Cybercrime

INC Ransom – Incident Response

The lawyers at ATB.LAW, experienced in cyberattacks, together with experts in IT, IT security, forensics, PR, and crisis communication, offer specific assistance – from the initial situation assessment to the legally secure handling of any ransom payment.

Ransomware attacks by the group INC Ransom increasingly affect Austrian companies, healthcare and educational institutions. Typical features are encrypted systems, exfiltrated data, and massive pressure from the threat of publication on a leak portal. In this situation, management, IT, data protection, and communication must make viable decisions within a very short time.

If you are currently affected by a ransomware attack, we are available to assist you at any time by phone available. We take over the coordination of an incident response team and support you in all aspects of damage management.

 

 

INC RANSOM

Table of Contents

What is behind the ransomware group INC Ransom?

INC Ransom is an organized ransomware and extortion group that has been active since around 2023, specifically targeting businesses and organizations. It is characterized by the combination of traditional encryption ransomware and systematic data exfiltration. The perpetrators operate their own leak portal on the Tor network, where they announce victims and publish data if no agreement is reached.

The main focus is on data sets with a high protection requirement: health data, client files, research and development data, internal communication and contract documents. Those affected include hospitals, industrial enterprises, professional service providers (including law firms and IT service providers), educational institutions and public bodies. The economic and reputational damage can be considerable, especially if sensitive data becomes public.

Typical workflow of an INC Ransom attack

An attack by INC Ransom proceeds in several steps. First, the attackers gain access to the network. This often happens via security vulnerabilities in externally accessible systems such as VPN gateways, remote access points, or appliances. Additionally, targeted phishing emails are used to obtain access credentials. Weak or reused passwords and a lack of multi-factor authentication facilitate this entry.

This is followed by a systematic reconnaissance of the network. The perpetrators analyze domain structures, file servers, backups, and particularly critical systems. In doing so, they often use legitimate admin tools to remain undetected and escalate their privileges up to domain admin rights. The goal is to gain the most comprehensive access possible to all relevant data assets.

In the next step, data is bundled and exfiltrated from the network. This affects file servers, mail systems, and databases containing personal data, trade secrets, and confidential documents in particular. This data later forms the core of the extortion.

Only then does the actual encryption phase begin. Important systems and data sets are encrypted, and local backups and recovery mechanisms are, as far as possible, deleted or rendered unusable. In the affected directories, INC Ransom leaves behind ransom notes with instructions for the perpetrators' communication portal. The extortion follows a twofold logic: payment for a working decryptor and an additional payment to prevent the publication or for the alleged deletion of the previously exfiltrated data.

INC RANSOM

Figure: Extortion letter / Ransom note INC Ransom

Possible consequences of an attack by INC Ransom

The immediate consequences usually affect the availability of IT systems. Business processes, production, logistics, patient care, or office operations can only be continued to a limited extent or not at all. If backups are missing or inadequate, the recovery time is extended considerably.

Added to this is the data protection law dimension. Due to the data exfiltration, the personal data of customers, patients, clients, employees, or business partners no longer resides exclusively with the data controller, but also with the attackers. This results in notification obligations toward data protection supervisory authorities and affected individuals, as well as potential liability for material and non-material damage. In regulated sectors, such as in healthcare or among professional secret holders, the requirements become even stricter.

At the same time, the reputation-related component comes into play. An entry on a leak portal, media coverage, or becoming known among customers can lead to a significant loss of trust. In addition to IT costs, this also causes damages through lost contracts, disrupted business relationships, and increased communication efforts.

Figure: Leak Portal INC Ransom

Prevention and preparation: Reduce the risk of ransomware attacks

Even though a ransomware attack can never be completely ruled out, the risk can be significantly reduced. A combination of technical and organizational measures is crucial.

