INC Ransom
Aliases: INC, INC Ransomware
Source profile review date: 2026-06-21
Added to the source registry: 2023-08-09 · Source snapshot: 2026-09-15
Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.
Research status: Existing researched dossier
Locally generated translation; linguistic review is still pending.
Executive summary
INC Ransom is an active extortion group that is mainly relevant due to data diode, leak site claims and attacks on organizations where continuity and sensitive data weigh heavily.
INC Ransom is a current double-extortion threat: access is converted into data extortion, reputation printing and sometimes encryption. The group is practically relevant to care, education, government, industry and professional services.
Latest five known victim claims
Loading stored claims…
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Management summary
INC Ransom is one of the ransomware groups that have remained visible in victim feeds over recent years. The group is especially relevant because they are using data diary and publication pressure against organizations where downtime, privacy and reputation come together.
The risk for organizations lies in the preparation for encryption phase. If an actor can look around internally, collect privileges and select data, the incident is already serious before files are encrypted. INC Ransom should therefore be approached as a data and access threat, not only as a malware family.
For Amuneth users, this profile is useful as a checklist: are remote access, identity, data access and backups separated enough to slow down and make visible a human ransomware operator?
Grouping and development
INC Ransom became publicly visible as a double-extortion group with leak-site. The group claimed victims in multiple sectors and fits the broader trend in which data storage is often more important than technical encryption.
The group should not be confused with a static payload. As with many modern operations, exact access, tooling and impact may depend on affiliate or incident. Therefore, the profile must be directed to attack chain and behaviour.
INC Ransom remains relevant because many organisations still have insufficient data access and exfiltration visibility. Backup can restore systems, but no stolen data.
Operation and attack chain
A INC Ransom scenario usually starts with usable access: credentials, VPN, vulnerable systems, remote management or third-party access. Then comes domain, shares, applications and sensitive repositories discovery.
The actor tries to identify and collect valuable data. Note file share scraping, database exports,ZIP /7/RAR- archives, temporary staging locations, cloud sync and large outbound volumes.
For impact services can be stopped, security tools adjusted, shadow copies removed and encryption initiated. The exact payload behaviour can change; the preparatory actions are often more consistent.
Incident response should distinguish between claim, access, data diode and encryption. A leak site claim does not prove everything but is enough reason to secure logs around data access, outbound traffic and identity.
Known IOCs and artifacts
Artefacts are INC Ransom leak-site claims, ransom notes, proof files, archives, datastaging, outbound upload tracks, remote management tools and potentially encrypted file artifacts.
Hard IOC pictorials age quickly. Use hashes and infrastructure only with source, date and confidence. For structural detection behavior patterns are better: remote access anomaly, privilege escalation, bulk data access, exfiltration and impact preparation.
Make sure file server logs, cloud audit logs, EDR, firewall and identitylogs are kept long enough. Without these sources it is difficult to confirm or disprove a INC Ransom claim.
Victim pattern and lessons
INC Ransom is listed in public statements as one of the newer or rising groups in 2025. The group fits the pattern where affiliates switch to other programs after takedowns or brand problems.
Victims are not only interesting by sector, but by pressure value: sensitive data, operational dependency, public name, customer obligations and recovery complexity.
The lesson is that data classification, logging and exfiltration detection have administrative value. They determine whether an organization can quickly say what has been affected and what obligations apply.
How to arm yourself
Limit external access and admin rights. MFA, conditional access, PAM and periodic review of service accounts are directly relevant.
Detect data diode early. Bulk entries, archiving, unexpected exports and cloud sync outside normal patterns should alarm before encryption starts.
Test recovery and data breach response together. A restore test without scenario for stolen data is incomplete at INC Ransom-like threat.
Specific Hunts
Hunt at INC Ransom wide on data collection. Search for accounts that suddenly open many different shares, create database exports, run mailbox exports or access cloud storage in bulk. Leave this next to VPN- and SSO-logins.
Check command lines for archiving and staging: 7z, WinRAR, tar, robocopy, PowerShell Compress-Archive, rclone and cloud sync clients. Pay particular attention to output from servers where such tools are not normally running.
