LockBit
DisruptedLockBit Black, LockBit 3.0
Ransomware-as-a-Service (financially motivated)
A ransomware-as-a-service operation that was, by volume, the most active ransomware group globally before an international law enforcement takedown in February 2024.
LockBit ran an affiliate model that let independent criminal groups use its ransomware in exchange for a cut of ransom payments, which let it scale to claim over 2,000 victims and extort more than $120 million. In February 2024, the FBI, UK's National Crime Agency, Europol, and international partners executed Operation Cronos, seizing LockBit's servers, leak site, and source code, and deliberately eroding trust between LockBit and its roughly 200 affiliates. Attacks attributed to LockBit dropped sharply afterward, though the ransomware-as-a-service model it popularized continues through successor groups.
Target SectorsManufacturing, healthcare, financial services, public sector, and professional services, largely indiscriminate by industry.
Ransomware Detection & Response →BlackCat / ALPHV
DefunctALPHV, Noberus
Ransomware-as-a-Service (financially motivated)
A ransomware-as-a-service operation active from late 2021 that collapsed in an apparent exit scam in March 2024, stealing an affiliate's ransom payment instead of paying out.
BlackCat was known for being written in the Rust programming language, unusual for ransomware at the time, and for aggressive double-extortion tactics. By September 2023, the FBI estimated it had compromised over 1,000 victims and collected close to $300 million in ransom payments, second only to LockBit. After a US law enforcement disruption of its infrastructure in December 2023, the operation exit-scammed in March 2024, taking roughly $22 million meant for an affiliate rather than paying out. The original service has not resumed; many of its estimated 90+ affiliates are believed to have moved to successor operations such as RansomHub and Embargo.
Target SectorsHealthcare, financial services, and other sectors handling high-value data, targeted opportunistically.
Ransomware Detection & Response →Akira
ActiveRansomware-as-a-Service (financially motivated)
A closed ransomware-as-a-service operation active since April 2023 that became one of the most prolific ransomware groups globally by ransom proceeds in 2025.
Akira uses the standard double-extortion model, encrypting systems while also stealing data to pressure payment. The group generated an estimated $150 million in 2025 alone and has shown a consistent ability to adapt its targeting and tooling in response to law enforcement pressure. Activity has continued to accelerate into 2026, with monthly victim counts posted on its leak site more than doubling between February and March 2026.
Target SectorsManufacturing, professional services, healthcare, and education, with a pattern of exploiting VPN and remote-access vulnerabilities for initial access.
Ransomware Detection & Response →Cl0p
ActiveClop, TA505
Data extortion (financially motivated)
A group known for mass-exploiting vulnerabilities in file-transfer and enterprise software to steal data at scale, often without deploying encryption at all.
Cl0p's signature approach is exploiting a single vulnerability in widely used enterprise software to compromise dozens or hundreds of organizations in one campaign, then extorting them over stolen data rather than encrypting systems. Its 2023 mass-exploitation of a MOVEit Transfer vulnerability affected thousands of downstream organizations. In 2026, Cl0p ran a comparable campaign exploiting a vulnerability in PTC's Windchill and FlexPLM product lifecycle management software, naming over 40 organizations including major manufacturers. As of mid-2026, Cl0p remained highly active, with over 1,300 victims claimed on its leak site.
Target SectorsAny organization using the specific enterprise software being mass-exploited in a given campaign, span across manufacturing, finance, and professional services.
24/7 SOC Monitoring & MDR →FIN7
ActiveCarbon Spider, Sangria Tempest
Financially motivated
A financially motivated group active since around 2013, historically known for targeting point-of-sale systems and, more recently, for links to multiple ransomware affiliate operations.
FIN7 originally focused on stealing payment card data from retail and hospitality point-of-sale systems using spear-phishing to gain initial access. Over its long operational history it has repeatedly reorganized under different front-company identities and has been linked by researchers to ransomware deployment through affiliations with multiple ransomware-as-a-service brands over the years. Its longevity and repeated reinvention make it one of the most persistent financially motivated threat groups tracked by the security industry.
Target SectorsRetail, hospitality, restaurants, and increasingly a broader range of sectors as it has diversified beyond point-of-sale theft.
Phishing Training →Scattered Spider
ActiveUNC3944, Octo Tempest, Muddled Libra
Financially motivated / extortion
A financially motivated group known for sophisticated social engineering, particularly help-desk impersonation and SIM swapping, that has evolved into deploying ransomware directly.
Unlike most ransomware operators, Scattered Spider's core skill is manipulating people, not exploiting software: calling IT help desks impersonating employees to reset credentials and bypass MFA, or SIM-swapping a target's phone number to intercept authentication codes. A joint FBI/CISA advisory (updated July 2025) documented the group's shift toward deploying DragonForce ransomware and targeting VMware ESXi environments directly. Despite multiple arrests of alleged members through 2024 and 2025, its decentralized structure has kept it operationally resilient, with activity continuing into 2026.
Target SectorsTechnology, telecommunications, financial services, and increasingly critical infrastructure and retail.
Phishing Training →