TL;DR
THIS WEEK IN 30 SECONDS
Ransomware that can't be decrypted, even if you pay. Vect isn't ransomware. It's a wiper wearing a ransomware costume. Files over 128KB are gone forever. The ransom note is a lie. Your backups are now your only lifeline.
Robinhood's own email system was turned into a phishing weapon. Attackers didn't spoof Robinhood. They sent phishing emails from Robinhood's actual servers. When the threat arrives in a trusted envelope, the game changes entirely.
71% of IT workers say AI is making their jobs harder. Not easier. Harder. More oversight. More cognitive load. More pressure. The technology sold as the solution to IT burnout is accelerating it. Someone has some explaining to do.
THIS WEEK’S TOP STORY
RANSOMWARE THAT DESTROYS YOUR DATA… (EVEN AFTER YOU PAY!)
What Happened: A new malware strain called Vect is being marketed and deployed as ransomware. It isn't. Researchers discovered a fatal encryption flaw: any file over 128KB cannot be decrypted.
Ever.
…Not by the victim.
…Not by the attacker.
…Not by anyone.
The ransom note is theater. The data is already gone. Across 40+ organizations (allegedly including names like Carnival, Pitney Bowes, Hallmark and Zara) victims are discovering that negotiation is not a recovery strategy. It never was. This week it's just more obvious than usual.
Our Take
Ransomware always was a hostage situation. Vect just forgot to keep the hostage alive. Paying buys you nothing. Negotiating buys you nothing. The only organizations walking away from Vect intact are the ones that never needed to negotiate in the first place — because their backups were tested, their containment was fast, and their recovery plan existed outside a PowerPoint.
This is the future of ransomware: not extortion, obliteration.
Plan accordingly.
SOURCE:
Computer Weekly | https://www.computerweekly.com/news/366642421/Vect-ransomware-actually-destructive-wiper-malware
Headlines
May 1, 2026
Attackers have figured out that hospitals will pay anything to keep devices running. The question isn't whether attacks are rising. It's whether anyone can stop them…
May 1, 2026
Attackers didn't spoof Robinhood. They didn't fake the sender address. They exploited a flaw in Robinhood's own signup process to send convincing phishing emails directly from Robinhood's legitimate servers. When the threat arrives in a trusted envelope, every filter fails…
May 1, 2026
Agentic AI is flooding enterprises with new APIs. Every one is a potential entry point. Akamai's research puts a dollar figure on what most organizations are ignoring entirely…
Editorial
You Can't Negotiate With a Psycho… Your Hostage Was Gone Before You Even Picked Up The Phone.

Heath Ledger's Joker didn't rob the mob to keep the money.
He burned it.
Sitting in a warehouse surrounded by millions in cash, he touched a single match to the pile and watched it go. "It's not about the money," he said. "I'm an agent of chaos. It's about sending a message."
Not greed. Not ambition. Chaos.
Pure, purposeless, irreversible destruction for its own sake.
That scene just became a cybersecurity case study.
Vect malware is like the Joker’s match. It sends a ransom note. It demands payment. It implies, with the practiced confidence of a seasoned extortionist, that your data is being held safely somewhere, waiting for you to make the right financial decision.
And then you discover it was lying the whole time.
The data was already ash before the ransom note was even written....
Your files are already destroyed. The negotiation was theater. The hostage was dead before you picked up the phone.
This is the moment the ransomware era officially mutates into something darker.
For fifteen years, ransomware operated on a brutal but comprehensible logic: we have your data, you want it back, here's the price. It was criminal. It was devastating. But it was transactional. There was a deal to be made. Organizations paid. Sometimes they got their data back. Sometimes they didn't. But the fiction of negotiation held the whole ecosystem together — victims paid because paying might work, and attackers collected because victims believed it might work.
Vect just burned that fiction to the ground.
When the ransom note is a lie, when the decryption key doesn't exist, when the data is gone the moment the malware executes — ransomware stops being extortion and starts being sabotage. And sabotage has no business model. It has only one purpose: destruction.
Which raises the question nobody in the industry wants to answer out loud: what comes after ransomware?
Because here's what the Vect story is really telling us. The criminal ecosystem is fracturing. On one side, sophisticated ransomware operations running like professional enterprises, negotiation teams, customer service portals, carefully managed reputations built on the perverse promise that paying actually works. On the other side, something new and far more dangerous: attackers who don't want your money. Attackers who want your operations dark, your data gone, your organization on its knees. Nation-states. Ideologues. Competitors. People for whom destruction is the point.
And sitting right in the middle of all of this, completely unprepared for either threat, is the average organization - still debating whether to test their backups this quarter, still treating patch management as optional, still assuming that cyber insurance and a ransom budget constitute a recovery strategy.
They don't.
They never did. Vect just made that impossible to ignore.
Meanwhile, agentic AI is flooding enterprise environments with APIs that cost $700,000 a year when they go wrong. Medical devices are being targeted in hospitals where downtime isn't an inconvenience… it's a body count. Robinhood's own email infrastructure was turned into a weapon against its users. And 71% of IT workers (aka, the humans responsible for keeping all of this running) say AI is making their jobs harder, not easier, while their organizations cheerfully add more of it.
We are simultaneously increasing the complexity, the attack surface, the stakes and the cognitive load, while decreasing the human capacity to manage any of it.
This is not a technology problem.
It is a priorities problem.
The organizations that survive what's coming aren't the ones with the biggest security budgets or the most sophisticated tools. They're the ones that treated resilience as a discipline before they needed it as a lifeline. Tested backups. Practiced incident response. Owned their APIs. Governed their AI. Hired humans who could think, not just tools that could automate.
