Skip to content

— NightSpire

Threat-actor battle card · maintained from public sources · last updated 2026-08-18

CategoryRansomware
AttributionUnknown
First seenEarly 2025
StatusActive
Rank#8
Victims YTD74
Primary targetsManufacturing, Business Services, Healthcare, Technology, Consumer Services; US, France, Spain, India, Turkey

Overview

NightSpire is a financially motivated ransomware operation active since early 2025 that runs its operations in-house rather than through an affiliate-based RaaS model — a less common structure that gives it tighter operational control. It has claimed 314+ victims across 28 industries as of August 10, 2026, posting 74 victims on its DLS in Q1 2026 alone and building steadily through Q2. Activity has tapered from peak Q1 2026 pace: only ~7 new victims listed in the trailing 30 days as of August 10. Manufacturing is the single largest targeted sector (18%), followed by Business Services and Healthcare. The US accounts for the majority of victims (71+), with France (11), Spain (10), India (10), and Turkey (9) the next highest.

Tradecraft

  • Double-extortion: exfiltrate then encrypt; threatens publication and third-party data sale when deadlines expire.
  • Aggressive ransom deadlines, sometimes as short as two days.
  • In-house operations (not RaaS) — no affiliate network to disrupt or flip.
  • Targets predominantly SMEs with limited cybersecurity infrastructure; ransom demands typically $150K–$2M.
  • Primary confirmed initial-access vector: CVE-2024-55591 (Fortinet FortiOS/FortiProxy authentication bypass, CVSS 9.6), exploited in-the-wild by NightSpire from Q4 2024 into Q1 2026 — Bitsight.

Notable recent victims

  • Winona County, Minnesota (US, government) — attack detected April 7, 2026; second ransomware attack on county this year; MN National Guard assisted; NightSpire leaked data DLS June 14, 2026; county confirmed data release same day — GovTech
  • Krum Public Library, Texas (US, government/education) — attack May 14, 2026; 50 GB: financial docs, HR data, supervisor info; city confirmed June 3, 2026; no SSNs/financial info compromised — Dysruption Hub
  • Artistic Smiles (US, consumer services) — DLS, June 2026
  • Dean Cosmetic Dentistry (US, healthcare) — DLS, June 2026 (attack est. May 2025)

Assessment

A self-contained operator with 314+ victims across 28 industries as of August 2026. Rank 8 on the Tier-1 leaderboard. Activity has decelerated from its Q1 2026 peak (74 victims in Q1 alone) to approximately 7 new victims in the trailing 30 days as of August 10 — near-dormant by prior standards. The in-house model makes affiliate disruption ineffective. Primary access via CVE-2024-55591 (FortiOS auth bypass) is well-understood but the group may be developing new initial-access methods given the FortiOS vulnerability is increasingly patched. Healthcare and government targets with two-day extortion deadlines retain high impact potential; watch for a tempo increase if new initial-access capability is confirmed.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

July 2026

Jul 14 Cedar Crest College NightSpire Ransomware · Education · USA Liberal arts college in Allentown PA listed on NightSpire DLS July 14. Estimated attack date July 13. No public statement from Cedar Crest College. · Sources: https://ransomware.live/group/nightspire
Jul 08 PCCC Realty LLC NightSpire Ransomware · real estate · US NightSpire DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/nightspire · Sources: [ransomware.live]

June 2026

Jun 21 Artistic Smiles NightSpire Ransomware · consumer services · US https://www.redpacketsecurity.com/nightspire-ransomware-victim-artistic-smiles/ · Sources: ransomware.live DLS / [RedPacket Security]
Jun 18 Dean Cosmetic Dentistry NightSpire Ransomware · healthcare · US Sources: ransomware.live DLS
Jun 14 Winona County NightSpire Ransomware · government · US second ransomware attack on county in 2026; attack detected April 7; county network partially taken offline; MN National Guard assisted; NightSpire leaked data June 14 2026; county confirmed data leak same day; personal info affected pending review; 🟨 county-confirmed · https://www.govtech.com/security/cyber-criminals-leak-data-from-minnesota-ransomware-incident · https://www.dexpose.io/nightspire-ransomware-attack-on-k-county/ · Sources: [GovTech] · [DeXpose]

May 2026

May 15 Krum Public Library NightSpire Ransomware · education-library · US 50 GB claimed exfiltrated: financial docs, HR data, supervisor info; attack May 14 2026; city of Krum confirmed ransomware in June 3 public notice; no SSNs/financial account info compromised; backups prevented permanent data loss; 🟨 city-confirmed · https://dysruptionhub.com/krum-library-ransomware-wifi/ · https://www.ransomware.live/id/S3J1bSBQdWJsaWMgTGlicmFyeUBuaWdodHNwaXJl · Sources: [Dysruption Hub] · [ransomware.live]

← All threat actors · Full victim database →