← ALL ARTICLES
// RANSOMWARE

Ransomware Intelligence

33 articles. Ransomware threat intelligence. Attack analysis, threat actor profiling, and victim impact assessment across MENA, EU, and US.

πŸ‡ΊπŸ‡Έ USA CRITICAL

Los Angeles City Attorney: World Leaks Publishes LAPD Personnel and Internal Affairs Records From a Discovery System With No Password

The Office of the Los Angeles City Attorney became aware on March 20, 2026 that a file-sharing system holding LAPD litigation discovery had been accessed. Two sources told the Los Angeles Times the system was not password-protected, though access was supposed to be restricted to authorized users.

2026-04-10
πŸ‡³πŸ‡± Netherlands HIGH

ChipSoft HiX Ransomware: Vendor Says Data Theft Was Confined to Its Hosted Tier

Ransomware at ChipSoft, whose HiX electronic health record serves 70 to 76 percent of Dutch hospitals, forced 11 hospitals to pull patient portals offline. ChipSoft says only customers on its vendor-hosted HiX 365 tier had data stolen.

2026-04-08
πŸ‡ΊπŸ‡Έ USA CRITICAL

Conduent/SafePay: 25M Americans Exposed in 84-Day Ransomware Dwell - Largest US Government Data Breach

SafePay ransomware operators spent 84 days inside Conduent's network, exfiltrating 8.5TB of data affecting 25M+ Americans across 30+ states.

2025-01-13
πŸ‡¦πŸ‡ͺ THREAT BRIEF HIGH

UAE Foils AI-Powered Ransomware Campaign - 200,000 Attacks/Day Intercepted

UAE Cybersecurity Council announced disruption of coordinated attacks involving AI-powered ransomware targeting national platforms.

2026-02-21
πŸ‡ΊπŸ‡Έ THREAT BRIEF CRITICAL

University of Mississippi Medical Center: 35 Clinics Shut Down 9 Days by Ransomware

Ransomware attack shut down all 35 statewide clinics for 9 days. Mississippi's only Level 1 trauma center. Recovery expected to take weeks to months.

2026-02-19
πŸ‡ΊπŸ‡Έ USA HIGH

Passaic County, NJ: Medusa Ransomware Disables Government Services for 526,000 Residents

Medusa ransomware knocked out Passaic County phone lines and IT systems. $800K ransom demanded. Same group that shut down UMMC's 35 clinics.

2026-03-04
πŸ‡ΈπŸ‡¦ Saudi PDPL CRITICAL

Omrania & Associates: INC Ransom Publishes 4TB of Saudi Critical Infrastructure Drawings

INC Ransom published 4TB from Saudi Arabia's premier architecture firm - 53 years of drawings for PIF Tower, GCC HQ, National Guard facilities.

2026-01-09
πŸ‡ΊπŸ‡Έ THREAT BRIEF CRITICAL

Interlock Ransomware Exploits Cisco FMC Zero-Day (CVE-2026-20131) - CVSS 10.0

Interlock ransomware exploited a Cisco FMC zero-day for 36 days before disclosure. Unauthenticated RCE as root. Also affects Cisco Security Cloud Control.

2026-03-04
πŸ‡ͺπŸ‡Ί THREAT BRIEF HIGH

AkzoNobel: Anubis Ransomware Steals 170GB - Passports, Client Agreements, Financial Records Leaked

Dutch paint giant AkzoNobel confirmed breach of US site. Anubis ransomware exfiltrated 170,000 files including passport scans, financial records.

2026-03-01
πŸ‡¬πŸ‡§ THREAT BRIEF HIGH

Salford City College: DragonForce Exfiltrates 256GB Including Mental Health Records

DragonForce ransomware cartel claims exfiltration of 256.92GB from one of Greater Manchester's largest FE colleges Mar 6, 2026.

2026-03-06
πŸ‡ΈπŸ‡¦ Saudi PDPL CRITICAL

ACWA Power: INC Ransom Exfiltrates 400GB from PIF-Backed Energy Giant

INC Ransom exfiltrated 400GB from Saudi Arabia's largest private energy company - engineering drawings, financial records.

2026-02-01
πŸ‡΄πŸ‡² Oman PDPL HIGH

NAMA Group: Clop Ransomware Targets Oman's Electricity Utility

Cl0p ransomware listed Oman's sole electricity and water utility on its leak site, threatening 4.9M residents' data 76 days before PDPL enforcement.

2025-11-01
πŸ‡¦πŸ‡ͺ UAE PDPL HIGH

American Hospital Dubai: 450M Patient Records Claimed by Gunra Ransomware

Gunra ransomware claimed 450M patient records from American Hospital Dubai including Emirates IDs, credit cards, and fertility data.

2025-06-01
πŸ‡―πŸ‡΄ Jordan MEDIUM

Jordan Kuwait Bank: Everest Ransomware Steals 11.7GB of Employee Data

Everest ransomware exfiltrated 11.7GB from Jordan Kuwait Bank, exposing national IDs, salaries, and employment contracts of 1,003 employees on its dark.

2025-05-01
πŸ‡ΈπŸ‡¦ Saudi PDPL CRITICAL

Al Bawani: DragonForce Ransomware Exfiltrates 7TB Including Defense Documents

DragonForce ransomware exfiltrated 6.96TB from Saudi contractor Al Bawani including airbase plans and defense blueprints. $20M ransom refused.

