RansomNews

ransomNews

delivers timely ransomware news, expert analysis, threat intelligence,
and monthly updates via the iconic RedACT and RedACTinsights reports

learn more about us

About Us

watchdogs in the age of digital warfare

real data. real threats.


ransomNews is an independent observatory dedicated to tracking and analyzing global ransomware activity. We monitor cyber extortion claims across the world, verify each incident manually, and compile clear, data-driven insights with a sharp focus on Italy.

Every month, we publish RedACT, in-depth report to inform, educate, and raise awareness - empowering businesses, institutions, and individuals to better understand the evolving ransomware landscape.

Our mission: to turn raw data into actionable knowledge, making cybersecurity a shared responsibility.

RedACT & dataset
follow us

FOLLOW US

Behind every alert, there’s a story - and a lot of work.
We sift through noise, verify facts, and enrich raw data to bring you clarity in the chaos of cyber threats. Follow us to see the bigger picture, and the small details that matter.

Stay up to date with real-time news on ransomware events, emerging threat groups, critical vulnerabilities, and more. We share timely alerts, expert insights, and key developments to keep you informed and ahead of the curve. Because cybersecurity awareness starts with staying connected.

What we do

ransomware disclosure, activity tracking & more

Ransomware Events Tracking

We monitor and jot down public claims made by threat actors, verifying their credibility. The data is then enriched and aggregated to provide a structured, up-to-date view of ransomware activity, supporting analysis, prevention, and response efforts.

Reports and Insights

We compile RedACT and RedACTinsights, free resources offering rigorously verified, data-driven reporting on ransomware activity and threat actors. Each edition distills complex intelligence into clear, structured insights, built to inform, and always grounded in verifiable evidence.

Open Source Threat Intel

We conduct deep OSINT and SOCMINT investigations to extract, verify, and contextualize threat actor claims and more. Turning open data and social signals into structured intelligence for proactive defense and strategic awareness.

Technical Data Support

We support organizations and institutions with tailored ransomware intelligence reports, sector-specific, data-driven, and designed to inform strategic decisions and strengthen cyber resilience.

Threat Landscape Briefings

We deliver curated threat landscape briefings, sector-specific, timely, and actionable. Each brief considers actual ransomware trends and scenarios, group activity, and vulnerabilities relevant to any organization.

Awareness

We raise awareness around invisible exposure: how our digital habits, overlooked traces, and public signals can silently map our vulnerabilities. Understanding what we reveal is the first step toward reclaiming control in an increasingly transparent world.

Where our data Speaks

From global stages to specialized forums, our insights power the conversation

RedACT and RedACTinsights

Our flagship outputs and bespoke sector reports

Intel Hub

Your central access point for ransomware knowledge

Lynx-Sinobi Incident Advisory

An incident advisory quick sheet about Lynx threat actor, now rebranded in Sinobi. Origin, tactics, infrastructure, and operational patterns.

akira ransomware group

An OSINT-based analysis of akira ransomware group's tactics, infrastructure, and operational patterns.

The Team

behind the firewall