Also research security and repair preparation: stopped EDR-services, disabled logging, vssadmin, wbadmin, bcdedit, backup consoles access and privileged group changes shortly before data movement.
Exposure and prevention
INC Ransom affects organizations where data extortion gives administrative pressure. Therefore, exposure scans should not only view ports and patches, but also data exposure: which sensitive repositories are widely accessible?
Check SaaS and on-prem together. Many data diary stands run via SharePoint, OneDrive, Google Workspace, Salesforce, databases and file servers at once. A single file server check will then miss half.
Do not allow cloud sync, external shares and personal storage from servers. Use DLP or minimal alerting on large uploads and new external destinations.
Sources and uncertainty
INC Ransom is well visible in public feeds, but technical details vary per incident. Affiliates can use different tools, making IOC cyclists not universal.
A claim should be designated as extortion signal. Proven data diode requires logs around access, staging or outbound traffic, or convincing unique samples.
The profile should therefore describe behaviour and defence choices, which gives users value even when exact hashes are missing.
Executive Scenario and SOC
A INC Ransom scenario is often administratively difficult because the organization may still be operating while data has already been stolen. Without encryption, the urgency can be underestimated internally.
The SOC should therefore treat datahunting as an incident phase. New archives, file-share scraping, cloud exports and database dumps are not just suspicious activity; they may be the main damage point.
Management is about probability. Can we show which data has been hit, which have not, which customers may have been affected and which source logs are reliable? That determines legal and communicative choices.
What the visitor needs to check out in concrete terms
Check if sensitive datasets have owners. Data without owner rarely gets good logging, retention or access reviews. That's exactly what blackmailers benefit from.
Check cloud exports. SharePoint, OneDrive, Google Workspace, CRM and databases must give alerts on massive downloads or exports outside normal pattern.
Check if incident response also exercises .data breach without encryption . If you have ransomware playbooks with restore steps only, the dominant INC Ransom risk is missing.
Relationship with Amuneth Exposure
Exposure scans can enhance INC Ransom prevention by linking technical vulnerabilities to data routes. A vulnerable web app is more serious when it gives access to customer data or API- keys.
Reports should show customers what findings directly enable data digs: open backups, directory listing, old database dumps, admin panels and misconfigured cloud storage.
The scans are also an entry to talk about logging. A risk that is not logged can not be reliably assessed after a claim.
Additional Defence Notes
INC Ransom shows that data diodestall research should be as mature as malware research. An organisation should be able to demonstrate which data has been viewed, what data has been copied and what data may have been removed from the environment. Without this justification legal and customer communication remain speculative.
A good hunt starts with identity and ends with data. Who logged in, which device was used, what rights were active, which repositories have been hit, which archives have been created, and which outbound traffic followed? Only this will create a useful timeline.
Data minimisation is important for prevention. Ancient exports, double datasets and forgotten project shares increase extortion value without operational utility. Cleaning up data is also ransomware weasurability.
Additional operational questions
For INC Ransom, the log-in must be clear for each sensitive data type. For customer data, this can be a database audit log, file server auditing documents, an export log for SaaS and an emailbox audit trail for e-mail.
Check that security teams have access to those logs without waiting days for application administrators or suppliers. Extortion counts speed. A slow log request gives the actor more pressure space.
Limit old exports. Many organizations protect the source system well, but leave CSV-, Excel- or backup copies in project folders. For an extortionist, these copies have the same value as the live database.
Last control point
A final checkpoint at INC Ransom is communication between security, privacy and business. This actor often causes damage via data uncertainty. If technical teams cannot quickly explain which datasets have been hit, privacy and governance must decide on the basis of suspicions. Therefore, make advance appointments about evidence, data classification, customer impact and escalation.
Indicators of compromise (IOCs)
Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.
| Type | Value | Source | Context |
|---|---|---|---|
| behavior | double extortion via stolen data and leak site | public INC Ransom reporting | Main model. |
| behavior | bulk file access, archiving and exfiltration | ransomware operating pattern | Important detection. |
| artifact | INC Ransom proof files or victim claim | public leak-site monitoring | Extortion information; technically validating. |
Sources
Evidence and limitations
Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.