A leak site that did not exist a week ago is now advertising ten victims, and the two names at the top of the list are a national education ministry and a national-scale internet provider. The group calls itself n0n. IntelFusions logged all ten claims on 18 September 2026; WatchGuard's ransomware tracker, which picked the crew up independently, dates the actual extortion posts to 12 through 14 September. Every detail below comes from the group's own leak-site postings or from trackers scraping them. Nothing here is confirmed by a victim, a regulator, or a national CERT, and no victim has publicly acknowledged an intrusion at the time of writing.
What Happened
A new extortion brand appeared with a fully populated victim list rather than the usual single test target. By IntelFusions' mapping the ten listings span eight countries: Argentina, Brazil, Luxembourg, Sweden, Turkiye, the United States (twice), Venezuela and Vietnam (twice). The sector spread is equally scattered: a government ministry, a telecoms operator, a teachers' union, a pharmaceutical subsidiary, three finance and payments firms, a legal services company, an education provider and a betting operator.
Victim counts already differ by tracker. IntelFusions counts ten listings. The GalaxyWarden breach tracker, a commercial takedown service rather than a research outfit, indexes eight n0n incidents. That gap is normal for a site being scraped by different importers at different hours, but it means any "n0n has hit N organisations" figure should be read as a snapshot, not a total.
The timeline is also softer than the single-date feeds suggest. IntelFusions is explicit that its 18 September stamp reflects when its importer first scraped the site, at 18:00 UTC that evening, not when the posts went up. WatchGuard's 12 to 14 September window is the better estimate of when n0n actually published.
Two individual listings have been documented in detail by third-party feeds. HackerFeeds recorded the United Federation of Teachers entry on 18 September with an active countdown expiring 19 September at 14:58 UTC, and the STOKR entry in Luxembourg with a deadline of 20 September at 22:40 UTC. UNDERCODE NEWS reports that RansomLook logged the UFT entry at approximately 16:07 UTC on 18 September, alongside an unrelated Securotrop listing for Prefix Corp posted the same day.
What Was Taken
Nothing is verified. What follows is what n0n claims, and the claims are about access and records rather than encrypted servers.
The Inter Venezuela figure is where sources visibly disagree. IntelFusions and the body text of the UNDERCODE NEWS report both put the claim at more than 15.3 million subscriber connection records plus a full internal network map. UNDERCODE's own headline says 153 million, a figure its article body contradicts within two paragraphs. Treat 15.3 million as the claimed number and the 153 million headline as an error, but note that neither has been checked against Inter's actual subscriber base.
The largest claim by raw volume is not Inter at all. IntelFusions reports that the listing naming Transcom WorldWide, an outsourced customer support provider, advertises 86.7 million connection records drawn from support agent sessions into a client's corporate remote access systems. That is a supply-chain claim wearing a call-centre label: the alleged value is not Transcom's own data but the agents' authenticated paths into someone else's network.
For the United Federation of Teachers, HackerFeeds reproduces a claim of roughly 181,420 documents forming the union's complete legal case archive: grievance and arbitration files, disciplinary appeal decisions, personnel case files named for individual members, collective bargaining agreements and side letters, nurse-federation and health-benefit-fund case materials, teacher evaluation and class-size complaints, and staff search and case-view audit logs.
The STOKR listing claims a KYC investor register with full names, emails, countries, nationalities, wallet addresses and tax IDs where present, an identity-to-wallet mapping covering investors in France, Germany, Switzerland, Belgium, the Netherlands, the UK and elsewhere, and an internal admin directory with staff accounts and roles. The post adds a threat rarely seen stated so plainly: the investor data will also be delivered to the tax authorities of the investors' countries.
An AstraZeneca Turkiye entry also appears in IntelFusions' mapping; the source text is truncated before the claimed volume, so no figure should be attributed to it.
Why It Matters
Encryption is conspicuously absent from every post. WatchGuard's tracker classifies n0n as a data broker rather than a crypto ransomware operation, records it as first seen in September 2026, and notes both direct and double extortion. Its one-line assessment of the group is simply "emerging and active." Defenders tuned for ransomware detection signals, mass file rewrites, shadow copy deletion, ransom notes on shares, will see none of that from an actor whose entire business is staged exfiltration.
