Last Ransomware victims

Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Groups

0


Victims

0


Victims this month

0


Victims this year

0
This page lists the latest 100 ransom claims detected by Ransomware.live. We continously scrape ransomware group sites to detect new victims.
Ransomware.live has been tracking ransomware's victims since April 2022.


Ransomware.livedoes not exfiltrate, download, host, repost, or disclose any stolen data. Any legal concerns regarding the content should be directed at the attackers, notRansomware.live. This platform is dedicated to cybersecurity awareness, reporting on ransomware incidents to inform the public.Ransomware.liveoperates independently, with no affiliation or alignment with any ransomware groups, and does not host or distribute infringing content. All information is automatically gathered and redacted from publicly accessible sources, including ransomware leak sites on the dark web.




View summary page

US flag

ehdd.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-20 03:00

Sector: Technology
Founded in 1946, EHDD seeks to create built environments that enhance our culture, honor the natural environment, and respect and delight the people who use them. Headquartered in San Francisco, EHDD serves clients around the world in Aquariums, Museums and Science Centers, Education, Corporate Office, Mixed-Use Development, and Government. EHDD is a Top 10 AIA COTE honoree, and featured in " The Habits of High-Performance Firms, Lessons from frequent winners of the AIA COTE Top Ten Award.

Victim:   |  Group: 
GB flag

Ligentia 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 23:58

Ligentia provides freight forwarding and supply chain management solutions. The company was founded in 1996 and is headquartered in Leeds, United Kingdom

Victim:   |  Group: 
AE flag

rossmanmedia.ae 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 22:27

Sector: Technology
[AI generated] Rossman Media is a Dubai-based full-service digital marketing agency. They offer various services like social media management, SEO, content creation, website design & development, and PPC advertising. Their focus is on delivering top-notch strategies that strengthen online presence, convert leads, and engage audiences for businesses of all sizes. They aim to influence, educate, and form a deep connection between brands and their audiences. With a customer-centric approach, they emphasize creating compelling, creative digital experiences.

Victim:   |  Group: 
BG flag

Supreme Administrative Court of Bulgaria 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 20:25
Estimated Attack Date: 2025-01-27

The Supreme Administrative Court provides for supreme judicial supervision over the precise and uniform application of laws in administrative justice. The Supreme Administrative Court hears complaints and protests against the actions of the Council of Ministers, the Prime Minister, Deputy Prime Ministers, Ministers, heads of other positions directly subordinate to the Council of Ministers, Acts of the Supreme Judicial Council, Acts of the Bulgarian Citizen Bank, Acts of Regional Regional Governing Acts, as well as other actions specified in the law; This is pronounced in disputes about the legality of taxes; It has reviewed the quality of judicial acts issued in administrative cases and is considering requests for annulment of compulsory courts' decisions in administrative cases.

Victim:   |  Group: 
ES flag

Ondunova 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 17:08

Sector: Not Found
Grup Ondunova is one of the leading corrugated cardboard packagin g manufacturing groups in Catalonia and is formed by the companie s Ondunova and Wondu, with their respective production centers in Santa Margarida i Els Monjos, Barcelona. We are ready to upload more than 31 GB of essential corporate doc uments such as: NDA’s, financial data (audits, payment details, r eports), internal correspondence, contact numbers and e-mail addr esses of employees and customers, etc.

Group: 
DE flag

ziese.net 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 16:28

Sector: Not Found
Ziese & Sons Excavating, Inc. is your premier excavation company serving Crown Point and the surrounding areas. Contact us today for a free consultation.

Victim:   |  Group: 
 flag

rwrhine.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 16:27

Sector: Not Found
[AI generated] Rwrhine.com is a professional dental practice led by Dr. Richard W. Rhine, a reputed dentist renowned for his expertise in general and cosmetic dentistry. The practice is located in Hayward, California, and is dedicated to offering personalized service and comprehensive dental care. The company's services ranges from preventive care and routine cleanings to restorative procedures and cosmetic treatments.

Victim:   |  Group: 
BE flag

foyernotredamedepaix.be 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 16:25

Sector: Healthcare
[AI generated] Foyernotredamedepaix.be is a Belgian healthcare company that specializes in treating people with mental illnesses and disabilities. The company provides personalized care plans focusing on respect, autonomy, and personal development while preserving patients' dignity. They offer aid to families affected by such illnesses and aim to create a peaceful, supportive environment for each individual under their care.

Victim:   |  Group: 
US flag

fastrans.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 16:24

Fastrans Logistics

Victim:   |  Group: 
DE flag

Südkabel GmbH 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 15:37

Südkabel in Mannheim develops, produces and supplies underground cables for medium, high and extra-high voltage as well as the cor responding accessories for energy transmission and distribution c ustomers. We are ready to upload more than 27 GB of essential corporate doc uments such as: many NDA’s, financial data (audits, payment detai ls, reports), contact numbers and e-mail addresses of employees a nd customers, etc.

