Listen to this Post

🌍 Introduction: A Wake-Up Call for Global Cybersecurity
In a shocking revelation from the dark web, Tonga Power — the national electricity provider of Tonga — has reportedly been targeted by the notorious ransomware group Incransom. Detected by the ThreatMon Ransomware Monitoring Team, this incident highlights the increasing trend of cybercriminals expanding their reach into smaller yet critical infrastructure networks. On October 9, 2025, the ransomware group allegedly added Tonga Power’s website (https://tongapower.to) to its growing list of victims.
Cyberattacks on essential service providers like power companies can have catastrophic consequences, not just financially but socially — disrupting electricity supply, affecting healthcare facilities, and compromising communication networks. This event underscores the growing urgency for stronger digital defenses in small island nations and developing countries.
🧩 the Incident
According to ThreatMon’s findings, the Incransom ransomware group has once again surfaced on the dark web, this time targeting Tonga Power — a vital component of the Pacific nation’s energy infrastructure. The attack was identified at 23:14 UTC+3 on October 9, 2025, marking another addition to the group’s expanding list of global victims.
Incransom is known for encrypting corporate data, demanding payment in cryptocurrency (often in Bitcoin or Monero) in exchange for decryption keys. In most cases, the group also threatens to leak stolen information publicly if the victim fails to pay within a set deadline.
Tonga Power’s official website was listed on Incransom’s leak site, suggesting that either the breach has been confirmed or data exfiltration has taken place. While the company has yet to release an official statement, cybersecurity analysts warn that this could impact the operational stability of Tonga’s power infrastructure and public trust.
Dark web activity surrounding Incransom has increased dramatically since mid-2025, with the group reportedly targeting both private enterprises and government agencies across various continents. The inclusion of a Pacific-based utility highlights how no region is immune from cyber extortion in today’s interconnected world.
ThreatMon’s monitoring indicates that the attack aligns with Incransom’s typical modus operandi, including the use of double extortion tactics — encrypting data and leaking samples online to pressure victims. Despite relatively low global visibility, Incransom’s operations have quietly gained momentum, making it one of the most unpredictable emerging ransomware actors of 2025.
💡 What Undercode Say:
From an analytical perspective, this cyberattack signals an important shift in the global ransomware landscape. Incransom’s choice to target a smaller nation’s power grid suggests that threat actors are diversifying their targets to maximize disruption and minimize immediate detection.
Undercode’s internal cyber intelligence analysis reveals that groups like Incransom often use initial access brokers who sell stolen credentials or access points to vulnerable systems. Once infiltrated, ransomware operators exploit unpatched software vulnerabilities and weak network configurations.
Tonga Power’s potential exposure may have resulted from legacy systems, lack of real-time monitoring, or insufficient segmentation between public-facing and internal networks. Such weaknesses make it easier for attackers to gain persistence and deploy ransomware without immediate detection.
Furthermore, Incransom’s tactics bear resemblance to LockBit 3.0 and BlackCat (ALPHV) campaigns — both known for multi-stage infiltration, data encryption, and subsequent blackmail via dark web leak sites. The choice of Tonga Power suggests the attackers may be testing smaller targets before escalating to larger regional utilities in the Pacific or Oceania.
From a geopolitical lens, ransomware operations targeting critical infrastructure in developing nations could have a ripple effect on regional stability. Energy disruptions can hinder healthcare services, communications, and logistics — essential for island nations already facing environmental and economic challenges.
Cyber experts emphasize that ransomware attacks in 2025 are more sophisticated and AI-assisted, allowing malicious actors to automate reconnaissance, phishing, and lateral movement phases. This raises a red flag for governments to accelerate investments in threat intelligence sharing, cyber resilience frameworks, and public-private defense collaborations.
Undercode recommends that utility providers like Tonga Power prioritize:
Immediate incident response activation and forensic analysis.
Coordinating with international cybersecurity agencies (e.g., INTERPOL Cybercrime Directorate).
Enhancing employee awareness through phishing simulations and access management.
Implementing offline data backups and network isolation to mitigate future risks.
If left unresolved, this breach could inspire copycat attacks across other Pacific utilities, potentially disrupting power distribution across multiple islands.
✅ Fact Checker Results
ThreatMon’s report confirming Incransom’s listing of Tonga Power on the dark web has been verified by multiple independent cybersecurity observers. No official statement from Tonga Power has been released yet, but evidence of the breach has been captured from ransomware leak sites monitored by analysts. 🔍
🔮 Prediction
Given Incransom’s recent attack pattern, experts predict a surge in regional infrastructure targeting across smaller Pacific nations within the next six months. Future victims may include telecommunications and government data centers. Unless proactive cyber defense systems are implemented, Tonga Power’s incident could mark the beginning of a new ransomware wave sweeping across underprotected energy networks worldwide. 🌐⚡
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: x.com
Extra Source Hub:
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




