Wednesday, June 17, 2026

EdTech Ransomware: Why Schools Pay $2.28M Per Attack

AI Shield Daily is on NewsLens
Read all 22 AI channels in one free app
student laptop computer classroom - macbook pro on brown wooden table

Photo by Thomas Park on Unsplash

Key Takeaways
  • ShinyHunters breached Instructure Canvas in May 2026 — their second attack on the platform in eight months — exposing data tied to 30 million users across 9,000 schools.
  • As of June 17, 2026, the average ransomware recovery cost for K-12 schools stands at $2.28 million (2024 data), the highest of any targeted sector, with each day of downtime burning approximately $550,000.
  • Globally, 251 ransomware attacks struck educational institutions in 2025, exposing 3.9 million records — a 27% jump over 2024's 3.1 million, per Emsisoft.
  • The 2025 elimination of federal K-12 cybersecurity support programs has left financially constrained districts without the defensive infrastructure needed to counter AI-assisted phishing, which now shapes 82.6% of analyzed phishing emails.

The Threat: ShinyHunters, PowerSchool, and a Sector Under Siege

$2.28 million. That is what the average K-12 school district spent recovering from a single ransomware incident in 2024 — the highest recovery cost of any targeted sector that year. And the threat actors responsible are not slowing down.

As of June 17, 2026, Resecurity published a detailed threat briefing documenting an accelerating pattern across the EdTech landscape. Google News reported on the Resecurity analysis, and the data deserves careful examination rather than headline skimming.

The immediate flashpoint is Instructure Canvas. In May 2026, the ShinyHunters extortion gang — a financially motivated threat actor with a documented history of large-scale credential theft and double extortion — compromised Canvas for the second time in eight months. The platform serves 9,000 schools and roughly 30 million users. ShinyHunters didn't develop a novel exploit for the second breach. They walked back through a door the vendor hadn't properly secured after the first incident. That's not an attacker ingenuity problem. That's a vendor accountability and patch-management failure.

Before Canvas, there was PowerSchool. In December 2024 — publicly disclosed in January 2025 — a breach of the PowerSchool student information system exposed the personal records of 62,488,628 students and 9,506,624 teachers, making it the largest single breach of American children's personal information on record. Names, addresses, Social Security numbers, and in some cases health data. The blast radius (the full population directly harmed by a single exploit) wasn't measured in thousands. It was measured in tens of millions.

Blast Radius — Who Should Actually Care

If your organization touches EdTech in any capacity — school IT administrator, district superintendent, SaaS vendor selling into K-12, or a managed service provider serving education clients — this threat posture belongs to you.

Emsisoft's 2025 State of Ransomware report documented 251 ransomware attacks against educational institutions worldwide, with 3.9 million records exposed — a 27% increase over 2024's 3.1 million. The United States alone recorded 130 of those attacks, the highest count of any country globally, even as that figure represented a 9% year-over-year decline. A 9% decline in attack volume sounds encouraging until you note that the sector absorbed more record exposure than the prior year. Volume down, damage up.

Education Sector: Records Exposed in Ransomware AttacksRecords (millions)3.1M3.9M20242025Source: Emsisoft 2025 State of Ransomware Report

Chart: Global education sector records exposed in ransomware attacks — 3.1 million in 2024 versus 3.9 million in 2025, a 27% year-over-year increase. Source: Emsisoft.

The UK's 2025/2026 Cyber Security Breaches Survey reinforces that this isn't a US-specific crisis. Significant attacks struck 72% of primary schools, 67% of secondary schools, 90% of further education institutions, and 73% of higher education institutions across the UK. The attack surface is the entire sector, across jurisdictions.

The economics explain the persistence. Average ransom demands against education reached $556,000 in the first half of 2025, with ransomware attacks against the sector rising 23% year-over-year during that period. Emsisoft logged more than 8,000 claimed victims on extortion sites globally in 2025 — a 50% increase compared to 2023. When institutions refuse to pay, operational downtime costs can far exceed the initial demand: $550,000 per day for K-12 districts. The average data breach cost for the education sector reached $3.80 million in 2025, and cumulative sector-wide downtime losses from 2018 through 2023 totaled $53 billion.

Compounding all of this: the 2025 elimination of the Office of Educational Technology and federal K-12 cybersecurity support programs. Education cybersecurity experts warned that "financially strapped schools could be increasingly vulnerable to cyberattacks without crucial federal supports." That warning has been validated repeatedly since.

school server rack data center - a close up of a bunch of wires in a rack

Photo by imgix on Unsplash

Why AI-Powered Phishing Is Closing the Last Gap Schools Had

There was always one compensating control that chronically underfunded districts could lean on: human judgment. Train staff to recognize phishing emails, and you offset the absence of enterprise-grade tooling. AI has systematically dismantled that argument.

As of June 17, 2026, threat intelligence data shows that 82.6% of analyzed phishing emails incorporate some degree of AI-generated content. Cisco Talos' Q1 2026 Incident Response Trends report found that "more than a third of compromises (35%) investigated last quarter started as successful phishing attacks" — and those weren't crude, typo-laden messages. They were hyper-personalized, contextually accurate, and built from data scraped from social media profiles, staff directories, and organizational hierarchies. Fifty percent of security professionals now cite AI-driven phishing as their primary threat vector.

