Ransomware Group n0n Targeted Global Backup Infrastructure

The newly identified operation uses double-extortion tactics and countdown timers to pressure victims into paying.

Updated on Sept. 24, 2026 in Cybersecurity

Isometric editorial illustration of a dense, industrial server rack stack in deep teal and slate blue, representing secure data storage.
Cybersecurity researchers are tracking the n0n ransomware group, which uses double-extortion tactics and threatens backup infrastructure to pressure victims into paying ransoms. AI Illustration. Upload story photo >

Live Poll

Do you trust that your organization has the necessary tools to prevent a ransomware data breach?

Cybersecurity researchers have identified a ransomware group known as n0n that threatens to destroy victim backup infrastructure. The group employs double-extortion tactics, publicly leaking data from organizations that refuse to pay ransom demands.

Why it matters

This group leverages countdown timers as a psychological tactic to force rapid payment, signaling an escalation in aggressive extortion methods within the threat landscape. The group specifically targets a broad range of sectors including finance, retail, and education across multiple continents.

The group primarily gains initial network access using credentials harvested by third-party infostealer malware. Once inside, attackers escalate their privileges to administrative tools to stage and manipulate internal data.

The players

n0n

A newly identified ransomware group that utilizes double-extortion and backup destruction tactics.

CyberXTron

A cybersecurity research firm that tracks and documents emerging threat actor behavior.

The details

The n0n group utilizes a strategy of double extortion, where attackers steal sensitive data before encrypting local files to threaten release on a leak site. By specifically targeting backup infrastructure for destruction, the group aims to eliminate recovery options for organizations that do not comply. Access is facilitated through previously stolen credentials, which allow the threat actors to move laterally into administrative environments.

Timeline

  1. September 18, 2026: Researchers first spotted activity by the n0n group.

  2. September 22, 2026: The group's leak site listed over a dozen victims.

  3. September 23, 2026: CyberXTron researchers published details about the group.

The Tech Race

The n0n group's strategy follows the precedent set by the double-extortion ransomware model, where data theft supplements file encryption to increase leverage. This development highlights an ongoing shift toward aggressive backup targeting as threat actors compete for victim compliance.

Organizations should prioritize securing administrative accounts and ensuring backup infrastructure is air-gapped or immutable to prevent unauthorized manipulation. Those in the financial, retail, and education sectors face the highest immediate risk of targeting by this group.

The takeaway

The rise of n0n emphasizes the necessity of robust, off-site backup strategies that remain inaccessible to network-wide administrative compromises. Security teams should monitor for the use of infostealer logs in corporate environments as a leading indicator of a potential n0n intrusion.

Further reading

For more context on current threat trends, browse our Cybersecurity section.

Live Poll

Do you trust that your organization has the necessary tools to prevent a ransomware data breach?

Ransomware Group n0n Targeted Global Backup Infrastructure