The claimed data types matter more than the claimed counts. Connection records and internal network maps are targeting material: they support follow-on intrusion, SIM and account takeover, and physical-location inference on subscribers. The UFT archive, if real, is a dossier of named individuals in the worst moments of their employment, disciplinary cases, health-benefit disputes, grievances. The STOKR claim maps real identities to crypto wallets, which is both a deanonymisation set and a shopping list.
The tax-authority threat against STOKR investors is the strategic signal here. n0n is experimenting with coercion aimed at a victim's customers rather than its balance sheet, in a jurisdictional structure (Luxembourg platform, EU-wide investors) where the regulatory exposure is genuinely painful. Expect imitation.
Finally, the debut shape fits the 2026 market IntelFusions describes: more groups arriving, fewer victims apiece. A brand that opens with a ministry and a national ISP is buying credibility, and a new operator with something to prove has every incentive to publish on schedule rather than negotiate.
The Attack Technique
No source identifies an initial access vector, a malware family, or an exploited CVE. Any claim otherwise is not supported by the reporting available.
What can be inferred from the listings themselves is limited but useful. The Transcom claim describes records from support agent sessions into a client's corporate remote access systems, which points at third-party operator accounts as the pivot rather than a perimeter exploit. The Inter claim pairs bulk subscriber records with a network map, a combination more consistent with access to operational or provisioning systems than with a single database dump. Deadlines running 24 to 72 hours after posting, and the batch-publication language in the UFT post, suggest data was already staged before any listing went live.
Absence of encryption also implies the operator either lacked or chose not to use a locker, which lowers the technical bar for affiliates and removes the noisiest stage of a traditional ransomware intrusion.
Verification Status
Every source in this brief is OTHER-tier: aggregators, trackers and a commercial takedown vendor. There is no victim statement, no regulator filing, no CERT advisory, and no vendor forensic report. UNDERCODE NEWS says so directly for the Inter claim, noting the available evidence consists primarily of a threat-actor assertion rather than independently verified forensics. HackerFeeds carries the same caveat on both the UFT and STOKR entries.
Sources agree on the broad picture: a new group, a leak site, roughly ten claimed victims, no encryption. They disagree on when the posts appeared (12 to 14 September per WatchGuard, versus 18 September scrape stamps in the feeds), on how many victims are listed (ten per IntelFusions, eight per GalaxyWarden), and on the Inter record count (15.3 million in article bodies, 153 million in one headline). None of those disagreements is resolvable from open sources today.
What Organizations Should Do
- Audit third-party and BPO remote access now. The Transcom-style claim, agent sessions into a client's corporate systems, is the highest-leverage item on this list. Inventory every outsourced support account with access to your environment, enforce per-agent identities rather than shared logins, and require phishing-resistant MFA on the vendor side, not just your own.
- Hunt for exfiltration, not encryption. Tune detections for bulk egress: anomalous volumes to cloud storage and file-transfer services, unusual database export activity, and service accounts reading far outside their baseline. A data-broker operator will never trip your locker rules.
- Treat connection and session logs as crown-jewel data. Subscriber connection records, CDR-adjacent stores and network documentation deserve the same access controls, monitoring and retention limits you apply to payment data. Reduce what you keep and how long you keep it.
- Segment and restrict network documentation. Internal network maps and architecture diagrams should not be readable by everyone with a corporate login. Move them behind explicit access grants and log every read.
- Pre-build the customer-notification path for KYC and case-file data. If your organisation holds identity documents, wallet mappings, or named personnel case files, decide in advance who notifies affected individuals, which regulators apply, and what your position is when an actor threatens to route data to tax authorities. That decision is much worse to make against a 48-hour countdown.
- Monitor the leak site listings for your own supply chain. Two of the ten claims describe data belonging to a customer of the listed company. Your name may never appear on the site while your data does.
Sources: New extortion crew opens with a ministry and an ISP IntelFusions | Ransomware group N0n hits United Federation of Teachers HackerFeeds | N0n Ransomware Breach Tracker (8 incidents) | N0n Ransomware Claims Major Breach of Venezuela’s Inter ISP, Allegi... | N0n Ransomware Group Adds United Federation of Teachers and Prefix... | Ransomware group N0n hits STOKR (digital securities platform) Hack...