Victim:   |  Group: 
DE flag

Hochschule 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 15:01
Estimated Attack Date: 2023-09-28

Sector: Education
Extract from Gitlabs: Next TI, VISEO, Hochschule Trier - Hochschule Trier is a German university of applied sciences offering a wide range of practice-oriented programs and conducting forward-looking research across its main campus and specialized campuses for design and environmental studies.

Victim:   |  Group: 
FR flag

VISEO 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 15:01

Sector: Technology
Extract from Gitlabs: Next TI, VISEO, Hochschule Trier - VISEO is a global technology company offering digital transformation services, including customer experience, modern ERP cloud systems, supply chain management, finance transformation, custom development, and data analytics & AI, to help businesses optimize processes and enhance customer interactions.

Victim:   |  Group: 
ID flag

Next TI 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 14:54

Sector: Technology
Extract from Gitlabs: Next TI, VISEO, Hochschule Trier: Next TI is an Indonesian IT solutions company specializing in financial digital platforms for banking and multifinance industries, supported by South Korea's Hana Financial Group.

Victim:   |  Group: 
US flag

Alabama Ophthalmology Associates 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 14:52

Sector: Healthcare
Alabama Ophthalmology Associates is a six physician subspecialty ophthalmology practice.

Victim:   |  Group: 
US flag

DR.Claims FL LLC 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 13:28

Sector: Not Found
N/A

Victim:   |  Group: 
IN flag

EzyLegal 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 13:27

N/A

Victim:   |  Group: 
US flag

Vector Engineering, Inc 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 13:15

Sector: Not Found
Vector Engineering, Inc is a company that operates in engineering and environmental consulting for mining, mineral processing, was te management. We are ready to upload more than 10 GB of sensitive corporate doc uments such as: confidential licenses, agreements and contracts, financial data (audits, payment details, reports), contact number s and e-mail addresses of employees and customers, marriage certi ficates, etc.

Victim:   |  Group: 
US flag

Hall Law Group LLP 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 13:15

Hall Law Group LLP has been offering probate planning, estate adm inistration, tax, business and family office services for over 25 years. We are ready to upload more than 55 GB of essential corporate doc uments such as: SSN’s, driver licenses, contact numbers and e-mai l addresses of employees and customers, passports (including thos e of famous individuals) and other employee and customer document s, financial data (audits, payment details, reports), medicare do cuments, etc.

Victim:   |  Group: 
US flag

haleycomfort.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 12:34
Estimated Attack Date: 2025-02-18

[AI generated] Haley Comfort Systems, operating as haleycomfort.com, is a leading provider of heating and cooling services. Offering a range of products, from HVAC systems to fireplaces and custom home remodeling services, this company prioritizes expert installations and stellar customer service. Located in Rochester and Burnsville, Minnesota, Haley Comfort Systems has built its reputation on quality craftsmanship, energy-efficient products, and comprehensive maintenance services.

Victim:   |  Group: 
DE flag

DBK 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 12:32

Company has 48 hours. Leak include maildumps, finances and other company documents.

Victim:   |  Group: 
US flag

Haggin Oaks Golf (hagginoaks.com) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 11:52

29,2 GB

Victim:   |  Group: 
 flag

traffic-advertising-llc 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 11:05

We are a full-service automotive advertising agency that caters to dealerships across the continental U.S. It is the job of our media team to perform comprehensive market analyses for each of our clients to ensure that all of our TV buys cons ...

Victim:   |  Group: 
 flag

dr-elizabeth-bjornson 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 11:03

Sector: Not Found
We make it easy for you to obtain optimal dental health that is affordable, whether you undergo a routine comprehensive exam or more invasive procedures. We accept all major credit cards, personal checks, and cash. We also offer payment optio ...

Victim:   |  Group: 
ZM flag

Eservices.gov.zm 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 10:21
Estimated Attack Date: 2025-02-12

To the leadership of Zamservices We have compromised Eservices.gov.zm main servers, backup, internal network, we also exfiltrated all data before […]

Victim:   |  Group: 
US flag

lake-washington-vascular 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 09:26

Sector: Healthcare
Lake Washington Vascular Center is the best place for your Vein Treatments, Vascular Surgeons, and vascular care

Victim:   |  Group: 
 flag

Gitlabs: Next TI, VISEO, Hochschule Trier 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 08:46

Sector:

Victim:   |  Group: 
US flag

h2o.ai 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 07:29
Estimated Attack Date: 2025-01-29

Sector: Technology
As a result of our operation, we have discovered the following concerning data: 1. Unanonymized customer datasets intended for AI training. 2. Full source code of programs from the Git repository, including code for driverless systems, GPT models, and others. 3. A substantial amount of internal information, including contracts, customer personal data, project costs, and project documentation. 4. Backup copies of employee email accounts containing customer correspondence.

