惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
V
Visual Studio Blog
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
B
Blog
I
InfoQ
博客园 - 三生石上(FineUI控件)
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs
H
Help Net Security
博客园 - Franky
宝玉的分享
宝玉的分享
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
When ransomware gets physical: cybercriminals turn to thr...
Graham CLULEY · 2026-05-14 · via Consumer Insights

For years, ransomware has been a crime committed at arm's length. Hackers in one country, victims in another. The only weapon is the hackers' threat to release stolen data, or leave your systems permanently encrypted.

But that's changing.

As a BBC News report describes, a growing number of online extortionists are no longer content with locking up your files and threatening to leak your data. Instead, they are making threats to hurt their victims. Or their families. Or staff who refuse to pay up.

A study last year by identity security firm Semperis found that 40% of ransomware attacks saw criminals threatening physical violence against employees who refused to pay.

In the United States that figure rose to 46%.

A spokesperson for Semperis, which helps organisations negotiate with ransomware attackers, told BBC News that one gang had left a threatening note on his own doorstep while he was working an incident for a US government agency.

In another case, Zac Warren of security firm Tanium described how a ransomware-hit hospital had received phone calls, where callers asked for nurses by name, and then recited their home addresses and social security numbers down the line.

The theory is that hackers themselves are unlikely want to get their own hands dirty in such intimidatory tactics, but instead post on message boards, offer cash, and recruit somebody local to do it for them.

I guess you can call it violence-as-a-service.

And the FBI has been taking note. Last summer it issued an alert about the loose-affiliated cybercriminal network known as "The Com", which is said to have sometimes resorted to violent tactics such as throwing bricks through windows, arson, kidnapping, and even shootings.

Some of the most disturbing instances of cybercrime spilling out into physical violence can be found where cryptocurrency and organised crime intertwine.

Last May, French police rescued the father of a cryptocurrency millionaire who had been kidnapped and held for ransom in a Paris suburb. According to reports the victim had one of his fingers cut off. More than 18 similar attacks against holders of large sums of cryptocurrency holders were reported across Europe last year.

With physical threats seemingly becoming more common than ever before, it's clearly important for defenders to learn some lessons.

Firstly, the personal information held by a company about its staff - such as home addresses and family details - must be considered critically important to protect. If hackers break into your network you are not just facing the threat of customer records and intellectual property being stolen, but also the material which could be used for intimidation.

Secondly, incident response plans must be looked at again. It is one thing to have a plan for restoring your company from backups, but it is quite another to have a plan for what to do when a member of staff takes a phone call from a stranger who knows their home address.