October 11, 2026

#5 INC Ransom

inc ransom

Inc Ransom continues to pose a significant cyber security threat to organisations across Australia and New Zealand. Its broad targeting strategy, ransomware-as-a-service (RaaS) model and focus on data extortion mean organisations across multiple industries need to prepare for potential compromise.

Who is Inc Ransom?

Inc Ransom, also known as the Inc Ransomware Group, has been active since 2023 and continues to conduct ransomware and data-extortion operations.

The group is generally assessed to be a Russian-speaking, financially motivated ransomware-as-a-service (RaaS) operation, rather than a single publicly identified individual or definitively named core crew. Public reporting most consistently associates it with a Russian-based criminal ecosystem.

Its RaaS model allows affiliates to conduct intrusions and deploy ransomware within a broader criminal service structure. This means attacks attributed to Inc Ransom may involve different individuals and affiliate operators, rather than one consistent team using identical methods in every incident.

New Zealand’s National Cyber Security Centre (NCSC) and the Australian Cyber Security Centre (ACSC) have highlighted the threat posed by Inc Ransom and its affiliates to organisations across the region.

The group uses a double-extortion approach, seeking to disrupt victims through ransomware while threatening to publish stolen information to increase pressure on victims to pay.

Recent activity demonstrates its continued reach across multiple regions and industries. Between 1 and 7 October 2026, the group claimed victims in education, government, construction, manufacturing, utilities, sports and healthcare across North America, Europe, Asia and the Middle East. Among its recent high-profile claims is an alleged major healthcare data breach involving Winnipeg’s Health Sciences Centre. As with other ransomware leak-site claims, these allegations should be distinguished from independently verified incidents.

Although many publicly listed victims are based in the United States and Europe, Inc Ransom has also demonstrated a sustained presence in Australia. This is particularly relevant to New Zealand organisations given the shared technology ecosystem, interconnected supply chains and similarities in the operating environments of organisations across both countries.

Why is Inc Ransom a threat to NZ and Australian organisations?

1. Broad, opportunistic targeting

Inc Ransom does not appear to restrict its operations to one industry or a particular class of organisation. Its reported victims span healthcare, professional services, finance, industrial distribution, energy, engineering and telecommunications.

Organisations should not assume they are unlikely to be targeted because they are small, operate outside critical infrastructure, or lack the profile of a major enterprise. Businesses may hold valuable information, provide access to larger partners or depend on systems whose disruption creates significant operational pressure.

2. Healthcare and sensitive information

Healthcare is a particularly concerning area of exposure. Medical and associated service providers hold sensitive personal information, clinical records and commercially valuable data. A compromise can create privacy, regulatory, financial and reputational consequences beyond the immediate cost of restoring systems.

Inc Ransom’s reported healthcare victims, including Australian healthcare organisations and its claim involving Winnipeg’s Health Sciences Centre, highlight the importance of protecting both clinical systems and the business applications supporting healthcare delivery.

The potential consequences extend beyond service disruption. Stolen information may expose patients, employees and business partners to privacy risks, fraud or further targeted attacks.

3. Data theft extends the impact beyond encryption

Modern ransomware incidents are not simply a matter of restoring encrypted servers. Where attackers steal information before deploying ransomware, restoring systems does not remove the risk of data disclosure.

Potential consequences include privacy breaches, contractual disputes, regulatory scrutiny, fraud and harm to affected individuals.

Organisations should therefore maintain controls for preventing and detecting data exfiltration alongside tested backup and recovery arrangements. Incident response plans should account for the possibility that sensitive information has been stolen even when systems can be restored successfully.

4. Third-party and supply-chain exposure

The diversity of Inc Ransom’s reported victims demonstrates why security assurance must extend beyond an organisation’s primary IT environment.

Business service providers, engineering firms, healthcare suppliers and telecommunications organisations may hold information or provide access that matters to their customers and partners.

Australian and New Zealand organisations should consider how a compromise of a supplier, managed service provider or shared technology platform could affect their own operations. Third-party access should be restricted, monitored and periodically reviewed.

5. A changing affiliate ecosystem

The RaaS model adds another layer of complexity. Different affiliates may use different initial access methods, tools and infrastructure. Defenders who focus exclusively on a single set of indicators of compromise may therefore miss related activity using different techniques.

Organisations should prioritise behavioural detection and security controls that address the broader attack lifecycle, including initial access, credential misuse, reconnaissance, lateral movement, data theft and ransomware deployment.

Recent Inc Ransom victim listings in Australia

The following organisations appeared in the supplied Inc Ransom victim-listing data during 2026. These are group-posted claims and should not be interpreted as independent confirmation of compromise or the extent of any data breach.

Organisation Domain name First post date (UTC) Industry
Brighton East Dental Clinic bedc.com.au 12 August 2026 Healthcare
LCC Group lccgroup.com 3 August 2026 Advertising, Marketing, Business Services
Partnered Health partneredhealth.com.au 30 July 2026 Healthcare
Metaval (Australia) metaval.com.au 17 May 2026 Industrial Distribution
Earth Systems earthsystems.com.au 7 May 2026 Energy and Natural Resources, Engineering
BDAC bdac.com.au 13 April 2026 Non-governmental organisation, Healthcare
Mastercom Australia mastercom.com.au 11 April 2026 Telecommunications
Rx Management rxm.com.au 8 April 2026 Pharmaceuticals
Submission Finance submissionfinance.com 30 March 2026 Finance

Source: supplied Inc Ransom victim-listing data. First post dates indicate when the organisations were first listed in the dataset, not necessarily when the initial compromise occurred.

