Rhysida Ransomware Group
Threat Actor
Because Rhysida ransomware first appeared in May 2023, not much is known about the ransomware or the group at this time [June 2023].
They do not seem to be listing victims to warn them publicly before leaking information. The only entries on the site currently are the ones that they have leaked totally. None of the listings indicate when Rhysida attacked or encrypted the victims.
Incidents Associated with this Threat
- September 12, 2025: Marine Electronics Manufacturer, Furuno, Hit in Ransomware Attack
- February 7, 2025: Ransomware Attack at London Literary Agency
- January 10, 2025: Extensive Databreach fully Exposes Qualinet’s Operation Methods
- August 24, 2024: Cyberattack Disrupts Seattle Airport for Days, affecting Labor Day Weekend Rush
- July 18, 2024: Rhysida Demands $1.9M from Ohio State Government for Sensitive Exfiltrated Data
- July 18, 2024: City of Columbus Hackers Leak over 3TB Data
- November 24, 2023: Ransomware Attack at Slovenian Power Company HSE
- October 27, 2023: British Library Systems Disrupted for Weeks after Ransomware Attack
- August 6, 2023: Cyberattack Suspends Clinical Activity in Madeira Health Service
- August 3, 2023: 16 Hospitals of Prospect Medical Holdings Impacted by Ransomware Attack
- May 16, 2023: Critical Infrastructure Disrupted in Martinique by Prolonged Cyberattack
Malware Used by this Threat Actor
No malware identified for this threat actor.
