When people keep advising victims not to pay ransom because threat actors can't be trusted to really delete all the data, my inner researcher kicks in and wants to know how often that really happens.

So I started sending out inquiries.

Now you might think that those who publicly and repeatedly urge journalists to "spread the word" not to pay would respond and share some of their experiences with untrustworthy threat actors, but no..... they didn't even respond.

Read about the replies I did get, because they really surprised me.

I have no doubt that some professionals will hate what I have reported, but then, perhaps they should have responded, too, if they think differently.

How often do threat actors default on promises to delete data?
https://databreaches.net/2026/04/05/how-often-do-threat-actors-default-on-promises-to-delete-data/

#databreach #incidentresponse #ransom

@zackwhittaker @campuscodi @euroinfosec @lawrenceabrams @jgreig @securityaffairs @Hackread @h4ckernews

New playlist online: from malware analysis to ethical hacking demos. Check it out here πŸ‘‰ https://www.youtube.com/playlist?list=PLXqx05yil_meQN-JX5Ej-kj07xEK8QYLH
#Malware #EthicalHacking #CyberDefense #NetworkSecurity #IncidentResponse
260404 rootshell.online

YouTube
New playlist online: from malware analysis to ethical hacking demos. Check it out here πŸ‘‰ https://www.youtube.com/playlist?list=PLXqx05yil_meAulcBo3AfHjo3yM_aYpS3
#Malware #EthicalHacking #CyberDefense #NetworkSecurity #IncidentResponse
260404 rootshell.online

YouTube
New playlist online: from malware analysis to ethical hacking demos. Check it out here πŸ‘‰ https://www.youtube.com/playlist?list=PLXqx05yil_mflapCAVj54j9RMYOIFa4BD
#Malware #EthicalHacking #CyberDefense #NetworkSecurity #IncidentResponse
260404 rootshell.online

YouTube
The Modern SOC Analyst's Arsenal: Tools, AI, and Skills for 2026

I've spent years staring at dashboards at 2am, chasing false positives, and piecing together attack chains from fragmented log data. The job has changed dramati

I am a big fan of BakerHostetler's annual data security incident response reports because they are based on actual client experiences and data.

I just posted about their 2026 report, and commented on their healthcare sector data. As I had mentioned to @siguza, healthcare breaches tend to get higher ransom demands and higher settlements. Take a look at the 2025 data -- the highest initial ransom demand for a health entity client was $98M.

I'd love to know who the victim was and what TA or group demanded that much.

That said, the highest ransom actually paid for a healthcare sector breach by one of their clients last year was $5M.

Big delta.

My post: https://databreaches.net/2026/04/03/bakerhostetlers-2026-report-findings-from-1250-clients-breach-experiences-in-2025/

#ransomware #healthsec #incidentresponse #statistics #phishing #ransom #malware #databreach #cybersecurity

@campuscodi @amvinfe

This Is What a Personal Surveillance System Actually Looks Like

You stop thinking of it as surveillance. It becomes β€œthe system.” Just part of how things run.

https://cha1nc0der.wordpress.com/2026/04/03/this-is-what-a-personal-surveillance-system-actually-looks-like/

🧠Turn your team into threat hunters, one dice roll at a time πŸ’₯

🎲 π——π—¨π—‘π—šπ—˜π—’π—‘π—¦ & 𝗗π—₯π—”π—šπ—’π—‘π—¦: π—§π—›π—˜ π—¦π—˜π—–π—¨π—₯π—œπ—§π—¬ 𝗣𝗒π—ͺπ—˜π—₯ π—§π—’π—’π—Ÿ 𝗬𝗒𝗨 π——π—œπ——π—‘β€™π—§ π—žπ—‘π—’π—ͺ 𝗬𝗒𝗨 π—‘π—˜π—˜π——π—˜π—— - Klaus Agnoletti ( @klausagnoletti ) & Glen Sorensen πŸ›‘οΈ

Roleplaying isn’t just for nerds, it’s a proven method for building real security muscle. This talk reveals how structured tabletop roleplaying games unlock deeper learning, improve team cohesion, and turn abstract security concepts into lived experience. By simulating incident response, threat modeling, and zero-trust design through narrative-driven play, teams develop adaptive thinking, shared mental models, and faster decision-making under pressure.

Klaus Agnoletti https://www.linkedin.com/in/agnoletti/ is a freelance storytelling cyber security advisor, co-founder of BSides KΓΈbenhavn, neurodiversity advocate, and architect of playful security transformation through narrative and gamification.

Glen Sorensen https://pretalx.com/bsidesluxembourg-2026/speaker/J3PRCC/ is a Solutions Engineer at DeleteMe, former vCISO, and incident master for HackBack Gaming. 20+ years in security engineering, GRC, and operations. Passionate about OSINT, AI-powered social engineering, and using tabletop games to train real-world response.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg #GamifiedSecurity #CyberTraining #IncidentResponse #RolePlaying #SecurityLeadership #InfosecEducation #PlayToLearn

From pentesting tips to cloud defense, today’s curated cyber playlist has it all. πŸŽ₯ https://www.youtube.com/playlist?list=PLXqx05yil_mfPzrrUslCIwoih9RZQzDkQ
#PenTesting #AppSec #CyberSecurity #ThreatIntelligence #IncidentResponse
260402 rootshell.online

YouTube

@infoseclogger very nice framework, I like the clear yet really detailed workflow!

#forensics #incidentresponse