Ransomware Group:  
Cactus



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | External Information | Tools | Yara Rules | TTPs | Ransom Note(s) | Activity | Worldmap | Victims (190)

The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure.

There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.
Source: https://github.com/crocodyli/ThreatActors-TTPs


Sites

Title Available Last Visit FQDN Screenshot
None 🟢 2024-11-21 08:45:51.119412 cactusbloguuodvqjmnzlwetjlpj6aggc6iocwhuupb47laukux7ckid.onion 📸
None 🟢 2024-11-21 08:46:04.804279 cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion 📸

External information

Tools used

Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
Nmap AnyDesk Cobalt Strike Chisel RClone
SoftPerfect NetScan Splashtop
SuperOps

This information is provided by Ransomware-Tool-Matrix

Yara Rules

TTPs

Ransom Note(s)

Activity over time

Worldmap

190 Victims

GB flag

ottosimon.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-11-08 08:33
Estimated Attack Date: 2024-10-30

Sector: Construction
Commercial & Residential Construction. “Otto Simon is an independent specialist engineering consultancy and project delivery organisation based in Manchester, UK. We successfully align the dynamics of a young, forward thinking organisation with decades of experience vested in the very best professionals that we employ.” Website: https://www.ottosimon.co.uk/ Revenue : $16.6M Address: 5 The Cres, Cheadle And Gatley Ward, Cheshire, SK8 1PS, United Kingdom Phone Number: +44 1614917440 Download link #1: https://[redacted].onion/OSL/PROOF/ Mirror: https://[redacted].onion/OSL/PROOF/ DATA DESCRIPTIONS: Personal Identifiable Information, actual database backups, financial documents, executives\employees personal data, customer personal information, corporate confidential data, projects, drawings, correspondence, etc.

Victim:   |  Group: 
FR flag

lumiplan.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-01 19:43

Sector: Technology
Software. “We work in three main areas of activity : citizen communication, mobility and the revitalization of mountain tourist sites. These three areas of activity have one thing in common: useful information in real time, on physical and digital screens, which can be controlled by our LumiPlay platform.” Website: https://www.lumiplan.com/ Revenue : $49.2M Address: 1 Impasse Augustin Fresnel Parc D Act Du Moulin Neuf Cedex, Saint-Herblain, Pays de la Loire, 44800, France Phone Number: +33 240921543 Download link #1: https://[redacted].onion/LUMIPLAN/PROOF/ Mirror: https://[redacted].onion/LUMIPLAN/PROOF/ DATA DESCRIPTIONS: Personal Identifiable Information, financial documents, executives\employees personal data, customer personal information, corporate confidential data and correspondence, projects\drawings etc.

Victim:   |  Group: 
GB flag

lsst.ac 

Company logo
Ransomware Group:

Discovery Date: 2024-11-01 13:24

Sector: Technology
Colleges & Universities. “LSST aims to support the government's widening participation policy that focuses on ensuring every student has an equal chance to further their education. LSST has successfully operated partnerships with the University of West London and London Metropolitan University, since 2013 and 2016 respectively.” Website: https://www.lsst.ac/ Revenue : $72.2M Address: 4 Dunstable Rd, Luton, Bedfordshire, LU1 1DX, United Kingdom Phone Number: +44 1582729486 Download link #1: https://[redacted].onion/LONDONSST/PROOF/ Mirror: https://[redacted].onion/LONDONSST/PROOF/ DATA DESCRIPTIONS: Personal identifiable information, confidential corporate documents\correspondence, financial documents, students and staff personal data, etc.

Victim:   |  Group: 
US flag

hacla.org 

Company logo
Ransomware Group:

Discovery Date: 2024-10-31 11:15

Federal. “The Housing Authority of the City of Los Angeles (HACLA) is a public agency established in 1938 to provide affordable housing options to low-income residents of Los Angeles.” Website: https://www.hacla.org/ Revenue : $1.9B Address: 2600 Wilshire Blvd Fl 5, Los Angeles, California, 90057, United States Phone Number: (213) 252-5313 Download link #1: https://[redacted].onion/HACLA/PROOF/ Mirror: https://[redacted].onion/HACLA/PROOF/ DATA DESCRIPTIONS: Personal Identifiable Information, actual database backups, financial documents, executives\employees personal data, customer personal information, corporate confidential data and correspondence, etc.

Victim:   |  Group: 
US flag

picsolve.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 10:09

Consumer Services. “Pomvom Picsolve is the leading image capture partner for the leisure and entertainment industry. We have over 20 years of experience pioneering and delivering innovative image capture solutions. With offices in the UK, UAE, USA and Hong Kong, we provide everything you need to deliver a smooth running operation” Website: https://www.picsolve.com/ Revenue : $32M Address: 6220 Hazeltine National Dr Ste 110, Orlando, Florida, 32822, United States Phone Number: (407) 482-3131 Download link #1: https://[redacted].onion/PSIDB/PROOF/ Mirror: https://[redacted].onion/PSIDB/PROOF/ DATA DESCRIPTIONS: Personal identifiable information, actual database backups, corporate confidential data and correspondence, customer data\contracts, financial documents, etc.

Victim:   |  Group: 
GB flag

bcllegal.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 10:06

Business Services. “From BCL Legal we have established long standing relationships with law firms and law schools alike. We understand that looking for the perfect graduate or the first step on the legal career ladder can be tough. BCL Graduates now makes that process easy with a few simple clicks.” Website: https://www.bcllegal.com/ Revenue : $16.7M Address: 77 Deansgate Lancaster Buildings Fl 3, Manchester, Lancashire, M3 2BW, United Kingdom Phone Number: +44 1618197475 Download link #1: https://[redacted].onion/XCLOUD/PROOF/ Mirror: https://[redacted].onion/XCLOUD/PROOF/ DATA DESCRIPTIONS: Personal identifiable information, actual database backups, corporate confidential data and correspondence, customer data\contracts, financial documents, personal data, etc.

Victim:   |  Group: 
FR flag

synertrade.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-16 09:08

Sector: Technology
Software. “SynerTrade is the global Source to Pay solution with over 650 customers and managing over $600 Billion in spend. SynerTrade is a leading international provider of cloud-based procurement solutions for the digitalization of companies’ procurement process.” Website: https://www.synertrade.com/ Revenue : $42M Address: 1120 Avenue of the Americas Fl 4, New York City, New York, 10036, United States Phone Number: +49 89 122 8 722-0, +33 1 41 67 30 00 Download link #1: https://[redacted].onion/SynerTrade/PROOF/ Mirror: https://[redacted].onion/SynerTrade/PROOF/ DATA DESCRIPTIONS: Personal identifiable information, database backups, corporate confidential documents\contracts\correspondence, projects, customer confidential data, etc.

