惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
I
InfoQ
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
Y
Y Combinator Blog
博客园_首页
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
A
About on SuperTechFans
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
C
Check Point Blog
B
Blog RSS Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Engineering at Meta
Engineering at Meta
B
Blog
爱范儿
爱范儿
Stack Overflow Blog
Stack Overflow Blog
aimingoo的专栏
aimingoo的专栏
WordPress大学
WordPress大学
F
Fortinet All Blogs
月光博客
月光博客
GbyAI
GbyAI

GRAHAM CLULEY

'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself Google's Gemini lets strangers send messages from your locked Android phone Anubis ransomware: what you need to know
When ransomware gets physical: cybercriminals turn to thr...
Graham CLULEY · 2026-05-14 · via GRAHAM CLULEY

For years, ransomware has been a crime committed at arm's length. Hackers in one country, victims in another. The only weapon is the hackers' threat to release stolen data, or leave your systems permanently encrypted.

But that's changing.

As a BBC News report describes, a growing number of online extortionists are no longer content with locking up your files and threatening to leak your data. Instead, they are making threats to hurt their victims. Or their families. Or staff who refuse to pay up.

A study last year by identity security firm Semperis found that 40% of ransomware attacks saw criminals threatening physical violence against employees who refused to pay.

In the United States that figure rose to 46%.

A spokesperson for Semperis, which helps organisations negotiate with ransomware attackers, told BBC News that one gang had left a threatening note on his own doorstep while he was working an incident for a US government agency.

In another case, Zac Warren of security firm Tanium described how a ransomware-hit hospital had received phone calls, where callers asked for nurses by name, and then recited their home addresses and social security numbers down the line.

The theory is that hackers themselves are unlikely want to get their own hands dirty in such intimidatory tactics, but instead post on message boards, offer cash, and recruit somebody local to do it for them.

I guess you can call it violence-as-a-service.

And the FBI has been taking note. Last summer it issued an alert about the loose-affiliated cybercriminal network known as "The Com", which is said to have sometimes resorted to violent tactics such as throwing bricks through windows, arson, kidnapping, and even shootings.

Some of the most disturbing instances of cybercrime spilling out into physical violence can be found where cryptocurrency and organised crime intertwine.

Last May, French police rescued the father of a cryptocurrency millionaire who had been kidnapped and held for ransom in a Paris suburb. According to reports the victim had one of his fingers cut off. More than 18 similar attacks against holders of large sums of cryptocurrency holders were reported across Europe last year.

With physical threats seemingly becoming more common than ever before, it's clearly important for defenders to learn some lessons.

Firstly, the personal information held by a company about its staff - such as home addresses and family details - must be considered critically important to protect. If hackers break into your network you are not just facing the threat of customer records and intellectual property being stolen, but also the material which could be used for intimidation.

Secondly, incident response plans must be looked at again. It is one thing to have a plan for restoring your company from backups, but it is quite another to have a plan for what to do when a member of staff takes a phone call from a stranger who knows their home address.