SECTION9 is an emerging ransomware and data-theft extortion group first observed in mid-2026. It appeared abruptly with a comparatively high volume of victim claims, including 13 claims in one reporting week, and was subsequently noted among newly emerged ransomware and data-theft groups claiming attacks against numerous companies. Available reporting associates the group with ransomware incidents and breach-style victim disclosures on leak infrastructure, indicating extortion activity centered on public victim naming and stolen-data pressure rather than only opportunistic malware deployment. High-confidence reporting confirms at least one claimed victim in the United States. SECTION9 has been tracked alongside other contemporary leak-site-driven ransomware actors and is notable primarily for its sudden emergence and early operational tempo. Publicly available information in this dataset does not support a reliable attribution to a nation-state sponsor, nor does it establish distinct sub-groups or additional widely used aliases beyond SECTION9/Section9.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly emerged data theft/ransomware group reported as claiming attacks on numerous companies.
Conducting a ransomware attack resulting in a data breach against a U.S.-based organization.
Ransomware group mentioned only for comparison with the prior week; present in week 28 but not among the most active in week 29.
Newly observed ransomware/extortion group in this dataset, debuting with a significant number of claimed victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.