Topic
Ransomware
Ransomware crews, double-extortion tradecraft, and what each campaign means for Saudi financial institutions.
42 articles in this topic
ScreenConnect CVE-2024-1708: Medusa Ransomware Threat to SAMA Banks
CISA added ConnectWise ScreenConnect CVE-2024-1708 to the KEV catalog on April 28, 2026, after China-linked Storm-1175 and North Korean Kimsuky weaponized the path-traversal flaw to deploy Medusa ransomware and ToddlerShark malware against managed service providers and their downstream customers.
RansomwareEverest Ransomware Hits Frost and Citizens: SAMA CSCC Lessons
Everest's April 2026 attacks on Frost Bank and Citizens Financial expose data-first extortion tactics SAMA-regulated banks must defend against now.
RansomwareCVE-2025-61882: Oracle EBS Clop Extortion Hits Saudi Banks
Clop is weaponizing Oracle EBS zero-day CVE-2025-61882 (CVSS 9.8) against insurers like Allianz UK. Saudi banks running EBS face direct SAMA CSCC and PDPL exposure.
RansomwareDragonForce Hits Conrad Capital: SAMA TPRM Lessons for Saudi Banks
DragonForce ransomware claims 74.23 GB of stolen data from US investment firm Conrad Capital Management. The breach delivers an urgent SAMA CSCC and TPRM wake-up call for Saudi financial institutions.
RansomwareQilin Ransomware Tops Q1 2026: Threat Profile for Saudi Banks
Qilin became Q1 2026's most active ransomware group with 342 victims worldwide and a sharpened focus on financial services. Here is what Saudi CISOs operating under SAMA CSCC need to act on this quarter.
RansomwareEverest Ransomware Hits Frost & Citizens Banks: A Saudi TPRM Wake-Up Call
Everest ransomware listed Frost Bank and Citizens Financial Group on its leak site after compromising a shared third-party vendor. For SAMA-regulated banks, this is a textbook stress test of CSCC Domain 4 controls.
Breaches & Data Leaks824,000 Customers Exposed: Marquis-SonicWall Lessons for Saudi Banks
An unpatched SonicWall firewall at a trusted banking vendor cascaded into an Akira ransomware breach affecting 80 banks and 824,000 customers. Saudi financial institutions face the same third-party exposure under SAMA CSCC.
RansomwarePayouts King Ransomware Hides Inside QEMU Virtual Machines to Evade Your EDR — A Critical Alert for Saudi Financial Institutions
A ransomware group tracked as STAC4713 is using QEMU — a legitimate open-source emulator — to spin up hidden Linux VMs inside Windows hosts, tunneling out over SSH while your endpoint security sees nothing. Saudi financial institutions are a high-value target.
RansomwareThe Gentlemen: The RaaS Group That Built a Database of 14,700 FortiGate Devices — and Why Saudi Financial Institutions Are in the Crosshairs
The Gentlemen ransomware group has grown 420% in a single quarter and maintains a database of 14,700 pre-exploited FortiGate devices. Saudi financial institutions running FortiOS must act now — here is what you need to know.
RansomwareAnubis RaaS: When Ransomware Weaponizes the Regulator — A Direct Threat to Saudi Financial Institutions
Anubis ransomware doesn't just encrypt your data — it threatens to report you to your own regulator. Here's why SAMA-regulated institutions face a uniquely dangerous exposure and what your SOC must do now.
RansomwareStorm-1175 Deploys Medusa Ransomware in 24 Hours Using Zero-Days in GoAnywhere and SmarterMail
Microsoft's April 2026 alert: Storm-1175 weaponized zero-days in GoAnywhere MFT and SmarterMail to encrypt victim networks within 24 hours — a direct threat to Saudi financial institutions relying on MFT platforms for SAMA-regulated data transfers.
RansomwareAkira Ransomware Claims 6 Victims in 96 Hours: A Saudi Financial Sector Alert
Akira ransomware escalated sharply in early April 2026, claiming six victims in under 96 hours including an insurance firm with 63GB of sensitive data stolen. Here is what Saudi financial institutions must do today.