CRPx0 ransomware: what you need to know

Published September 9, 2026

CRPx0 is a ransomware gang that steals files and locks them up, then demands money to unlock them. They also steal data to blackmail victims further.

Report priority
High
Group
CRPx0

What to do

If your business was targeted by CRPx0 ransomware, check if your files were encrypted or if you received a ransom demand. CRPx0 often sends emails or uses phishing to trick employees into opening malicious files or links. If you suspect an attack, contact Fortra support or your IT team immediately.

If you were hit, do not pay the ransom. Instead, report the attack to Fortra or your IT security team. They can help recover your data and prevent further damage. For prevention, train employees to spot phishing emails and avoid opening unknown attachments or links. Keep backups of important files in a secure, offline location.

Reported details

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.