Rhysida (hacker group)
hacker group using ransomware

Rhysida is a ransomware group that encrypts data on victims' computer systems and threatens to make it publicly available unless a ransom is paid. The group uses eponymous ransomware-as-a-service techniques, targets large organisations rather than making random attacks on individuals, and demands large sums of money to restore data.
The group perpetrated the notable 2023 British Library cyberattack and Insomniac Games data dump. It has targeted many organisations, including some in the US healthcare sector, and the Chilean army.
In November 2023, the US agencies Cybersecurity and Infrastructure Security Agency (CISA), FBI and MS-ISAC published an alert about the Rhysida ransomware and the actors behind it, with information about the techniques the ransomware uses to infiltrate targets and its mode of operation.
The group takes its name from the genus of centipedes, and uses a centipede logo. Their location is unknown, but authorities believe the group to be based in Russia or multiple Russian-speaking countries, as comments found within their malware's code are written in Russian.
Attacks
Chilean army, June 2023
British Library cyberattack, October 2023
Insomniac Games data dump, December 2023, releasing details of the Marvel's Wolverine game and employee details
Prospect Medical Holdings, 2023
City of Columbus, Ohio, July 2024, where over 3 TB of data was released onto the dark web, after an attempt to extort $1.7M (30 Bitcoin) from the city.
Seattle-Tacoma International Airport, August 2024
Ranney School, August 2024
Rutherford County Schools (Tennessee), November 2024
Pembina Trails School Division, December 2024
Maryland Department of Transportation, September 2025
Stelia Aerospace, April 2026
Berlin state administration, August 2026
Ransomware as a service
The US CISA report states:
Threat actors leveraging Rhysida ransomware are known to impact "targets of opportunity", including victims in the education, healthcare, manufacturing, information technology, and government sectors. Open source reporting details similarities between Vice Society (DEV-0832) activity and the actors observed deploying Rhysida ransomware.
“Rhysida (hacker group)” enters the record as hacker group using ransomware. Crown Archives preserves that source wording while asking what Rhysida, hacker and group can confirm, complicate or overturn.
Why this record matters
“Rhysida (hacker group)” is worth following because a concise public description often conceals a longer documentary argument. Here, Rhysida, hacker and group provides the most credible route into that argument.
The citation trail is more important than the brevity of the summary: it shows where individual claims can be examined in context. The source revision retrieved here is dated Sep 12, 2026. The linked authority identifier is Q124166522. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2023, 2024, 2025 and 2026.
Overview language is designed for orientation and should not be treated as a substitute for the evidence cited beneath it. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “Rhysida (hacker group)”, its source revision and the description used here.
- Expand the search: follow Rhysida (hacker group) primary sources, Rhysida (hacker group) archive and Rhysida research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Rhysida (hacker group)”?
- Which institution is responsible for the underlying evidence?
- What terminology or title could unlock a more precise catalogue search?
Search terms from this dossier
This entry incorporates text from “Rhysida (hacker group)” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.