www.infosecurity-magazine.com 24 Sept 2026, 15:00 UTC

Ransomware Group n0n Threatens to Destroy Victims’ Backups

Ransomware Group n0n Threatens to Destroy Victims’ Backups
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
n0n

A newly identified ransomware group called n0n is threatening to encrypt or destroy victims’ backups and shadow copies if they refuse to pay. Cybersecurity researchers at CyberXTron said they first observed the group’s activity on 18 September 2026; by 22 September, its Tor-based leak site had listed information on more than a dozen victims. The group uses double extortion, stealing data before demanding payment, while the backup threats are intended to make recovery difficult or impossible.

Financial services organisations account for 23% of confirmed victims, followed by technology, retail and education at 15% each. Healthcare, defence and professional services organisations have also been targeted. The US is the most frequently claimed location, although victims have also been reported in Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg.

Some countdown timers have expired and stolen data has been published, indicating that at least some victims have refused to pay; the article does not confirm that n0n successfully destroyed those organisations’ backups.

CyberXTron’s analysis says the attacks begin with credentials stolen by third-party infostealer malware. The attackers then escalate privileges, access administrative tools and prepare stolen data for extortion.

The researchers advised treating n0n as an active threat and recommended multi-factor authentication for external access, limiting exposure of VPN, RDP and other remote-access services, applying least-privilege controls, segmenting critical networks and monitoring for suspicious lateral movement or privilege misuse.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline