Blackout is a crime-motivated ransomware group known for double-extortion attacks on the technology sector since 2024.
Analyst brief
Blackout is a crime-motivated ransomware group that emerged in early 2024, primarily conducting extortion operations. They target organizations in the Technology and Professional Services sectors across Japan, the United States, and the United Kingdom. The group operates a double-extortion model, combining data encryption with exfiltration and publication on a data leak site. Defenders should focus on network segmentation, regular offline backups of critical data, and monitoring for suspicious outbound traffic indicative of data exfiltration.
blackout
activecrime
Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site.