TL;DR: RansomHub surfaced in February 2024 as a ransomware-as-a-service operation (tracking under earlier names Cyclops and Knight) and grew into one of the most active crews of 2024-2025 [1][6]. CISA, the FBI, MS-ISAC, and HHS published joint advisory AA24-242A on August 29, 2024 saying RansomHub had breached at least 210 victims across eleven U.S. critical-infrastructure sectors since February 2024 [1]. Confirmed victims include Halliburton (which disclosed $35 million in losses), Patelco Credit Union (726,000 customers), Planned Parenthood of Montana, the Manpower Lansing franchise (144,189 people), Bologna Football Club in Italy, and Change Healthcare (data leaked after the BlackCat/ALPHV exit scam) [2][3][4][5][6]. RansomHub affiliates break in through unpatched internet-facing appliances (Citrix, Fortinet, Apache ActiveMQ, Confluence, F5 BIG-IP, and SMBv1 exploits are all in the playbook), then use off-the-shelf admin software for everything from credential dumping to encryption [1]. This tracker is the running list: every confirmed victim, every CVE, every named indictment. Updated as cases develop.

What RansomHub Actually Is

RansomHub is a ransomware-as-a-service (RaaS) brand, not a single hacker. The operators run the leak site, the negotiation chat, and the payment infrastructure. Affiliates do the intrusions and split the proceeds. The BleepingComputer tag page for RansomHub and the CISA advisory both place the first known activity in February 2024 [1][6]. Symantec's Threat Hunter Team, writing about a multi-function backdoor linked to a RansomHub affiliate in March 2025, called RansomHub "previously known as Cyclops and Knight" and surfaced "in February 2024" [6].

Two things made RansomHub matter in 2024. First, the brand grew fast. By the August 29, 2024 advisory date, the FBI counted at least 210 victims across U.S. critical-infrastructure sectors in roughly six months of operation [1]. Second, RansomHub soaked up talent from older crews that had been disrupted. The ransomware ecosystem analyst community flagged RansomHub as a top destination for affiliates migrating off the groups that law enforcement had pressured that year. The Playbook is the playbook of every RaaS that came before: encrypt everything, steal it first, extort twice.

The technical fingerprint is internal and small. The CISA advisory documents a Windows file-encryptor that uses Curve 25519, encrypts files in 0x100000 (1 MiB) chunks with a skip size of 0x200000 bytes, appends 58 (0x3A) bytes per file, and ends every encrypted file with the four-byte marker 0x00ABCDEF [1]. Those numbers are what defenders look for when triaging a possible RansomHub hit.

Confirmed Victims (So Far)

This list covers the cases the victim company, a regulator, or a court filing has publicly tied to RansomHub. Click through for the breakdown of each attack.

At Least 210 Victims Since February 2024

The most authoritative single tally comes from the August 29, 2024 joint advisory AA24-242A: at least 210 victims across eleven U.S. critical-infrastructure sectors since February 2024 [1]. The sectors CISA names are water and wastewater, information technology, government facilities, healthcare and public health, emergency services, food and agriculture, financial services, commercial facilities, critical manufacturing, transportation, and communications [1]. The advisory does not list every victim by name; it lists sectors.

Change Healthcare (February 2024 onward)

The biggest single victim by records exposed. RansomHub picked up the Change Healthcare data after the BlackCat/ALPHV exit scam in 2024 and posted the records on the RansomHub leak site. A March 2025 Symantec summary cited by BleepingComputer puts the Change Healthcare breach at over 190 million individuals and notes the original $22 million payment had gone to BlackCat, not RansomHub [6].

Halliburton (August 2024)

Halliburton filed an SEC Form 8-K on August 23, 2024 disclosing that an "unauthorized third party" had gained access to its systems [2]. The company identified RansomHub as the responsible group a few days later. On November 11, 2024, Halliburton's CEO Jeff Miller told investors the incident cost $35 million and a $0.02 per share hit to adjusted earnings from lost or delayed revenue tied to the August cybersecurity event and storms in the Gulf of Mexico [2]. Halliburton operates in 70 countries, employs 48,000 people, and reported $23.02 billion in revenue at the time of disclosure [2].

