N0n ransomware gang – what you need to know
A new ransomware extortion group called N0n emerged in mid‑September 2026 and quickly began publishing victim data on a dark‑web leak site. Within days the gang claimed responsibility for about a dozen organizations, and the number of reported victims has continued to rise.
The group appears to follow a typical double‑extortion model: it first encrypts files on a victim’s network, then threatens to release the stolen data unless a ransom is paid. The public leak site shows screenshots of stolen files, ransom notes, and instructions for payment, which suggests the gang is trying to pressure victims into paying quickly. So far, the victims disclosed include small‑to‑medium businesses in the United States and Europe, though the exact industries have not been confirmed.
Security researchers who have examined the leak site say the encryption method uses a known ransomware variant that has been modified with a new code signing key. This change makes it harder for standard antivirus tools to flag the malicious payload. The gang also appears to use compromised email accounts to send phishing emails that deliver the ransomware payload, a tactic that blends social engineering with malware distribution.
For everyday users, the risk is indirect. If a business you work with is compromised, personal data such as email addresses, payment details, or login credentials could be exposed. Even if you are not directly targeted, phishing emails that mimic the N0n ransomware campaign may appear in inboxes, trying to lure recipients into downloading malicious attachments.
To protect yourself, start by updating all software and operating systems promptly; many ransomware strains exploit known vulnerabilities. Use strong, unique passwords for each online account and enable two‑factor authentication wherever possible. Be cautious with email attachments and links, especially if the sender is unknown or the message contains urgent language. Free tools available on ComputerScams.com, such as the password‑strength checker and the email‑header analyzer, can help you verify the legitimacy of suspicious messages.
If you suspect a device has been infected, disconnect it from the network immediately and run a full scan with reputable anti‑malware software. Do not pay a ransom, as there is no guarantee the attackers will restore access or delete leaked data. Instead, report the incident to local law enforcement and consider contacting a professional incident‑response service.
A practical step you can take right now is to enable multi‑factor authentication on your most important accounts, such as email, banking, and cloud storage. This adds an extra layer of security that can stop attackers even if they obtain your password.
Source: Read the original report