Victim:   |  Group: 
GB flag

matki.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-10-08 13:09

Design & Accessories. “Established in 1971, Matki have pioneered innovative design in luxury showers and brassware for over 40 years, enabling a deep understanding and a pragmatic approach to shower design - technically, aesthetically and architecturally.” Website: https://www.matki.co.uk/ Revenue : $23M Address: Churchward Rd, Yate, Bristol, BS37 5PL, United Kingdom Phone Number: +44 1454322888 Download link #1: https://[redacted].onion/MTK/PROOF/ Mirror: https://[redacted].onion/MTK/PROOF/ DATA DESCRIPTIONS: Personal Identifiable Information, database backups, financial documents, executives\employees personal data, corporate confidential data and correspondence, etc.

Victim:   |  Group: 
US flag

corporatejobbank.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-08 13:06

Business Services. “Founded in 1985 and headquartered in Tempe, Arizona, Corporate Job Bank is a staffing organization and a full service personnel firm providing temporary, temp-to-hire, and direct hire services ranging from the production personnel to the upper levels of management” Website: https://corporatejobbank.com/ Revenue : $22.8M Address: 1955 E Broadway Rd Ste 102, Tempe, Arizona, 85282, United States Phone Number: (480) 966-0709 Download link #1: https://[redacted].onion/CJB/PROOF/ Mirror: https://[redacted].onion/CJB/PROOF/ DATA DESCRIPTIONS: Personal identifiable information, corporate confidential documents\correspondence, employees and executives personal data, projects, customer information, etc.

Victim:   |  Group: 
DE flag

www.galab.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-01 10:01

Business Services. “GALAB is an independent service laboratory for external quality control. We analyse and evaluate food, food packaging, consumer products or hygiene products and their raw materials for substances or contaminants.” Website: https://www.galab.com/ Revenue : $7.9M Address: Am Schleusengraben, Hamburg, Hamburg, 21029, Germany Phone Number: +49 403680770 Download link #1: https://[redacted].onion/GALAB/PROOF/ Mirror: https://[redacted].onion/GALAB/PROOF/ DATA DESCRIPTIONS: Database backups, corporate data, projects\drawings, corporate correspondence, etc.

Victim:   |  Group: 
US flag

actionfirepros.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-27 11:03

Sector: Construction
Commercial & Residential Construction “We pride ourselves on our thoroughness and our follow through. We are there until the job is done to the customer's satisfaction. We keep our promises. We are accountable for our work and our word. Our integrity is unwavering and we follow the rules. When we make a commitment, customers know we will keep it. You can count on us.” Website: https://actionfirepros.com/ Revenue : $17.4M Address: 3709 S Interstate Hwy 35 E, Waxahachie, Texas, 75165, United States Phone Number: (254) 235-8300 Download link #1: https://[redacted].onion/ACTIONFIREPROS/PROOF/ Mirror: https://[redacted].onion/ACTIONFIREPROS/PROOF/ DATA DESCRIPTIONS: Personal Identifiable Information, financial documents, customer data, corporate documents\contracts, employees\executives personal data, corporate correspondence, etc.

Victim:   |  Group: 
GB flag

hindlegroup.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-25 08:07

Sector: Construction
Industrial Machinery & Equipment “Hindle Group based in Bradford, West Yorkshire on a 22,000 sq.m site comprises of 2 divisions involved with gears & gearbox manufacture, engine component remanufacture/manufacture and distributors for engine parts.” Website: https://www.hindlegroup.com/ Revenue : $30.6M Address: Caledonia St, Bradford, West Yorkshire, BD5 0EL, United Kingdom Phone Number: +44 1274727234 Download link #1: https://[redacted].onion/HINDLE/PROOF/ Mirror: https://[redacted].onion/HINDLE/PROOF/ DATA DESCRIPTIONS: Personal Identifiable Information, database backups, employees\executives personal data, corporate documents, customer information, contracts\projects, financial documents, corporate correspondence, etc.

Victim:   |  Group: 
GB flag

kjtait.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-25 08:04

Sector: Construction
Membership Organizations “KJ Tait Engineers provides professional consultancy for the design and management of engineering services for buildings and associated infrastructure throughout the UK. We are a professional practice of Mechanical and Electrical and Public Health (MEP) building services engineers with offices in Aberdeen, Cambridge, Edinburgh, Glasgow, and London.” Website: https://kjtait.com/ Revenue : $18.8M Address: 42 Union Ter, Aberdeen, Aberdeenshire, AB10 1NP, United Kingdom Phone Number: +44 1224621794 Download link #1: https://[redacted].onion/KJTAIT/PROOF/ Mirror: https://[redacted].onion/KJTAIT/PROOF/ DATA DESCRIPTIONS: Personal Identifiable Information, database backups, corporate documents\contracts\projects\drawings, employees personal data, customer information, financial documents, corporate correspondence, etc.

Victim:   |  Group: 
US flag

www.amchar.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-25 08:01

FIrearms Retail. “AmChar Wholesale, Inc. has been in the firearms business since 1980. During the last 40 years, we have become one of the top distributors in the industry for law enforcement entities and independent dealers in the United States. AmChar is backed by industry professionals who have been in the firearms business for over a half century.” Website: https://www.amchar.com/ Revenue : $28.7M Address: 100 Airpark Dr Fl 1, Rochester, New York, 14624, United States Phone Number: (585) 328-3951 Download link #1: https://[redacted].onion/AMCHAR2/PROOF/ Mirror: https://[redacted].onion/AMCHAR2/PROOF/ DATA DESCRIPTIONS: Personal Identifiable Information, financial documents, database backups, employees personal documents, corporate data\contracts, customer information, corporate correspondence, etc.

Victim:   |  Group: 
US flag

ten8fire.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-23 11:34

Emergency products “Ten-8 Fire Equipment, Inc. is a distributor of fire and emergency apparatus and equipment. They strive to serve the emergency response field with reliability and integrity. From their professional sales staff to their dedicated service team and 7 service locations, Ten-8 is committed to providing exceptional care to the fire and emergency field.” Website: https://ten8fire.com/ Revenue : $149M Address: 2904 59th Avenue Dr E, Bradenton, Florida, 34203, United States Phone Number: (941) 756-7779 Download link #1: https://[redacted].onion/TEN8/PROOF/ Mirror: https://[redacted].onion/TEN8/PROOF/ DATA DESCRIPTIONS: Personal Identifiable Information, accounting\payroll, database backups, customer data, contracts, employees\executives personal and corporate data, corporate correspondence, etc.

