Rhysida is a ransomware group that encrypts data on victims' computer systems and threatens to make it publicly available unless a ransom is paid.[1] The group uses eponymous ransomware-as-a-service techniques, targets large organisations rather than making random attacks on individuals, and demands large sums of money to restore data.[2]

The group perpetrated the notable 2023 British Library cyberattack[1] and Insomniac Games data dump.[3] It has targeted many organisations, including some in the US healthcare sector, and the Chilean army.[4]

In November 2023, the US agencies Cybersecurity and Infrastructure Security Agency (CISA), FBI and MS-ISAC published an alert about the Rhysida ransomware and the actors behind it,[5] with information about the techniques the ransomware uses to infiltrate targets and its mode of operation.[6]

The group may be based in the Commonwealth of Independent States.[1]

The group takes its name from the genus of centipedes, and uses a centipede logo.[4]

Attacks

edit

Ransomware as a service

edit

The US CISA report states:[6]

Threat actors leveraging Rhysida ransomware are known to impact "targets of opportunity", including victims in the education, healthcare, manufacturing, information technology, and government sectors. Open source reporting details similarities between Vice Society (DEV-0832) activity and the actors observed deploying Rhysida ransomware. Additionally, open source reporting has confirmed observed instances of Rhysida actors operating in a ransomware-as-a-service (RaaS) capacity, where ransomware tools and infrastructure are leased out in a profit-sharing model. Any ransoms paid are then split between the group and the affiliates.

References

edit
  1. ^ a b c Milmo, Dan (24 November 2023). "Rhysida, the new ransomware gang behind British Library cyber-attack". The Guardian. Retrieved 23 December 2023.
  2. ^ Hollingworth, David (19 December 2023). "Snikt! Rhysida dumps more than a terabyte of Insomniac Games' internal data". www.cyberdaily.au. Retrieved 23 December 2023.
  3. ^ a b Acres, Tom (20 December 2023). "Wolverine: What we know about the cyberattack that leaked one of PlayStation's most anticipated games". Sky News.
  4. ^ a b c Cluley, Graham (10 August 2023). "Rhysida ransomware โ€“ what you need to know". Tripwire.
  5. ^ "CISA, FBI, and MS-ISAC Release Advisory on Rhysida Ransomware". Cybersecurity and Infrastructure Security Agency (CISA). 15 November 2023. Retrieved 23 December 2023.
  6. ^ a b "#StopRansomware: Rhysida Ransomware". Cybersecurity and Infrastructure Security Agency (CISA). 15 November 2023. Alert Code AA23-319A. Retrieved 23 December 2023.
  7. ^ "Insomniac: PlayStation studio 'angered' by ransomware hack". BBC News. 22 December 2023. Retrieved 24 December 2023.
  8. ^ "Rhysida Ransomware Gang Strikes Again, Targets Chilean Army And Martinique". The Cyber Express. 12 June 2023. Retrieved 25 December 2023.
  9. ^ Bush, Bill. "Hackers release reams of stolen Columbus data on dark web". The Columbus Dispatch. Retrieved 10 August 2024.
  10. ^ "Sea-Tac cyberattack caused by global ransomware gang, Port says". The Seattle Times. 13 September 2024. Retrieved 15 September 2024.
  11. ^ Breachsense. "Ranney School". www.breachsense.com. Retrieved 28 August 2025.
  12. ^ "Hackers appear to sell data stolen from Rutherford County Schools". WKRN News 2. 11 December 2024. Retrieved 11 December 2024.
  13. ^ Kitching, Chris (10 April 2025). "Hackers put price of $1.6M on student data". Winnipeg Free Press. Archived from the original on 14 April 2025. Retrieved 14 April 2025.
  14. ^ Burris, Journey (26 September 2025). "Ransomware attack on MDOT exposes personal data, disrupts bus tracking". The Baltimore Sun. Retrieved 23 October 2025.


๐Ÿ“š Artikel Terkait di Wikipedia

List of hacker groups

partial list of notable hacker groups, in alphabetical order: Anonymous, originating in 2003, Anonymous was created as a group for people who fought for

Marvel's Wolverine

characters were leaked online. The hackers, Rhysida, threatened to publish all procured images and resources obtained from the hack within seven days and they

List of security hacking incidents

Indian government. The hacker group Lulz Security is formed. April 9: The Bank of America website got hacked by a Turkish hacker named JeOPaRDY. An estimated

British Library cyberattack

In October 2023, Rhysida, a hacker group, attacked the online information systems of the British Library. They demanded a ransom of 20 bitcoin, at the

List of data breaches

employees". The Guardian. 2024-05-29. ISSNย 0261-3077. Retrieved 2024-06-11. "Rhysida ransomware gang claims British Library cyberattack". BleepingComputer.

Scattered Lapsus$ Hunters

and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks". The Hacker News. Retrieved 3 November 2025. "ShinyHunters Wage Broad Corporate Extortion

Prospect Medical Holdings

However, following a high-profile six-week cyberattack in 2023 by hacker group Rhysida against Prospect, YNHH began to raise concerns about Prospect's financial

Fur Affinity

2024, the Fur Affinity website's domain records were compromised. The hacker redirected the domain to other sites, including a fake Shopify storefront