaignHow related: In a blog post published on September 23, researchers said activity by n0n was first spotted on September 18 and by September 22 the group’s Tor-hosted leak site had published information about over a dozen victims.
About this happening: The n0n ransomware campaign is actively extorting organizations across financial services, technology, retail, and education, with a Tor leak site already listing over a...
Timeline
-
24.09.2026 03:00 1 articles · 16h ago
n0n begins ransomware activity using stolen credentials
Exploitation ObservedOn September 18, n0n activity was first observed as attackers used compromised credentials sourced from third-party infostealer malware to gain initial access to corporate networks and start privilege escalation.
Show sources
- Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims — www.infosecurity-magazine.com — 24.09.2026 18:00
-
24.09.2026 03:00 1 articles · 16h ago
n0n leak site lists more than a dozen victims and releases stolen data
Victim Impact UpdateBy September 22, n0n's Tor-hosted leak site had published information on over a dozen victims, claims spanned targets in the US and in Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg, and some countdown timers had reached zero as stolen data was released.
Show sources
- Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims — www.infosecurity-magazine.com — 24.09.2026 18:00
-
24.09.2026 03:00 2 articles · 16h ago
CyberXTron details n0n's backup-destruction extortion model
Initial DisclosureOn September 23, CyberXTron described n0n as a newly formed ransomware group using double extortion, including threats to encrypt or destroy backups and shadow copies, said financial services accounted for 23% of confirmed victims, and urged organizations to prioritize credential hygiene, access monitoring and backup isolation.
Show sources
- Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims — www.infosecurity-magazine.com — 24.09.2026 18:00
- Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims — www.infosecurity-magazine.com — 24.09.2026 18:00