N0N Ransomware Claim Targets Transcom

Unverified claim: N0N lists Transcom as PayPal support victim

An N0N ransomware claim has named Transcom WorldWide support operations linked to PayPal as an alleged victim. Published on 18 September 2026, the listing remains unconfirmed and should not be treated as evidence that either company was compromised.

What the N0N ransomware claim alleges

The listing appeared on a dark web leak site attributed to N0N and used the victim name “PAYPAL SUPPORT OPERATIONS (TRANSCOM WORLDWIDE)”. According to the source report, the post describes Transcom as providing outsourced customer support operations connected with financial services in the Netherlands and Tunisia.

The wording is important. The listing associates the alleged incident with support operations linked to PayPal, but it does not establish that PayPal’s wider corporate network, payment systems or customer accounts were accessed. It also does not provide enough information to determine which legal entity, network or operational environment was supposedly affected.

No compromise date is given. Therefore, 18 September 2026 can only be treated as the date on which the claim was reported, not the date of an intrusion, encryption event or data theft.

Alleged connection records and infrastructure details

The threat actor claims to hold 86.7 million connection records documenting daily support agent sessions involving PayPal corporate Citrix and authentication, authorisation and accounting systems, commonly abbreviated as AAA. The post does not explain the format, age or time span of these records.

Connection records can contain technical information about sessions, users, devices, network paths and access times. However, the N0N ransomware claim does not include samples that would show what fields are present, whether personal information is involved or whether the records are authentic.

N0N also claims to possess a complete infrastructure map covering internal Active Directory and public key infrastructure environments. Other named technologies include Netskope and Zscaler tenants, with the actor alleging visibility across all eight operational sites.

No product editions, software versions or configuration details are identified. There is also no disclosed vulnerability, CVE reference, exploit chain, malicious tool, initial access method or account compromise technique. Citrix, Active Directory, Netskope and Zscaler are mentioned only as parts of the infrastructure the actor claims to have mapped, not as products confirmed to contain a security flaw.

Blackout and deadline claims

The leak-site post further alleges that all eight sites are enforcing a network blackout pending a settlement. It sets a deadline of 21 September 2026 at 03:01 UTC, but does not state what the actor intends to do after that point.

No ransom amount is shown. The listing also does not clearly categorise the alleged impact as file encryption, data exfiltration, extortion without encryption or disruption. As a result, calling the event a confirmed ransomware attack would go beyond the evidence currently available.

N0N ransomware claim lacks independent evidence

The strongest qualification attached to this incident is the verification alert published alongside the source report. It warns that listings attributed to N0N have reportedly included unverified or fabricated victim claims and says this allegation should be treated as unconfirmed until independent evidence appears.

The reported leak page contains no screenshots, images or downloadable files. There are no redacted documents, directory listings, sample records, file trees, negotiation messages or other artefacts that could help validate the actor’s assertions.

RedPacket Security states that its page was generated from an automated and redacted scrape of the N0N Tor blog. It also says it did not obtain, download, host, view or republish any allegedly stolen information. The report therefore documents what the actor posted, rather than independently verifying the substance of the post.

As of the publication date, the available material contains no confirmation from Transcom WorldWide or PayPal. It also provides no independently verified evidence from investigators, regulators or trusted security researchers. There is consequently no established exploitation status, confirmed breach scope or verified operational impact.

What remains unknown

Several central questions cannot be answered from the N0N ransomware claim:

  • Whether any Transcom or PayPal-linked system was accessed.
  • Whether the claimed 86.7 million records exist or are authentic.
  • Whether personal, customer, employee or payment information is involved.
  • Whether any systems were encrypted, disabled or taken offline.
  • How an attacker allegedly gained access or maintained persistence.
  • Whether the claimed network blackout affected any of the eight sites.

The absence of public evidence does not prove that no incident occurred. Equally, a criminal leak-site entry is not proof of compromise, particularly where the named group has been associated with allegedly fabricated victim listings.

Why the Transcom allegation matters

The N0N ransomware claim deserves measured attention because outsourced support providers can hold session records and detailed knowledge of customer environments. If authentic, infrastructure maps covering identity systems, certificates, security services and multiple sites could help attackers understand trust relationships or plan further activity.

However, the alleged scale must not be repeated as confirmed fact. The figure of 86.7 million records comes solely from the threat actor, while the nature and sensitivity of those records remain unknown. Organisations should distinguish clearly between monitoring an allegation and declaring a breach.

What organisations should do now

Organisations with a direct operational relationship to the named support environment should use internal evidence, rather than the leak post, to assess exposure. Relevant teams should preserve logs and check for unusual access involving support accounts, Citrix sessions, remote administration and identity infrastructure.

  • Confirm whether the named provider has issued a formal incident notification.
  • Review recent support account activity and unexpected authentication patterns.
  • Validate privileged access granted to outsourced support personnel.
  • Check whether any network restrictions or service interruptions correspond with the actor’s claims.
  • Avoid downloading supposed samples from criminal sites to investigate the allegation.

Public conclusions should remain cautious unless Transcom, PayPal or a credible independent source supplies corroborating evidence. Until then, this is best described as an unverified extortion-site allegation, not a confirmed compromise.

Originally reported by redpacketsecurity.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call