Emerging n0n Ransomware Gang Threatens to Destroy Backups to Force Financial Victims to Pay
New ransomware crew n0n listed 12+ victims in four days, hits financial services hardest and threatens to wipe backups and shadow copies so recovery fails without paying.

A ransomware crew that did not exist two weeks ago is going after the one thing victims count on to avoid paying: their backups.
The group calls itself n0n. Threat intelligence firm CyberXTron first spotted it on September 18, and by September 22 its Tor leak site already listed more than a dozen victims. That is a fast start for a brand-new operation.
Steal, encrypt, then threaten the backups
n0n runs the familiar double extortion playbook. It steals data, encrypts systems, and threatens to publish the files unless the victim pays. What sets it apart is an explicit third threat: it says it will encrypt or destroy backups and shadow copies so the victim cannot restore on their own.
That threat is the pressure tactic. There is no public evidence that backups were wiped in every case. But a company that suspects its recovery path is compromised has far less room to refuse, which is exactly the point.
Banks first
Financial services make up 23% of n0n's victims, the largest share. Technology, retail and education follow at 15% each, with healthcare, defense and professional services also on the list.
The United States is the most common location, but victims also sit in Vietnam, Uzbekistan, Brazil, Sweden and Luxembourg. For a crew this young, that spread suggests opportunistic targeting rather than a narrow focus.
Walking in with stolen logins
n0n does not appear to need an exotic exploit. Researchers say it gets in with credentials harvested by third-party infostealer malware, then escalates privileges and uses legitimate admin tools to stage data before encrypting. It is the same stolen-login economy that keeps fueling attacks like the AT&T extortion case tied to a US soldier.
Not everyone is paying. Some countdown timers on the leak site have already hit zero, and the stolen data went public.
CyberXTron calls n0n an active, credible threat. Its advice is basic hygiene done properly: enforce MFA, cut VPN and RDP exposure, apply least privilege, segment networks, watch for lateral movement, and keep backups isolated where an intruder with admin rights cannot reach them.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free