At a technical level, consistent patch and vulnerability management plays a central role. Exposed systems such as VPN gateways, remote access points, or security appliances should be regularly updated and hardened. Consistently implemented multi-factor authentication for administrators, external access, and critical cloud services makes unauthorized access more difficult. In addition, network segmentation, restrictive permissions (least privilege), and a clear role and rights concept are important to hinder lateral movement within the network.

Equally essential is professional monitoring. Modern EDR or XDR solutions, centralized log analysis, and defined alarm thresholds help detect unusual activities at an early stage, such as mass encryption processes, suspicious file movements, or suspicious connections to the internet. Paired with a multi-stage backup concept—including offline or immutable backups and regularly tested recovery processes—technical resilience can be significantly increased.

At the organizational level, an incident response plan should exist that explicitly considers ransomware scenarios. Responsibilities for IT, management, data protection, legal, PR, and insurance should be clearly defined. The better prepared and practiced these structures are, the more orderly the response will be if INC Ransom actually strikes.

Help by ATB.LAW

ATB.LAW has already handled several complex ransomware incidents in which INC Ransom operated as a perpetrator group. In these engagements, we work closely with specialized partners from IT, IT security, forensics, PR, and crisis communication. Experience from real INC Ransom incidents flows directly into our consulting and operational support.

At the beginning, there is a structured initial assessment. Together with the technical incident management team, it is clarified which systems are affected, whether and to what extent data was exfiltrated, and what legal obligations currently exist, for example toward regulatory authorities, affected parties, professional organizations, or insurers. At the same time, we assist in establishing an internal crisis organization and in coordinating between management, IT, data protection, PR, and other stakeholders.

A central element of our INC Ransom assistance is taking over the negotiations with the attackers. We conduct the communication in the perpetrators' chat portals in a matter-of-fact, controlled tone and document all steps. The goal is to gain reliable information about the scope of the data and technical decryption options, and to take away time pressure. These negotiations take place in close coordination with management, IT forensics, and, if applicable, insurers.

Before any discussion about a ransom payment, a detailed sanctions and compliance check is conducted. In particular, this involves analyzing whether the specific payment to INC Ransom is permissible in light of sanctions law, terrorism financing, and anti-money laundering regulations. The review and the basis for the decision are documented in a comprehensible manner to ensure transparency vis-à-vis shareholders, supervisory bodies, and insurers.

If management decides on a payment as a last resort after careful consideration, we assist with the legally compliant structuring and processing. This includes, for example, phased payment models (test decryptor, partial payments, conditions), the involvement of specialized service providers for procuring and transferring the cryptocurrency, and the documentation of the entire procedure.

In parallel, we are assisting with the data protection review. This includes assessing the data breach, preparing notifications to regulatory authorities, drafting information letters to affected individuals, and coordinating with PR and crisis communication teams for external statements to the media, customers, and partners. The goal is to keep legal risks manageable while maintaining a credible and consistent communication strategy.

Conclusion: Why specialized INC Ransom help is crucial

INC Ransom is a professional and strategically operating ransomware group. It combines technical attacks, systematic data exfiltration, and massive psychological pressure through threats of publication. For affected companies, law firms, and institutions, this represents a multifaceted crisis in which technical, legal, and communicative aspects are inextricably linked.

A prepared organization with solid technical measures, clear responsibilities, and a resilient Incident Response Plan has significantly better chances of containing an attack. If an incident involving INC Ransom still occurs, specialized support can make all the difference—especially when it comes to negotiations, evaluating courses of action, and legally compliant implementation of the chosen strategy.

As Cybercrime Lawyers specializing in Incident Response we provide comprehensive support – legally sound, fast, and efficient. For further information and individual consultation, you can contact Roman Taudes available at any time. Contact us at office@atb.law or by phone at +43 1 39 123 45.

More articles

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Picture of Roman Taudes
Roman Taudes
Business Email Compromise (BEC)

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?
Picture of Roman Taudes
Roman Taudes
Cyberattack reporting obligations NIS GDPR MAR

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies
Picture of Roman Taudes
Roman Taudes