What Is n0n? And Is It Really Spelt Like That?
N0n is a newly-emerged cyber extortion gang (and yes, that's a zero, not an "o" in its first name). The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow.
So What Is n0n Threatening to Do?
Aside from the usual threat of "pay up or we leak your data", n0n claims that it shuts down victims' networks, and destroys backups and shadow copies. All of which would sound terrifying to the typical organization - but the group's claims should perhaps be treated with a pinch of salt.
So Is This Even Ransomware We Are Talking About?
The truth is that there is some disagreement in the community of cybersecurity researchers. Experts at CyberXTron describe what n0n does as "double extortion" - in other words, data is stolen alongside threats to encrypt or destroy backups. However, SOCRadar describes n0n as "focusing on data theft and extortion without relying on traditional ransomware."
Whatever It Is - I Don't Want Them Crawling Around My Network! How Do They Get in?
It appears that the breaches use valid usernames, passwords and other credentials that have been harvested by infostealer malware. The attacks take advantage of legitimate admin tools and RDP to move around networks - rather than exploiting an exotic unpatched software vulnerability.
I Know It's Early Days for n0n, but Have There Been Many Victims that Have Made the Headlines?
For now, the best we know are the unconfirmed claims from n0n's own leak site. These include: Transcom, a Netherlands-based outsourcer that runs customer support for major brands such as PayPal. The n0n gang claims to have exfiltrated 86.7 million support agent records from PayPal's Citrix and authentication systems, as well as a map of the internal network.
- Venezuela's largest ISP, Inter. N0n claims to have stolen over 15.3 million subscriber connection records, including customer addresses.
- US sports merchandise and ecommerce giant Fanatics is another organization that n0n claims to have hacked, stealing around 108 GB of data, including customer details, invoices from brand partners, and other financial details.
- TapClicks, a US marketing analytics platform has supposedly lost its full source code its multi-tenant management system, and one customer's marketing database. This includes user accounts with password hashes and ad platform credentials.
- Cloud hosting provider Dediserve is, according to n0n's claims, had 46 of its servers "paused", 167 customer accounts breached, and disk images of customer servers stolen.
So Can We Trust that These Organizations Have Really Been Hit by n0n?
Not yet. A hacking group published a company's name on a leak site is an accusation, not proof of a breach.
Nonetheless, It's Better to be Prepared...
Right. Here are some tips of what I would recommend to protect against attacks like those perpetrated by the n0n hacking gang:
- Enforce multi-factor authentication (MFA) whenever someone attempts to access systems from outside the organization. This is particularly important when it comes to VPN, RDP and cloud admin consoles.
- If you have any reason to believe credentials may have been stolen by infostealer malware, reset them to something unique, and hard to crack.
- Ensure that your network is segmented and that you have limited privileges.
- Ensure that cloud admin accounts are properly protected to prevent deletion.
- Properly protect your backups by keeping them offline, immutable, and with at least one air-gapped. You should always test that backups can be properly restored.
- Monitor outbound traffic for unusual data transfers which may indicate an unauthorized party is attempting to exfiltrate data.
- Put in place a plan for if your company ever receives an extortion threat - rather than just how it would deal if its data was encrypted. Remember that stolen data remains stolen, even if you restore from a backup.