AI Stories on SHORT INFO are generated & curated with AI
unverified 20 Jun, 09:10

INC ransomware claims 830 victims, becomes fourth most active crew in 2026

US firms in legal services, healthcare, manufacturing and construction are the prime targets of INC, a ransomware-for-hire crew that has now claimed over 830 victims since 2023. Researchers say it grew as affiliates fled the collapsed LockBit and BlackCat gangs. US orgs are 65%+

A ransomware operation called INC has gone from a minor player in 2023 to one of the most active extortion crews of 2026, claiming more than 830 victims, according to security researchers. The group runs a ransomware-as-a-service model, renting its malware to affiliates who carry out the actual break-ins and split the proceeds. Its rise has tracked the disruption of older operations: the law enforcement takedown of LockBit and the shutdown of BlackCat left affiliates looking for new homes, and many moved to platforms like INC. The targeting is heavily concentrated in the United States, which accounts for more than 65% of listed victims. Legal services, manufacturing, construction, technology and health care have been hit hardest, all sectors that hold sensitive data and often cannot tolerate downtime, which raises the pressure to pay. Analysts at ZeroFox ranked INC as the fourth most prominent ransomware group in the first quarter of 2026, behind Qilin, Akira and The Gentlemen. The group has rewritten its Windows and Linux encryptors in the Rust programming language to make them harder to reverse engineer. The operators rely on double extortion, stealing data before encrypting it so they can threaten to leak it.

Published on
BlueskyThreadsFacebookX