logo

INC ransomware opsec fail allowed data recovery for 12 US orgs

ID: 47a04331-1f5c-513b-9640-7e3f5771cf4c

STIX ID: report--47a04331-1f5c-513b-9640-7e3f5771cf4c

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cyber Centaurs' forensic investigation into the INC ransomware operation uncovered attacker-controlled Restic backup repositories that retained encrypted exfiltrated data from 12 unrelated U.S. organizations; artifacts including renamed binaries, PowerShell scripts with hardcoded credentials, and other tooling were recovered and used to decrypt and preserve victim data, and the researchers produced YARA/Sigma rules to help detect related activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.