TL;DR: RansomHub surfaced in February 2024 as a ransomware-as-a-service operation, formerly known as Cyclops and Knight [1][6]. CISA, the FBI, MS-ISAC, and HHS published joint advisory AA24-242A on August 29, 2024, saying RansomHub had encrypted and exfiltrated data from at least 210 victims across eleven critical-infrastructure sectors since February 2024 [1]. Victims it claimed include Halliburton (which reported $35 million in losses), Patelco Credit Union (726,000 customers notified), Planned Parenthood of Montana, a Manpower franchise in Lansing, Michigan (144,189 people notified), and Bologna Football Club in Italy; it also leaked Change Healthcare data after the BlackCat/ALPHV exit scam [2][3][4][5][6][7]. Affiliates got in through phishing, password spraying, and known vulnerabilities in internet-facing systems such as Citrix, Fortinet, Apache ActiveMQ, Confluence, and F5 BIG-IP, then used common remote-access and admin tools to move through networks before encrypting [1]. According to BleepingComputer, the operation quietly shut down in April 2025, with many affiliates moving to DragonForce [9]. This page covers the cases publicly reported in 2024 and 2025; it is not a complete victim list, and no 2026 activity under the RansomHub name appears in the sources below.

What RansomHub Actually Is

RansomHub is a ransomware-as-a-service (RaaS) brand, not a single hacker. The operators run the leak site, the negotiation chat, and the payment infrastructure. Affiliates do the intrusions and split the proceeds. The CISA advisory dates its inception to February 2024 and describes it as "formerly known as Cyclops and Knight" [1]. BleepingComputer's March 2025 report on a RansomHub affiliate's custom backdoor gives the same history [6].

Two things made RansomHub matter in 2024. First, the brand grew fast. By the August 29, 2024 advisory date, the authoring agencies counted at least 210 victims across critical-infrastructure sectors in roughly six months of operation [1]. Second, the advisory says RansomHub had been "recently attracting high-profile affiliates from other prominent variants such as LockBit and ALPHV" [1]. The model is double extortion: steal the data first, then encrypt, then demand payment for both [1].

The CISA advisory documents an encryptor that typically uses Curve 25519, encrypts files in 0x100000-byte chunks while skipping 0x200000 bytes between chunks, appends 58 (0x3A) bytes to each file, and ends that appended block with the four-byte sequence 0x00ABCDEF [1]. Those numbers are what defenders look for when triaging a possible RansomHub hit.

Known Victims

This list covers publicly reported cases in which RansomHub claimed the attack and the victim confirmed a security incident. It is a selection, not a complete list. In several cases the victim did not name the attacker; the RansomHub link rests on the gang's own leak-site claim as reported by BleepingComputer.

At Least 210 Victims Since February 2024

The main official tally comes from the August 29, 2024 joint advisory AA24-242A: at least 210 victims across eleven critical-infrastructure sectors since February 2024 [1]. The sectors the advisory names are water and wastewater, information technology, government services and facilities, healthcare and public health, emergency services, food and agriculture, financial services, commercial facilities, critical manufacturing, transportation, and communications [1]. The advisory does not list every victim by name; it lists sectors.

Change Healthcare (February 2024 onward)

The original Change Healthcare attack was BlackCat/ALPHV's. BleepingComputer reports that RansomHub leaked Change Healthcare's stolen data after the BlackCat/ALPHV operation's $22 million exit scam, and describes the breach as the most significant healthcare breach in recent years, impacting over 190 million individuals [6].

Halliburton (August 2024)

Halliburton told the SEC in an August 23, 2024 filing that an unauthorized third party had gained access to its systems [2]. A few days later, reporting linked the attack to RansomHub, and a subsequent 8-K confirmed data had been stolen [2]. In November 2024, BleepingComputer reported that Halliburton had revealed $35 million in losses from the attack [2]. In the third-quarter 2024 earnings report, Chairman, President, and CEO Jeff Miller said: "We experienced a $0.02 per share impact to our adjusted earnings from lost or delayed revenue due to the August cybersecurity event and storms in the Gulf of Mexico" [2]. Halliburton operates in 70 countries, employs 48,000 people, and reported revenue above $23.02 billion [2].

Patelco Credit Union (June 2024)

Patelco, a not-for-profit credit union with assets exceeding $9 billion, told customers an unauthorized party first accessed its network on May 23, 2024, then accessed databases on June 29, 2024 [3]. The ransomware attack on June 29, 2024 forced it to shut down customer-facing banking systems, an outage that lasted about two weeks [3]. Patelco confirmed on August 14, 2024 that the accessed databases contained personal information including full name, Social Security number, driver's license number, date of birth, and email address [3]. Patelco did not name the attackers; RansomHub claimed responsibility on August 15, 2024, when it published the stolen data on its extortion portal [3]. A listing on the Maine Attorney General's website puts the number of impacted customers at 726,000 [3].

Planned Parenthood of Montana (August 2024)

On August 28, 2024, Planned Parenthood of Montana (PPMT) identified a cybersecurity incident affecting its IT systems and took portions of its network offline [4]. In early September 2024, RansomHub claimed the attack on its dark web extortion portal, threatening to leak 93GB of allegedly stolen data in six days [4]. PPMT CEO and President Martha Fuller told BleepingComputer, in a report published September 5, 2024: "We are aware of the RansomHub post, and want to assure our community that we are taking this matter very seriously. We have reported this incident to federal law enforcement, and will support their investigation" [4]. At the time of that report there was no confirmation that any data had been stolen [4]. A separate, earlier ransomware attack on Planned Parenthood Los Angeles (PPLA) in late 2021 stole records of 400,000 patients [4].

Manpower (Lansing franchise, December 2024 - January 2025)

Manpower notified 144,189 individuals of a data breach in a filing with the Maine Attorney General, reported by BleepingComputer on August 12, 2025 [5]. The unauthorized network access window ran from December 29, 2024 to January 12, 2025. The incident was discovered on January 20, 2025 while investigating an IT outage at the Lansing, Michigan franchise, and Manpower of Lansing learned on July 28, 2025 that personal information may have been involved [5]. A ManpowerGroup spokesperson told BleepingComputer the franchise "operates on an independent data platform, making this an isolated incident where no ManpowerGroup corporate systems were affected" [5]. Manpower did not attribute the attack to a specific group; RansomHub claimed responsibility in January 2025 and said it had stolen roughly 500GB of data including passport scans, IDs, SSNs, addresses, contact information, test results, corporate correspondence, financial statements, HR data analytics, and confidential contracts and NDAs [5]. RansomHub later removed the Manpower entry from its leak site, which BleepingComputer said suggests a ransom may have been paid [5]. ManpowerGroup has over 600,000 workers in more than 2,700 offices serving over 100,000 clients worldwide and reported $17.9 billion in revenue and $3.1 billion in gross profit for 2024 [5].

Bologna Football Club (November 2024)

On November 19, 2024, RansomHub listed Bologna FC on its leak site and threatened to publish player and sponsor data [7]. The Italian club confirmed a "ransomware cyber attack recently targeted its internal security systems" and that "the crime resulted in the theft of company data which may appear online" [7]. The club's statement also warned "it is a serious criminal offense to be in possession of such data or facilitate its publication or diffusion" [7]. RansomHub's message said the "club's management refused to protect the confidential data of players and sponsors" and that the group would publish "all medical, personal, and confidential data of all players of the club" within two days [7]. The gang had tried to pressure the club by listing examples of fines paid by other teams and by invoking GDPR fines as a threat. After giving Bologna an extension to pay, the gang published the complete stolen dataset on the dark web [7].

Other Victims Named in 2025 Coverage

BleepingComputer's March 20, 2025 report also lists the Christie's auction house, Frontier Communications, the Rite Aid drugstore chain, and Kawasaki's EU division among the high-profile victims RansomHub claimed [6]. In September 2025, furniture retailer Lovesac confirmed a data breach after RansomHub had claimed an attack on March 3, 2025; Lovesac did not name the attackers [9].

The Playbook: How RansomHub Gets In

The CISA advisory AA24-242A lists the techniques in detail [1]:

  • Unpatched internet-facing appliances. The advisory says exploits based on the following CVEs have been observed: CVE-2023-3519 (Citrix ADC remote code execution), CVE-2023-27997 (FortiOS SSL-VPN heap buffer overflow), CVE-2023-46604 (Apache ActiveMQ remote code execution), CVE-2023-22515 (Confluence administrative account creation), CVE-2023-46747 (F5 BIG-IP authentication bypass), CVE-2023-48788 (FortiClientEMS SQL injection), CVE-2017-0144 (EternalBlue / SMBv1), CVE-2020-1472 (Zerologon), and CVE-2020-0787 (Windows privilege escalation) [1]. All of these had patches available when the advisory was published.
  • Phishing and password spraying. Initial access via phishing emails (MITRE T1566) and password spraying (T1110.003), which the advisory says targets accounts compromised through data breaches [1].
  • Post-access persistence. Affiliates create new user accounts for persistence and re-enable disabled accounts (T1136 and T1098) [1].
  • Credential dumping. Affiliates used Mimikatz on Windows systems to gather credentials (T1003) and escalate privileges [1].
  • Lateral movement and remote access. RDP (T1021.001), PsExec, AnyDesk, ConnectWise, N-Able, Cobalt Strike, and Metasploit [1].
  • Custom backdoors. In March 2025, Symantec researchers described a custom multi-function backdoor they named Betruger, dropped under the filenames 'mailer.exe' and 'turbomailer.exe', and linked to at least one RansomHub affiliate [6]. Its capabilities include keylogging, network scanning, privilege escalation, credential dumping, screenshotting, and uploading files to a C2 server [6]. Symantec's Threat Hunter Team said: "The functionality of Betruger indicates that it may have been developed in order to minimize the number of new tools dropped on a targeted network while a ransomware attack is being prepared" [6].
  • Defense evasion. The CISA advisory says affiliates cleared Windows and Linux system logs (T1070), used WMI to disable antivirus products (T1047), and in some instances deployed RansomHub-specific tools to disable EDR (T1562.001) [1]. In September 2024, Malwarebytes reported RansomHub abusing Kaspersky's legitimate TDSSKiller tool to try to disable EDR services [8].
  • Exfiltration and extortion. Exfiltration methods depend on the affiliate; the advisory lists PuTTY (T1048.002), Amazon AWS S3 (T1537), HTTP POST requests (T1048.003), WinSCP, Rclone, Cobalt Strike, and Metasploit. The ransomware binary itself does not normally exfiltrate data. Encryption is the impact (T1486), and the advisory notes shadow-copy deletion with vssadmin.exe to inhibit recovery (T1490) [1].