Victim:   |  Group: 
US flag

natcoglobal.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-17 17:00

Business Services “Founded in 1991, North American Textile Company, LLC (NATco) is a global manufacturer of labels, trims and hardware. NATco corporate headquarters is located in Los Angeles, California and owns and operates plants in several countries throughout the world including Italy, China, India and more.” Website: https://www.natcoglobal.com/ Revenue : $38.5M Address: 346 W Cerritos Ave, Glendale, California, 91204, United States Phone Number: (818) 409-0019 Download link #1: https://[redacted].onion/NATCO/full/ Mirror: https://[redacted].onion/NATCO/full/ DATA DESCRIPTIONS: Employees personal and corporate data, customer information, corporate correspondence, database backups, etc.

Victim:   |  Group: 
US flag

peerlessumbrella.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-17 12:45

Manufacturing “Peerless Umbrella is a full service manufacturer of quality umbrellas. Operating with a Union Shop, this family owned business has been a manufacturer of traditional, as well as golf and fashion umbrellas for more than 70 years. Today Peerless is a leader in umbrella technology and manufacturing, as well as one of the largest importers in the country.” Website: https://www.peerlessumbrella.com/ Revenue : $23.2M Address: 427 Ferry St At, Newark, New Jersey, 07105, United States Phone Number: (973) 578-4900 Download link #1: https://[redacted].onion/PEERLESS/full/ Mirror: https://[redacted].onion/PEERLESS/full/ DATA DESCRIPTIONS: Personal Identifiable Information, database backups, employees\executives personal and corporate data, customer data, contracts\projects\drawings, financial documents, corporate correspondence, etc.

Victim:   |  Group: 
US flag

thomas-lloyd.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-17 12:42

Finance “ThomasLloyd is a global investment and advisory firm dedicated to leading the necessary process for social and environmental change, focusing exclusively on the financing, construction and operation of sustainable projects in the infrastructure, agriculture and property sectors.” Website: https://www.thomas-lloyd.com/ Revenue : $66.1M Address: 427 Bedford Rd, Pleasantville, New York, 10570, United States Phone Number: (914) 495-3630 Download link #1: https://[redacted].onion/TLG/PROOF/ Mirror: https://[redacted].onion/TLG/PROOF/ DATA DESCRIPTIONS: Personal Identifiable Information, employees\executives personal data, corporate confidential documents, customer information, financial documents, corporate correspondence, database backups, etc.

Victim:   |  Group: 
US flag

riomarineinc.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-06 08:24

Sector: Construction
Download link #1:  https://[redacted].onion/RIOMARINEINC/PROOF/Mirror: https://[redacted].onion/RIOMARINEINC/PROOF/DATA DESCRIPTIONS: Personal Identifiable Information, employees\executives personal data, engineering data\drawings\projects, customer information, financial documents, contracts, corporate correspondence, database backups etc.

Victim:   |  Group: 
CA flag

champeau.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-06 08:21

Sector: Construction
Download link #1:  https://[redacted].onion/JMCINTERNET/PROOF/Mirror: https://[redacted].onion/JMCINTERNET/PROOF/DATA DESCRIPTIONS: Personal Identifiable Information, employees\executives personal data, engineering documents\projects\drawings, customer information, financial documents, corporate correspondence, etc.

Victim:   |  Group: 
CA flag

simson-maxwell.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-04 00:08
Estimated Attack Date: 2024-09-03

Sector: Energy
Download link #1:  https://[redacted].onion/SIMSONMAXWELL/PROOF/Mirror: https://[redacted].onion/SIMSONMAXWELL/PROOF/DATA DESCRIPTIONS: Personal Identifiable Information, Employees personal and corporate data, customer information, contracts, projects, drawings, financial documents, corporate and personal correspondence, etc.

Victim:   |  Group: 
US flag

balboabayresort.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-04 00:05
Estimated Attack Date: 2024-09-03

Download link #1:  https://[redacted].onion/BBS/PROOF/Mirror:  https://[redacted].onion/BBS/PROOF/DATA DESCRIPTIONS: Personal Identifiable Information, employees\executives personal data, customer information, financial data, contracts, corporate correspondence, etc.

Victim:   |  Group: 
US flag

flodraulic.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-03 20:38

Download link #1:  https://[redacted].onion/FLODRAULIC/PROOF/Mirror: https://[redacted].onion/FLODRAULIC/PROOF/DATA DESCRIPTIONS: Employees personal and corporate data, customer information, contracts, projects, drawings, financial documents, corporate correspondence, etc.

Victim:   |  Group: 
GB flag

mcphillips.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-09-03 20:35

Sector: Construction
Download link #1:  https://[redacted].onion/MCPHILLIPS/PROOF/Mirror: https://[redacted].onion/MCPHILLIPS/PROOF/DATA DESCRIPTIONS: Personal Identifiable Information, customer information, engineering data\drawings\projects, employees\executives personal data, financial documents, contracts, corporate correspondence, etc.

Victim:   |  Group: 
PR flag

rangeramerican.com 

Company logo
Ransomware Group:

Discovery Date: 2024-09-03 20:32

Download link #1:  https://[redacted].onion/RANGERAMERICAN/PROOF/Mirror: https://[redacted].onion/RANGERAMERICAN/PROOF/DATA DESCRIPTIONS: Personal Identifiable Information, customer info, contracts, employees\executives personal and corporate data, accounting\payroll, corporate correspondence, etc.

Victim:   |  Group: 
US flag

securityinstrument.com 

Company logo
Ransomware Group:

Discovery Date: 2024-08-27 10:10

Sector: Technology
Download link #1:  https://[redacted].onion/SIWILM/PROOF/Mirror: https://[redacted].onion/SIWILM/PROOF/DATA DESCRIPTIONS: Corporate confidential data, Personal identifiable information, contracts, employees and executives personal files, financial documents, corporate correspondence, database exports\backups etc.

Victim:   |  Group: 
 flag

tibaitservices.com 

Company logo
Ransomware Group:

Discovery Date: 2024-08-08 08:28

Sector: Technology
Download link #1:  https://[redacted].onion/TIBA/PROOF/Mirror: https://[redacted].onion/TIBA/PROOF/DATA DESCRIPTIONS: Personal Identifiable Information, employees and executives personal and corporate data, financial documents, contracts, corporate correspondence, etc.

Victim:   |  Group: 
US flag

mihlfeld.com 

Company logo
Ransomware Group:

Discovery Date: 2024-08-08 08:02

Download link #1:  https://[redacted].onion/MIHLFELD/PROOF/Mirror: https://[redacted].onion/MIHLFELD/PROOF/DATA DESCRIPTIONS: Employees personal and corporate data, Personal Identifiable Information, financial documents, customer information, contracts, corporate and personal correspondence, etc.