2025-02-01
πŸ‡ͺπŸ‡¬ Egypt

EgyptAir: FunkSec Ransomware Targets National Carrier

AI-assisted ransomware group FunkSec attacked Egypt's flag carrier EgyptAir, claiming passenger manifests, passport numbers, and employee records.

2024-12-01
πŸ‡ͺπŸ‡¬ Egypt

Egyptian Tax Authority: Money Message Ransomware Attack

Money Message ransomware group targeted Egypt's tax authority in a double-extortion attack, threatening to publish taxpayer financial records.

2024-11-01
πŸ‡΄πŸ‡² Oman PDPL

OQ (Oman Oil Company): Termite Ransomware Attack

Oman's state-owned energy giant OQ, operating across 17 countries, was among the first victims of the newly emerged Termite ransomware using a modified.

2024-11-01
πŸ‡΄πŸ‡² Oman PDPL

Towell Engineering Group: RansomHub Exfiltrates 490GB

RansomHub ransomware exfiltrated 490GB from Omani engineering conglomerate Towell, including employee PII, payroll records, and financial documents.

2024-09-01
πŸ‡¦πŸ‡ͺ UAE PDPL

Dubai Municipality: Daixin Ransomware Exfiltrates Government Data

Daixin ransomware exfiltrated approximately 60-80 GB from Dubai Municipality including Emirates IDs, passport scans, HR records, and land ownership data.

2024-01-01
πŸ‡¦πŸ‡ͺ UAE PDPL

Habib Bank AG Zurich: 2.5TB Stolen by Qilin Ransomware

Qilin ransomware stole 2.5TB from UAE-operating Habib Bank AG Zurich, exposing passport numbers, account balances, KYC documents, and transaction records.

2024-01-01
πŸ‡°πŸ‡Ό Kuwait

Kuwait Ministry of Health: Ransomware Attack Disrupts Healthcare Systems

Ransomware disabled the Sahel EHR system across 16 hospitals and 100+ clinics serving 4.8M residents, forcing Kuwait's healthcare ministry offline.

2024-01-01
πŸ‡΄πŸ‡² Oman PDPL

Special Oilfield Services: Double-Hit by LockBit 3.0 & Meow Ransomware

Omani oilfield services provider SOS was hit by LockBit 3.0 in April 2024 and Meow ransomware four months later, a rare double-hit exposing persistent.

2024-04-01
πŸ‡ΊπŸ‡Έ USA

Change Healthcare: 190M Patient Records Breached in $3.09B Ransomware Attack

ALPHV/BlackCat breached UnitedHealth's payment processor via a Citrix portal without MFA, exfiltrating 6TB covering 190M patients. Total cost reached $3.09B.

2024-02-01
πŸ‡―πŸ‡΄ Jordan

Abdali Hospital: Rhysida Ransomware Targets Jordan's Premier Healthcare Provider

Rhysida ransomware breached Abdali Hospital in Amman, demanding 10 BTC (~$430K) for stolen patient data. Jordan has no comprehensive data protection law.

2023-12-01
πŸ‡ͺπŸ‡¬ Egypt

Fawry: LockBit 3.0 Ransomware Hits Egypt's Largest Payment Platform

LockBit 3.0 attacked Fawry, Egypt's largest digital payment platform serving millions through 250,000+ POS terminals, threatening to publish stolen.

2023-11-01
πŸ‡°πŸ‡Ό Kuwait

Kuwait Ministry of Finance: Rhysida Ransomware Hits Government Systems

Rhysida ransomware hit Kuwait's Ministry of Finance, the fiscal nerve center of one of the Gulf's wealthiest states, disrupting government financial systems.

2023-09-01
πŸ‡¦πŸ‡ͺ UAE PDPL

Wizz Air Abu Dhabi: 22GB Stormous Ransomware Attack

Stormous ransomware stole 22GB from Wizz Air Abu Dhabi including air operator certificates, crew records, flight operations data, and passenger manifests.

2025-03-01
πŸ‡°πŸ‡Ό Kuwait

Kuwait MOCI: LockBit 3.0 Ransomware Targets Commerce Ministry

LockBit 3.0 listed Kuwait's Ministry of Commerce and Industry on its leak site, claiming data covering business registrations, trade licenses.

2023-01-01
πŸ‡°πŸ‡Ό Kuwait

Zain Group: Clop Ransomware Targets Major Gulf Telecom Operator

Cl0p ransomware listed Zain Group, Kuwait's largest telecom serving 50M+ subscribers across seven countries, after exploiting the MOVEit Transfer zero-day.

2025-11-21
πŸ‡ΈπŸ‡¦ Saudi PDPL

GlobeMed Saudi: 201GB Healthcare Ransomware Attack

Ransomware attackers exfiltrated 201GB from GlobeMed Saudi, the kingdom's largest healthcare claims administrator, in a double-extortion attack on patient.

2022-01-01
πŸ‡°πŸ‡Ό Kuwait

Kuwait Airways: LockBit 2.0 Breach Exposes 600K Passenger Records

LockBit 2.0 claimed a breach of Kuwait's national carrier, threatening to publish 600,000 passenger records including identity documents and travel data.

2022-01-01
πŸ‡΄πŸ‡² Oman PDPL

Oman United Insurance: New Year's Day Ransomware Attack

Ransomware encrypted the main server of one of Oman's largest insurers on New Year's Day, demanding 50 BTC (~$360K). Backup systems enabled recovery.

2020-01-01