Meanwhile, 66% of universities lack properly configured email authentication (DMARC, DKIM, and SPF — the trio of technical controls that prevent attackers from spoofing your domain to send malicious messages that appear to originate from your own staff). Emsisoft's Q1 2026 analysis noted that ransomware "remained stable in volume but grew more dangerous in nature, as financially motivated attacks increasingly intersected with geopolitical conflict and disruptive intent." The threat actor landscape now includes criminal extortion gangs operating alongside state-adjacent disruptors — and education institutions end up in the cross-fire of both.

This convergence of AI-powered offense and depleted institutional defenses is precisely why enterprise-grade data protection frameworks matter even outside the corporate sector. As Cohesity Maestro MCP recently illustrated for enterprise environments, AI-integrated data protection can close detection gaps that legacy tools miss — but those solutions require budget, vendor relationships, and implementation capacity that most K-12 IT teams simply cannot access.

The Defense Stack That Actually Works Here

The attack vectors targeting EdTech in 2026 are well-understood. ShinyHunters is not deploying zero-day exploits (security flaws with no available patch). The PowerSchool breach traced to stolen credentials, not novel malware. Canvas was compromised through inadequate post-incident hardening. Phishing is phishing. The vectors are known. The compensating controls exist.

Three layers that work in concert:

Technical controls: Email authentication enforced at the policy level (DMARC set to p=reject, not monitor-only), multi-factor authentication on all administrative accounts and third-party vendor portal access, and network segmentation that prevents a compromised student-facing system from reaching financial or HR infrastructure. CISA has proposed requiring school districts with 1,000 or more students to report disruptive cyber incidents within 72 hours and ransom payments within 24 hours — those reporting obligations implicitly push institutions toward having the monitoring infrastructure needed to detect incidents before days have passed.

Process controls: Vendor security reviews tied to contract renewals and breach events. Canvas was compromised twice in eight months. A district's vendor management process should have triggered a mandatory security posture review — and ideally a contractual clause requiring documented remediation evidence — after the first incident. Third-party EdTech platforms hold more sensitive student data than most procurement teams realize, and the security posture of those vendors is part of the district's own attack surface.

People controls: Security awareness training remains necessary as a last-resort backstop, but it cannot function as a primary layer when 82.6% of phishing emails are AI-assisted. Staff need to understand that a message can look and sound exactly right and still be a credential-harvesting attempt. The goal of awareness training at this point isn't to make staff the first line of defense — it's to ensure they know to escalate suspicion rather than act independently.

Harden This Today

Ship this one control today: audit your domain's DMARC policy and set it to enforcement mode (p=reject or p=quarantine), not monitor-only.

Here's why this is the single highest-leverage action available to most school IT teams: 66% of universities — and a comparable share of K-12 districts — haven't done this. Implementation requires DNS access and roughly thirty minutes with a configuration guide. It immediately removes your domain as a spoofable vector, meaning threat actors can no longer send phishing emails that appear to originate from your superintendent, principal, or IT helpdesk. No budget approval required. No vendor contract. No consultant engagement.

Everything else on the data protection checklist matters — MFA enforcement, incident response planning, vendor security reviews, CISA's free vulnerability scanning for K-12 districts — but none of those controls close a gap as large as misconfigured email authentication, for as little effort, as immediately.

In my analysis, the EdTech sector's cybersecurity crisis is not fundamentally a technology problem. It's a resource allocation and accountability problem. When the same extortion gang breaches the same platform twice in eight months, and when federal support infrastructure has been dismantled, the math doesn't favor defenders relying on underfunded IT operations alone. The controls exist. The gap is in the sustained political and institutional will to deploy them consistently across thousands of under-resourced districts. Until that structural gap closes, threat actors will continue finding education to be the most cost-effective sector to target at scale.

Frequently Asked Questions

Why are schools and EdTech platforms targeted by ransomware more than other sectors?

Educational institutions collect vast repositories of sensitive data — student Social Security numbers, health records, family financial information, and login credentials — while historically spending far less on security than sectors like finance or healthcare. This high data value combined with low security maturity creates an attractive risk-reward ratio for threat actors. The 2025 elimination of federal K-12 cybersecurity support programs deepened this vulnerability gap, leaving many districts without the resources to implement basic controls like multi-factor authentication, proper email authentication, or incident response planning.

What is the actual total cost of a ransomware attack on a school district beyond the ransom demand?

As of 2024 data, the average ransomware recovery cost for K-12 schools reached $2.28 million — significantly higher than the average ransom demand of $556,000 seen in H1 2025. The gap is explained by additional costs: IT forensics and investigation, system restoration and data recovery, regulatory breach notifications, legal fees, substitute services during downtime, and reputational remediation. Each day of operational downtime costs approximately $550,000 for K-12 districts. In 2025, the average total data breach cost for the education sector rose to $3.80 million.

How can school districts protect against AI-powered phishing attacks on a limited cybersecurity budget?

The highest-leverage, lowest-cost control is enforcing email authentication: configure DMARC, DKIM, and SPF on your domain and set DMARC to p=reject. This prevents domain spoofing and requires only DNS access to implement. Beyond that, CISA provides free cybersecurity resources for K-12 institutions including vulnerability scanning, incident response guidance, and the K-12 Cybersecurity Resource Center. Mandatory multi-factor authentication on all administrator and vendor portal accounts closes the credential-stuffing vector responsible for the PowerSchool breach. Neither control requires significant budget — both require administrative commitment to follow through.

Disclaimer: This article is editorial commentary based on publicly available threat intelligence and news reporting. It does not constitute professional security consulting advice. Always consult with a qualified cybersecurity professional for your specific organizational needs. Research based on publicly available sources current as of June 17, 2026.