Victim:   |  Group: 
CA flag

BeniPlus 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 06:03

N/A

Victim:   |  Group: 
UK flag

Brolly 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 06:02

Sector: Not Found
N/A

Victim:   |  Group: 
 flag

Revi 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 06:00
Estimated Attack Date: 2024-06-26

Sector: Not Found
N/A

Victim:   |  Group: 
US flag

Help Me Grow Yolo 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 05:58

Sector: Education
N/A

Victim:   |  Group: 
FI flag

NimuSoft 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 05:57

Sector: Not Found
N/A

Victim:   |  Group: 
IL flag

footballticketnet.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 19:30

[AI generated] Footballticketnet.com is an online marketplace that allows customers to buy tickets to football matches across the globe. Launched in 2007, it prides itself on providing secure transactions and often hard-to-get tickets. The platform offers a wide range of events, from the English Premier League to the UEFA Champions League. Known for its good customer service and positive reviews, they offer a 100% money-back guarantee if they are unable to supply the tickets sold.

Victim:   |  Group: 
US flag

uniekinc.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 19:26

Furniture. “Uniek is the premier designer, manufacturer and supplier of picture frames and home decor accents for retailers in North America. They sell mirrors, albums, photo frames, art and other home decor. Uniek are a privately owned company headquartered in Waunakee, Wisconsin. Its products are exclusively manufactured in the United States.” Website: https://uniekinc.com/ Revenue : $37.5M Address: 805 Uniek Dr, Waunakee, Wisconsin, 53597, United States Phone Number: (608) 849-9999 Download link #1: https://[redacted].onion/UNIEK/PROOF/ Mirror: https://[redacted].onion/UNIEK/PROOF/ DATA DESCRIPTIONS: Personal identifiable information, corporate confidential data, engineering data, customer information, financial\payroll documents, HR documents, projects, employees\executives personal data, corporate correspondence, database backups, etc

Victim:   |  Group: 
US flag

midwayimporting.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 19:24

Drug Stores & Pharmacies. “Midway Importing is the leading Hispanic health and beauty care distributor in the United States because we are dedicated towards providing the best mix of Hispanic brands, at the right price. We have achieved unmatched success for the past 25 years by complementing our brands with excellent merchandising services, and a comprehensive marketing program. Here at Midway we are truly a family, committed to improving the lives of the US Hispanic consumer.” Website: https://www.midwayimporting.com/ Revenue : $43.7M Address: 1807 Brittmoore Rd, Houston, Texas, 77043, United States Phone Number: (713) 802-9363 Download link #1: https://[redacted].onion/MIDWAY/PROOF/ Mirror: https://[redacted].onion/MIDWAY/PROOF/ DATA DESCRIPTIONS: Personal identifiable information, employees and executives personal folders\docs, corporate OneDrives, database backups, confidential agreements, financial docs, corporate correspondence, HR dept data, etc.

Victim:   |  Group: 
US flag

revitalash.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 19:23

Cosmetics. “Athena Cosmetics, Inc. Is committed to the belief that it’s continuing business success is built upon the manufacture and sale of safe, reliable, quality products, combined with uncompromised integrity and the spirit of philanthropy. As a company, we embrace and pass these values on to our customers, employees and partners.” Website: https://www.revitalash.com/ Revenue : $21.5M Address: 23000 Avalon Blvd, Carson, California, 90745, United States Phone Number: (805) 662-2020 Download link #1: https://[redacted].onion/REVITALASH/PROOF/ Mirror: https://[redacted].onion/REVITALASH/PROOF/ DATA DESCRIPTIONS: Personal Identifiable information (both customers and employees), database backups (150k+ customers private data), various confidential corporate and employees docs, financials, HR dept data, agreements, complaints, QA docs, corporate correspondence, etc.

Victim:   |  Group: 
US flag

bestbrands.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 19:21

“We are a 60+year old company with operations in New York, Hong Kong and China. Our products are as diverse as the capabilities of our young and tenacious team of artists. We work with major brands and licenses in the industry including Cuisinart, Waring, Rachael Ray, Imusa,Daisy Fuentes, CFA, Safety First, Disney, Nick, Marvel and Hasbro. We also cater to major and specialty customers' private label needs in the US, Canada and South America.” Website: https://bestbrands.com/ Revenue : $10.5M Address: 25 MERRICK AVE, Merrick, New York, 11566, United States Phone Number: 646-432-4373 Download link #1: https://[redacted].onion/BESTBRANDS/PROOF/ Mirror: https://[redacted].onion/BESTBRANDS/PROOF/ DATA DESCRIPTIONS: Personal Identifiable information, database backups, corporate documents\agreements\contracts, financial data, payroll, HR dept docs, shipping\operations data, corporate OneDrive export, employees personal folders, corporate and personal correspondence, etc.

