Data Breaches · Ransomware

n0n Scales Extortion Through Stolen Logins

Fortra says the newly seen n0n extortion group went from a mid-September 2026 debut to roughly a dozen named victims on its leak site in days, and the list has kept growing. The group claims data theft along with network shutdowns and backup destruction, but reporting still disagrees on whether to call it ransomware or pure extortion.

The intrusion path is ordinary on purpose: n0n appears to use usernames, passwords, and other credentials already stolen by infostealer malware, then moves through Remote Desktop Protocol (RDP) and other admin tools. That means the activity can look like routine administrator traffic, with no exotic exploit chain on the victim side to patch away.

For organizations that expose remote admin access or reuse credentials, the exposure sits in identity hygiene and admin pathways, not in a specific software flaw. The fast-growing leak site suggests the group is trying to aggregate stolen data for more leverage, whether or not each claim about encryption or backup destruction holds up.

1 source · 5h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-03

Every edition of this story: n0n Scales Extortion Through Stolen Logins