New n0n Ransomware Gang Threatens to Destroy Victims' Backups
Cybersecurity researchers at CyberXTron have detailed a new ransomware group called n0n, first spotted on September 18, whose Tor leak site listed over a dozen victims by September 22. Beyond stealing data, the gang explicitly threatens to encrypt or destroy backups and shadow copies to pressure victims into paying.
- Financial services accounts for 23% of n0n victims; tech, retail and education 15% each
- Attacks begin with credentials stolen by third-party infostealer malware
- Countdown timers for some victims have hit zero and stolen data was released
- CyberXTron urges MFA, backup isolation and least-privilege access controls
Read next
Security