Skip to content

INC Ransom

Ransomware Group8 claimsLast activity:

Overview

INC Ransom is a financially motivated ransomware-as-a-service operation that emerged in mid-2023. A joint advisory from the Australian Cyber Security Centre, CERT Tonga and New Zealand’s NCSC describes a division of labor in which affiliates conduct intrusions and deploy the ransomware, while the core operation maintains extortion infrastructure and handles payments. The group remained active through at least 2025, but public reporting about technical overlap with Lynx and older ransomware families does not by itself establish a common operator or confirmed rebrand.

Activity and targeting

INC Ransom affiliates have compromised organizations in multiple countries since 2023. The joint government advisory says earlier activity concentrated on the United States and United Kingdom and that targeting increased across Australia, New Zealand and Pacific island states from early 2025; it also reports a disproportionate focus on health-care organizations. Trend Micro’s 2024 research likewise found health care prominent in its telemetry and leak-site sample, alongside education, nonprofits, construction, professional services and manufacturing. Leak-site entries represent the actor’s claims and should not be treated as independently verified victim counts.

Methods and operational characteristics

Observed access routes include compromised or purchased credentials, spear-phishing and exploitation of known vulnerabilities in internet-facing systems. In one early incident, Huntress observed an operator using a compromised account and RDP, staging files with 7-Zip, installing MEGASync, accessing credentials and moving laterally before distributing the encryptor with WMIC and PsExec. The government advisory also documents the use of legitimate utilities such as 7-Zip, WinRAR and rclone for staging and exfiltration, underscoring that affiliate tradecraft can vary between intrusions.

INC Ransom uses double extortion: affiliates may steal sensitive data and encrypt systems, after which the operation threatens publication through a Tor-based data-leak site to pressure victims to pay. Trend Micro analyzed Windows and Linux variants and reported capabilities including partial or full file encryption, process termination and attempts to delete shadow copies. Encryption and data theft should still be assessed separately in each incident; an INC Ransom claim does not establish that either occurred.

What type of group is it?

INC Ransom is best characterized as a financially motivated cybercriminal service and affiliate network, not as a single intrusion team with an invariant playbook. That structure means access methods, tooling and target selection may reflect individual affiliates as much as the core operators. The reviewed sources do not publicly identify the people directing the operation, establish their jurisdiction or support state sponsorship.

Incident claims

Westfield Public Schools Cyberattack

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

INC Ransom’s listing for Westfield Public School District showed an update at 2:33 p.m. UTC Sept. 2, 2026, adding a tranche of files the group claimed it stole from the district. Sample documents displayed with the post included employee Form W-2 wage and tax statements. The district has not confirmed the group’s attribution, the authenticity of the files or a data breach.

Lansing Urgent Care network-access incident

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Ransomware.live records an INC Ransom leak-site listing naming Lansing Urgent Care at 6:25 p.m. UTC Aug. 17, 2026. Screenshots attributed to the listing show a 2015 safety data sheet for a third-party skin-care product, one page of a Lansing Urgent Care business-associate agreement and one page of an apparently incomplete employee nondisclosure agreement. The safety sheet contains no visible Lansing Urgent Care identifier, and the other documents are administrative rather than patient or clinical records. The images substantiate that INC displayed material it associated with the provider but do not authenticate the documents, establish that they were private, show how they were obtained or prove access to Lansing Urgent Care’s current network. WILX published the provider’s statement about an outsider’s access attempt and system shutdown about 24 hours after the claim. The timing and exact victim match make the claim likely related, but Lansing Urgent Care has not attributed the event to INC or confirmed ransomware, data theft or encryption.

Acworth cyber incident followed by INC Ransom claim

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

INC Ransom listed the City of Acworth’s official domain July 2, 2026, claimed to have obtained municipal data and threatened release if the city did not make contact. Public reporting said the listing included alleged samples. Acworth has not confirmed the actor, authenticity of the samples, data theft, encryption, a demand, negotiation or payment.

Impacted organizations

Impacted locations

Sources