Victim:   |  Group: 
 flag

exco-solutions.com 

Company logo
Ransomware Group:

Discovery Date: 2024-08-05 07:47

Download link #1:  https://[redacted].onion/EXCO/PROOF/Mirror: https://[redacted].onion/EXCO/PROOF/DATA DESCRIPTIONS: Personal Identifiable Information, employees and executives personal and corporate data, customer data, financial documents, contracts, corporate correspondence, etc.

Victim:   |  Group: 
CA flag

dahlvalve.com 

Company logo
Ransomware Group:

Discovery Date: 2024-08-01 12:08

Download link #1:  https://[redacted].onion/DAHLVALVE/PROOF/Mirror: https://[redacted].onion/DAHLVALVE/PROOF/DATA DESCRIPTIONS: Personal identifiable information, corporate confidential data, agreements, contracts, engineering data\drawings\projects, employees and executives personal files, financial documents\statements, corporate correspondence, database backups etc.

Victim:   |  Group: 
GB flag

chubb-bulleid.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-07-30 19:37

Download link #1:  https://[redacted].onion/CBS/PROOF/Mirror: https://[redacted].onion/CBS/PROOF/DATA DESCRIPTIONS: Personal identifiable information, customer confidential information, litigation documents, corporate confidential data, NDA, contracts, employees and executives personal files, financial documents\statements, corporate correspondence, etc.

Victim:   |  Group: 
US flag

leonardssyrups.com 

Company logo
Ransomware Group:

Discovery Date: 2024-07-30 19:36
Estimated Attack Date: 2024-07-21

Download link #1:  https://[redacted].onion/LEONARDDOMAIN/PROOF/Mirror: https://[redacted].onion/LEONARDDOMAIN/PROOF/DATA DESCRIPTIONS: Employees personal and corporate data, Personal Identifiable Information, accounting, financial documents, customer data, contracts, corporate correspondence, database exports etc.

Victim:   |  Group: 
US flag

westernwyomingbeverages.com 

Company logo
Ransomware Group:

Discovery Date: 2024-07-30 19:35
Estimated Attack Date: 2024-07-21

Download link #1:  https://[redacted].onion/WWBEV/PROOF/Mirror: https://[redacted].onion/WWBEV/PROOF/DATA DESCRIPTIONS: Database exports, Employee personal files, personal Identifiable Information, financial data, customer data, contracts, corporate correspondence, etc.

Victim:   |  Group: 
FR flag

demos.fr 

Company logo
Ransomware Group:

Discovery Date: 2024-07-30 19:34

Sector: Technology
Download link #1:  https://[redacted].onion/DEMOSGROUP/PROOF/Mirror: https://[redacted].onion/DEMOSGROUP/PROOF/DATA DESCRIPTIONS: Personal identifiable information, corporate confidential data, NDA, contracts, employees and executives personal files, financial documents\statements, customer information, corporate correspondence, etc.

Victim:   |  Group: 
US flag

denkaiamerica.com 

Company logo
Ransomware Group:

Discovery Date: 2024-07-30 19:34
Estimated Attack Date: 2024-07-26

Download link #1:  https://[redacted].onion/DAI/PROOF/Mirror: https://[redacted].onion/DAI/PROOF/DATA DESCRIPTIONS: Personal identifiable information, corporate confidential data, customers data, contracts, employees and executives personal files, financial documents\statements, corporate correspondence, etc.

Victim:   |  Group: 
US flag

isometrix.com 

Company logo
Ransomware Group:

Discovery Date: 2024-07-17 09:37
Estimated Attack Date: 2024-06-02

Sector: Technology
Download link #1:  https://[redacted].onion/ISOMETRIX/PROOF/Mirror: https://[redacted].onion/ISOMETRIX/PROOF/DATA DESCRIPTIONS: Personal identifiable information, employees and executives personal files, financial data, customer information, contracts\NDA, corporate correspondence, software development data etc.

Victim:   |  Group: 
GB flag

verco.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-07-16 10:06
Estimated Attack Date: 2024-07-02

Download link #1:  https://[redacted].onion/VERCO/PROOF/Mirror: https://[redacted].onion/VERCO/PROOF/DATA DESCRIPTIONS: Personal identifiable information, corporate confidential data, contracts, engineering data\drawings\projects, employees and executives personal files, financial documents\statements, corporate correspondence, etc.

Victim:   |  Group: 
 flag

hydmech.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-24 22:15

Download link #1:  https://[redacted].onion/HYDMECH/PROOF/Mirror: https://[redacted].onion/HYDMECH/PROOF/DATA DESCRIPTIONS: Engineering data - drawings, r&d, QA, Personal Identification information (passports, DLs, etc.), customer agreements, HR confidential data, executives and employees personal folders, financial statements\payroll, etc.

Victim:   |  Group: 
 flag

westfalia-automotive.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-24 22:13

Download link #1:  https://[redacted].onion/MONOFLEX/PROOF/Mirror: https://[redacted].onion/MONOFLEX/PROOF/DATA DESCRIPTIONS: Personal identifiable information, engineering data\drawings, employees and executives personal files, financial data, customer information, database exports, corporate correspondence, etc.

Victim:   |  Group: 
FR flag

millimages.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-23 19:44
Estimated Attack Date: 2023-07-03

Sector: Not Found
Download link #1:  https://[redacted].onion/MILLIMAGES/PROOF/Mirror: https://[redacted].onion/MILLIMAGES/PROOF/DATA DESCRIPTIONS: Personal identifiable information, corporate confidential agreements, contracts, financial documents, personnel data, employees personal files, legal documents, corporate correspondence, etc.

Victim:   |  Group: 
ZA flag

www.glynmarais.co.za 

Company logo
Ransomware Group:

Discovery Date: 2024-06-23 19:43
Estimated Attack Date: 2023-10-12

Download link #1:  https://[redacted].onion/JGM/PROOF/Mirror: https://[redacted].onion/JGM/PROOF/DATA DESCRIPTIONS: Employees and executives personal files, personal identifiable information, financial documents, corporate confidential files, correspondence, etc.

Victim:   |  Group: 
DE flag

hundhausen.de 

Company logo
Ransomware Group:

Discovery Date: 2024-06-23 19:42

Download link #1:  https://[redacted].onion/HUNDHAUSEN/PROOF/Mirror: https://[redacted].onion/HUNDHAUSEN/PROOF/DATA DESCRIPTIONS: Corporate confidential data: projects, drawings, financial documents\payrolls, correspondence etc.