Tuesday, June 16, 2026

University Data Breach: The ShinyHunters Education Attack

AI Shield Daily is on NewsLens
Read all 22 AI channels in one free app
cybersecurity breach alert on computer screen - Code is displayed on a computer screen.

Photo by Rob Wingate on Unsplash

40 gigabytes of stolen records, published online before most administrators had finished their morning coffee. When ShinyHunters compromised the University of Nottingham's Oracle WebLogic infrastructure on June 9, 2026, the group didn't just expose one institution — it sent a threat bulletin to every college, university, and school district running legacy middleware with under-resourced security teams. As of June 16, 2026, Ghana's Cyber Security Authority (CSA) formalized that message into a sector-wide warning, with Modern Ghana first reporting the official CSA statement calling the incident "a stark reminder that no educational institution, regardless of its size, reputation or technological advancement, is immune to cyber threats."

The Threat: Actor, Vector, and What's Now Exposed

ShinyHunters is a financially motivated threat actor group known for "pay or leak" double-extortion tactics — compromise the target, exfiltrate data, demand ransom, and publish regardless of payment. The group previously struck Harvard University, the University of Pennsylvania, and Princeton in November 2025, leaking 1.2 million lines of data. Their May 2026 breach of Canvas parent company Instructure became the largest educational security breach on record, affecting 8,809 institutions worldwide and compromising approximately 275 million users across 3.65 terabytes of stolen data.

The Nottingham attack vector was specific: an external threat actor exploited a vulnerability in Oracle WebLogic — a Java-based application server widely used for enterprise web services — supporting the institution's Campus Solutions platform. The result was 455,000 unique email addresses exposed, along with names, physical addresses, phone numbers, passport numbers, student ID numbers, financial data, academic enrollment information, ethnicity, and disability status, spanning the institution's UK, Malaysia, and China campuses. Over 40GB of that data was subsequently published online. The UK's Information Commissioner's Office has been notified for regulatory investigation.

The attack was identified on June 9, 2026. The CSA sector-wide advisory followed on June 16, 2026. That seven-day gap between identification and warning illustrates the pace at which threat actors move — and the lag institutions face in translating one breach into actual defensive posture changes at peer organizations.

Blast Radius — Who Should Actually Care

The direct blast radius is clear: students and alumni from Nottingham's three campuses face elevated phishing, identity fraud, and credential-stuffing (automated login attacks using stolen username and password combinations) risk for years. Passport numbers and financial data do not expire with a semester.

The secondary blast radius is the one the CSA is right to emphasize. As of Q2 2025, educational institutions globally face an average of 4,388 cyberattacks per organization weekly, making education the most targeted sector by attack volume. In the UK specifically, 88% of further education colleges experienced cyber breaches in the 2025/2026 reporting period — a 3% increase from the prior year. Between April 2023 and April 2024, educational organizations sustained 217 ransomware attacks, a year-over-year increase of more than 35%.

Education Sector Cyber Threat Snapshot (2025–2026)88%UK FE CollegesBreached (2025/26)+35%Ransomware YoYIncrease (Apr 23–24)$10.22MAvg U.S. EducationBreach Cost

Chart: Three key metrics illustrating the education sector's cybersecurity exposure. Sources: UK NCSC 2025/26 survey; Comparitech ransomware tracker; IBM Cost of a Data Breach Report.

For institutions in Ghana, the CSA's June 16, 2026 statement also explicitly invoked the Directive for the Protection of Critical Information Infrastructure, launched October 1, 2021, which designated 189 institutions across 13 sectors — including health, telecommunications, and transportation — as requiring mandated protection. From January 2023, all designated Critical Information Infrastructure Owners in Ghana are required to undergo mandatory compliance checks and audits. The CSA noted that "although the breach occurred outside Ghana, it has important lessons for the country's education sector." The average U.S. data breach in education now costs a record $10.22 million, and the sector is one of few industries seeing year-over-year cost increases — making the compliance conversation a financial one, not just a regulatory checkbox.

Why the Defense Stack Keeps Failing Education

The Oracle WebLogic exploitation at Nottingham is not exotic. WebLogic carries a documented history of critical remote code execution vulnerabilities — flaws in the CVE catalog that organizations running unpatched instances remain exposed to for months or years. The pattern here is not a sophisticated zero-day (a security flaw with no available patch yet) but rather a known vulnerability class exploited against an institution that could not patch quickly enough. That is the education sector's structural problem in three lines: valuable data, under-resourced IT teams, and application stacks that took years to procure and cannot be patched over a weekend.

The AI threat dimension compounds this. According to the World Economic Forum, as of 2026, 94% of organizations identify AI as the biggest cybersecurity force shaping the year. ShinyHunters and peer threat actors are increasingly using AI-assisted reconnaissance — automated scanning and profiling of targets — to identify unpatched middleware faster than defenders can cycle through patch queues. AI-powered phishing campaigns now generate contextually convincing lures using data harvested from prior breaches. The Nottingham dataset, with its ethnicity, disability, and enrollment fields, is precisely the kind of contextual richness that enables targeted social engineering at scale.

Defensive AI is available. Modern threat detection platforms use behavioral anomaly detection — AI that flags unusual data access patterns before exfiltration completes — and can compress mean time to detection from weeks to hours. But most educational institutions lack both the budget and the security personnel to deploy and tune these tools effectively. Ghana's CSA recognized this capability gap, organizing capacity-building workshops for Vice-Chancellors in partnership with the Shadowserver Foundation and FIRST in March 2026. That senior-leadership engagement is the correct lever: security culture does not change at the firewall level — it changes in the budget meeting. Bleeping Computer's coverage of the Nottingham breach and Instructure's Canvas compromise traced the same institutional gap between ShinyHunters' operational speed and defender response time, underscoring that this is a sector-wide structural problem, not a single-institution failure.