The single biggest lesson from AA24-242A is also the most boring one. Patching closes the exploit-based entry paths, and the first item under the advisory's "Actions to take today" is to install updates as soon as they are released [1]. The rest of its mitigations include phishing-resistant MFA, offline and segmented backups, least privilege, and time-based (Just-in-Time) admin access [1].

What You Can Do If You Are A RansomHub Victim

If you got a breach notification letter from Patelco, Manpower, or another organization RansomHub claimed, take the offered identity protection. Then add these steps:

  • Freeze your credit at all three bureaus. Equifax, Experian, TransUnion. A credit freeze is free, instant, and stops new account fraud. Thaw it temporarily when you actually apply for credit.
  • File your taxes early. Stolen SSNs end up in fraudulent refund claims. The earlier you file, the less window a thief has to claim your refund.
  • Watch your Explanation of Benefits. For healthcare breaches such as Change Healthcare, check medical insurance statements for providers you never visited. Stolen medical identity is a longer-tail risk than credit-card fraud.
  • Switch to a hardware security key or passkey on every account that supports it. SIM swap attacks bypass SMS MFA, and phishing-resistant MFA blunts the password-spray step of the RansomHub playbook.
  • If your employer runs internet-facing Citrix, Fortinet, Confluence, or ActiveMQ: ask IT which version is in production and when it was last patched. The CVEs in the advisory were exploited by RansomHub affiliates in 2024, and patches exist for all of them.

If you are an IT or security lead at a company exposed to these techniques, the single highest-impact change is to patch every internet-facing appliance on the AA24-242A CVE list before the next scan. The second highest-impact change is to enforce phishing-resistant MFA on every admin portal.

The Honest Takeaway

RansomHub shows how fast a ransomware brand can grow when affiliates are looking for a new home. It attracted affiliates from LockBit and ALPHV, and grew into a 210-victim operation in about six months [1]. ALPHV's $22 million exit scam left Change Healthcare data in RansomHub's hands [6]. Then, in April 2025, RansomHub itself quietly shut down, with many affiliates moving to DragonForce [9]. The brand ended; the affiliates did not.

What does not change is the playbook. Unpatched internet-facing systems, reused passwords open to spraying, and phishing were the front door in AA24-242A [1], and the same affiliates carry those habits to whichever brand they work under next.

The sources on this page cover RansomHub activity from February 2024 to its April 2025 shutdown, plus breach notifications that followed later in 2025. No 2026 activity under the RansomHub name appears in them.

Sources

  1. CISA, FBI, MS-ISAC, HHS, #StopRansomware: RansomHub Ransomware (AA24-242A, August 29, 2024)
  2. BleepingComputer, Halliburton reports $35 million loss after ransomware attack (November 11, 2024)
  3. BleepingComputer, Patelco notifies 726,000 customers of ransomware data breach (August 26, 2024)
  4. BleepingComputer, Planned Parenthood confirms cyberattack as RansomHub claims breach (September 5, 2024)
  5. BleepingComputer, Manpower discloses data breach affecting nearly 145,000 people (August 12, 2025)
  6. BleepingComputer, RansomHub ransomware uses new Betruger multi-function backdoor (March 20, 2025)
  7. BleepingComputer, Bologna FC confirms data breach after RansomHub ransomware attack (November 29, 2024)
  8. BleepingComputer, RansomHub ransomware abuses Kaspersky TDSSKiller to disable EDR software (September 10, 2024)
  9. BleepingComputer, Lovesac confirms data breach after ransomware attack claims (September 8, 2025)