Victim:   |  Group: 
 flag

fbttransport.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-23 19:41

Download link #1:  https://[redacted].onion/OFFICE/PROOF/Mirror: https://[redacted].onion/OFFICE/PROOF/DATA DESCRIPTIONS: Personal identifiable information, financial documents, corporate confidential files, employees and executives personal files, corporate correspondence, etc.

Victim:   |  Group: 
US flag

daystar.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-23 19:40
Estimated Attack Date: 2024-05-02

Sector: Not Found
Download link #1:  https://[redacted].onion/DAYSTARTV/PROOF/Mirror: https://[redacted].onion/DAYSTARTV/PROOF/DATA DESCRIPTIONS: Personal identifiable information, corporate confidential documents, financial data, personnel information, employees personal files, legal documents, corporate correspondence, etc.

Victim:   |  Group: 
 flag

deskcenter.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-23 16:21

Sector: Technology
Download link #1:  https://[redacted].onion/DESKCENTER/PROOF/Mirror: https://[redacted].onion/DESKCENTER/PROOF/DATA DESCRIPTIONS: Employees personal and corporate data, personal identifying documents, financial documents, customer information, database backups\exports, etc.

Victim:   |  Group: 
US flag

suminoe.us 

Company logo
Ransomware Group:

Discovery Date: 2024-06-19 16:45

Download link #1:  https://[redacted].onion/STA/PROOF/Mirror: https://[redacted].onion/STA/PROOF/DATA DESCRIPTIONS: Personal identification documents, corporate data, drawings, financial documents, supplier\customer information, employee personal data, corporate and personal correspondence, etc. 

Victim:   |  Group: 
IT flag

sofidel.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-18 11:44
Estimated Attack Date: 2023-10-06

Download link #1: https://[redacted].onion/SOFIDSAP/PROOF/Mirror: https://[redacted].onion/SOFIDSAP/PROOF/DATA DESCRIPTIONS: Personal identifiable information, financial documents, employees and executives personal files, customer information, corporate correspondence, etc. 

Victim:   |  Group: 
DK flag

sky-light.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-18 11:43
Estimated Attack Date: 2023-09-25

Sector: Technology
Download link #1: https://[redacted].onion/SKY-LIGHT/PROOF/Mirror: https://[redacted].onion/SKY-LIGHT/PROOF/DATA DESCRIPTIONS: Personal identifiable information, corporate agreements, projects, financial documents, employees and executives personal files, corporate correspondence, etc.

Victim:   |  Group: 
US flag

reawire.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-18 11:42
Estimated Attack Date: 2023-09-06

Sector: Technology
Download link #1: https://[redacted].onion/REAWIRE/PROOF/Mirror: https://[redacted].onion/REAWIRE/PROOF/DATA DESCRIPTIONS: Personal identifiable information, employees personal files, corporate agreements, projects, financial documents, personnel data, corporate correspondence, etc.

Victim:   |  Group: 
CA flag

transportlaberge.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-10 14:19

Download link #1:  https://[redacted].onion/TRANSLAB/PROOF/Mirror: https://[redacted].onion/TRANSLAB/PROOF/DATA DESCRIPTIONS: Employees personal and corporate data, Personal Identifiable Information, financial documents, customer information, corporate and personal correspondence, database exports, etc.

Victim:   |  Group: 
JP flag

sanyo-shokai.co.jp 

Company logo
Ransomware Group:

Discovery Date: 2024-06-10 14:17

Download link #1:  https://[redacted].onion/SANYOSHOKAI/PROOF/Mirror: https://[redacted].onion/SANYOSHOKAI/PROOF/DATA DESCRIPTIONS: Personal identifying information, financial documents, customer data, engineering information, employee\executives personal files, corporate correspondence, etc.

Victim:   |  Group: 
US flag

jmthompson.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-10 13:47

Sector: Construction
Download link #1:  https://[redacted].onion/JMT/PROOF/Mirror: https://[redacted].onion/JMT/PROOF/DATA DESCRIPTIONS: Personal identification documents, employee personal files, confidential corporate data, projects, drawings, financial documents, supplier\customer information,  corporate and personal correspondence, etc.

Victim:   |  Group: 
TW flag

ctsystem.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-10 13:46

Sector: Technology
Download link #1:  https://[redacted].onion/CTSYSTEM/PROOF/Mirror: https://[redacted].onion/CTSYSTEM/PROOF/DATA DESCRIPTIONS: Corporate confidential data, engineering documents, financial data, customer information, personal identification documents, database backups, etc.

Victim:   |  Group: 
US flag

ctgbrands.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-10 13:45

Download link #1:  https://[redacted].onion/CANASIA/PROOF/Mirror: https://[redacted].onion/CANASIA/PROOF/DATA DESCRIPTIONS: Personal identifiable information, corporate confidential data, corporate correspondence, employees and executives personal files, financial documents, customer information, database backups, etc.

Victim:   |  Group: 
US flag

fpr-us.com 

Company logo
Ransomware Group:

Discovery Date: 2024-06-06 18:15

Sector: Technology
Download link #1:  https://[redacted].onion/FPS/PROOF/Mirror: https://[redacted].onion/FPS/PROOF/DATA DESCRIPTIONS: Employees and executives personal data, contracts, reports, customer data, personal identification information, etc. 

Victim:   |  Group: 
IT flag

dollmar.com 

Company logo
Ransomware Group:

Discovery Date: 2024-05-31 18:05

Download link #1:  https://[redacted].onion/CORP.DOLLMAR.COM/PROOF/Mirror: https://[redacted].onion/CORP.DOLLMAR.COM/PROOF/DATA DESCRIPTIONS: Confidential corporate data, drawings, engineering files, Q&A, personal identifying information, financial documents, corporate and personal correspondence, employee personal files, database backups, etc. 

Victim:   |  Group: 
BS flag

familyguardian.com 

Company logo
Ransomware Group:

Discovery Date: 2024-05-31 18:04

Download link #1:  https://[redacted].onion/FAMILYGUARDIAN/PROOF/Mirror: https://[redacted].onion/FAMILYGUARDIAN/PROOF/DATA DESCRIPTIONS: Hundreds of confidential client documents and personal identifying information (passports, utility bills, contracts), corporate correspondence, employee phones backups, executives personal data, database backups, etc. 

Victim:   |  Group: 
ES flag

espackeuro.com 

Company logo
Ransomware Group:

Discovery Date: 2024-05-31 18:04

Download link #1:  https://[redacted].onion/SYSTEMS/PROOF/Mirror: https://[redacted].onion/SYSTEMS/PROOF/DATA DESCRIPTIONS: Employees and executives personal and corporate data, financials, database exports, etc. 

