ZeroFox Intelligence Flash Report - Emerging Threat Actor Targets Data Backups
|by Alpha Team

ZeroFox Intelligence Flash Report - Emerging Threat Actor Targets Data Backups
Product Serial: F-2026-09-29a
TLP:CLEAR
In this Flash Report, ZeroFox researchers discuss a newly observed threat actor with a novel technique of threatening to encrypt or delete victim's data backups.
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On September 21, 2026, ZeroFox observed a new data leak site attributed to the threat actor "n0n”. By the next day, the group had already claimed over a dozen victims on the Tor-hosted site. During its short operational life, n0n has attacked across nearly all business sectors, with technology and professional services combined accounting for 46 percent of its targeting activity.
- What sets n0n apart from other recently launched threat collectives is its threat to encrypt or delete data backups. In recent months, ZeroFox has reported on an increase in the number of ransomware and digital extortion (R&DE) incidents eschewing the encryption model commonly seen in traditional ransomware attacks in favor of encryption-free data extortion.
- The combination of improved data backups and reduced ransom payments has likely created a trajectory in the R&DE landscape that trends toward less encryption and more data extortion. Further, it is unclear whether n0n is able to access victim data backups.
- With a sharp reduction in paid ransoms over the past several years, threat actors will very likely continue to deploy new techniques in an effort to increase profits and decrease reliance on expensive infrastructure. It is almost certain that further tactical experiments will continue over the next six to 12 months.
Tags: tlp:clear, dark web, threat actor