The listings illustrate the breadth of the group’s reported Australian targeting. Healthcare appears multiple times, alongside finance, telecommunications, engineering, industrial distribution and business services.

No New Zealand victim was included in the supplied dataset. This should not be interpreted as evidence that New Zealand organisations are unaffected or not at risk.

MITRE ATT&CK techniques and defensive considerations

The following table maps the supplied technique IDs to their MITRE ATT&CK names and highlights the defensive relevance for organisations in Australia and New Zealand.

These techniques describe behaviours relevant to the supplied TTP set. They should not be interpreted as confirmation that Inc Ransom uses every technique in every intrusion.

Technique ID MITRE ATT&CK technique Defensive consideration
T1190 Exploit Public-Facing Application Patch internet-facing applications and investigate exploitation attempts.
T1566 Phishing Use email security, phishing-resistant MFA and user reporting mechanisms.
T1078 Valid Accounts Detect unusual sign-ins, privilege escalation and suspicious account use.
T1021.001 Remote Services: Remote Desktop Protocol Restrict RDP exposure, enforce MFA and monitor remote logons.
T1047 Windows Management Instrumentation Monitor unusual WMI execution and remote administrative activity.
T1046 Network Service Discovery Detect unexpected network scanning and service enumeration.
T1049 System Network Connections Discovery Monitor suspicious commands and processes enumerating network connections.
T1069.002 Permission Groups Discovery: Domain Groups Alert on unusual domain-group enumeration and reconnaissance.
T1087.002 Account Discovery: Domain Account Monitor unexpected bulk account discovery and directory queries.
T1135 Network Share Discovery Monitor enumeration of file shares and sensitive repositories.
T1105 Ingress Tool Transfer Detect suspicious downloads and tools introduced into endpoints.
T1219 Remote Access Tools Restrict unauthorised remote access software and monitor its installation and use.
T1537 Transfer Data to Cloud Account Monitor unusual transfers to external cloud accounts and storage services.
T1560.001 Archive Collected Data: Archive via Utility Detect unusual archive creation, especially involving large volumes of sensitive files.
T1562.001 Impair Defenses: Disable or Modify Tools Alert on attempts to disable security tools, logging or endpoint protection.
T1569.002 System Services: Service Execution Monitor suspicious service creation and remote service execution.
T1570 Lateral Tool Transfer Detect tools copied between hosts using administrative shares or other transfer mechanisms.
T1490 Inhibit System Recovery Alert on deletion of shadow copies and changes to backup or recovery configurations.
T1070.004 Indicator Removal: File Deletion Investigate suspicious deletion of logs, tools and other forensic artefacts.
T1486 Data Encrypted for Impact Detect abnormal file-modification rates and widespread encryption activity.

What organisations should prioritise

For security teams and technology leaders, Inc Ransom’s activity is a prompt to review the attack paths and business consequences commonly associated with ransomware operations.

1. Reduce initial access opportunities

Prioritise patching internet-facing systems, securing remote access and strengthening identity controls. Enforce multifactor authentication, preferably phishing-resistant methods for privileged and high-risk accounts, and investigate suspicious authentication activity.

2. Improve detection coverage

Ensure endpoint, identity and network telemetry can identify reconnaissance, lateral movement, suspicious remote administration and attempts to disable security controls. Detection rules should be tested regularly and tuned to identify meaningful behaviours rather than generating unmanageable alert volumes.

3. Protect sensitive information

Review access to clinical records, financial data, customer information and shared file repositories. Apply least privilege and monitor abnormal bulk access, archive creation and outbound transfers. Consider where sensitive information is stored and which third parties can access it.

4. Protect recovery capability

Maintain isolated or immutable backups and regularly test restoration. Monitor attempts to delete backups, remove shadow copies or inhibit recovery. Recovery plans should account for compromised administrator accounts and the possibility that production systems cannot be trusted immediately after an incident.

5. Prepare for data extortion

Establish procedures for investigating suspected data theft, assessing the information involved, engaging incident responders and meeting applicable regulatory and contractual obligations. Ensure executive leadership understands that successful restoration does not necessarily resolve the privacy and extortion aspects of an incident.

6. Review third-party exposure

Assess the access granted to suppliers, managed service providers and other external parties. Require appropriate authentication, logging and access restrictions, and ensure third-party incidents can be escalated quickly.

Conclusion

Inc Ransom is a relevant threat to Australian and New Zealand organisations because its reported victim profile is broad, its operations combine ransomware with data-extortion pressure, and its Australian victim listings span multiple industries.

Its ransomware-as-a-service structure also means that individual affiliates, tools and infrastructure may change, making it important to defend against the behaviours associated with the broader attack lifecycle rather than relying exclusively on static indicators.

No organisation should assume it is too small, too specialised or insufficiently profitable to be targeted. Effective preparation requires layered prevention, early detection, strong identity security, protection of sensitive data and recovery plans that remain available even if attackers compromise the primary environment.

Organisations should use Inc Ransom’s activity as a prompt to validate their defensive controls, test their incident response arrangements and assess their exposure to data extortion—not rely on victim lists alone to determine their risk.