Resilience isn't a feature you purchase. It's a habit you build.
Vect didn't create the vulnerability it exploited. It just revealed the one that was already there: the catastrophic gap between what organizations assume about their security and what is actually true.
The negotiator picked up the phone.
The line was dead.
So was the hostage.
Don't be the negotiator.
The editorial opinions expressed here are those of the author and represent the view from the cheap seats — which, it turns out, have an excellent view of the dumpster fire.
Other News From Around The Web
Breach roundup: 40+ firms exposed in major ransomware campaign
This week’s breach news highlights a large ransomware campaign across retail, insurance, and hospitality, reportedly affecting brands including Carnival, Pitney Bowes, Hallmark, and Zara.
Source: Kaseya | Wed, Apr 29 - https://www.kaseya.com/blog/the-week-in-breach-news-04-29-26/
AI in IT: More Power, More Pressure
IT workers say AI is making their jobs more demanding
A SolarWinds survey finds 71% of IT workers say AI is increasing job demands, with many reporting added oversight, trust issues, and cognitive load. AI may reduce manual work, but it is also creating a new management burden for already-stretched teams.
Source: Computer Weekly | Wed, Apr 29 - https://www.computerweekly.com/news/366642578/IT-workers-say-AI-is-making-their-jobs-more-demanding
API security issues rise as agents enter the enterprise
As agentic AI moves into business workflows, APIs become an even more critical security layer. Akamai research pegs the average cost of API-related security incidents at roughly $700K per year.
Source: Developer Tech News | Wed, Apr 29 - https://www.developer-tech.com/news/api-security-issues-in-the-spotlight-as-agents-enter-the-enterprise/
Agentic AI security for executives enters the market
VanishID is positioning AI-powered protection around C-suite digital exposure, reflecting how executive risk has expanded beyond physical security into identity, impersonation, and online attack surfaces.
Source: Cybercrime Magazine | Wed, Apr 29 - https://cybersecurityventures.com/vanishid-agentic-ai-powered-cybersecurity-protects-c-suite-executives/
Healthcare, Critical Infrastructure & High-Stakes Cybercrime
Medical device cyberattacks are rising
Legacy technology remains a major driver of healthcare cyber risk, with medical devices increasingly exposed as attackers target environments where uptime and safety are critical.
Source: Silicon Republic | Wed, Apr 29 - https://www.siliconrepublic.com/enterprise/cybersecurity-medical-devices-cyberattacks-reports-runsafe
Policy, Privacy & Surveillance
House passes 3-year FISA Section 702 extension
The bill now moves to the Senate, where reauthorization could face additional obstacles tied to unrelated digital currency provisions.
Source: Nextgov | Wed, Apr 29 - https://www.nextgov.com/policy/2026/04/house-passes-3-year-fisa-702-extension/413223/
Congress tries again on national data privacy law
House Republican leaders introduced new federal privacy bills that would preempt state laws—reviving the long-running debate over a single national privacy standard.
Source: Nextgov | Wed, Apr 29 - https://www.nextgov.com/digital-government/2026/04/congress-tries-again-national-preemptive-data-privacy-law/413205/
Enterprise Security: Access, Patching & Phishing
Hackers abuse Robinhood signup process to send phishing emails
Robinhood fixed a flaw that allowed attackers to send convincing phishing emails from its own systems—another example of trusted platform abuse.
Source: TechRepublic | Wed, Apr 29 - https://www.techrepublic.com/article/news-robinhood-phishing-emails-official-address/
Simplifying access control with Cisco Catalyst Center
Cisco outlines how site-based and role-based access control can help teams securely delegate permissions across enterprise networks.
Source: Cisco Networking Blog | Wed, Apr 29 - https://blogs.cisco.com/networking/simplify-access-control-in-five-easy-steps
Patch management remains foundational
Kaseya revisits patch management best practices, noting how MSPs continue to prioritize patching as a core security and operations service.
Source: Kaseya | Date not shown in feed - https://www.kaseya.com/blog/patch-management/
Cyber Leadership, Talent & MSP Operations
The CISO gap leaves SMBs exposed
Cybercrime Magazine highlights growing concern that many small and mid-sized businesses lack dedicated security leadership—creating an opening for MSSPs to fill the gap.
Source: Cybercrime Magazine | Tue, Apr 28 - https://cybersecurityventures.com/ciso-gap-smbs-exposed-mssps-to-the-rescue/
Pentagon launches cyber apprenticeship program
The Defense Department is leaning into skill-based hiring with a new cyber apprenticeship initiative aimed at addressing technology and cybersecurity vacancies.
Source: Nextgov | Tue, Apr 28 - https://www.nextgov.com/cybersecurity/2026/04/pentagon-launches-cyber-apprenticeship-program/413187/
What PSA software means for MSPs and IT service providers
A practical guide to professional services automation, with MSPs continuing to focus on growth, customer acquisition, and operational efficiency.
Source: Kaseya | Wed, Apr 29 - https://www.kaseya.com/blog/professional-services-automation-psa/
The Bottom Line
Vect doesn't want your money. It wants your data dead. The ransom note is a lie, the negotiation is theater, and the hostage was already gone before you opened the email.
This week made one thing undeniable…
The organizations that survive what's coming already built their resilience before they needed it.
Tested backups.
Governed APIs.
Patched devices.
Trained humans.
Not because an auditor required it.
Not because the insurance policy demanded it.
Because when the Wiper comes (and make no mistake, it's coming) the only recovery strategy that works is the one you built before the attack, not after it.
See you next week. Don't click anything.




