-
Crime Stoppers International has put up a reward of $22,000 for any information about the INC Ransomware Gang.
-
This particular gang has been a major problem for healthcare organizations and critical infrastructures.
-
INC Ransom recently emerged as the sixth most active ransomware group.

Ransomware keeps hitting organizations everywhere, disrupting business operations, hospitals, and a lot of other critical services. Due to this, cybersecurity professionals and law enforcement are constantly looking for fresh strategies to stop these attacks.
One of the latest efforts comes from Crime Stoppers. The non-profit organization has announced a reward worth $22,000 for information that can lead to the identification of members belonging to the INC Ransomware Group or the destruction of their criminal infrastructure.
The non-profit wants individuals who can provide any information on the gang members, their location, crypto wallets, or cyber infrastructure. It is a new strategy in dealing with ransomware against the ordinary citizenry.
A New Strategy Against Cybercrime
Crime Stoppers International, a U.S.-based non-profit that has supported law enforcement investigations since the 1970s, launched this bounty through its CyberCrime Bounty Program. This program marks the first time the organization has applied its anonymous reporting model specifically to cybercrime.
The US government has similarly used financial rewards, offering $10 million for information leading to the identification of Russian bulletproof hosting operators.
The group chose the INC Ransomware operation as its first target under this new program. They hope that the initiative will assist with locating the people behind the INC Ransomware operations. According to Crime Stoppers’ disclosure, the criminal group’s incessant attacks on critical infrastructure are the reasons for the initiative.
Crime Stoppers stated in their announcement that INC Ransomware doesn’t show restraint in its attacks. They noted that the group loves attacking “organizations whose disruption puts real people at risk.”
According to Crime Stoppers, the reward is open to any individual, business, or organization that can provide information leading to meaningful action against the group. Intelligence that’ll qualify for the bounty may include the identities or locations of gang members and their associates.
Information about cryptocurrency wallets used to receive ransom payments, communication methods, and funding sources is part of it too. Other relevant intel includes details about the servers and digital infrastructure supporting the operation. Information that ultimately leads to infrastructure seizures or arrests may also qualify for the reward.
INC Ransom Remains a Persistent Threat
The reward comes as the INC Ransomware group continues to maintain a strong presence in the global ransomware landscape.
The gang has built a reputation for targeting organizations across several industries. Healthcare entities and operators of critical infrastructure have been some of its favorite targets. Any attack on this sector may lead to the interruption of services such as hospitals, power supplies, and water management services.
Apart from encrypting the files, ransomware attacks lead to operational disruptions and other costly damages to organizations. This is even more dangerous for critical service providers due to the threat to public safety.
The organization conducts business in the ransomware-as-a-service model. Under this model, core developers lease their platform to affiliates who carry out actual attacks. This model has allowed INC to expand rapidly and target organizations across multiple sectors.
Threat intelligence published this year highlights the group’s continued activity. Research from the NCC Group and Point Wild ranked INC Ransom as the sixth most active ransomware group during June 2O26.
Analysts also noted that the operation has remained among the world’s most active ransomware groups since 2O23. This suggests that the group has sustained its capabilities despite increasing law enforcement pressure on the wider ransomware ecosystem.
INC has claimed over 800 victims globally since its emergence. Between 2O24 and 2O25, Australia alone reported 11 ransomware incidents tied to INC Ransom, according to the Australian Cyber Security Centre.
INC Ransomware’s Technical Sophistication and Expansion
INC Ransomware has demonstrated considerable adaptability technically, making it a big challenge for experts trying to stop it. They rewrote their encryptors using a programming language called Rust.
This programming language supports development on multiple systems, like Windows and Linux or ESXi, without much hassle. Plus, using Rust makes it tougher for experts to analyze their malware. That’s why the group can strike a wider range of targets and stay a step ahead in making life difficult for anyone trying to stop them.
Recent incident reports describe scenarios where INC used credential-dumping utilities capable of extracting credentials from newer Veeam backup environments. For the victims, the consequences can be dire when the attackers compromise backup systems.
Once inside the network, they start by performing reconnaissance, learning the locations of everything within the network. After that, they proceed to gain access to other systems and seek higher privileges.
After that, they swipe sensitive data and lock up systems with encryption. This group doesn’t just stop at holding data hostage; they also carry out double extortion, where they encrypt the system and ask for ransom. They’ll threaten to leak what they stole if no one pays up, making the pressure even worse.
The influence of this group stretches across several countries around the world. The US is their primary target, but they also target victims in Australia, Spain, and the United Kingdom.
Public Cooperation Becomes Another Tool Against Ransomware
Crime Stoppers is of the opinion that public involvement can contribute a lot in fighting against ransomware attacks. Information from insiders, security experts or organizations familiar with the group’s operations can be very useful for investigators.
Any piece of verified intelligence, no matter how small, can assist investigators in linking the cases or finding any connection between ransomware campaigns. It is important not just to find the attackers themselves but also to disrupt the communication channels, places where they store stolen data, and the systems they use in collecting ransoms from victims.
The Crime Stoppers’ program guarantees a safe platform for submitting tips and rewards people who provide information leading to arrests or some other law enforcement actions. The secure portal is open for reporting to everyone, regardless of nationality.
Cybersecurity experts claim that joint action is a good way to hunt cybercriminals down more effectively and get them punished. The bounty set for INC Ransomware proves that the war against such threats is escalating.
Non-profits, researchers, and law enforcement are teaming up to take on the surge in cybercrime. With ransomware attacks on the rise, efforts like this boost intelligence gathering and mess up the plans of some of the most dangerous groups out there.