— NightSpire¶
Threat-actor battle card · maintained from public sources · last updated 2026-08-18
Overview¶
NightSpire is a financially motivated ransomware operation active since early 2025 that runs its operations in-house rather than through an affiliate-based RaaS model — a less common structure that gives it tighter operational control. It has claimed 314+ victims across 28 industries as of August 10, 2026, posting 74 victims on its DLS in Q1 2026 alone and building steadily through Q2. Activity has tapered from peak Q1 2026 pace: only ~7 new victims listed in the trailing 30 days as of August 10. Manufacturing is the single largest targeted sector (18%), followed by Business Services and Healthcare. The US accounts for the majority of victims (71+), with France (11), Spain (10), India (10), and Turkey (9) the next highest.
Tradecraft¶
- Double-extortion: exfiltrate then encrypt; threatens publication and third-party data sale when deadlines expire.
- Aggressive ransom deadlines, sometimes as short as two days.
- In-house operations (not RaaS) — no affiliate network to disrupt or flip.
- Targets predominantly SMEs with limited cybersecurity infrastructure; ransom demands typically $150K–$2M.
- Primary confirmed initial-access vector: CVE-2024-55591 (Fortinet FortiOS/FortiProxy authentication bypass, CVSS 9.6), exploited in-the-wild by NightSpire from Q4 2024 into Q1 2026 — Bitsight.
Notable recent victims¶
- Winona County, Minnesota (US, government) — attack detected April 7, 2026; second ransomware attack on county this year; MN National Guard assisted; NightSpire leaked data DLS June 14, 2026; county confirmed data release same day — GovTech
- Krum Public Library, Texas (US, government/education) — attack May 14, 2026; 50 GB: financial docs, HR data, supervisor info; city confirmed June 3, 2026; no SSNs/financial info compromised — Dysruption Hub
- Artistic Smiles (US, consumer services) — DLS, June 2026
- Dean Cosmetic Dentistry (US, healthcare) — DLS, June 2026 (attack est. May 2025)
Assessment¶
A self-contained operator with 314+ victims across 28 industries as of August 2026. Rank 8 on the Tier-1 leaderboard. Activity has decelerated from its Q1 2026 peak (74 victims in Q1 alone) to approximately 7 new victims in the trailing 30 days as of August 10 — near-dormant by prior standards. The in-house model makes affiliate disruption ineffective. Primary access via CVE-2024-55591 (FortiOS auth bypass) is well-understood but the group may be developing new initial-access methods given the FortiOS vulnerability is increasingly patched. Healthcare and government targets with two-day extortion deadlines retain high impact potential; watch for a tempo increase if new initial-access capability is confirmed.
Sources¶
- Barracuda Networks — NightSpire: Wannabe warlords in ransomware's shadow realm
- AttackIQ — Emulating the Persuasive NightSpire Ransomware
- HivePro — NightSpire Ransomware Expands Reach with Aggressive Extortion Deadlines
- Picus Security — NightSpire Ransomware Attack Chain, Tools and Tactics
- Huntress — NightSpire Ransomware: In-Depth Analysis
- SOS Ransomware — NightSpire ransomware group
- ProvenData — NightSpire Ransomware: Technical Deep-Dive
- DeXpose — NightSpire ransomware victims
🗂️ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
July 2026
June 2026
May 2026