← The Desk The Wire RSS
The Perimeter Site

The current playbook of INC ransomware

Dr Amara Osei
2026-08-04
# The current playbook of INC ransomware The noise in the wire this week is deafening. We've seen reports of over 100,000 UK police officer records leaked by ExfilSquad and a massive breach at Paidwork involving over 23 million user records. While these headlines dominate the feed, alongside ADT's loss of 5.5 million accounts and an npm worm poisoning hundreds of packages, there is a quieter, more calculated shift happening with INC ransomware. INC isn't just exploiting a zero-day in SonicWall products; they are changing how they apply pressure once they're inside. Specifically, they've moved toward direct phone calls to victims. This is not an accidental evolution. It's a psychological pivot. Most ransomware groups rely on the "leak site" as their primary lever: a digital billboard of shame that forces a company to negotiate or face public exposure. By moving the conversation to a phone call, INC bypasses the corporate filter. An email from a hacker can be forwarded to legal and IT teams for hours of deliberation. A ringing phone in an executive's office creates an immediate, visceral state of emergency. It triggers a fight-or-flight response that often leads to mistakes in negotiation or a rushed decision to pay. My confidence level that INC is the primary driver behind this specific combination of SonicWall exploits and vishing is moderate. The telemetry on the exploit itself is cleaner than the attribution of the phone calls, which are reported by victims rather than captured in logs. To move this to high confidence, I would need to see overlapping C2 infrastructure between the initial zero-day entry and the communication channels used for the call coordination. I distrust fast attribution here because zero-days are rarely the exclusive property of one group. They're traded, leaked, or independently rediscovered. It's entirely possible that INC is simply the most aggressive party currently using a tool developed by someone else. This rhymes with the "Big Game Hunting" era of 2019 and 2020. Groups like Maze shifted away from indiscriminate encryption toward targeted extortion where they acted more like corporate consultants, albeit malicious ones, who managed their victims through a structured process. The parallel breaks down, however, in the speed of the attack. Maze took weeks to exfiltrate data and build a case; INC is leveraging a zero-day for rapid entry and immediate psychological pressure. The second-order effect here isn't just the risk of data loss or financial payout. It's the collapse of the internal incident response chain. When an attacker calls a victim directly, they often target individuals who aren't trained in crisis communication. This creates a divergence between what the C-suite believes is happening and what the technical team is seeing on the wire. The result is "shadow negotiation," where executives might agree to terms or make promises that the IT department cannot technically fulfill, or worse, before the security team even knows the perimeter has been breached. Some will argue that phone calls are a gimmick, a desperate attempt to add flavor to a standard ransomware play. They'll say that professional organizations have protocols to handle this and that a phone call doesn't actually increase the probability of payment. I disagree. Professional protocols fail when the person answering the phone is terrified. In any high-stakes breach, the technical vulnerability is rarely the hardest part for the attacker; it's the human volatility. By introducing a live voice into the equation, INC is attacking the emotional stability of the target, not just their firewall. We are seeing this against a backdrop of systemic fragility. New York State is currently spending $9 million to shore up 153 water systems because they've realized how exposed their operational technology is. The same logic applies here. We focus on patching the SonicWall zero-day (which we must), but we ignore the fact that our corporate communication structures are completely unprepared for a live, adversarial conversation. If we start seeing other groups adopting this "high-touch" extortion model, it suggests a broader trend where ransomware actors are moving away from being mere software operators and toward becoming psychological operators. I'll be watching to see if these phone calls accompany the use of different entry vectors. If INC begins using this pressure tactic across multiple disparate vulnerabilities, we're not looking at a SonicWall problem; we're looking at a refined extortion methodology.
◼
← More from the Desk Live Wire →

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.