n0n is a financially motivated cyber extortion group that emerged in September 2026, focusing on data theft and extortion without relying on traditional ransomware. They gain unauthorized access to corporate networks to threaten public disclosure of stolen data, targeting entities across various sectors worldwide.
Key insights
•Utilizes compromised credentials from third-party infostealer malware to gain access to corporate networks.
•Exfiltrates sensitive data such as Active Directory mappings and legal documents before issuing ransom demands.
•Employs public leak postings on the dark web to pressure victims into paying ransoms.
•Avoids traditional ransomware techniques, instead manipulating victim data using administrative tools.
•Targets sectors including investment services, telecommunications, retail, education, and pharmaceuticals.