Independent Reporting · Not Legal or Security Advice · Verify With the Breached Company · Editorial Policy

Cybersecurity — RansomHub Guide 2026: What Happened, Who Is Affected, and Next Steps

RansomHub was the most prolific ransomware-as-a-service operation of 2024, and by 2026 it no longer exists — but the affiliates and tactics that powered it did not disappear, they moved to successor groups like Qilin, Akira, and DragonForce. If your organization was hit or named on its leak site, the exposure is permanent; if you were not, the defensive priorities remain exactly what they were, because the playbook outlived the brand. The group launched in February 2024, compromised at least 210 victims across every critical infrastructure sector within six months, and went dark without explanation on April 1, 2025. This guide covers what RansomHub was, who it hurt, why its collapse did not make anyone safer, and what to do now.

Table of Contents

What was RansomHub and how did it operate?

RansomHub was a ransomware-as-a-service (RaaS) operation — a criminal business that rents its malware and infrastructure to independent attackers, called affiliates, in exchange for a share of ransom payments. It had operated earlier under the names Cyclops and Knight before relaunching in February 2024, according to the joint FBI/CISA advisory AA24-242A. Its growth was extraordinary. The same advisory counted at least 210 victims by August 2024, roughly six months after launch, and affiliates averaged at least three victims per day in July 2024.

Every attack used double extortion: encrypting systems so they stop working, and stealing data first so victims face publication even if they restore from backups. Timing explains the speed. Law enforcement disrupted LockBit and the ALPHV/BlackCat group collapsed in early 2024, and CISA and the FBI identified RansomHub as the destination for many of those displaced affiliates. The brand was new; the operators behind the keyboards largely were not.

Who was affected?

Victims spanned water and wastewater systems, IT, government, healthcare, emergency services, food and agriculture, financial services, manufacturing, transportation, and communications — every critical infrastructure sector the advisory tracks. No industry profile made an organization safe; affiliates targeted whatever they could reach. The named victims show the range.

RansomHub claimed attacks on Halliburton, Rite Aid, Kawasaki's EU division, Christie's auction house, Frontier Communications, Planned Parenthood of Montana, and Bologna FC, per BleepingComputer's reporting. It also leaked data stolen in the Change Healthcare breach, which affected more than 190 million people — meaning a large share of Americans had data touched by this group without ever hearing its name. For individuals, the practical consequence is that data published on a leak site stays published. If a company you use appeared on RansomHub's site, treat any data it held — Social Security numbers, health records, financial details — as exposed indefinitely, and act on breach notices with credit freezes and fraud alerts rather than waiting to see whether misuse happens.

How did the attacks actually start?

The entry points were mundane, which is what makes the record useful. Incident data reported by Dark Reading shows affiliates exploiting known, patchable vulnerabilities — including Zerologon (CVE-2020-1472), a domain controller flaw disclosed in 2020, four years before RansomHub existed.

Once inside, affiliates favored legitimate software over custom malware: Atera and Splashtop remote access tools and NetScan for mapping the network. These are the same products IT departments use every day, so their presence alone rarely trips alerts. The lesson for defenders is that an unexpected remote-access install is a stronger signal than any ransomware signature.

  • Unpatched, publicly known vulnerabilities on internet-facing or identity systems
  • New remote-access software (Atera, Splashtop) appearing without a change ticket
  • Network scanning tools running from workstations that have no business running them

Why did RansomHub disappear — and where did the threat go?

On April 1, 2025, RansomHub's leak site and negotiation infrastructure went offline with no official explanation, stranding affiliates mid-negotiation, as The Hacker News reported. The rival group DragonForce claimed on the RAMP criminal forum that RansomHub had joined its "cartel" infrastructure; RansomHub disputed that, and then never resurfaced. The collapse was total as a brand: from 736 claimed victims to zero within twelve months, per ThreatDown.

But the affiliates migrated rather than retired — mainly to Qilin, which led all ransomware groups with 74 claimed attacks in April 2025 according to Cyble, plus Akira and DragonForce. The aggregate numbers prove the point. The Black Kite 2026 Ransomware Report counted 7,551 ransomware victims in the 2026 reporting year, up 24.9%. A defunct brand name is not a reduced threat; it is the same operators under new letterhead.

Next steps that still apply in 2026

The joint advisory's mitigations were written against RansomHub's techniques, and because Qilin, Akira, and DragonForce affiliates run the same playbook, they remain the current to-do list: One warning: do not treat a quiet leak-site landscape as safety. RansomHub's own disappearance briefly looked like relief, and the 24.9% rise in victims the following year is what it actually preceded.

  • Patch known exploited vulnerabilities first, prioritizing anything on CISA's KEV catalog — Zerologon was a five-year-old bug when affiliates were still using it.
  • Enforce phishing-resistant multi-factor authentication (hardware keys or passkeys, not SMS codes) on VPNs, email, and admin accounts.
  • Segment networks so a compromised workstation cannot reach domain controllers and backups directly.
  • Keep multiple copies of critical data in physically separate, secured, offline locations, and test that restores actually work.
  • Inventory remote-access tools in use and alert on any others appearing.

Frequently Asked Questions

Is RansomHub still active in 2026?

No. Its infrastructure went dark on April 1, 2025 and never returned, but its affiliates moved to Qilin, Akira, and DragonForce, which use the same techniques.

How do I know if my data was exposed in a RansomHub attack?

Watch for breach notifications from affected companies — including Change Healthcare, Rite Aid, and Frontier Communications — and treat any notified exposure as permanent, since leaked data remains circulating.

Does a ransomware group shutting down mean I can deprioritize ransomware defenses?

No. Total ransomware victims rose 24.9% to 7,551 in the year after RansomHub vanished, because affiliates and tooling migrated rather than exiting.


You Might Also Like

Owed money from a settlement? Check what is open at OpenClassActions.com. Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy. Cookie Policy.