Victim:   |  Group: 
RO flag

autogedal.ro 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 17:48
Estimated Attack Date: 2025-02-07

Sector: Not Found
AutoGedal, the destination of confidence for passengers of travel, nature and adventure . With a ...

autogedal.ro has been previously claimed by Funksec for an attack estimated on 2025-02-07.

This could suggest a new attack, a cross-claim between brands by the same threat actor, or the recycling of previously leaked stolen data.

Update Date: 2025-02-18

Victim:   |  Group: 
 flag

www.mwmechanicalinc.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 17:09
Estimated Attack Date: 2025-02-07

Sector: Construction
[AI generated] MW Mechanical Inc. is an American enterprise specializing in providing reliable heating and cooling system services. With a team of skilled professionals operating for more than 20 years, they offer diverse services such as custom ductwork, commercial refrigeration, system installation, maintenance, and repair. Their services prioritize energy efficiency, cost-effectiveness, and client satisfaction.

Victim:   |  Group: 
 flag

www.alphamedctr.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 17:07
Estimated Attack Date: 2025-02-02

Sector: Healthcare
[AI generated] Alpha Medical Center is a medical establishment dedicated to promoting health and wellness through exceptional patient care. They offer an array of medical services, including primary care, preventive medicine, women's health, and more. Their team of healthcare professionals places a high emphasis on tailored treatment plans, innovation and continuous education to ensure patients receive the best possible healthcare experience.

Victim:   |  Group: 
US flag

www.ccttechnologies.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 17:05
Estimated Attack Date: 2025-02-02

Sector: Technology
[AI generated] CCT Technologies Inc., also known as ComputerLand of Silicon Valley, is a US-based IT solutions and services provider. Founded in 1978, the company offers a wide range of solutions including enterprise computing, network services, system integration, and software solutions. It works with a broad array of public and private sector clients, specializing in both software and hardware solutions to help businesses keep pace with technological advancements.

Victim:   |  Group: 
US flag

www.copleystoughton.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 17:04
Estimated Attack Date: 2025-01-30

Sector: Healthcare
Skilled Nursing and Rehabilitation Center

Victim:   |  Group: 
 flag

www.macmed.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 17:01

Sector: Healthcare
[AI generated] Macmed Healthcare is a leading healthcare company with a focus on wound care and dermatology. Based in Australia, they provide innovative, cost-effective solutions for the healthcare industry. Their products include wound dressings, prevention devices, and skin care products. With decades of experience, they aim to improve patient outcomes through their offering of comprehensive and tailored healthcare solutions.

Victim:   |  Group: 
US flag

Decore-Ative Specialties 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 16:15

Lean manufacturer of custom cabinet components for the kitchen, b ath, closet, garage, and home organization industries. We are ready to upload more than 8 GB of essential corporate docu ments such as: NDA’s, confidential licenses, agreements and contr acts, financial data (audits, payment details, reports), medical documents, contact numbers and e-mail addresses of employees and customers, etc.

Group: 
US flag

Daniels Homes 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 14:44

Sector: Construction
Daniels Homes provides remodeling and renovation services with th e same level of care and attention to detail as in building a new home. We are ready to upload more than 60 GB of essentials corporate do cuments such as: contact numbers and e-mail addresses of employee s and customers, financial data (audits, payment details, reports ), confidential licenses, agreements and contracts, etc.

Group: 
GB flag

PREMIER HOUSEWARES LIMITED 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 14:44

Wholesaler supplying trade buyers with on-trend home lifestyle pr oducts, luxury furniture and quality kitchenware. We are ready to upload more than 110 GB of essential corporate do cuments such as: contact numbers and e-mail addresses of employee s and customers, financial data (audits, payment details, reports ), confidential licenses, agreements and contracts, etc.

Group: 
MY flag

Ranhill Bersekutu 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 12:23

Sector: Energy
Ranhill Bersekutu together with Ranhill Consulting is a leading Malaysian Bumiputera engineering firm established in 1973. The company's history dates back to more than 50 years through its earlier overseas affiliation. The company participates in all sectors of nation building projects including Transportation related, Power, Water & Wastewater, Building & Ecological Sustainable Design, Project Management, Independent Check Engineers and Auditors. We have executed work in more than 20 countries and are active throughout Asia, Middle East and Africa.

