Shiba, a new ransomware brand, lists two victims in its debut
A previously unknown actor calling itself Shiba activated its leak site on 28 September 2026 and has posted two entries so far. No link to earlier groups has been established, marking it as an emerging threat worth monitoring.
What happened
On 28 September 2026, a new name surfaced in the digital extortion landscape: an actor going by Shiba (alias: shiba). Since that date, RansomLook tracking records a total of two posts on its leak site, both dated the same day.
The two organisations named so far are Friendly Senior Living, a healthcare and senior care provider in the United States, and I.T. Foods Industries, an agri-food company in Thailand. It is important to stress that these are claims made by the group itself. Neither has been independently confirmed, and a listing on an extortion portal is not proof of an incident, nor does it verify the scope of the data the group says it holds.
What is known about the group
Very little, and that is precisely the point. Shiba does not appear in reference catalogues such as MISP Galaxy or MITRE ATT&CK, and available sources identify no similarity with known operations and no sign that this is the rebranding of an earlier crew. There is currently no reliable public information on its initial access vectors, its tooling, or whether it runs an affiliate model.
With two posts in two days, it is too early to say whether Shiba will become a persistent operator or a short-lived venture. The affected sectors (healthcare and food production) and the wide geographic spread suggest opportunism rather than a targeted sectoral campaign, at least for now.
What organisations can do
When a group has no known technical profile, the sensible response is not to hunt for specific indicators but to reinforce the controls that stop most ransomware operations, whatever the brand on the leak site.
- Enforce multi-factor authentication on every remote access path: VPN, remote desktop, email and administrative portals.
- Prioritise patching of internet-facing devices such as firewalls, VPN concentrators, web servers and file transfer systems.
- Keep offline or immutable backups and test full restoration, not merely the existence of a backup copy.
- Reduce the number of accounts with administrative privileges and review supplier and third-party access.
- Monitor for large outbound data transfers to unusual storage services, a common precursor to encryption.
- Maintain a written response plan covering regulator communication, including the 72-hour breach notification required in the EU when personal data is involved.
About the group: Shiba
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.