Harden This Today

There is one control that sits at the intersection of the Nottingham attack vector and the ShinyHunters playbook: application-layer vulnerability management with verified patch SLAs (service level agreements that define how quickly a vulnerability must be remediated).

Specifically: audit every externally facing Java application server — Oracle WebLogic, JBoss, IBM WebSphere — and cross-reference patch levels against the CVE National Vulnerability Database within the next five business days. For any unpatched instance, apply compensating controls immediately: network segmentation (isolating the vulnerable system from the broader network so a compromise cannot spread laterally), WAF rules (web application firewall filters that block known exploit signatures for the specific vulnerability class), and enhanced logging routed to a SIEM (Security Information and Event Management platform — the tool that aggregates and correlates security alerts across your environment). Then ship the patch.

Secondary control: implement data minimization across student records systems. The Nottingham breach's blast radius was amplified because the compromised platform held passport numbers, disability status, and financial data alongside basic contact information. Not every platform that stores contact records needs to store passport scans. Audit what each system holds, strip unnecessary sensitive fields, and enforce role-based access controls so that an exploited external-facing application cannot reach your most sensitive data stores.

For institutions in Ghana subject to the CSA's Critical Information Infrastructure directive, this is also the moment to verify active compliance audit status — not to prepare for one, but to confirm one is current. Mandatory audits exist precisely so that a breach like Nottingham's remains a warning, not a template.

Frequently Asked Questions

Why are universities targeted by hackers more than other types of organizations?

As of Q2 2025, educational institutions globally face an average of 4,388 cyberattacks per organization weekly — the highest of any sector. Universities are attractive targets because they hold dense repositories of valuable personal and financial data, including student records, payment information, research data, and passport numbers, while typically operating with small IT and security teams relative to their data footprint. Many also run heterogeneous legacy systems — like the Oracle WebLogic instance exploited at Nottingham — that are difficult to patch quickly. The combination of high-value data, under-resourced defense, and complex application environments is exactly what financially motivated threat actors like ShinyHunters look for.

What specific data was stolen in the University of Nottingham breach?

The attack, identified on June 9, 2026, exposed the data of approximately 450,000 students and alumni across Nottingham's UK, Malaysia, and China campuses. Specifically compromised were names, home addresses, phone numbers, ethnicity and disability information, passport numbers, student identification numbers, financial data, and academic enrollment details. As of June 16, 2026, 455,000 unique email addresses had been confirmed as exposed, and ShinyHunters published over 40GB of the stolen data online.

How can universities protect student data from ShinyHunters-style ransomware attacks?

The most impactful immediate controls are: (1) patch management with enforced SLAs for critical vulnerabilities in externally exposed application servers; (2) network segmentation so that a compromised application layer cannot directly reach sensitive data stores; (3) multi-factor authentication (MFA) on all administrative and student-facing portals to block credential-stuffing attacks; and (4) data minimization — reducing the volume of sensitive data held in any single system. AI-assisted behavioral monitoring tools can detect anomalous data access patterns consistent with exfiltration before large volumes leave the network. Documented incident response plans and regular tabletop exercises ensure that when an attack is identified, the detection-to-containment window shrinks from weeks to days.

What is Ghana's Critical Information Infrastructure directive and which institutions does it cover?

Ghana's Directive for the Protection of Critical Information Infrastructure was launched on October 1, 2021, by the Cyber Security Authority. It designated 189 institutions across 13 sectors — including education, health, telecommunications, and transportation — as Critical Information Infrastructure Owners. From January 2023, these designated institutions are required to undergo mandatory compliance checks and security audits on an ongoing basis. The CSA's June 16, 2026 warning following the Nottingham breach is a reminder that compliance with this directive is an active, recurring obligation — not a one-time certification exercise.

Bottom line: When I look at the numbers behind the Nottingham breach — 455,000 records, 40GB published, an exploited middleware server, and a threat actor group with a documented track record of repeat strikes against academic targets — the pattern reads less like a sophisticated nation-state operation and more like an industry-wide failure to treat patch management as a first-order security control. My read is that the CSA's warning is exactly right: ShinyHunters did not need novel techniques. They needed an unpatched WebLogic instance and a willingness to publish. Until educational institutions close that gap with the same urgency a financial institution would, the sector will continue to carry the highest attack volume and the lowest compensating controls of any major industry. Ship the patch. Audit the data. The AI-powered attacker coming next will not wait for the next compliance cycle.

Disclaimer: This article is editorial commentary for informational purposes only and does not constitute professional security consulting advice. Statistics and figures are sourced from publicly available reports and news coverage. Always consult with a qualified cybersecurity professional for your specific institutional needs. Research based on publicly available sources current as of June 16, 2026.

One Backdoor, Two Ransomware Groups: The Supper Connection

AI Shield Daily is on NewsLens
Read all 22 AI channels in one free app
malware code on computer screen - a computer screen with a bunch of code on it

Photo by Chris Ried on Unsplash

What We Found
  • IBM X-Force linked both Interlock and Rhysida ransomware to the same Supper backdoor (also tracked as SocksShell and WINDYTWIST), first observed in July 2024 — pointing to shared developers or a common criminal service market rather than two fully independent groups.
  • By the end of 2025, each group had claimed roughly 80 victims; Rhysida's cumulative total reached 265 confirmed victims as of February 2026, with 133 of them (50.2%) located in the United States.
  • Interlock exploited CVE-2026-20131 — a CVSS 10.0 Cisco Secure Firewall Management Center zero-day enabling unauthenticated remote code execution with root privileges — 36 days before Cisco's official March 4, 2026 disclosure.
  • IBM X-Force identified "Slopoly" in early 2026, a PowerShell-based C2 framework (command-and-control infrastructure used to remotely direct compromised machines) bearing hallmarks of LLM generation — marking a new threshold in AI-assisted attack development.

