Breaches · 4h ago
Fortra says the newly seen n0n extortion group went from a mid-September 2026 debut to roughly a dozen named victims on its leak site in days, and the list has kept growing. The group claims data theft along with network shutdowns and backup destruction, but reporting still disagrees on whether to call it ransomware or pure extortion.
The intrusion path is ordinary on purpose: n0n appears to use usernames, passwords, and other credentials already stolen by infostealer malware, then moves through Remote Desktop Protocol (RDP) and other admin tools. That means the activity can look like routine administrator traffic, with no exotic exploit chain on the victim side to patch away.
For organizations that expose remote admin access or reuse credentials, the exposure sits in identity hygiene and admin pathways, not in a specific software flaw. The fast-growing leak site suggests the group is trying to aggregate stolen data for more leverage, whether or not each claim about encryption or backup destruction holds up.
1 source covering this story
n0n Ransomware: What You Need to Know| Fortra
See how the emerging n0n cyber extortion gang operates, its alleged victims, and the steps organizations can take to reduce ransomware risk.
Part of the PlainSec briefing for 2026-10-03