Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

redact Ransomware Group

Ransomware group profile

2Victims
United StatesSource country
45Impact score

Description

Redact is a cybercrime group that emerged in May 2026, focusing on non-encrypting data extortion following the cessation of BlackFile. It employs sophisticated tactics such as identity compromise, voice phishing, and real-time bypassing of multi-factor authentication to extract sensitive data from high-value corporate targets, primarily in the healthcare, insurance, and financial sectors.

Key insights

  • Redact utilizes voice phishing (vishing) to gain initial access and capture user credentials.
  • They establish persistence in compromised sessions by registering unauthorized MFA devices.
  • Data exfiltration is conducted directly from cloud platforms using native APIs and automated scripts.
  • The group pressures victims by publishing stolen data on a Tor-based leak site.
  • Target sectors include healthcare, insurance, and financial services within the United States.
  • Redact operates as part of a decentralized cybercriminal ecosystem known as The Com.

Threat Level & Status Breakdown

For redact · Based on incidents in selected period

1.7threat level
Aggressiveness0.5/ 10
Lethality0/ 10
Criticality5/ 10

Status Breakdown

Claimed100.0%2
First seenJun 2026
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 10, 2026

Recent activity

Monthly attack count for redact in the selected period

2Total attacks
2peak in Jun
2avg / month
Jun00.511.52

Intelligence

IOCs, YARA/Sigma rules, and related families for redact

  1. 185.178.208.153
  2. 38.42.59.171
  3. 23.234.75.84
  4. 179.43.185.226
  5. 193.34.212.132
  6. 179.43.185.230
  7. 179.43.171.42
  8. 31.7.56.61
  9. 31.7.56.52
  10. 195.140.213.115
  11. 195.140.213.114
  12. 107.128.45.122
  13. 76.103.148.180
  14. 47.218.103.146
View full IOC feed90 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for redact

Credential Access

T1110

Brute Force

Defense Evasion

T1562

Impair Defenses

Discovery

T1046

Network Service Discovery

T1082

System Information Discovery

Impact

T1490

Inhibit System Recovery

T1486

Data Encrypted for Impact

Lateral Movement

T1021

Remote Services

Other

T1086

T1086

Persistence

T1078

Valid Accounts

Victims(2)

United StatesHealthcarehologic.com
Claimed
about 1 month ago
United StatesFinancial Servicesfcci-group.com
Claimed
about 1 month ago

Affected countries(3)

Countries where this group has been reported to target or leak victims.