A Ransomware Gang That Prints Its Own Demands

Most ransomware groups leave their extortion notes as text files scattered across a victim's encrypted folders. INC ransomware takes a more unsettling approach: according to a technical breakdown from Picus Security, the malware also attempts to send its ransom note directly to any connected printers and fax machines on a compromised network, physically printing the demand for anyone in the building to see.

It's a small detail, but it says a lot about how INC operates. This is a group that wants maximum psychological pressure on its victims, and it has found that healthcare and education networks, often filled with legacy printers, shared fax lines, and connected devices that IT teams rarely audit, are fertile ground for that kind of disruption.

Why Healthcare and Education Keep Getting Hit

INC ransomware, tracked as a ransomware-as-a-service operation since it emerged, has repeatedly targeted hospitals, clinics, and schools alongside other sectors like retail and finance. The reasons aren't mysterious. Healthcare networks run on interconnected medical devices, aging infrastructure, and systems that can't always be patched or taken offline without risking patient care. Education networks, meanwhile, often serve thousands of students and staff on shared infrastructure with limited security budgets and inconsistent access controls.

Both sectors also hold exactly the kind of data that makes double-extortion ransomware profitable: patient records, health histories, financial details, and personal information about minors. INC, like many modern ransomware operations, doesn't just encrypt files. It steals data first and threatens to leak it publicly if the ransom isn't paid, giving victims two separate reasons to comply.

That playbook has made hospitals a particularly high-stakes target. When ransomware locks down electronic health records or scheduling systems, the fallout isn't limited to inconvenience. It can delay treatment, force ambulance diversions, and put patient safety directly at risk, which is part of why healthcare cybersecurity has become a policy priority well beyond IT departments.

The Access Point Problem

Ransomware groups need a way into a network before they can deploy anything, and INC has shown it's willing to exploit whatever vulnerability gives it that foothold. A recent case illustrates this well: SonicWall confirmed that two critical zero-day vulnerabilities in its SMA 1000 series appliances were actively exploited by the INC ransomware group for 22 days before a patch became available. That kind of window, nearly three weeks of active exploitation before a fix existed, is exactly the opportunity ransomware operators look for, particularly against organizations that may be slower to patch remote access appliances due to staffing constraints or operational demands.

This pattern underscores a broader truth about ransomware in general and INC specifically: the initial breach rarely comes from something exotic. It comes from unpatched software, exposed remote access tools, or credentials that were never rotated. Once inside, the group moves laterally, identifies valuable data to exfiltrate, deploys its encryption payload, and in INC's case, tries to get its message printed out for maximum visibility.

What This Means for You

If you work in or interact with healthcare or education systems, either as an employee, patient, student, or parent, INC ransomware is a reminder that the data these institutions hold about you is a real target, not a hypothetical one. Health records and student data are attractive precisely because they're hard to replace and often tied to financial or medical fraud opportunities.

For IT and security teams, the practical lesson is about patching cadence and network segmentation. Remote access appliances, connected printers, and fax gateways are often treated as low-priority devices, but INC's behavior shows attackers will use every device on a network, however mundane, to achieve their goals. Segmenting printers and IoT-style devices from core systems, and patching internet-facing appliances quickly when vendors disclose vulnerabilities, meaningfully reduces the attack surface.

For individuals, the actionable steps are more familiar but still worth repeating: monitor for breach notifications from your healthcare provider or school district, use unique passwords for portals that store personal or medical information, and be wary of follow-up phishing attempts that often piggyback on ransomware incidents once stolen data starts circulating.

Staying Ahead of Targeted Ransomware Campaigns

INC ransomware isn't unique in targeting healthcare and education, but its willingness to physically print ransom notes highlights how far these groups will go to force payment. Organizations in these sectors should treat every internet-facing device, no matter how unremarkable, as a potential entry point, and individuals should stay alert to breach notices tied to institutions holding their sensitive data. Awareness and timely patching remain the most effective defenses against a threat that shows no sign of slowing down.