New Ransomware Gang 'n0n' Threatens to Destroy Backups If Ransoms Aren't Paid
A newly formed ransomware group named n0n is escalating extortion tactics by threatening to destroy or encrypt backup infrastructure and shadow copies, not just steal sensitive data. Researchers at CyberXTron first spotted the group's activity on September 18, and within days its dark web leak site had listed information on more than a dozen victims. The threat to wipe out backups is designed to remove any fallback option for victims, increasing pressure to pay.
n0n follows the common double extortion model, combining data theft with public leak threats, but adds the backup destruction threat as a psychological lever. Financial services has been the most targeted sector so far, accounting for 23% of victims, followed by technology, retail and education at 15% each. Healthcare, defense and professional services organisations have also been hit, with victims identified across the US, Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg.
Despite the severity of the threats, some victims have refused to pay, evidenced by countdown timers reaching zero and stolen data being published regardless. According to researchers, the group gains initial access using compromised credentials sourced from infostealer malware, then escalates privileges to reach administrative tools before staging data for extortion.