CACrown ArchivesThe cinema collection
Menu
Research dossier · General Reference

Rhysida (hacker group)

hacker group using ransomware

Cross-disciplinary reference desk with index cards, atlas, dictionary and catalogue
General referenceInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionSep 12, 2026
Entity authorityQ124166522 ↗
Source-derived summary

Rhysida is a ransomware group that encrypts data on victims' computer systems and threatens to make it publicly available unless a ransom is paid. The group uses eponymous ransomware-as-a-service techniques, targets large organisations rather than making random attacks on individuals, and demands large sums of money to restore data.

The group perpetrated the notable 2023 British Library cyberattack and Insomniac Games data dump. It has targeted many organisations, including some in the US healthcare sector, and the Chilean army.

In November 2023, the US agencies Cybersecurity and Infrastructure Security Agency (CISA), FBI and MS-ISAC published an alert about the Rhysida ransomware and the actors behind it, with information about the techniques the ransomware uses to infiltrate targets and its mode of operation.

The group takes its name from the genus of centipedes, and uses a centipede logo. Their location is unknown, but authorities believe the group to be based in Russia or multiple Russian-speaking countries, as comments found within their malware's code are written in Russian.

Attacks

Chilean army, June 2023

British Library cyberattack, October 2023

Insomniac Games data dump, December 2023, releasing details of the Marvel's Wolverine game and employee details

Prospect Medical Holdings, 2023

City of Columbus, Ohio, July 2024, where over 3 TB of data was released onto the dark web, after an attempt to extort $1.7M (30 Bitcoin) from the city.

Seattle-Tacoma International Airport, August 2024

Ranney School, August 2024

Rutherford County Schools (Tennessee), November 2024

Pembina Trails School Division, December 2024

Maryland Department of Transportation, September 2025

Stelia Aerospace, April 2026

Berlin state administration, August 2026

Ransomware as a service

The US CISA report states:

Threat actors leveraging Rhysida ransomware are known to impact "targets of opportunity", including victims in the education, healthcare, manufacturing, information technology, and government sectors. Open source reporting details similarities between Vice Society (DEV-0832) activity and the actors observed deploying Rhysida ransomware.

Editorial summary

“Rhysida (hacker group)” enters the record as hacker group using ransomware. Crown Archives preserves that source wording while asking what Rhysida, hacker and group can confirm, complicate or overturn.

Editorial reviewA dependable orientation record for establishing vocabulary, names and a first evidence trail. The current lead gives the account dated anchors—2023, 2024, 2025, 2026—that can be checked directly. The selected authority fields contribute no independent date. Its strongest next move is a source search built around Rhysida, hacker and group.
Editorial analysis

Why this record matters

“Rhysida (hacker group)” is worth following because a concise public description often conceals a longer documentary argument. Here, Rhysida, hacker and group provides the most credible route into that argument.

Evidence profile

The citation trail is more important than the brevity of the summary: it shows where individual claims can be examined in context. The source revision retrieved here is dated Sep 12, 2026. The linked authority identifier is Q124166522. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2023, 2024, 2025 and 2026.

Critical limits

Overview language is designed for orientation and should not be treated as a substitute for the evidence cited beneath it. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.

Best used for
  • Subject orientation
  • Search vocabulary
  • Locating named sources
Verify next

The closest primary source, responsible institution and strongest cited specialist reference.

Three-step research path

  1. Establish the record: confirm the title “Rhysida (hacker group)”, its source revision and the description used here.
  2. Expand the search: follow Rhysida (hacker group) primary sources, Rhysida (hacker group) archive and Rhysida research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “Rhysida (hacker group)”?
  2. Which institution is responsible for the underlying evidence?
  3. What terminology or title could unlock a more precise catalogue search?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from “Rhysida (hacker group)” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.