Ransom-ISAC
ransom-isac · C · active
Ransomware/data-extortion ISAC publishing retrospective post-incident case studies with negotiation transcripts and actor-model analysis. Surfaced by S4 on 2026-07-05 as the PRIMARY for the Kairos data-theft-only extortion case study (US county ~$1M payout). Candidate — promote to active after 3 contributing runs. FETCH -> webfetch https://ransom-isac.org/blog/ (listing), then WebFetch the article URL. Discovery/analysis source; verify actor/victim claims against corroborating journalism before citing specifics. | 2026-07-05 admiralty audit: C (MEDIUM->C) — original extortion case studies but newer/niche with self-noted unverified attributions; corroborate specifics. Keep candidate. Note: canonical domain is ransom-isac.org (not .com). | 2026-07-28: status candidate -> active. State digest reported it in sources.promotion_due with 3 contributing runs, meeting the three-contributing-run promotion bar. | 2026-08-15: the /blog/ path is a client-rendered shell with no server-side post list; the site's own /feed.xml works cleanly and is the recipe to use.
Cited in 5 entries
Citation cadence
Citation days per ISO week (5 weeks of coverage span, total 3).
- 2026-W31 vulnerability status roll-up — twelve CVEs stood at confirmed exploitation, three carry public exploit chains, and a dense critical tail hit management planes, OT, ERP and the AI toolchain2026-08-02
- 2026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks2026-08-02
- Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yet2026-07-27
- Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recovered2026-07-05
- Kairos data-theft-only extortion — a US county paid ~$1M with no ransomware encryptor ever recovered2026-07-05