Skip to content

SECTION9

SECTION9 is a ransomware extortion group that emerged in publicly tracked leak-site claim data in mid-2026.

Profile source: Mallory opens in a new tab

SECTION9

Family profile

SECTION9 is a ransomware extortion group that emerged in publicly tracked leak-site claim data in mid-2026. It appeared abruptly with a notable volume of claimed victims, indicating an operationally active group rather than a marginal entrant. Available high-confidence reporting ties SECTION9 to ransomware victim claims and data-extortion activity, but does not provide sufficient corroborated detail to attribute the group to a specific country, state sponsor, or broader criminal umbrella.

Observed activity places SECTION9 within the financially motivated ransomware ecosystem, where operators publicly list victims to pressure organizations into payment. The group has been associated with a short-lived spike in claimed activity followed by a rapid drop from the most active rankings in the subsequent reporting period, suggesting either inconsistent operational tempo, limited visibility, or a newly established brand still consolidating its presence.

There is currently no reliable public information in the provided material on SECTION9’s malware lineage, initial access methods, preferred intrusion vectors, victimology by sector or geography, affiliate structure, or distinctive tradecraft. No confirmed sub-groups or widely used aliases beyond SECTION9 are established here. As a result, SECTION9 should presently be treated as an emerging ransomware actor with limited but notable observed claim activity and insufficient corroborated detail for deeper attribution.

Operational record

Recent claims

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.