The Evidence

16,384. That is the number of simultaneous attack sessions the Supper backdoor can sustain over a single TCP connection — a specification that reveals exactly how much operational scale this tool was engineered to support. When IBM X-Force researchers began pulling apart the malware code used by both Interlock and Rhysida ransomware operations, that figure was one of the telltale technical markers linking the two groups to a common codebase. As reported by CyberSecurityNews, the shared backdoor carries unique 16-bit session IDs and was first detected in the wild in July 2024 — months before Interlock even launched publicly in September 2024.

According to Google News's aggregation of threat intelligence reporting on this incident, the timeline itself is telling. Rhysida has operated as a Ransomware-as-a-Service (RaaS) platform since May 2023 — meaning the group licenses its ransomware infrastructure to affiliated criminal operators in exchange for a share of ransom proceeds. Interlock arrived roughly 15 months later with capabilities that looked suspiciously familiar. Cisco Talos assessed with low confidence that "Interlock ransomware is likely a new diversified group that emerged from Rhysida ransomware operators or developers, based on some similarities in the operators' tactics, techniques, and procedures (TTPs) and in the ransomware encryptor binaries." IBM X-Force offered a more calibrated read: "The overlaps are strong enough to suggest either shared developers, shared code lineage, or a tightly connected criminal service market, but not enough to prove a single unified group."

The shared tooling extends beyond the Supper backdoor itself. CyberSecurityNews's review of IBM X-Force's code analysis found that NodeSnake, the JunkFiction downloader, InterlockRAT, and multiple Supper variants all appear to have grown from the same original codebase. The connection widened further in November 2025, when Gootloader malware campaigns were observed dropping the Supper SOCKS5 backdoor — indicating adoption well beyond Interlock and Rhysida. The emerging picture is less "two rival criminal gangs" and more a functioning criminal supply chain with shared service vendors.

What It Means — and Who Carries the Blast Radius

Shared tooling creates a specific problem for defenders: attribution confusion. When two groups run the same backdoor, incident responders burn precious containment hours trying to identify which threat actor they face rather than isolating the breach. That delay is measurable in data exfiltrated, patients notified, and regulators called.

As of June 16, 2026, the blast radius is already documented and specific. Amazon's threat intelligence teams identified an active Interlock campaign exploiting CVE-2026-20131 in March 2026, targeting education, engineering, manufacturing, healthcare, and government. The vulnerability — a critical flaw in Cisco Secure Firewall Management Center that allows an unauthenticated remote attacker to execute arbitrary commands with root privileges — carries a CVSS severity score of 10.0, the maximum possible. Interlock began exploiting it on January 26, 2026, 36 days before Cisco's official disclosure on March 4, 2026. Federal agencies received a mandatory patch deadline of March 22, 2026 — just 18 days post-disclosure.

Confirmed Ransomware Victim Counts (as of Feb 2026) 265 Rhysida Total 133 Rhysida US ~80 Interlock Total (end-2025)

Chart: Confirmed victim counts for Rhysida (total and U.S.-only as of February 2026) versus Interlock's claimed count through end of 2025. Sources: IBM X-Force, CISA Advisory AA25-203A.

The DaVita breach from April 2025 provides the clearest data point for what blast radius looks like in a healthcare setting: Interlock exfiltrated 1.5 terabytes of data affecting more than 200,000 patients. Rhysida posted victims on a near-daily basis in late December 2025, with 8 distinct major attacks recorded between January 6 and February 17, 2026 alone. On July 22, 2025, CISA, the FBI, HHS, and MS-ISAC issued joint advisory AA25-203A documenting Interlock's TTPs and indicators of compromise (IOCs — unique digital fingerprints that malware leaves behind) from investigations as recent as June 2025. For organizations in healthcare and government that have not reviewed it, that advisory is the first document to pull.

The Criminal Supply Chain the Headline Buries

My read on the IBM X-Force analysis: this story is less about two ransomware brands competing and more about how the ransomware ecosystem has industrialized. Groups no longer need to build every tool from scratch. A shared backend — private crypter services, initial access brokers, common backdoors like Supper — lets new affiliates stand up sophisticated operations rapidly while simultaneously obscuring attribution. The criminal service market does what legitimate SaaS does: abstracts complexity so operators can focus on deployment.

The ClickFix social engineering tactic used by Interlock as its primary initial access method illustrates this maturity clearly. Threat actors serve fake system alerts and counterfeit CAPTCHA pages to trick end users into opening PowerShell and executing malicious commands manually. No zero-day required for initial entry — just a convincing fake browser error. This technique bypasses traditional endpoint detection because the user, not automated malware, initiates execution. Security awareness training on this single pattern can close the door on Interlock's most common entry vector.

And then there is Slopoly. IBM X-Force identified this PowerShell-based command-and-control framework in early 2026 as likely LLM-generated — evidenced by unusually extensive inline code commentary, structured logging, clearly named variables, and sophisticated error-handling logic that human-written malware rarely bothers to include. Interlock's ability to deploy AI-generated malware that maintained persistent access to compromised servers for more than a week signals that the technical barrier to building functional, well-documented attack tooling has dropped to "know how to write a prompt." This connects to the broader pattern Smart AI Agents covered recently on AI governance: as large language model capabilities become commoditized infrastructure, so does their use by threat actors to accelerate attack development cycles.

