INC Ransom: The Cybercriminal Elite That Keeps the World on the Hook

✨ Megiddo

✨ President ✨
Staff member
May 15, 2016
3,760
2,574
1,730
CNN Indonesia has fallen victim to the hacker group INC Ransom. The cybercriminals announced the hack on January 28, adding the media company to the list of attacked companies on their website. The hackers posted a so-called “evidence package” on the darknet, but it was unavailable when trying to view it.

The hackers placed CNN Indonesia between two other victims — educational institutions in the United States. Among them are Broward College, which INC announced was hacked on the same day, and the private school Lake Highland Preparatory School, mentioned the day before.

k1qo39k6hfdxbwmrxipk5olia3d8n0kp.png

[td]List of attacked organizations on the INC Ransom website (Cybernews)[/td]
It is not yet known what data was stolen or encrypted in the attack on CNN Indonesia. There is also no information on the possible ransom amount that the group may have demanded.

INC Ransom is a relatively new but aggressive hacker group, first noticed in July 2023. The group's attacks target large organizations in the US, UK, Australia, as well as in the healthcare, education, and government sectors. One of the most recent high-profile claims was the theft of 4 TB of data from American defense contractor Stark Aerospace, which develops missile systems.

INC Ransom has attacked at least 135 organizations over the past year. Among them:

  • Tri-City Medical Center in California;
  • San Francisco Ballet;
  • San Francisco Sheriff's Department;
  • Leicester City Government in England;
  • Scotland's health system NHS Dumfries and Galloway;
  • Xerox Corporation.
The group uses multi-stage extortion methods, first encrypting the victim’s data, then stealing it and threatening to publish it if demands are not met. Attack methods include phishing campaigns and exploitation of known vulnerabilities. In particular, INC actively exploited the CitrixBleed vulnerability, which has already led to attacks on Change Healthcare, Boeing, ICBC Financial Services and Australian port operator DP World.

CNN Indonesia, part of the CNN Worldwide portfolio, broadcasts in Indonesian 24 hours a day. Since its launch in 2014, the network has become a significant news platform in the country, reaching more than 1.7 million viewers across free and paid services. CNN Worldwide did not provide any comment on the incident at the time of publication.


In May 2024, an attacker using the pseudonym "salfetka" offered the source code of ransomware for Windows and Linux/ESXi for $300,000 on hacker forums. And in September, the Vanilla Tempest hacker group began attacking healthcare organizations in the United States using the INC Ransom ransomware.
 

About us

  • Our community has been around for many years and pride ourselves on offering unbiased, critical discussion among people of all different backgrounds. We are working every day to make sure our community is one of the best.

Quick Navigation

User Menu