Security News

New Ransomware Gang 'n0n' Threatens to Destroy Backups If Ransoms Aren't Paid

Infosecurity Magazine · 25 Sept 2026
Key Takeaway Maintain offline, immutable backup copies that attackers cannot reach from your network, and strengthen credential hygiene to prevent infostealer-sourced logins from granting initial access.

A newly formed ransomware group named n0n is escalating extortion tactics by threatening to destroy or encrypt backup infrastructure and shadow copies, not just steal sensitive data. Researchers at CyberXTron first spotted the group's activity on September 18, and within days its dark web leak site had listed information on more than a dozen victims. The threat to wipe out backups is designed to remove any fallback option for victims, increasing pressure to pay.

n0n follows the common double extortion model, combining data theft with public leak threats, but adds the backup destruction threat as a psychological lever. Financial services has been the most targeted sector so far, accounting for 23% of victims, followed by technology, retail and education at 15% each. Healthcare, defense and professional services organisations have also been hit, with victims identified across the US, Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg.

Despite the severity of the threats, some victims have refused to pay, evidenced by countdown timers reaching zero and stolen data being published regardless. According to researchers, the group gains initial access using compromised credentials sourced from infostealer malware, then escalates privileges to reach administrative tools before staging data for extortion.

ransomware data extortion backup security credential theft threat intelligence

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.