Skip to content
You can now search across every topic, entity and event.What's new
INC Ransom
Organisation

INC Ransom

Double-extortion ransomware crew, active since 2023, whose leak-site operator also runs Lynx's negotiation panels.

INC Ransom is a double-extortion ransomware crew active since mid-2023. On 8 July 2026 threat-intelligence firm SOCRadar found the same operator running its negotiation panels and those of the separate Lynx crew, the first confirmed link between the two brands.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Two ransomware brands, one operator: how tied is INC Ransom really to Lynx?

Timeline for INC Ransom

#11 16 Jul

Mentioned in: CISA's KEV list runs a month late

Cybersecurity: Threats and Defences
#10 8 Jul

Shared a negotiation-panel operator with INC Ransom

Cybersecurity: Threats and Defences: One operator ran both ransomware brands
#9 4 Jul

Mentioned in: BOD 26-04, a fortnight of triage

Cybersecurity: Threats and Defences
#9 1 Jul

Lynx crew cashes in FortiBleed haul

Cybersecurity: Threats and Defences
#6 31 May

Mentioned in: Ransomware tempo holds at 95 in May

Cybersecurity: Threats and Defences
View full timeline →

Background

INC Ransom is a double-extortion ransomware crew that emerged in mid-2023, encrypting victim systems and threatening to publish stolen data on its own dark-web leak site unless paid. It claimed NHS Scotland's Dumfries and Galloway board and NHS Lanarkshire in 2024, drawing ICO scrutiny and NCSC guidance, and returned to UK targeting on 5 June 2026 by posting manufacturer Stuga Machinery, its only confirmed UK victim in BlackFog's May tempo count.

The crew relies on living-off-the-land binaries for lateral movement and customises its payload per victim, working mainly against healthcare, manufacturing, professional-services and government targets across North America and Europe.

On 8 July 2026, threat-intelligence firm SOCRadar reported that one operator ran INC Ransom's negotiation panel alongside that of Lynx, a separate crew with which INC Ransom shares code lineage. The finding does not merge the two brands: INC Ransom keeps its own leak site and victim list, but its staffing now overlaps with a rival's at the point where ransom terms get set.

Common Questions
Is Lynx ransomware the same group as INC Ransom?
No. Lynx and INC Ransom are separate ransomware brands with their own leak sites, but SOCRadar found they share code lineage and, as of July 2026, one operator running both groups' negotiation panels.Source: SOCRadar
How many organisations has the FortiBleed access chain reached so far?
SOCRadar confirmed admin-level access on 409 targets, completed a full attack chain on 354, and counted at least 12 resulting ransomware deployments.Source: SOCRadar
How did the Lynx/INC crew get hold of 86,644 FortiGate passwords?
They cracked the credentials offline on a 45-GPU Hashtopolis cluster, exploiting legacy SHA-256 FortiOS hashes never re-hashed to PBKDF2.Source: SOCRadar
What should a company do if INC_RANSOM posts it on their leak site?
A leak-site posting means INC_RANSOM is asserting it has stolen data and is using the threat of publication as leverage. Affected organisations should immediately engage a specialist Incident Response firm, notify the ICO within 72 hours under UK GDPR Article 33, preserve all forensic evidence, and seek specialist legal advice before any ransom payment consideration. Payment does not guarantee data deletion.Source: NCSC incident response guidance, ICO breach notification requirements
What is INC_RANSOM and which organisations has it attacked?
INC_RANSOM is a double-extortion ransomware group active since mid-2023. It encrypts victim systems and threatens to publish stolen data on a dark-web leak site. Notable victims include NHS Scotland in early 2024 and UK manufacturer Stuga Machinery posted in June 2026. The group targets healthcare, manufacturing and professional services in North America and Europe.Source: NCSC guidance, NHS Scotland incident reporting, BlackFog ransomware report
What did SOCRadar find about INC Ransom and Lynx sharing an operator?
On 8 July 2026, SOCRadar reported a single operator running the negotiation panels for both INC Ransom and Lynx, the first confirmed link tying the FortiBleed credential haul to live ransomware deployment across both brands.Source: SOCRadar
Did INC_RANSOM attack the NHS?
Yes. In early 2024, INC_RANSOM attacked NHS Scotland, specifically Dumfries and Galloway NHS Board and NHS Lanarkshire, encrypting systems and stealing patient data. The group threatened to publish the stolen data. The incidents prompted NCSC guidance and ICO scrutiny. INC_RANSOM continued UK targeting in June 2026 with the posting of manufacturer Stuga Machinery.Source: NHS Scotland incident reports, NCSC advisory
Source Material