logo

INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

ID: c490a8c9-239e-58fa-b20e-49f458f44bc4

STIX ID: report--c490a8c9-239e-58fa-b20e-49f458f44bc4

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2026-03-06

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

The ACSC advisory profiles INC Ransom, a Ransomware-as-a-Service operation whose affiliate model has enabled large-scale ransomware and data-extortion campaigns targeting healthcare and other critical sectors worldwide; affiliates exploit known, unpatched vulnerabilities (several CVEs cited), perform privilege escalation and lateral movement, exfiltrate data (published to a leak site), and apply double-extortion tactics, with recommendations to prioritize patching, phishing-resistant MFA, network segmentation, and monitoring of administrative tool usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.