<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Ransomware on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/ransomware/</link>
    <description>Recent content in Ransomware on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:45 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/ransomware/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)</title>
      <link>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</link>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</guid>
      <description>Executive Summary Sysdig’s Threat Research Team published or documented JADEPUFFER on 2026-07-01, assessing it as an end-to-end ransomware operation driven by a large-language-model agent. That date is a publication/documentation date, not an independently established victim-specific compromise date; one source places the activity in late June. The operation began against an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then reached a separate production environment running MySQL and Alibaba Nacos. No victim organization is publicly identified, and no affected-person count is reported.</description>
    </item>
    <item>
      <title>Conduent Business Services Data Breach (January 2025)</title>
      <link>https://securityblueprints.io/data-breaches/conduent-business-services-data-breach-january-2025/</link>
      <pubDate>Mon, 13 Jan 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/conduent-business-services-data-breach-january-2025/</guid>
      <description>Executive Summary Conduent Business Services, a business-process outsourcing provider for government agencies, health plans, and other enterprises, discovered on January 13, 2025 that an unauthorized third party had accessed a limited portion of its environment and that client-associated files had been exfiltrated. Subsequent investigation placed the beginning of unauthorized access on October 21, 2024. Conduent restored affected systems within days, and in some cases within hours, but the data review and notification process continued through 2025 and into 2026.</description>
    </item>
    <item>
      <title>Change Healthcare February 2024 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</link>
      <pubDate>Mon, 12 Feb 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</guid>
      <description>Executive Summary The Change Healthcare data breach involved a ransomware attack in February 2024, attributed to the BlackCat group, also known as ALPHV. This cyber assault led to considerable disruptions within pharmacy operations and potentially exposed sensitive client data. source Severity of Impact The breach significantly impacted Change Healthcare&amp;rsquo;s extensive network, which comprises over 1.6 million healthcare professionals, 70,000 pharmacies, and 8,000 healthcare facilities. The breach&amp;rsquo;s financial impact is estimated at $872 million, highlighting the substantial economic consequences.</description>
    </item>
    <item>
      <title>British Library Ransomware Attack October 2023</title>
      <link>https://securityblueprints.io/data-breaches/british-library-ransomware-attack-october-2023/</link>
      <pubDate>Sat, 28 Oct 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/british-library-ransomware-attack-october-2023/</guid>
      <description>Executive Summary The British Library experienced a ransomware attack carried out by the Rhysida ransomware group in 2023. This cyber incident was identified on October 28, 2023. Public announcements regarding ongoing technology outages followed on November 17, 2023. The attack demonstrated vulnerabilities within the library&amp;rsquo;s IT infrastructure, resulting in significant disruptions due to data encryption.&#xA;Severity of the Impact The ransomware attack severely affected services, disrupting digital and physical operations including public Wi-Fi and possibly internal human resources files.</description>
    </item>
    <item>
      <title>MGM Grand Data Breach - September 2023</title>
      <link>https://securityblueprints.io/data-breaches/mgm-grand-cyberattack/</link>
      <pubDate>Fri, 08 Sep 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/mgm-grand-cyberattack/</guid>
      <description>Executive Summary In September 2023, MGM Resorts International experienced a major cyberattack attributed to the hacking group Scattered Spider, known for its association with the ALPHV/BlackCat ransomware group. The attack resulted in significant disruptions to operations at MGM&amp;rsquo;s Las Vegas venues, including the MGM Grand and Bellagio, with estimated financial losses ranging from $80 million to $100 million. This incorporates direct impacts on revenue and heightened cybersecurity expenses. The attackers exploited vulnerabilities in service desk operations through social engineering tactics like vishing, which allowed unauthorized system access.</description>
    </item>
    <item>
      <title>MOVEit Data Breach June 2023</title>
      <link>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</link>