Victim:   |  Group: 
US flag

schuettemetals.com 

Company logo
Ransomware Group:

Discovery Date: 2024-05-20 09:51

Download link #1:  https://[redacted].onion/SMI/PROOF/Mirror: https://[redacted].onion/SMI/PROOF/DATA DESCRIPTIONS: Financial documents, supplier agreements, contracts, NDAs, Personal identifying information, Engineering data, employee personal files, database exports, etc. 

Victim:   |  Group: 
US flag

fulcrum.pro 

Company logo
Ransomware Group:

Discovery Date: 2024-05-16 16:45

Sector: Technology
Download link #1: https://[redacted].onion/FULCRUMGROUP/PROOFMirror: https://[redacted].onion/FULCRUMGROUP/PROOFDATA DESCRIPTIONS: Employees\executives personal data, corporate correspondence, agreements, private and corporate financial documents, personal identifying information, etc.

Victim:   |  Group: 
MX flag

scanda.com.mx 

Company logo
Ransomware Group:

Discovery Date: 2024-05-13 14:29

Sector: Technology
Download link #1: https://[redacted].onion/MEXCENTRO/PROOFMirror: https://[redacted].onion/MEXCENTRO/PROOFDATA DESCRIPTIONS: Personal Identification information, corporate documents, legal information, financial data\payroll\reports, employee personal data, correspondence, customer information, contracts, database backups. 

Victim:   |  Group: 
CL flag

acfin.cl 

Company logo
Ransomware Group:

Discovery Date: 2024-05-13 12:32

Download link #1: https://[redacted].onion/ACFIN/PROOFMirror: https://[redacted].onion/ACFIN/PROOFDATA DESCRIPTIONS: Client confidential data - agreements\reports etc., Personal identification Information (passports, DL, etc), financial statements\reports, executives personal data, security officer private photos and files, etc.

Victim:   |  Group: 
NL flag

iddink.nl 

Company logo
Ransomware Group:

Discovery Date: 2024-04-27 02:04
Estimated Attack Date: 2024-04-26

Sector: Education
Download link #1: https://[redacted].onion/IDDINKNL/PROOFMirror: https://[redacted].onion/IDDINKNL/PROOFDATA DESCRIPTIONS: Personal identifying information, financial documents, customer data, database exports, various confidential documents, corporate correspondence, employees personal documents, private software sources, etc. 

Victim:   |  Group: 
AU flag

ghimli.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-23 09:50

Sector: Not Found
Download link #1Ghim Li is a global textile and apparel supply chain manager of casual lifestyle knitwear apparel to major U.S. retailers. We supply over 62 million garments a year through our global marketing and manufacturing network. We offer you a total solution package with an integrated one-stop service approach, from in-house product design and development, commercialization of orders, material management, production planning and control, to comprehensive post manufacturing logistics solutions.Website: https://www.ghimli.com /Revenue : $189.1MAddress: 264 George Australia Square St L 42 Ste 4201, Sydney, New South Wales, 2000, AustraliaPhone Number: +65 6211 3600Download link #1: https://[redacted].onion/GHIMLI/fullMirror: https://[redacted].onion/GHIMLI/full

Victim:   |  Group: 
CA flag

saglobal.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-22 16:35
Estimated Attack Date: 2024-04-19

Sector: Technology
Download link #1At sa.global, we empower people and project-led businesses with tools that deliver value and drive growth in a seamless, Microsoft-based workspace.Website: https://www.saglobal.com/Revenue : $243.7MAddress: 300-1055 W Hastings St, Vancouver, British Columbia, V6E 2E9, CanadaPhone Number: +86 8883503123Download link #1: https://[redacted].onion/SAGLOBAL/fullMirror: https://[redacted].onion/SAGLOBAL/full

Victim:   |  Group: 
CA flag

concordegroup.ca 

Company logo
Ransomware Group:

Discovery Date: 2024-04-22 16:34
Estimated Attack Date: 2024-04-19

Sector: Construction
Download link #1Concorde Group has celebrated over three decades of unprecedented success while becoming one of city’s most influential hospitality brands. Since the opening of their first venue, Republik nightclub in 1987, these industry leaders have played an instrumental role in shaping Calgary’s food and drink culture and have set new standards for local hospitality.Website: https://www.concordegroup.ca/Revenue : $150MAddress: 2507 16 St SE, Calgary, Alberta, T2G 3R4, CanadaPhone Number: (403) 777-1050Download link #1: https://[redacted].onion/CONCORDE/fullMirror: https://[redacted].onion/CONCORDE/full

Victim:   |  Group: 
ES flag

ebir.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-22 16:33
Estimated Attack Date: 2024-04-19

Sector: Technology
Download link #1Our products and services reflect our 25 years' experience in the R&D of bathroom lighting systems. Specialties Bathroom lighting, bathroom lighting, illuminated mirrors, and bathroom fixturesWebsite: https://www.ebir.com/Revenue : $5MAddress: 9 Calle El Perelló, Torrent, Valencia, 46900, SpainPhone Number: +34 961-580-605Download link #1: https://[redacted].onion/EBIR/fullMirror: https://[redacted].onion/EBIR/full

Victim:   |  Group: 
US flag

coastalcargogroup.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-22 16:32
Estimated Attack Date: 2024-04-19

Download link #1Coastal Cargo Company, LLC is privately-owned and operated company located in New Orleans, Louisiana. With almost a century’s worth of experience in the transportation industry, we provide portside services as terminal operators and stevedores, specializing in the handling of metals, plywood, alloys, ro-ro, project cargo, bulk and break-bulk cargo.Our services extend to warehouse operations and management, along with trans-loading bulk cargo onto rail. Utilizing our highly experienced workforce, what sets Coastal Cargo apart isn’t just the unmatched breadth and depth of services to our clients, it is the quality work we provide every day.Website: https://www.coastalcargogroup.com/Revenue : $36.6MAddress: 3500 Terminal Drive New Orleans, LA, 70115, USAPhone Number: 504-587-1100Download link #1: https://[redacted].onion/JKGROUP/fullMirror: https://[redacted].onion/JKGROUP/full

Victim:   |  Group: 
NL flag

xdconnects.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-18 15:31

Download link #1:  https://[redacted].onion/XINDAO/PROOF/Mirror: https://[redacted].onion/XINDAO/PROOF/DATA DESCRIPTIONS: Hundreds of Personal Identifying information (passports\driver licences etc.), database backups, financial information - statements, payrolls, various confidential information, sales\customers data, executives and employees personal data, etc. 

Victim:   |  Group: 
US flag

drmarbys.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-17 14:33

Sector: Healthcare
Download link #1:  https://[redacted].onion/DRM/PROOF/Mirror: https://[redacted].onion/DRM/PROOF/DATA DESCRIPTIONS: Accounting\payroll documents, Personal Identifying information, HR documents, contracts, corporate correspondence, employees and executive managers personal folders, etc. 

