- Also known as: INC Ransomware, GOLD IONIC
- First observed: July/August 2023
- Believed origin: Russia-linked
- Model: Ransomware-as-a-Service (RaaS), double extortion with partial encryption
- Status: Active
Origin
Dark Reading's coverage of a 2026 threat research report from security vendor Acronis noted that, “INC is a group that emerged in 2023 and has claimed more than 800 victims to date - a ransomware actor that greatly benefited from the shutdown of ALPHV/BlackCat and the disruption of LockBit, a trait it shares with other ascendant gangs such as The Gentlemen.” The same report described the group's approach as unremarkable on the surface but effective, characterizing INC as a group that has "thrived by mastering the basics."
Threat detection firm SentinelOne, cited in early coverage of the group's activity by The Register, offered an assessment of INC's targeting philosophy, “INC Ransom is a relatively new gang on the block, spinning up in July 2023 and posting targets indiscriminately.” Cybersecurity firm Surefire Cyber's technical profile of the group's malware confirmed the operational timeline and named its formal tracking designation, stating that, “INC Ransom, also known as INC or GOLD IONIC, first emerged in July/August 2023 as a ransomware-as-a-service operation, marketing itself to victims as helping them "save their reputation" through paying ransoms.” Surefire's technical breakdown also noted the malware's speed-optimized design “employs partial encryption combined with multi-threading to accelerate the encryption process, with files encrypted and ransom notes written in both .TXT and .HTML formats as "INC-README.TXT" and "INC-README.HTML."
NHS Scotland: The attack that put INC on the map
INC Ransom's breakout moment came in March 2024, when it claimed a breach of NHS Scotland. The Register's coverage described how the group used the scale of stolen data itself as leverage, reporting that, “in typical fashion for modern-day ransomware and extortion groups, INC published a snippet of the alleged total 3TB of data it stole from the healthcare group, including patients' medical test results for both adults and young children, medication information, full names and home addresses, as well as the full names and contact details of medical professionals.” The Register's analysis suggested this level of disclosure indicated pressure tactics rather than confidence, noting “This dump of data could suggest the criminals behind the attack had grown less confident in their ability to secure a ransom payment, publicizing the attack to pressure the victim per the standard double extortion playbook.”
A Computer Weekly report situated INC's rise within the broader post-takedown ransomware landscape, describing it as “among a number of emergent ransomware operations that now seem to be filling the void left by recent law enforcement actions against the likes of ALPHV/BlackCat and LockBit - a technically savvy operation that, like LockBit, enthusiastically leverages zero-day vulnerabilities and has tended to favour attacking organisations in the healthcare and education sectors.”
McLaren Health Care: A second attack in twelve months
INC Ransom's attack on McLaren Health Care in Michigan was the health system's second major ransomware breach within a single year. BleepingComputer's coverage noted the scale of the organization affected, “McLaren is a nonprofit health system in the U.S. with $6.6 billion in annual revenue, operating a network that spans 14 Michigan hospitals with 2,624 beds, employing 490 physicians and 28,000 full-time staff while contracting with another 113,000 providers across Michigan and into Indiana.”
The attack took over several weeks before detection. BleepingComputer's timeline noted that, “the investigation determined that attackers maintained access to McLaren's and Karmanos' systems between July 17, 2024, and August 3, 2024, with a forensic review ultimately completed in May 2025 finding that 743,131 people had information stolen.”
Paubox reported that “a proposed $14 million settlement arising out of the two data breaches was reached with McLaren Health Care Corp, with McLaren not admitting wrongdoing but agreeing to the settlement to avoid prolonged litigation.” The same article noted the sequence of events fueled broader legal action, “the sequential nature of the incidents prompted multiple class action lawsuits alleging that McLaren failed to implement adequate safeguards and did not sufficiently strengthen its systems after the first breach.”
Paubox's technical description of INC Ransom's growing scale during this period showed just how much the group had expanded since its 2023 debut, “In 2025, the group increased its activities, listing over 300 victims, and - similar to ALPHV/BlackCat - most frequently targets the healthcare industry.”
Disruption to cancer treatment
Besides data-theft, some reports on INC Ransom's healthcare attacks have focused on the direct clinical consequences for patients undergoing active treatment. Security news outlet Breached. Company documented the human impact of the group's healthcare intrusions, describing how “patients undergoing cancer treatment, including chemotherapy and radiation, had appointments cancelled because doctors couldn't safely deliver therapies without compromised systems.” The same outlet tracked INC's growing pace through 2025, noting, “the group continued aggressive expansion with major attacks on healthcare, government, and manufacturing throughout 2024, and by 2025 had posted over 200 victims to its leak sites, becoming one of the top 10 most active ransomware groups - though the group's victim count represents only organizations that refused to pay ransoms, meaning the actual number of successfully compromised organizations is likely significantly higher.”
Affiliates and law enforcement response
INC Ransom operates on an affiliate model rather than carrying out every intrusion with its own team. Australia's Cyber Security Centre, in a joint advisory with New Zealand and Tongan authorities, described how affiliates conducting the group's attacks have escalated privileges by creating admin-level accounts and moving through victim networks. Microsoft's threat intelligence team has tied one such affiliate cluster, tracked as Vanilla Tempest, to the group, noting that the cluster switched to INC Ransom as its main payload in mid-2024 after previously relying on tools like BlackCat and Rhysida. So far, no INC Ransom operator or affiliate has been publicly identified in an arrest or indictment. Instead, the nonprofit Crime Stoppers International has taken the unusual step of offering a reward for information on the group, arguing in a released bulletin that the gang "shows no restraint against hospitals, healthcare providers, or critical services."
Tactics
INC Ransom's playbook favors speed and low cost of entry. Australian officials noted that affiliates get their initial access through spear-phishing campaigns, exploitation of unpatched internet-facing devices, or valid credentials bought from initial access brokers, before using legitimate software already present on a network to quietly move stolen data out. On the encryption side, a technical profile from Blackpoint Cyber found that the malware is engineered for speed, explaining that it multiplies the number of processor threads by four to accelerate the process, and only fully encrypts files smaller than 1MB while partially encrypting larger ones.
FAQs
What is Ransomware-as-a-Service (RaaS)?
RaaS is a business model where ransomware developers lease or license their malware and infrastructure to other criminals ("affiliates") in exchange for a cut of the ransom proceeds.
What does "double extortion" mean?
Double extortion is a tactic where attackers both encrypt a victim's files and steal a copy of the data beforehand, threatening to leak it publicly if the ransom isn't paid, giving victims two separate reasons to comply.
What is partial encryption, and why do groups use it?
Partial encryption only scrambles portions of each file rather than the whole thing, letting attackers lock down a network much faster while still making the data unusable without a decryption key.
How do initial access brokers fit into attacks like these?
Initial access brokers are separate criminals who specialize in breaching networks and then sell that access to ransomware affiliates.