Victim:   |  Group: 
IL flag

lavi.co.il 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 10:26

Sector: Technology
Kibbutz Lavi Hotel is a company that operates in the Furniture industry. It employs 50to99 people and has 10Mto25M of revenue. The company is headquartered in Israel. Phone Number +972 46799450 Total Files Listed: 119128 File(s) 93,202,615,220 bytes 67922 Dir(s) 5,706,414,174,208 bytes free

Victim:   |  Group: 
CA flag

pyasolutions.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 08:55

Sector: Technology
PYA Solutions specializes in Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central, offering industry-specific solutions to enhance business operations. The company is recognized for its innovative and responsive approach in delivering advanced technological solutions and best-business practices. Their clientele spans various sectors, including leasing, wholesale, and distribution. With a presence in Montreal, Quebec, Canada, and Jacksonville, USA, PYA Solutions is dedicated to improving business efficiency through tailored ERP solutions. Total Files Listed: 27962 File(s) 243,517,595,726 bytes 8275 Dir(s) 7,383,778,062,336 bytes free Phone Number (904) 880-8818

Victim:   |  Group: 
CA flag

Buanderie Centrale de Montreal 

Company logo
Ransomware Group:

Discovery Date: 2025-02-18 08:04

Buanderie Centrale de Montreal BCM is a non-profit organization that, since 1979 , has offered laundry services focused on the very varied needs of its clients.

Group: 
US flag

myhscu.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 22:22
Estimated Attack Date: 2025-02-14

Heritage South Credit Union was originally chartered in 1937 as the Avondale Employees Federal Credit Union. After many years and a couple of name changes, Heritage South Credit Union continues to have a strong presence in Sylacauga, Childersburg, Moody, and Alexander City as a fixture in the community and as a stable and secure financial institution. Heritage South Credit Union has grown to over $160 million in assets and over 14,000+ members. - 300 GB data including: - debit card numbers - account numbers - SSN - address - phone - email - DOB - current balances - debts - loans - insurance Here's data for CEO: JAMIE MCCAA PAYTON 3993 ODENS MILL RD SYLACAUGA AL 35151 DOB: 1969-11-18 SSN: 423-04-5662 Phone: 256-872-2885|256-245-0777 Email: jpayton@myhscu.com|cedarcreekcowboychurch@yahoo.com|jamie.hscu@gmail.com SPOUSE: CHRIS PAYTON (416-82-5751 1967-12-01)

Victim:   |  Group: 
PK flag

www.macter.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:50

Sector: Healthcare
[AI generated] Macter International Ltd is a pharmaceutical manufacturing company based in Karachi, Pakistan. It is among the leading pharmaceutical companies in the country. Macter manufactures a wide range of products including antibiotics, analgesics, antidiabetics, antifungal, and gastrointestinal treatments. The company is renowned for its quality, affordability, and competitiveness in both domestic and international marketplaces.

Victim:   |  Group: 
US flag

Cuna Supply 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:47

Sector: Not Found
United States

Victim:   |  Group: 
US flag

The Townsley Law Firm Information 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:45

United States

Victim:   |  Group: 
US flag

Bushmans 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:44

United States

Victim:   |  Group: 
US flag

Inland Empire Distribution Systems, Inc. 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:42

United States

Victim:   |  Group: 
US flag

Wylie Steel Fabricators 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:41

United States

Victim:   |  Group: 
US flag

Oxford Companies 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:39

Sector: Real Estate
United States

Victim:   |  Group: 
US flag

Stage 3 Separation 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:38

Sector: Energy
United States

Victim:   |  Group: 
CA flag

Transkid 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:36

Sector: Not Found
Canada

Victim:   |  Group: 
DE flag

Rheinischer Sch 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:35

Sector: Not Found
Germany

Victim:   |  Group: 
CA flag

Startek Peglar & Calcagni 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:33

Sector: Not Found
Canada

Victim:   |  Group: 
CA flag

Weed Man Canada 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:31

Canada

Victim:   |  Group: 
US flag

Bulldog Oilfield Services 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 21:30

Sector: Energy
United States

Victim:   |  Group: 
GB flag

danecourt.kent.sch.uk 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 19:27

Sector: Education
UK - Dane Court Grammar School

Victim:   |  Group: 
 flag

toitoiusa.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 19:26

Sector: Education
USA - Toi Toi USA

Victim:   |  Group: 
DK flag

lekiaviation.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 18:30

[AI generated] Leki Aviation specializes in the global aircraft parts distribution and services market. They cater to the suppliers and customers in the aftermarket aviation industry, providing deep expertise in areas like cabin interior needs, engine spares, and rotables, amongst others. Operating across USA, Europe, Asia, and Middle East, their extensive inventory serves commercial, business, and military sectors.

Victim:   |  Group: 
AU flag

bisindustries.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 18:28

[AI generated] Bis Industries is an Australian company providing logistics, materials handling, and specialized equipment services. They operate in the resources sector, including coal, steel, iron ore, and others. Bis also offers off-road load and haul, underground mining, site services, and innovative automation and digital solutions. The company's core values emphasize safety, reliability, and sustainability.