Victim:   |  Group: 
US flag

regulatormarine.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-15 19:18

Download link #1:  https://[redacted].onion/BOATS/PROOF/Mirror: https://[redacted].onion/BOATS/PROOF/DATA DESCRIPTIONS: Thousands of engineering documents and drawings, administrative docs, corporate correspondence, employees and executive managers personal data, Personal Identifying information, database backups\exports, etc 

Victim:   |  Group: 
US flag

mcalvain.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-04 13:28

Sector: Construction
Download link #1:  https://[redacted].onion/MCO/PROOF/Mirror: https://[redacted].onion/MCO/PROOF/DATA DESCRIPTIONS: Сonfidential personal identification data, private information, financial data, construction projects, agreements, drawings, corporate correspondence, accounting, operational data, top managers and key employees' personal folders and much more. 

Victim:   |  Group: 
US flag

regencyfurniture.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-02 23:58

Download link #1:  https://[redacted].onion/REGENCYFURNITUR/PROOF/Mirror: https://[redacted].onion/REGENCYFURNITUR/PROOF/DATA DESCRIPTIONS: Personal Identifying information, financial statements, corporate correspondence, contracts, employee and customer information, executive managers personal data, database backups, etc. 

Victim:   |  Group: 
US flag

aerodynamicinc.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-01 13:24

Download link #1:  https://[redacted].onion/AERO/PROOF/Mirror: https://[redacted].onion/AERO/PROOF/DATA DESCRIPTIONS: Engineering documents and drawings, confidential data and correspondence with various customers such as Boeing, SpaceX, Airbus etc., corporate correspondence, database backups\exports, employee personal documents and much more. 

Victim:   |  Group: 
US flag

besttrans.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-01 13:23

Download link #1:  https://[redacted].onion/BESTTRANS/PROOF/Mirror: https://[redacted].onion/BESTTRANS/PROOF/DATA DESCRIPTIONS: Employees and executives personal folders, financial statements, payroll data, customer agreements, etc. 

Victim:   |  Group: 
US flag

qosina.com 

Company logo
Ransomware Group:

Discovery Date: 2024-03-27 14:53

Sector: Healthcare
Download link #2Medical device manufacturer. “Qosina is a leading global provider of over 5,000 OEM single-use components, serving the medical and biopharmaceutical industries. Our unwavering commitment revolves around ensuring an exceptional customer journey. We provide complimentary component samples, minimum order quantities, just-in-time delivery, mold modifications, and new product design and development.”Website: https://www.qosina.com/Revenue : $37.9MAddress: 2002q Orville Dr N, Ronkonkoma, New York, 11779, United StatesPhone Number: (631) 242-3000Download link #1:  https://[redacted].onion/QOSINA/PROOF/Mirror: https://[redacted].onion/QOSINA/PROOF/Download link #1:  https://[redacted].onion/QOSINA/PROOF/Mirror: https://[redacted].onion/QOSINA/PROOF/DATA DESCRIPTIONS: Financial documents, employee and executive managers personal data, engineering documents and drawings, QA data, customer information, contracts, etc. 

Victim:   |  Group: 
US flag

contenderboats.com 

Company logo
Ransomware Group:

Discovery Date: 2024-03-27 08:54

Download link #1:  https://[redacted].onion/CONTENDERBOATS/PROOF/Mirror: https://[redacted].onion/CONTENDERBOATS/PROOF/DATA DESCRIPTIONS: Financial documents, Personal identification information. engineering documents and drawings, corporate correspondence, user personal folders, etc. 

Victim:   |  Group: 
US flag

newagesys.com 

Company logo
Ransomware Group:

Discovery Date: 2024-03-22 13:26

Sector: Technology
Download link #1:  https://[redacted].onion/NEWAGESYS/PROOF/Mirror: https://[redacted].onion/NEWAGESYS/PROOF/DATA DESCRIPTIONS: Accounting\payroll\tax documents, HR data, Personal Identifying information, background reports, corporate correspondence\mailbox backups, employees personal folders, etc. 

Victim:   |  Group: 
CA flag

kelson.on.ca 

Company logo
Ransomware Group:

Discovery Date: 2024-03-22 13:25

Sector: Construction
Download link #1:  https://[redacted].onion/KELSON/PROOF/Mirror: https://[redacted].onion/KELSON/PROOF/DATA DESCRIPTIONS: Accounting\payroll documents, Personal Identifying information, Engineering\QA data, projects and confidential design documents, contracts, tenders, various customer data, employees and executive managers personal folders, database exports, etc. 

Victim:   |  Group: 
US flag

eclinicalsol.com 

Company logo
Ransomware Group:

Discovery Date: 2024-03-18 14:57

Sector: Healthcare
Download link #1:  https://[redacted].onion/ECS/PROOF/Mirror: https://[redacted].onion/ECS/PROOFDATA DESCRIPTIONS: Thousands of customer data: drug tests, clinical studies and reports, analytical data, corporate correspondence, etc. Database exports. 

Victim:   |  Group: 
PL flag

grupatopex.com 

Company logo
Ransomware Group:

Discovery Date: 2024-03-18 14:56

Sector: Technology
Download link #1:  https://[redacted].onion/ALFA/PROOF/Mirror: https://[redacted].onion/ALFA/PROOF/DATA DESCRIPTIONS: Database exports, executive managers personal data, corporate data, financial documents, personal identification information, client information and much more. 

Victim:   |  Group: 
US flag

plymouth.com 

Company logo
Ransomware Group:

Discovery Date: 2024-03-11 13:24

Download link #1: https://[redacted].onion/PLYMOUTH/PROOFMirror: https://[redacted].onion/PLYMOUTH/PROOFDATA DESCRIPTIONS: Accounting\treasury\taxes 250GB+, HR - payrolls\personal documents\dossiers 150GB+, Customer data - projects\contracts\drawings 90GB+, Engineering\R&D\QA 120GB+, Legal documents 3GB+, corporate correspondence 20GB+, employees' personal folders... Hundreds of Personal Identifying information documents, executive managers personal and corporate documents, engineering database backups, etc.PRICE: $1.5MFILE TREE PRICE: $15K 

Victim:   |  Group: 
GB flag

cleshar.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-03-11 10:15

Sector: Construction
Download link #1: https://[redacted].onion/CCS/PROOFMirror: https://[redacted].onion/CCS/PROOFDATA DESCRIPTIONS: Accounting\treasury\taxes 40GB+, HR - payrolls\personal documents\dossiers 110GB+, Customer data - projects\contracts\drawings 130GB+, Engineering\R&D\QA, Legal documents 3GB+, corporate correspondence 120GB+, employees' personal folders, database exports\backups... Thousands of financial documents, employees background reports including Personal Identifying information, contracts and tenders, executive directors personal and corporate data, engineering database exports and much more.PRICE: $1MFILE TREE PRICE: $10K 