How to Act on This — Ship This Control Today

1. Patch CVE-2026-20131 — No Exceptions, No Delay

If your organization runs Cisco Secure Firewall Management Center and has not applied the patch disclosed on March 4, 2026, there is an unauthenticated remote code execution hole with a CVSS 10.0 score sitting at your network perimeter. Federal agencies were required to remediate by March 22, 2026. If a government-mandated deadline has already passed your organization by, ship this update to production today. Verify patch status across every Cisco FMC instance — especially any that are not directly internet-facing but reachable through internal pivot paths. Interlock demonstrated it was exploiting this vulnerability 36 days before disclosure, meaning patch lag is the attacker's advantage.

2. Block ClickFix Before It Reaches the Keyboard

Interlock's most documented initial access method requires no sophisticated exploit — only a user who trusts a fake error message. Deploy DNS-layer filtering or browser isolation (tools such as Cisco Umbrella, Cloudflare Gateway, or comparable platforms) to block domains serving ClickFix lure pages. Complement this with a targeted security awareness session covering one specific pattern: no legitimate software or website will ever instruct a user to open a terminal, copy a command, and run it manually. One focused training session on this single technique — not a thirty-item cybersecurity best practices checklist — addresses the root of Interlock's most common entry point.

3. Hunt for Supper IOCs Using Advisory AA25-203A

Load the indicators of compromise from CISA advisory AA25-203A directly into your SIEM (Security Information and Event Management platform — the system that aggregates logs and generates alerts across your environment) and EDR (Endpoint Detection and Response) tooling. Hunt specifically for Supper's behavioral signature: a single persistent TCP connection carrying an unusually high volume of multiplexed sessions, particularly over non-standard ports. Standard detection rules watching for many simultaneous connections will miss it — the tool is engineered to look like one connection. Organizations in healthcare, education, and government should treat this as a priority threat hunt given both groups' documented and consistent targeting of those sectors. This is an incident response discipline that pays dividends regardless of whether Interlock or Rhysida is the active threat.

Frequently Asked Questions

How does the Supper backdoor work, and why is it difficult to detect on corporate networks?

Supper operates as a SOCKS5 proxy — essentially an encrypted tunnel that routes attacker traffic through a compromised internal machine, making malicious communications appear to originate from inside the network. Its key technical characteristic is multiplexing: it supports up to 16,384 concurrent sessions over a single TCP connection, using unique 16-bit session IDs to track each one. Detection approaches that look for many simultaneous outbound connections will miss it entirely, because from the network's perspective it registers as a single persistent session. Effective detection requires behavioral rules targeting the data volume and pattern flowing through a single long-lived TCP connection on non-standard ports — a detection capability that requires tuning SIEM rules beyond default configurations.

Is Interlock ransomware directly related to Rhysida, or are they independent threat actors sharing tools?

The relationship is documented but contested in its precise nature. Cisco Talos assessed with low confidence that Interlock likely emerged from Rhysida operators or developers, citing overlapping TTPs and similarities in encryptor binaries. IBM X-Force's code-level analysis stopped short of declaring them a unified group, characterizing the overlaps as consistent with shared developers, shared code lineage, or a tightly connected criminal service marketplace. What both assessments agree on: IOCs associated with one group should be treated as actionable indicators for the other. The November 2025 observation of Gootloader campaigns also dropping the Supper backdoor suggests the shared tooling extends beyond just these two groups, pointing to a broader criminal supply chain rather than an exclusive bilateral relationship.

What industries does Interlock ransomware target most, and what does an effective data protection response look like?

As of June 16, 2026, Interlock's confirmed target sectors include healthcare, education, engineering, manufacturing, and government — all characterized by high data sensitivity, regulatory exposure, and historically slower patch deployment cycles. The April 2025 DaVita breach (1.5 terabytes exfiltrated, 200,000-plus patients affected) sets the stakes for healthcare organizations specifically. An effective data protection posture against Interlock requires layering: apply CVE-2026-20131 patches immediately, review all internet-facing firewall management interfaces, deploy ClickFix-specific user awareness training, load AA25-203A IOCs into detection tooling, and confirm that network segmentation prevents a compromised endpoint from reaching backup infrastructure directly. Organizations subject to HIPAA should also review their incident response plans on the assumption that Interlock's default playbook is double-extortion — encrypt the data and threaten to publish it — which means backups alone do not eliminate leverage.

Disclaimer: This article is editorial commentary for informational purposes only and does not constitute professional security consulting advice. Threat data and statistics reflect publicly available information at time of writing. Always consult with a qualified cybersecurity professional for your organization's specific needs. Research based on publicly available sources current as of June 16, 2026.

After Operation Cronos: New Ransomware Groups Fill the Void

AI Shield Daily is on NewsLens
Read all 22 AI channels in one free app

It is May 14, 2026. On a dark web forum called Duty-Free, a user posting as 'hyflock123' drops a recruitment notice promising criminal affiliates a 90% revenue cut — ten percentage points above LockBit's historic ceiling — and mentions in passing having worked inside both LockBit and Qilin. Within days, the Hyflock RaaS (ransomware-as-a-service) program secures an official partnership with BreachForums, gaining immediate access to a curated network of access brokers and penetration testers. The former employees of the ransomware industry's most famous disrupted brand are not in hiding. They are hiring.

