Cybersecurity authorities in Australia, New Zealand, and Tonga issued a joint advisory warning that the INC ransomware operation is actively targeting organizations across Oceania, with a pronounced impact on healthcare and other critical networks. Reporting highlights serious disruptions affecting 24/7 patient-care environments and notes that INC has expanded its operations globally while increasing focus on the region, prompting coordinated guidance from the ACSC, New Zealand NCSC, and CERT Tonga.
The advisory and follow-on analysis describe INC as a Ransomware-as-a-Service (RaaS) ecosystem that uses a distributed affiliate model, enabling multiple operators to deploy the ransomware while core actors manage extortion and payments. Defenders are urged to review the mitigation measures in the joint guidance, as the campaign reflects both the scale of INC’s affiliate-driven operations and the elevated risk to essential services—particularly healthcare providers—across Australia, New Zealand, and Pacific Island states.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Cybersecurity agencies from Australia, New Zealand, and Tonga issued a joint advisory warning of rising INC Ransom activity across the Pacific, especially against healthcare organizations. The advisory detailed the group's affiliate-driven RaaS model, common intrusion methods, and recommended mitigations such as MFA, hardened remote access, backups, and vulnerability management.
On 2025-06-15, INC Ransom attacked Tonga's Ministry of Health, disrupting its ICT environment and affecting core national healthcare services. The group later claimed responsibility on its leak site, and authorities publicly named alleged actor Roman Khubov, also known as "blackod."
In May 2025, a healthcare-sector victim in New Zealand was hit by INC Ransom, with servers and endpoints encrypted and data stolen. After the victim refused to pay, the group published the stolen data on its leak site.
Authorities said the INC ransomware operation, previously focused on the US and UK, began targeting organizations in Australia in mid-2024. ACSC later reported responding to 11 Australia-based incidents attributed to INC between 2024-07-01 and 2025-12-31.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.