logo

INC Ransomware Group Holds Healthcare Hostage in Oceania

ID: b31d2ace-662e-5604-a5d5-f46277839f8d

STIX ID: report--b31d2ace-662e-5604-a5d5-f46277839f8d

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-03-11

Date Updated: 2026-04-21

Author: Nate Nelson

...
...

Authorities in Australia, New Zealand and Tonga warn that the INC ransomware operation has targeted healthcare and professional services across Oceania—ACSC logged 11 Australian incidents between July 2024 and December 2025, INC published stolen data in New Zealand, and a June 2025 attack on Tonga’s Ministry of Health disrupted national health services; INC operates as a RaaS using initial access brokers, spear-phishing, and exploits, performing lateral movement, privilege escalation, encryption and exfiltration of PII/PHI, and responders recommend basic mitigations such as MFA, patching, and network access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.