Risky Bulletin Newsletter
February 19, 2025
Risky Bulletin: It's probably not a good idea to pay RansomHub
Presented by
News Editor
A recent CISA report and a series of tweets from Equinix threat intel analyst Will Thomas made me realize that quite a few infosec and adjacent cybersecurity experts are not fully aware that paying ransoms to a rising ransomware crew named RansomHub carries quite a high risk of breaking US sanctions.
The group launched in February 2024, when it started advertising its Ransomware-as-a-Service offering in underground hacking forums.
They got incredibly lucky because, just three weeks later, law enforcement agencies across the globe dismantled LockBit, which was, at the time, the largest RaaS platform on the market.