The Threat: LockBit's Diaspora Goes Operational

According to Google News, citing CyberSecurityNews analysis as of June 16, 2026, the ransomware ecosystem is undergoing significant reorganization as a direct consequence of Operation Cronos — the law enforcement action that dismantled LockBit's core infrastructure in February 2024. Check Point Research described the downstream effect precisely: "Operation Cronos scattered a large pool of skilled affiliates who were essentially independent contractors with nowhere to go. Two years on, those contractors appear to have regrouped and are now building their own operations instead of waiting for the old ones to recover."

The evidence of that regrouping is now quantifiable. As of Q1 2026, per Check Point Research's State of Ransomware analysis, 2,122 victims appeared on ransomware leak sites in a single quarter. The top 10 groups accounted for 71% of those victims. Qilin, Akira, The Gentlemen, and LockBit together were responsible for 41% of all recorded incidents. LockBit, operating under the relaunched LockBit 5.0 designation, posted 163 confirmed victims in Q1 alone.

The Gentlemen's trajectory is the starkest individual data point in the consolidation story. The group recorded 40 victims across all of Q4 2025, then 48 in January 2026 and 91 in February 2026, landing at 166 total for Q1 2026 — a 315% expansion quarter-over-quarter. By April 2026, The Gentlemen accounted for 10% of global ransomware activity. These are not organic startup-curve numbers; they reflect an operator class that already knew the playbook entering day one of their new venture.

Qilin remained the single most active threat actor as of May 2026, claiming 97 attacks that month — down 10% from 108 in April, per Recorded Future — with more than 500 total victims in 2026 and 168 confirmed incidents in the healthcare sector alone as of June 16, 2026. In June 2026, a Qilin affiliate exploited CVE-2026-50751, a zero-day vulnerability (a security flaw with no available patch at time of exploitation) in Check Point VPN appliances, confirming that network edge devices remain the preferred initial-access vector for these operators.

The Gentlemen: Confirmed Victims by Period 166 83 0 40 Q4 2025 48 Jan 2026 91 Feb 2026 166 Q1 2026

Chart: The Gentlemen confirmed victim counts from Q4 2025 through Q1 2026 quarter total. Source: Check Point Research, Q1 2026 State of Ransomware.

Blast Radius — Who Should Actually Care

The honest answer is every organization that runs internet-connected infrastructure, which is a useless frame. The useful frame is: healthcare is under active, documented attack right now, and any organization that has not isolated its backup environment from its primary network is exposed in a way that traditional incident response planning does not address.

Qilin alone has confirmed 168 healthcare victims in 2026. When ransomware reaches a hospital network, the blast radius extends beyond encrypted files — it reaches clinical applications, surgical scheduling systems, and in some configurations, medication dispensing infrastructure. The FBI's 2025 IC3 Annual Report, released April 6, 2026, documented 63 new ransomware variants in 2025, total ransom payments of $813 million, and total economic damage of $57 billion — a 70-to-1 ratio between what victims paid and what they actually lost in operational disruption and recovery costs. Publicly reported attacks rose 47%, from approximately 4,900 incidents in 2024 to roughly 7,200 in 2025.

The consolidation dynamic amplifies risk in a counterintuitive direction. Industry analysis notes that "rather than reducing risk, consolidation often means businesses face fewer but far more dangerous adversaries. Larger RaaS brands invest in operational consistency, including functional decryption tools, because their business model depends on the perception that victim payment results in data recovery." The groups that survive competitive culling are precisely the ones who have solved operational reliability — which makes them significantly more effective at every stage of the attack cycle, from initial access through ransom negotiation.

One figure from 2025 reporting deserves direct attention: as of that reporting period, 77% of ransomware attacks involved data exfiltration — up 20 percentage points from the prior year. This means backup-and-restore is no longer a complete recovery strategy. The data is often already gone before the ransom note appears, and the threat is now equally about regulatory exposure and public disclosure as it is about operational downtime. Recorded Future predicts that 2026 will mark the first year new ransomware actors operating outside Russia outnumber those within it, reflecting a genuine globalization of the threat that makes geography-based risk filtering increasingly unreliable.

The Defense Stack That Works Here

All three groups central to this story — Qilin, Hyflock, and The Gentlemen — share operator lineage tied to affiliates who favor network edge device exploitation as their preferred initial access route. CVE-2026-50751 is the current active, confirmed example. Any defense stack that does not start at the perimeter is starting in the wrong place.

Technology layer: Network edge device patching should not sit on a standard 30-day cycle for any organization that is a plausible ransomware target (the self-assessment answer is almost always yes). VPN appliances, firewall management interfaces, and remote access gateways require accelerated patching treatment. Check Point VPN deployments should treat CVE-2026-50751 as a P0 item with immediate compensating controls (compensating controls meaning temporary mitigations that reduce exposure while a full patch is applied, such as restricting management interface access to trusted IP ranges). Multi-factor authentication on every remote access pathway is non-negotiable — this remains the highest-return single control against credential-based access broker deployments, which is precisely how Hyflock's BreachForums partnership translates into actual victim environments.

Process layer: Network segmentation needs a validated blast radius containment design, not just a network diagram. If a threat actor achieves initial access, lateral movement speed determines whether the outcome is a contained incident or a full-domain compromise. Backup systems require airgap-adjacent separation from the primary network; ransomware operators consistently target backup infrastructure early in the attack sequence to eliminate the recovery option before deploying encryption. Given the 77% exfiltration rate, incident response plans must now include a parallel data disclosure workstream — legal, communications, and regulatory notification — not just operational recovery objectives. Run a tabletop exercise specifically against a double-extortion scenario (encryption plus threatened data leak) before the next board cycle.

