INC Ransom — Ransomware Profile
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
GOLD IONIC
IntelFusions coverage (15)
- Leak sites turn on Southeast Asia's listed companies 2026-09-03 · Cyber Incidents
- New crew Storm goes after US clinics, banks and factories 2026-08-25 · Ransomware
- Ransomware claims against Indian firms tripled in a month 2026-08-12 · Cyber Incidents
- Latin America's public bodies keep appearing on leak sites 2026-08-08 · Cyber Incidents
- Ransomware crew claims quantum computing firm Quantinuum 2026-08-01 · Ransomware
- Low-profile crew CMD keeps adding schools to its leak site 2026-08-01 · Ransomware
- Qilin ransomware lists Argentina's army on its leak site 2026-07-25 · Ransomware
- Smaller ransomware brands crowd the leak sites as Blackout debuts 2026-07-20 · Ransomware
- Qilin ransomware sweeps up US churches, schools and small businesses 2026-07-19 · Ransomware
- INC Ransom floods its leak site with Asia-Pacific victims 2026-07-18 · Ransomware
- New ransomware crew Wallstreet claims a US police department and rural hospital 2026-07-05 · Ransomware
- Ransomware crews pile onto US healthcare providers over the July 4 weekend 2026-07-04 · Ransomware
- INC Ransom adds US city governments and eye clinics to leak site 2026-07-04 · Ransomware
- Ransomware gang claims to hit German submarine builder Thyssenkrupp 2026-06-28 · Ransomware
- Newer ransomware crews claim diagnostics maker Hologic and an Australian fire service 2026-06-28 · Ransomware
Tools & malware
- AdFind Network Reconnaissance
- esentutl LOLBin
- INC Ransomware Ransomware
- Megasync Exfiltration Tool
- Meterpreter Post-Exploitation Framework
- Net Network Reconnaissance
- Nltest Network Reconnaissance
- PsExec Remote Execution
- Rclone Exfiltration Tool
- Tor Anonymization Tool
- WinRAR Archiving Tool
Recent claimed victims
- jms building corporation 2026-09-10
- https://mediengruppethiel.de/ 2026-09-09
- Cullotta Bravo Law Group 2026-09-09
- Wellness Partners network(combined revenue) 2026-09-07
- My Global Services Sdn Bhd 2026-09-03
- Specialty Textile Services 2026-09-02
- Asfaltos y Pavimentos S.A. (Asfalpasa) 2026-09-02
- Westfield Public School District 2026-09-02
- Trucka 2026-09-02
- Policlinico Triestino 2026-09-02
- Multiver Ltée 2026-09-02
- Metales Panamericanos 2026-09-02
- Zummo 2026-08-31
- Lichtvision 2026-08-31
- RENO Refractories, Inc. 2026-08-31
- cimbsecurities.com 2026-08-31
- New Century Ophthalmology Group 2026-08-31
- Oilquip Inc 2026-08-29
- wittmann 2026-08-29
- Ruby Seven Studios 2026-08-27
- Rohloff Group 2026-08-27
- BENCIVIL 2026-08-27
- FFKR Architects 2026-08-24
- el-group 2026-08-22
- BANGKOKCABLE 2026-08-19
Vendor research
- GOLD IONIC DEPLOYS INC RANSOMWARE Counter Threat Unit Research Team
- Threat Alert: INC Ransomware Cybereason Security Research Team
- GOLD IONIC DEPLOYS INC RANSOMWARE Secureworks
- Threat Alert: INC Ransomware Cybereason
- SentinelOne. (n.d.). What Is Inc. Ransomware? SentinelOne
- INC Ransom threatens to leak 3TB of NHS Scotland stolen data Bleeping Computer