Key Takeaways

  • Threat analysts report continued growth of the INC ransomware group, with Australia regularly appearing in victim disclosures
  • ACSC and Industrial Cyber data show INC among the most active global ransomware operations targeting healthcare and critical networks
  • Shifts in tooling, affiliate behavior, and regulatory obligations are reshaping how Australian organizations respond to ransomware activity

Acronis has outlined fresh evidence that the INC ransomware operation is expanding faster than previously modeled, placing increased pressure on Australian organizations. The group's rising victim count is compounded by the rapid pace at which it adjusts operations as other major cybercrime groups are disrupted.

INC emerged as a ransomware-as-a-service operation in 2023 and has already claimed more than 800 victims globally. This trajectory reflects broader turbulence in the ransomware market following enforcement actions targeting LockBit and the shutdown of BlackCat. Affiliates that once relied on larger operations have shifted to other platforms, accelerating growth for groups like INC that offer technical support, working infrastructure, and attractive profit sharing.

Australia features prominently in these disclosures. While the United States remains the primary target, threat data indicates Australia is regularly among the most impacted countries. The Australian Cyber Security Centre (ACSC) reported that between 1 July 2024 and 31 December 2025, it responded to 11 ransomware incidents linked to the INC Ransom operation in Australia. The ACSC noted an uptick in activity against high-value entities and critical networks, particularly healthcare providers. This aligns with data from Industrial Cyber, citing Comparitech findings, which shows INC became the most active ransomware strain targeting healthcare providers in 2025, accounting for 39 attacks globally and leading in confirmed incidents with 15.

Ransomware attacks on healthcare businesses, including vendors and service partners, rose 30% year-on-year in 2025. Analysts at Industrial Cyber noted that INC and several other strains contributed to 5,186 global ransomware attacks in the first nine months of 2025. That represents a 36% increase compared with the same period in 2024.

The Windows and Linux or ESXi variants of the INC ransomware have been rewritten in Rust. While Rust is traditionally known for modern software development, its performance characteristics support cross-platform development and make static and dynamic analysis more difficult for defenders. This challenge escalates when paired with targeted attacks on backup infrastructure. Recent incident reports detail scenarios where INC used a credential-dumping utility capable of extracting credentials from newer Veeam backup environments. When adversaries compromise these backup systems, victims face highly complex and costly recovery efforts.

Once an INC operator establishes a foothold, the workflow follows a sequence of reconnaissance, lateral movement, privilege escalation, data exfiltration, and encryption. The group uses a mix of opportunistic and targeted initial access methods, including credential theft, phishing, and the exploitation of public-facing vulnerabilities.

Many ransomware groups gravitate toward sectors that suffer disproportionately from downtime. INC’s targets include legal services, construction, manufacturing, technology, and healthcare. Service outages in any of these industries cause cascading operational and financial impacts, and the recurring appearance of Australian victims reflects a persistent level of exposure rather than a temporary spike.

A threat research evangelist at Acronis noted the group’s growth highlights how the ransomware market reorganizes quickly after major disruptions. Affiliates have expanded their tooling and target technologies linked to business continuity, increasing the likelihood of operational disruption during attacks.

Australia’s Cyber Security Act 2024 introduces mandatory ransomware and cyber-extortion payment reporting for entities with annual turnover above AUD $3 million and for critical infrastructure operators. Organizations must report such payments to the Department of Home Affairs or the Australian Signals Directorate (ASD), and civil penalties apply for non-compliance. This regulatory shift forces entities to establish formal processes for handling extortion demands, changing how incidents are managed at the board level.

Global ransomware patterns place INC’s growth into broader perspective. The U.S. Homeland Threat Assessment compiled in 2025 reported more than 5,600 publicly disclosed ransomware attacks worldwide in 2024. Fortinet summarized the data, noting that affiliate-driven operations such as INC Ransom sustain high global incident volumes. Similarly, the IEEE has published commentary on the rising complexity of cross-platform malware families, while analysts at Gartner point to the expanding use of scripting languages and commodity access tools in ransomware playbooks. Forrester emphasizes the necessity of identity-centric defensive architectures in enterprise security programs to combat these specific methods.

Defending against an evolving, affiliate-driven network requires organizations to implement strict multi-factor authentication, robust backup security, rapid patching cycles, and continuous monitoring for credential theft. These specific controls align directly with the NIST Cybersecurity Framework and the Australian Government’s Essential Eight mitigation strategies.

Numerous incidents still begin with compromised credentials or unpatched internet-facing systems. Prioritizing these attack vectors reduces overall ransomware risk. Even as adversaries adopt Rust-based payloads and sophisticated tooling, legacy security hygiene issues remain the primary entry points.

Australian organizations, especially those in healthcare and critical infrastructure, face a period of sustained pressure. The combination of growing affiliate networks, regulated reporting requirements, and the rapid adoption of new techniques by operations such as INC creates a complex operating environment. As analysts at IDC observe, aligning technical controls with business continuity planning is now a central priority for leadership teams reviewing budgets and risk. The rise of the INC ransomware group reinforces this requirement, demonstrating how rapidly the threat landscape shifts for enterprise networks.