Ransomware Group n0n Targeted Global Backup Infrastructure
The newly identified operation uses double-extortion tactics and countdown timers to pressure victims into paying.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust that your organization has the necessary tools to prevent a ransomware data breach?
Cybersecurity researchers have identified a ransomware group known as n0n that threatens to destroy victim backup infrastructure. The group employs double-extortion tactics, publicly leaking data from organizations that refuse to pay ransom demands.
Why it matters
This group leverages countdown timers as a psychological tactic to force rapid payment, signaling an escalation in aggressive extortion methods within the threat landscape. The group specifically targets a broad range of sectors including finance, retail, and education across multiple continents.
The group primarily gains initial network access using credentials harvested by third-party infostealer malware. Once inside, attackers escalate their privileges to administrative tools to stage and manipulate internal data.
The players
n0n
A newly identified ransomware group that utilizes double-extortion and backup destruction tactics.
CyberXTron
A cybersecurity research firm that tracks and documents emerging threat actor behavior.
The details
The n0n group utilizes a strategy of double extortion, where attackers steal sensitive data before encrypting local files to threaten release on a leak site. By specifically targeting backup infrastructure for destruction, the group aims to eliminate recovery options for organizations that do not comply. Access is facilitated through previously stolen credentials, which allow the threat actors to move laterally into administrative environments.
Timeline
September 18, 2026: Researchers first spotted activity by the n0n group.
September 22, 2026: The group's leak site listed over a dozen victims.
September 23, 2026: CyberXTron researchers published details about the group.
The Tech Race
The n0n group's strategy follows the precedent set by the double-extortion ransomware model, where data theft supplements file encryption to increase leverage. This development highlights an ongoing shift toward aggressive backup targeting as threat actors compete for victim compliance.
Organizations should prioritize securing administrative accounts and ensuring backup infrastructure is air-gapped or immutable to prevent unauthorized manipulation. Those in the financial, retail, and education sectors face the highest immediate risk of targeting by this group.
The takeaway
The rise of n0n emphasizes the necessity of robust, off-site backup strategies that remain inaccessible to network-wide administrative compromises. Security teams should monitor for the use of infostealer logs in corporate environments as a leading indicator of a potential n0n intrusion.
Further reading
For more context on current threat trends, browse our Cybersecurity section.
Live Poll
Do you trust that your organization has the necessary tools to prevent a ransomware data breach?