Patelco Credit Union (June 2024)

Patelco, a not-for-profit credit union with assets exceeding $9 billion, told customers an unauthorized party first accessed its network on May 23, 2024, then accessed databases on June 29, 2024 [3]. The credit union disclosed the ransomware attack the same day and shut down customer-facing banking systems for about two weeks. Patelco confirmed on August 14, 2024 that the accessed databases contained personal information including full name, Social Security number, driver's license number, date of birth, and email address [3]. On August 15, 2024, RansomHub published the stolen data on its extortion portal [3]. Patelco's breach filing with Maine's Attorney General lists 726,000 impacted customers [3].

Planned Parenthood of Montana (August 2024)

On August 28, 2024, Planned Parenthood of Montana (PPMT) identified a cybersecurity incident affecting its IT systems and took portions of its network offline [4]. On September 4, 2024, RansomHub posted to its dark web extortion portal claiming 93GB of data and giving the organization six days to pay [4]. PPMT CEO and President Martha Fuller told BleepingComputer on September 5, 2024: "We are aware of the RansomHub post, and want to assure our community that we are taking this matter very seriously. We have reported this incident to federal law enforcement, and will support their investigation" [4]. The data theft had not been independently confirmed at the time of the disclosure. A separate Planned Parenthood Los Angeles (PPLA) ransomware incident in late 2021 exposed records of 400,000 patients, predating the RansomHub claim [4].

Manpower (Lansing franchise, December 2024 - January 2025)

ManpowerGroup disclosed a breach affecting 144,189 individuals in a filing with the Maine Attorney General on August 12, 2025 [5]. The unauthorized network access window ran from December 29, 2024 to January 12, 2025. The incident was discovered on January 20, 2025 while investigating an IT outage at the Lansing, Michigan franchise, and Manpower of Lansing learned on July 28, 2025 that personal information may have been involved [5]. A ManpowerGroup spokesperson told BleepingComputer the franchise "operates on an independent data platform, making this an isolated incident where no ManpowerGroup corporate systems were affected" [5]. RansomHub claimed responsibility in January 2025 and said it had stolen roughly 500GB of data including passport scans, IDs, SSNs, addresses, contact info, test results, corporate correspondence, financial statements, HR data analytics, and NDAs [5]. ManpowerGroup has over 600,000 workers in more than 2,700 offices serving over 100,000 clients worldwide and reported $17.9 billion in revenue with $3.1 billion in gross profit for the prior fiscal year [5].

Bologna Football Club (November 2024)

On November 19, 2024, RansomHub listed Bologna FC on its leak site and threatened to publish player and sponsor data [7]. The Italian club confirmed a "ransomware cyber attack recently targeted its internal security systems" and that "the crime resulted in the theft of company data which may appear online" [7]. The post also warned "it is a serious criminal offense to be in possession of such data or facilitate its publication or diffusion" [7]. RansomHub's message said the "club's management refused to protect the confidential data of players and sponsors" and that the group would publish "all medical, personal, and confidential data of all players of the club" within two days [7]. RansomHub attempted to blackmail the team by citing GDPR fines imposed on other sports organizations. Bologna refused to pay and the full dataset was published on the dark web [7].

Other Confirmed Victims Named in 2025 Coverage

The Symantec / BleepingComputer March 20, 2025 summary of RansomHub-tied activity also names Christie's auction house, Frontier Communications, Rite Aid, and Kawasaki's EU division as confirmed prior victims [6]. The list reflects the breadth of the operation: an auction house, a U.S. telecom, a national drugstore chain, and an industrial manufacturer all on one affiliate network.

The Playbook: How RansomHub Gets In

The CISA advisory AA24-242A lists the techniques in detail [1]. The core entry vectors:

  • Unpatched internet-facing appliances. RansomHub affiliates work a queue of known-exploited CVEs against edge devices. The advisory names CVE-2023-3519 (Citrix ADC remote code execution), CVE-2023-27997 (FortiOS heap buffer overflow), CVE-2023-46604 (Apache ActiveMQ remote code execution), CVE-2023-22515 (Confluence administrative account creation), CVE-2023-46747 (F5 BIG-IP authentication bypass), CVE-2023-48788 (FortiClientEMS SQL injection), CVE-2017-0144 (EternalBlue / SMBv1), CVE-2020-1472 (Zerologon), and CVE-2020-0787 [1]. The recurring theme: appliances that sat on the perimeter, unpatched.
  • Phishing and password spraying. Initial access via phishing emails (MITRE T1566) and password spraying against internet-facing endpoints (T1110.003) [1].
  • Post-access persistence. Affiliates create new user accounts for persistence and re-enable disabled accounts (T1136 and T1098) [1].
  • Credential dumping. Mimikatz is on the menu for OS credential dumping (T1003) [1].
  • Lateral movement and remote access. RDP (T1021.001), PsExec, AnyDesk, ConnectWise, N-Able, and Cobalt Strike. The list is the usual RMM and living-off-the-land pile [1].
  • Custom backdoors. In March 2025 Symantec reported a custom multi-function backdoor called Betruger, disguised as "mailer.exe" or "turbomailer.exe," used by at least one RansomHub affiliate [6]. The malware does keylogging, network scanning, privilege escalation, credential dumping, screenshotting, and file upload to a C2 server. Symantec's Threat Hunter Team told the outlet: "The functionality of Betruger indicates that it may have been developed in order to minimize the number of new tools dropped on a targeted network while a ransomware attack is being prepared" [6].
  • Defense evasion. Affiliates have used Kaspersky's TDSSKiller utility to disable EDR products, then run the encryptor. The CISA advisory lists indicator removal (T1070), WMI abuse (T1047), and impairing defenses (T1562.001) as standard techniques [1].
  • Exfiltration and extortion. Data goes out via asymmetric encryption (T1048.002), cloud storage (T1537), or unencrypted channels (T1048.003) before encryption. The encryption itself is the impact (T1486), plus shadow-copy deletion with vssadmin.exe to inhibit recovery (T1490) [1].

The single biggest lesson from AA24-242A is also the most boring one. Patching internet-facing appliances kills most of these initial access paths. The advisory puts it first. The rest of the mitigations, segmented backups, phishing-resistant MFA, least-privilege, EDR, logging, and JIT admin access, are the same list every CISA advisory writes. They are the same list because they are the things that work.

What You Can Do If You Are A RansomHub Victim

If you got a notification letter from Patelco, Manpower, Halliburton, or any other company in the CISA AA24-242A victim pool, take the offered identity protection. Then add these steps:

  • Freeze your credit at all three bureaus. Equifax, Experian, TransUnion. A credit freeze is free, instant, and stops new account fraud. Thaw it temporarily when you actually apply for credit.
  • File your taxes early. Stolen SSNs end up in fraudulent refund claims. The earlier you file, the less window a thief has to claim your refund.
  • Watch your Explanation of Benefits. For the Patelco and healthcare breaches, check medical insurance statements for providers you never visited. Stolen medical identity is a longer-tail risk than credit-card fraud.
  • Switch to a hardware security key or passkey on every account that supports it. SIM swap attacks bypass SMS MFA, and phishing-resistant MFA stops the password-spray step of the RansomHub playbook.
  • If your employer runs internet-facing Citrix, Fortinet, Confluence, or ActiveMQ: ask IT which version is in production and when it was last patched. The CVEs in the advisory are the ones being exploited in the wild right now. Unpatched is the worst answer.

If you are an IT or security lead at a company RansomHub might target, the single highest-impact change is to patch every internet-facing appliance on the AA24-242A CVE list before the next scan. The second highest-impact change is to enforce phishing-resistant MFA on every admin portal.

The Honest Takeaway

RansomHub is the clearest example of what happens when a ransomware ecosystem gets pressured by law enforcement. LockBit was disrupted. ALPHV exit-scammed. Affiliates scattered. RansomHub absorbed the talent, kept the playbook, and grew into a 210-victim operation in six months. The CISA advisory AA24-242A is the public accounting [1].

What does not change is the playbook. Internet-facing appliances that go unpatched, help desks that hand out MFA resets, and SMBv1 still enabled on a printer subnet are the front door, every time. The fix is procedural, not technical, and it has been on the CISA list since the first edition of AA24-242A.

This tracker will be updated as new victims are confirmed, additional indictments land, and the international cases move forward.

Sources

  1. CISA, FBI, MS-ISAC, HHS, #StopRansomware: RansomHub Ransomware (AA24-242A, August 29, 2024)
  2. BleepingComputer, Halliburton reports $35 million loss after ransomware attack (November 11, 2024)
  3. BleepingComputer, Patelco notifies 726,000 customers of ransomware data breach (August 26, 2024)
  4. BleepingComputer, Planned Parenthood confirms cyberattack as RansomHub claims breach (September 5, 2024)
  5. BleepingComputer, Manpower discloses data breach affecting nearly 145,000 people (August 12, 2025)
  6. BleepingComputer, RansomHub ransomware uses new Betruger multi-function backdoor (March 20, 2025)
  7. BleepingComputer, Bologna FC confirms data breach after RansomHub ransomware attack (November 29, 2024)