Key Takeaways
- The INC Ransomware group has become one of the world’s most active ransomware operators, consistently ranking among the top threats since 2023.
- Its attacks frequently target healthcare providers and critical‑infrastructure sectors, risking service disruption, financial loss, and public‑safety hazards.
- Crime Stoppers, a U.S.-based non‑profit, has announced a $22,000 reward for credible information that helps identify, disrupt, or seize the gang’s infrastructure or members.
- Eligible tips include details about members’ identities, locations, associates, cryptocurrency wallets, funding sources, communication channels, and the servers or digital assets supporting the ransomware operation.
- Public participation—especially from insiders, researchers, or organizations that have encountered the group—can provide investigators with crucial leads and increase the likelihood of arrests.
- Recent threat‑intelligence reports from Point Wild and the NCC Group placed INC Ransom as the sixth most active ransomware group in June 2024, underscoring its persistent danger.
- The bounty exemplifies growing collaboration between non‑profits, cybersecurity experts, and law‑enforcement agencies to strengthen intelligence gathering and disrupt ransomware campaigns.
- Sustained efforts like this reward program are expected to raise the cost of cybercrime, deter future attacks, and improve overall resilience of vulnerable sectors.
Overview of the INC Ransomware Threat
The INC Ransomware group has emerged as a prominent player in the global ransomware landscape, demonstrating a steady rise in activity since its first notable appearances in 2023. Researchers from Point Wild and the NCC Group have tracked its operations and consistently ranked it among the most active ransomware syndicates, placing it sixth in June 2024. The group’s tactics involve gaining unauthorized access to networks, exfiltrating sensitive data, and then encrypting critical files while demanding substantial cryptocurrency payments for decryption keys. Its ability to adapt evasion techniques and maintain operational continuity has allowed it to remain a persistent threat despite increased law‑enforcement scrutiny and defensive measures across industries.
Impact on Critical Sectors
INC Ransomware’s primary victims include healthcare providers, hospitals, and operators of essential infrastructure such as power utilities, water‑treatment facilities, and transportation networks. By encrypting patient records, diagnostic systems, or supervisory control and data acquisition (SCADA) platforms, the gang can cripple service delivery, delay life‑saving treatments, and jeopardize public safety. The financial toll extends beyond ransom demands to encompass incident‑response costs, regulatory fines, reputational damage, and prolonged downtime. Because many of these organizations operate under strict regulatory frameworks and limited cybersecurity budgets, they are especially attractive targets for ransomware actors seeking high‑impact, high‑payoff outcomes.
Details of the $22,000 Reward from Crime Stoppers
In response to the escalating threat posed by INC Ransomware, Crime Stoppers—a U.S.-based non‑profit that has partnered with law enforcement since the 1970s—has unveiled a $22,000 reward for actionable intelligence. The initiative is designed to motivate individuals, businesses, or other organizations possessing credible information to come forward and assist investigators in identifying, disrupting, or seizing the gang’s infrastructure. By offering a financial incentive, Crime Stoppers aims to lower the barrier for whistleblowers and encourage timely reporting, thereby accelerating ongoing investigations and increasing pressure on the cybercriminal network.
Types of Information Eligible for the Reward
The reward program specifies a broad range of intel that could qualify for payment. This includes, but is not limited to, the physical locations or true identities of INC Ransomware members and their associates, details about cryptocurrency wallets used to collect ransom payments, and information on the group’s funding sources or money‑laundering methods. Additionally, tips concerning communication channels (e.g., encrypted messaging platforms, dark‑web forums), infrastructure specifics such as command‑and‑control servers, hosting providers, or any digital assets that support the ransomware operation are eligible. Information that leads to the seizure of equipment, the disruption of malicious activity, or the arrest of individuals linked to the gang may also be rewarded, provided it is deemed credible and actionable by authorities.
Role of Public Participation and Insider Intelligence
Law‑enforcement agencies frequently rely on external tips to close gaps in their investigations, especially when dealing with sophisticated cybercriminal groups that operate across jurisdictions and employ advanced anonymity tools. Insiders—such as current or former affiliates, contractors, or employees who have observed suspicious activity—can provide firsthand knowledge of internal workflows, toolsets, or operational timelines that are otherwise inaccessible. Likewise, cybersecurity researchers and victim organizations that have encountered INC Ransomware malware, ransom notes, or network artifacts can contribute valuable indicators of compromise (IOCs). By aggregating these diverse sources, investigators can build a more complete picture of the gang’s infrastructure, enhance attribution efforts, and increase the probability of successful prosecutions.
Recent Threat‑Intelligence Rankings
Analyses conducted by Point Wild and the NCC Group in mid‑2024 highlighted the sustained potency of INC Ransomware, positioning it as the sixth most active ransomware family globally for that month. The ranking reflects not only the volume of attacks but also the group’s ability to maintain a consistent presence among the top threats since 2023, indicating a mature and resilient operation. Metrics considered include the number of distinct victims reported, the severity of impacted sectors, and the sophistication of the ransomware payloads. This ongoing visibility underscores the necessity for continued vigilance, proactive threat hunting, and coordinated response strategies to mitigate the group’s impact.
Broader Collaborative Efforts Against Ransomware
The $22,000 bounty exemplifies a growing trend of collaboration between non‑profit organizations, private‑sector cybersecurity firms, and governmental law‑enforcement bodies. Crime Stoppers leverages its community‑oriented model to tip the scales in favor of authorities, while threat‑intelligence providers supply contextual data that enriches investigative leads. Such partnerships enhance information sharing, reduce silos, and create a unified front that raises the operational cost for ransomware actors. By increasing the likelihood of detection and apprehension, these collective actions aim to deter future attacks, discourage recruitment into cybercrime syndicates, and promote a safer digital ecosystem for critical infrastructure and private enterprises alike.
Conclusion and Outlook
The announcement of a substantial reward for information on INC Ransomware signals a decisive step toward curbing the influence of one of the most dangerous ransomware groups operating today. By incentivizing public and insider cooperation, law enforcement gains access to vital intelligence that can disrupt the gang’s command‑and‑control infrastructure, trace illicit financial flows, and ultimately bring perpetrators to justice. As ransomware tactics continue to evolve, sustained initiatives that blend community engagement, technical expertise, and authoritative action will be essential in reducing the frequency and severity of attacks. Continued investment in reward programs, information‑sharing platforms, and cross‑sector collaboration holds promise for strengthening global resilience against the ever‑present menace of ransomware.