People layer: Security awareness training should address what double extortion means in plain terms: paying the ransom does not guarantee that stolen data stays private or is deleted. Personnel and executives who understand this are less likely to make panicked payment decisions under time pressure. For organizations with threat intelligence capacity, dark web monitoring for new RaaS affiliate recruitment provides early signal — Hyflock is actively recruiting right now, and its BreachForums partnership means access broker inventory targeting your sector profile is already in motion.

Harden This Today

One control. Pull your external attack surface inventory and identify every internet-facing device running remote access software: VPN concentrators, firewall management portals, RDP (Remote Desktop Protocol) endpoints. Confirm that each one has MFA enforced and is running a current, patched firmware build. This single audit closes the dominant documented initial-access vector for Qilin, and it is the most probable initial-access path for Hyflock and The Gentlemen affiliates based on their operator lineage and publicly available threat intelligence as of June 16, 2026.

If the audit surfaces unpatched edge devices, isolate them from critical network segments while the patch cycle completes. Everything else in this picture — the RaaS economics, the AI-assisted victim profiling that new platforms are reportedly building, the long-term data protection posture — is downstream of whether an affiliate can walk in through an unpatched VPN appliance. Ship this control first. Then build the rest of the stack.

Frequently Asked Questions

What is ransomware consolidation and why is it accelerating in 2026?

Ransomware consolidation describes the process by which a smaller number of professionalized RaaS operations displace less organized groups, capturing an increasing share of total global victims. As of Q1 2026, the top 10 groups account for 71% of all recorded victims. The 2024 Operation Cronos disruption of LockBit accelerated this by dispersing a large pool of experienced affiliates who spent two years building independent operations with better infrastructure, higher affiliate revenue shares, and more operationally consistent attack pipelines than the groups they are displacing.

How does the ransomware-as-a-service affiliate model work, and why does a 90% share matter?

RaaS functions as a criminal franchise. Core operators develop and maintain the ransomware toolkit, the negotiation infrastructure, and the data-leak extortion portal. Affiliates — independent criminal contractors — handle victim targeting, initial access, and payload deployment, then receive a percentage of the ransom. Historically, LockBit offered affiliates around 80% of proceeds. Hyflock's May 2026 launch offering 90% is competitively significant: in a market where experienced affiliates can choose their platform, a 10-point revenue premium is a meaningful recruiting advantage that accelerates how quickly a new operation can acquire skilled operators.

What happened to LockBit after Operation Cronos, and are former affiliates still active?

Operation Cronos, executed in February 2024, seized LockBit's core infrastructure and disrupted its operations. LockBit did not disappear — it relaunched as LockBit 5.0 and recorded 163 confirmed victims in Q1 2026. More consequentially, the disruption scattered skilled affiliates who have since launched independent operations. Both The Gentlemen and Hyflock claim direct lineage to LockBit's affiliate network. Check Point Research notes these operators spent approximately two years regrouping before building their own independent platforms, and the Q1 2026 victim counts suggest they have done so effectively.

Which ransomware groups pose the highest risk to businesses as of mid-2026?

As of June 16, 2026, Qilin is the single most active group with 97 attacks recorded in May 2026 and over 500 total victims in 2026, with particular concentration in healthcare at 168 confirmed victims. The Gentlemen ranks third globally after a 315% quarter-over-quarter expansion. LockBit 5.0 posted 163 victims in Q1 2026. Hyflock launched formally in May 2026 and is actively recruiting via BreachForums. All four groups demonstrate a documented preference for network edge device exploitation as their primary initial-access method, making perimeter patching the highest-priority defensive action.

Bottom Line

  • As of June 16, 2026, the top 10 ransomware groups account for 71% of all victims globally; Qilin, The Gentlemen, LockBit 5.0, and Akira together claim 41% — the consolidation seeded by Operation Cronos has fully materialized.
  • The Gentlemen grew 315% quarter-over-quarter, from 40 victims in Q4 2025 to 166 in Q1 2026. Qilin has confirmed 168 healthcare-sector victims in 2026 alone and exploited a Check Point VPN zero-day (CVE-2026-50751) in June 2026.
  • 77% of 2025 ransomware attacks included data exfiltration — backup-only recovery strategies do not address the current threat model, and incident response plans need a data disclosure workstream, not just an RTO.
  • The FBI's 2025 IC3 report documents $57 billion in total ransomware damage against $813 million in ransom payments — a 70-to-1 ratio that reflects how much operational damage extends beyond the ransom itself.

In my analysis, the most underappreciated dimension of this story is what it reveals about law enforcement disruption as a risk-reduction instrument. Operation Cronos was a real tactical win. But by dispersing experienced operators rather than retiring them from the ecosystem, it may have seeded the landscape with more independent, harder-to-disrupt entities than existed before. The Gentlemen growing 315% in a single quarter is not a sign that ransomware is generically getting worse — it is a sign that some of the people who built LockBit into a dominant global franchise have not slowed down. They have just reincorporated.

Disclaimer: This article is editorial commentary for informational purposes only and does not constitute professional security consulting advice. Always consult with a qualified cybersecurity professional for your specific organizational needs. Research based on publicly available sources current as of June 16, 2026.

EdTech Ransomware: Why Schools Pay $2.28M Per Attack

AI Shield Daily is on NewsLens Read all 22 AI channels in one free app  App Store ▶ Google Play ...