Victim:   |  Group: 
US flag

kinseysinc.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 17:11

Retail. “Kinseys Inc. is dedicated to providing programs and services that help sporting goods and outdoor businesses save money, enhance profits and build relationships. They serve brick-and-mortar and eCommerce retailers nationwide, focusing on four-season retailers who sell archery, ammunition, and firearms.” Website: https://www.kinseysinc.com/ Revenue : $74.9M Address: 1660 Steel Way Dr, Mount Joy, Pennsylvania, 17552, United States Phone Number: (800) 366-4269 Download link #1: https://[redacted].onion/KINSEY/PROOF/ Mirror: https://[redacted].onion/KINSEY/PROOF/ DATA DESCRIPTIONS: Personal Identifiable information, database backups, corporate data: sales, financial docs, HR and IT dept data, employees and executives personal docs, customer data, corporate correspondence etc.

Victim:   |  Group: 
US flag

steelerubber.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 17:09

Automotive Service & Collision Repair. “Steele Rubber Products is a manufacturer of auto weatherstrip and rubber parts to fit classic cars, trucks, and hot rods since the mid 1960's. They supply high quality windshields, doors, windows, hoods and trunk parts as well as hard to find products such as gaskets, pedal pads, fuel systems parts and bumpers.” Website: https://www.steelerubber.com/ Revenue : $17.9M Address: 6180 Hwy 150 E, Denver, North Carolina, 28037, United States Phone Number: (704) 483-9343 Download link #1: https://[redacted].onion/STEELRUBBER/PROOF/ Mirror: https://[redacted].onion/STEELRUBBER/PROOF/ DATA DESCRIPTIONS: Personal identifiable information, corporate data, engineering documents\drawings, agreements, contracts, invoices, financial data\payroll, HR dept docs, corporate correspondence, employees personal folders, etc.

Victim:   |  Group: 
US flag

almostfamousclothing.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 17:07

Clothing. “The Almost Famous journey began in 1974. Millions of girls wore our clothes to create their own story. "Lifestyle creates Fashion" became our vision for the future. Our styling, our fabrics and our prints align with our girl's individuality helping then to curate their own existence. All tribes find something here to call their own ranging from denim, novelty tops, sweaters, dresses and outerwear.” Website: https://almostfamousclothing.com/ Revenue : $183M Address: 525 7th Ave, New York, NY 10018, US Phone Number: +1 (212) 764-4545 Download link #1: https://[redacted].onion/YOUNIQUENYC/PROOF/ Mirror: https://[redacted].onion/YOUNIQUENYC/PROOF/ DATA DESCRIPTIONS: Personal Identifiable information, corporate confidential data, production documents\drawings, corporate OneDrive exports, employees personal folders, financial data, contracts\NDAs, corporate correspondence, etc.

Victim:   |  Group: 
US flag

This entry has been removed following a request from the company. 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 17:06

Takedown notice of 18 February 2025 - Request #736

Group: 
US flag

ssmcoop.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 17:04

Business Services. “All West Select Sires Inc. provides bovine genetics and related services. The company offers services such as select mating services, estrus synchronization, artificial insemination school, breeding box plans, technicians, and programs for genetic advancement.” Website: https://ssmcoop.com/ Revenue : $22.5M Address: PO Box 1803, Turlock, California, 95381, United States Phone Number: (800) 278-8254 Download link #1: https://[redacted].onion/ALLWEST/PROOF/ Mirror: https://[redacted].onion/ALLWEST/PROOF/ DATA DESCRIPTIONS: Corporate documents, contracts\agreements, production data, corporate correspondence,financial documents, employee personal folders\files, etc.

Victim:   |  Group: 
BR flag

hiway.com.br 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 16:56

Sector: Not Found
[AI generated] Hiway.com.br is a Brazil-based company that specializes in providing quality internet services. They offer diverse packages that are suitable for both individual users and large businesses, focusing on delivering a seamless and fast internet connection. In addition to their internet services, they also offer solutions in telephony and data center services. Well-known for their innovative solutions and customer oriented approach, they strive to meet the evolving business needs in the digital age.

Victim:   |  Group: 
SG flag

Thong Sia 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 16:48

Sector: Not Found
THONG SIA GROUP, a member of STELUX Group of Companies, is also t he sole distributor of Seiko watches, Seiko clocks, Lorus clocks, Alba watches, Wired watches and Seiko special time equipment in Hong Kong, Malaysia, Brunei, Singapore and Macau. We are ready to upload a lot of sensitive corporate documents suc h as: financial data (audits, payment details, reports), passport s and other employee and customer documents, contact numbers and e-mail addresses of employees and customers, etc.

Group: 
CH flag

Swissmem 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 15:47

Exfiltraded data : yes - Encrypted data : yes

Victim:   |  Group: 
US flag

Bulverde Glass, Inc. 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 15:10

Bulverde Glass, Inc. was established in 1992 just outside the city of San Antonio in small-town Bulverde, but as the city has grown and expanded over the years, so has Bulverde Glass. In fact, we outgrew the small town of Bulverde and moved i ...