      <pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</guid>
      <description>Executive Summary In June 2023, a significant data breach involving the MOVEit Transfer software began; within its first weeks it had affected over 200 organizations globally, a toll that continued climbing for more than a year afterward (Axios ). This breach was triggered by exploiting a zero-day vulnerability, CVE-2023-34362, within the MOVEit Transfer tool by Progress Software Corporation. The Clop ransomware group, using its Ransomware as a Service (RaaS) model, claimed responsibility for the data theft operations.</description>
    </item>
    <item>
      <title>Yum! Brands Ransomware Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/yum-brands-ransomware-data-breach/</link>
      <pubDate>Thu, 06 Apr 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yum-brands-ransomware-data-breach/</guid>
      <description>Executive Summary In January 2023, Yum! Brands, which owns KFC, Taco Bell, and Pizza Hut, fell victim to a ransomware attack, resulting in a data breach. This incident compromised corporate and employee data and was publicly disclosed by Yum! Brands in April 2023. Formal notifications to employees and potentially affected individuals about the data compromise began around the same time.&#xA;Discovery and Disclosure The ransomware attack was first identified in January 2023.</description>
    </item>
    <item>
      <title>PharMerica Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/pharmerica-data-breach-march-2023/</link>
      <pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/pharmerica-data-breach-march-2023/</guid>
      <description>Executive Summary In March 2023, PharMerica, a prominent U.S. pharmacy services provider, encountered a notable data breach affecting approximately 5,815,591 individuals. This incident compromised sensitive patient information, impacting both PharMerica and its parent company, BrightSpring Health Services (source ).&#xA;Breach Timeline Intrusion Period: Unauthorized access was gained from March 12 to 13, 2023. Discovery Date: The breach was discovered on March 14, 2023. Public Disclosure: Notifications were issued to individuals on May 12, 2023.</description>
    </item>
    <item>
      <title>Los Angeles Unified School District (LAUSD) Ransomware Breach</title>
      <link>https://securityblueprints.io/data-breaches/los-angeles-unified-school-district-lausd-ransomware-breach/</link>
      <pubDate>Thu, 01 Sep 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/los-angeles-unified-school-district-lausd-ransomware-breach/</guid>
      <description>Executive Summary In September 2022, the Los Angeles Unified School District (LAUSD), the second-largest school district in the United States, experienced a significant ransomware attack orchestrated by the Vice Society gang. This incident, detected over the Labor Day holiday weekend, compromised more than 1,000 schools, affecting approximately 600,000 students and staff members. Sensitive data, including psychological evaluations and Social Security numbers, was exposed and disseminated on the dark web following LAUSD&amp;rsquo;s decision not to pay the ransom source .</description>
    </item>
    <item>
      <title>Norsk Hydro Ransomware Attack - March 2019</title>
      <link>https://securityblueprints.io/data-breaches/norsk-hydro-ransomware-attack/</link>
      <pubDate>Tue, 19 Mar 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/norsk-hydro-ransomware-attack/</guid>
      <description>Executive Summary In March 2019, Norsk Hydro, a significant global aluminum producer, encountered a ransomware attack via the LockerGoga malware. This attack caused substantial disruptions across 160 locations, impacting over 20,000 systems worldwide, and forced the company to shift to manual operations (source ).&#xA;Key Dates Discovery and Disclosure Date: March 19, 2019 Severity of Impact The attack resulted in significant financial repercussions, with initial losses estimated at $40 million USD within the first week, subsequently summing to over 350 million Norwegian krone (source ).</description>
    </item>
    <item>
      <title>NotPetya Ransomware Attack</title>
      <link>https://securityblueprints.io/data-breaches/notpetya-ransomware-attack/</link>
      <pubDate>Tue, 27 Jun 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/notpetya-ransomware-attack/</guid>
      <description>Executive Summary The NotPetya ransomware attack in June 2017 is considered one of the most destructive cyber incidents on record. Originating through a compromised update of MeDoc, a Ukrainian accounting software, the malware propagated swiftly, impacting organizations across more than 65 countries within hours of being detected on June 27, 2017. The event highlighted significant vulnerabilities in software supply chains.&#xA;Severity of the Impact NotPetya inflicted damages exceeding $10 billion globally, with significant disruptions in healthcare, logistics, and government sectors.</description>
    </item>
  </channel>
</rss>
