The N0n ransomware gang has quickly made a name for itself since its appearance in mid-September 2026. This cyber extortion group, identified by the zero in its name, has already listed around a dozen victims on its dark web leak site. The list of targeted organizations continues to expand, showcasing the group's aggressive approach.
N0n employs a strategy that includes threats to leak stolen data, shut down networks, and destroy backups and shadow copies. However, the claims made by N0n need careful examination. There is a split in opinion among cybersecurity researchers about the group's methods. CyberXTron describes N0n's actions as 'double extortion,' where data theft is accompanied by threats to encrypt or destroy backup systems. On the other hand, SOCRadar characterizes N0n as focusing solely on data theft and extortion without traditional ransomware tactics.
The group's attacks are facilitated by the use of valid credentials obtained through infostealer malware. Rather than exploiting complex software vulnerabilities, N0n leverages legitimate admin tools and Remote Desktop Protocol (RDP) to navigate and compromise networks. This method highlights the importance of credential security in defending against such attacks.
One notable claim from N0n involves Transcom, a Netherlands-based outsourcing company. The gang alleges it has exfiltrated 86.7 million records related to PayPal's customer support operations, including details from Citrix and authentication systems, and a map of the internal network. While these claims are serious, they remain unverified accusations at this point.
Organizations need to remain vigilant and implement robust security measures to protect against the tactics employed by groups like N0n. Ensuring strong password policies, monitoring network activity, and maintaining secure backup systems are essential steps in defending against these threats.