Victim:   |  Group: 
SE flag

Hisingstads Bleck 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 15:02

Hisingstads Bleck- och Plåtslageri AB has been in the sheet metal construction business for over 100 years.

Victim:   |  Group: 
US flag

Leadership Strategies 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 15:01

Take a facilitative approach with Leadership Strategies. We provide expert meeting facilitation and facilitation training to project managers, IT professionals, business analysts, human resources, learning and development, organization alignment and other leaders in business, non-profit and government sectors. We believe facilitation is a powerful tool for helping people reach better decisions, often faster, with much higher levels of buy-in and commitment. The more people in an organization who understand and are skilled at facilitation, the more productive and effective an organization can be. In our course, The Effective Facilitator youll build the skills and confidence to conduct successful meetings every time by learning the approach and techniques our own professional facilitators use. The Drivers Model is LSIs proven methodology for helping an organization identify its business problems and construct an effective strategic plan of action for solving them.

Victim:   |  Group: 
DK flag

LINTEC & LINNHOFF Holdings 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 14:59

Lintec & Linnhoff is a global manufacturer and distributor of leading-edge solutions for the concrete and asphalt industries. Its products include asphalt batching plants, concrete batching plants, pavement related technologies and machinery, and specialist concrete cooling solutions. All its machines are engineered to the highest levels and exceed global standards for environmental impact, recyclability and reusability. Lintec & Linnhoff combine the precision and engineering expertise of its German heritage with the exacting standards required to serve the varied needs of the global construction market. It provides purpose-built solutions to customers that are supported through its team of global experts and distribution partners. Lintec & Linnhoff machinery has helped deliver some of the world's most prominent construction achievements, including: the Hong Kong-Zhuhai-Macau bridge; Abu Dhabi's Yas Marina Circuit; The Palm Island, Dubai; and the Storebaelt Bridge Denmark.

Victim:   |  Group: 
 flag

HRS_IDEA_Expertises 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 14:58

Sector: Not Found
Créé en 2014, IDEA est un réseau dexperts automobile national et dans les DOM TOM, en plein développement. Conscient que le service et la qualité dune agence est le fruit dun bon dirigeant, le réseau IDEA a pris la décision de mettre en uvre une franchise avec lensemble des agences. Nos équipes expertisent lensemble des véhicules terrestres et maritimes. Lévolution des technologies et des techniques de réparation nous poussent à former de manire constante notre personnel. Grce à cela, nous pouvons intervenir efficacement sur différents types de véhicules : engins agricoles, deux roues, poids lourd, la navigation de plaisance, caravanes. Nos experts et personnels spécialisés reoivent également des formations sur les nouveautés du marché comme les véhicules électriques, les responsabilités civiles professionnelles, les malfaons, vices cachés Fort de notre volonté de devenir un acteur majeur du service clients, nous développons des produits informatiques afin de faire évoluer le schém

Victim:   |  Group: 
NL flag

Autoschade Pippel 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 14:57

Sector: Not Found
Autoschade Pippel BV is a company that operates in the Investment Banking industry. It employs 20to49 people and has 1Mto5M of revenue. The company is headquartered in Zaltbommel, Netherlands.

Victim:   |  Group: 
SE flag

Pedensia Graphics Distribution 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 14:55

Sector: Not Found
Pedensia Graphics Distribution is a company that operates in the Custom Software & IT Services industry. It employs 5to9 people and has 1Mto5M of revenue. The company is headquartered in Moelndal, Vaestra Goetaland, Sweden.

Victim:   |  Group: 
SE flag

Winbas 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 14:54

Sector: Not Found
Winbas r ett system utvecklat för grossist/handel, entreprenad, bokning/uthyrning samt tillverkande företag. Genom att anvnda verktyg och komponenter frn Microsoft har vi skapat ett grnslöst affrssystem bde för dagens och morgondagens Windowsmiljö. Den öppna databasen möjliggör enkel kommunikation mot andra system p marknaden.

Victim:   |  Group: 
 flag

hamton 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 14:53

Sector: Not Found
Letar du efter presenter eller gåvor till företag? På Hamton i Göteborg hittar du intressanta leverantörer och produkter.

Victim:   |  Group: 
US flag

Greencastle-Antrim Senior High School (gcasd.org) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 14:21

Sector: Education
7.6 GB

Victim:   |  Group: 
US flag

Woman's Athletic Club of Chicago 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 14:13

Woman's Athletic Club of Chicago is a private women's club residi ng in a historical landmark building on Michigan Avenue and the c ountry's first women's athletic club. We are ready to upload some essential corporate documents such as : confidential licenses, agreements and contracts, financial data (audits, payment details, reports), internal correspondences, HR documents, contact numbers and e-mail addresses of employees and customers, etc.

Group: 
GR flag

P.N. Sakkoulas 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 12:43

Sector: Not Found
P.N. Sakkoulas publishes law books and the journals "Criminal Chr onicles" and "Chronicles of Private Law". We are ready to upload a lot of essential corporate documents suc h as: contact numbers and e-mail addresses of employees and custo mers, financial data (audits, payment details, reports), confiden tial licenses, agreements and contracts, etc.

Victim:   |  Group: 
 flag

Allied Tenesis 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 12:22

Our Company Our solutions-based philosophy of producing products that deliver value to our customers, together with high-quality service and support, has resulted in a very extensive worldwide customer base.

Allied Tenesis has been previously claimed by Lockbit3 for an attack estimated on 2024-05-27.

This could suggest a new attack, a cross-claim between brands by the same threat actor, or the recycling of previously leaked stolen data.

Update Date: 2025-02-17

Victim:   |  Group: 
 flag

DA Capital 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 11:44

DA Capital LLC is a global investment manager specializing in cre dit and special situations. We are ready to upload a lot of sensitive corporate documents suc h as: NDA’s, employee credit cards, confidential licenses, agreem ents and contracts, employee medical cards, insurance documents, passports and visas, tax information, driver licenses, contact nu mbers and e-mail addresses of employees and customers, etc.

Group: 
IT flag

COSMED 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 11:44
Estimated Attack Date: 2025-02-14

Sector: Healthcare
COSMED is a privately owned company manufacturing Cardio Pulmonar y, Metabolic and Body Composition diagnostic equipment. We are ready to upload more than 25 GB of essential corporate doc uments such as: passport scans, NDAs, confidential files, financi al data (audits, payment details, reports), foreigner identity ca rds, etc.

Group: 
US flag

Persante Health Care 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 10:24

Sector: Healthcare
Persante Health Care is a leading provider of sleep management services across the nation. Over the past 20 years, Persante has revolutionized the sleep industry. Today, Persante stands at the forefront of technology and service and has become the partner of choice for hospitals and physicians looking to manage and scale their sleep centers the expert way. Contact for details: info@inchelps.com

Victim:   |  Group: 
US flag

annegrady.org 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 22:27
Estimated Attack Date: 2025-02-05

Sector: Healthcare
Anne Grady Services provides a vast array of assistance for adults and children with intellectual disabilities. - Anne Grady Services provides a vast array of assistance for adults and children with intellectual disabilities. Call The Anne Grady Center at 419-866-6500 to be connected to our administrative offices, therapy programs, and leadership team.

annegrady.org has been previously claimed by Ransomhub for an attack estimated on 2025-02-05.

This could suggest a new attack, a cross-claim between brands by the same threat actor, or the recycling of previously leaked stolen data.

Update Date: 2025-02-16

Victim:   |  Group: 
DE flag

Pamrya.de 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 11:05

Sector: Not Found
Extract from Gitlabs: Acqua development, QBurst, Pamyra.de- Pamyra.de is a platform that allows users to compare prices and book shipping services with over 600 verified freight companies.

Victim:   |  Group: 
IN flag

QBurst 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 11:04

Sector: Technology
Extract from Gitlabs: Acqua development, QBurst, Pamyra.de- QBurst is a full-service software development company offering services in cloud enablement, data and AI, digitalization, and more.

Victim:   |  Group: 
RO flag

Acqua development 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 11:04

Sector: Not Found
Extract from Gitlabs: Acqua development, QBurst, Pamyra.de

Victim:   |  Group: 
 flag

Gitlabs: Acqua development, QBurst, Pamyra.de 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 08:37

Sector:
[AI generated] Gitlabs: Acqua development, QBurst, Pamyra.de refers to a combination of several tech companies. GitLab, a web-based DevOps lifecycle tool that provides a Git-repository manager, is pivotal. Acqua Development creates personalized software solutions, while QBurst provides development services across digital platforms. Pamyra.de, on the other hand, is a German online shipping price comparison portal, focusing on courier, express and parcel services.

Victim:   |  Group: 
 flag

Gpstech2007.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 02:53
Estimated Attack Date: 2025-02-08

Sector: Technology
To the board of GPSTECH2007 We have compromised your system servers for Gpstech2007.com and locked out all user, we also

Victim:   |  Group: 
 flag

Mervis.info 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 02:52
Estimated Attack Date: 2025-02-08

Sector: Not Found
For the Administration of Mervis.info We have compromised Mervis.info system and extracted data to do with system control and operation

Victim:   |  Group: 
TW flag

Realtime.tw 

Company logo
Ransomware Group:

Discovery Date: 2025-02-16 02:49
Estimated Attack Date: 2025-02-08

Sector: Technology
To The council Of Realtime Taiwan We have breached Realtime.tw server and extracted data on all employee, and other company

Victim:   |  Group: 
Next