Victim:   |  Group: 
NL flag

ammega.com 

Company logo
Ransomware Group:

Discovery Date: 2024-03-11 10:14

Download link #1: https://[redacted].onion/AMMEGA/PROOFMirror: https://[redacted].onion/AMMEGA/PROOFDATA DESCRIPTIONS: Accounting\treasury\taxes 250GB+, HR - payrolls\personal documents\dossiers 150GB+, Customer data - projects\contracts\drawings 100GB+, Engineering\R&D\QA 250GB+, Legal documents, corporate correspondence 100GB+, employees' personal folders... Lots of corporate confidential data, employees Personal Identifying information, executive managers personal data, legal documents including lawsuits, contracts, etc. PRICE: $9MFILE TREE PRICE: $90K 

Victim:   |  Group: 
ES flag

renypicot.es 

Company logo
Ransomware Group:

Discovery Date: 2024-03-11 10:13

Download link #1:  https://[redacted].onion/RENYPICOT/PROOF/Mirror: https://[redacted].onion/RENYPICOT/PROOF/DATA DESCRIPTIONS: Accounting\treasury\taxes, HR - payrolls\personal documents\dossiers, Customer data, contracts, Engineering\R&D\QA documents, corporate correspondence, database exports with client information, employees' and executive managers personal folders and much more.PRICE: $1MFILE TREE PRICE: $10K 

Victim:   |  Group: 
NL flag

abtexelgroup.com 

Company logo
Ransomware Group:

Discovery Date: 2024-02-28 11:58

Download link #1: https://[redacted].onion/BAKKERTEXEL/PROOFMirror: https://[redacted].onion/BAKKERTEXEL/PROOF 

Victim:   |  Group: 
NL flag

remkes.nl 

Company logo
Ransomware Group:

Discovery Date: 2024-02-23 19:24

Download link #1: https://[redacted].onion/REMKESBV/PROOFMirror: https://[redacted].onion/REMKESBV/PROOF 

Victim:   |  Group: 
US flag

advancedprosolutions.com 

Company logo
Ransomware Group:

Discovery Date: 2024-02-20 14:36

Download link #1: https://[redacted].onion/APS/PROOFMirror: https://[redacted].onion/APS/PROOF 

Victim:   |  Group: 
FR flag

se.com 

Company logo
Ransomware Group:

Discovery Date: 2024-02-19 14:33
Estimated Attack Date: 2024-01-17

Sector: Technology
Download link #1: https://[redacted].onion/SUMMIT01/PROOFMirror: https://[redacted].onion/SUMMIT01/PROOF 

Victim:   |  Group: 
US flag

parksite.com 

Company logo
Ransomware Group:

Discovery Date: 2024-02-09 10:07

Sector: Construction
Download link #1: https://[redacted].onion/PARKSITE/PROOFMirror: https://[redacted].onion/PARKSITE/PROOF 

Victim:   |  Group: 
ES flag

gocco.com 

Company logo
Ransomware Group:

Discovery Date: 2024-02-06 13:21

Download link #1: https://[redacted].onion/GOCCO/PROOFMirror: https://[redacted].onion/GOCCO/PROOF 

Victim:   |  Group: 
ES flag

spbglobal.com 

Company logo
Ransomware Group:

Discovery Date: 2024-02-06 10:19

Download link #1: https://[redacted].onion/SPB/PROOFMirror: https://[redacted].onion/SPB/PROOF 

Victim:   |  Group: 
US flag

oogp.com 

Company logo
Ransomware Group:

Discovery Date: 2024-01-27 13:10

Sector: Healthcare
Download link #1: https://[redacted].onion/OOGP/PROOF  

Victim:   |  Group: 
US flag

jaygroup.com 

Company logo
Ransomware Group:

Discovery Date: 2024-01-26 11:51

Download link #1: https://[redacted].onion/JAYGROUP/PROOF 

Victim:   |  Group: 
US flag

asburyauto.com 

Company logo
Ransomware Group:

Discovery Date: 2024-01-12 14:44

Download link #1:  https://[redacted].onion/ABG/PROOF 

Victim:   |  Group: 
US flag

acutis.com 

Company logo
Ransomware Group:

Discovery Date: 2024-01-12 05:47

Sector: Healthcare
Download link #1: https://[redacted].onion/ACUTIS/PROOF 

Victim:   |  Group: 
US flag

dtsolutions.net 

Company logo
Ransomware Group:

Discovery Date: 2024-01-12 05:46

Sector: Technology
Download link #1:  https://[redacted].onion/DTS/PROOF 

Victim:   |  Group: 
US flag

intercityinvestments.com 

Company logo
Ransomware Group:

Discovery Date: 2024-01-12 05:46

Download link #1:  https://[redacted].onion/ICIREALESTATE/PROOF 

Victim:   |  Group: 
US flag

hi-cone.com 

Company logo
Ransomware Group:

Discovery Date: 2024-01-12 05:44

Download link #1:  https://[redacted].onion/HICONE/PROOF 

Victim:   |  Group: 
GB flag

bellgroup.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2023-12-29 13:20

Sector:
Download link #1: https://[redacted].onion/AIRDRIE/PROOF 

Victim:   |  Group: 
SE flag

coop.se 

Company logo
Ransomware Group:

Discovery Date: 2023-12-29 13:19

Sector:
Download link #1: https://[redacted].onion/KONSUM/PROOF 

Victim:   |  Group: 
AU flag

tridon.com.au 

Company logo
Ransomware Group:

Discovery Date: 2023-12-29 13:17

Sector:
Download link #1: https://[redacted].onion/TRIDON/PROOF 

Victim:   |  Group: 
CA flag

gdi.com 

Company logo
Ransomware Group:

Discovery Date: 2023-12-28 16:08

Sector:
Download link #1: https://[redacted].onion/GDI/PROOF

Victim:   |  Group: 
MX flag

bachoco.com.mx 

Company logo
Ransomware Group:

Discovery Date: 2023-12-28 16:08

Sector:
Download link #1: https://[redacted].onion/BACHOCO/PROOF

Victim:   |  Group: 
 flag

pbssystems.com 

Company logo
Ransomware Group:

Discovery Date: 2023-12-28 16:08

Sector:
Download link #1: https://[redacted].onion/PBS/PROOF  

Victim:   |  Group: 
 flag

quakerwindows.com 

Company logo
Ransomware Group:

Discovery Date: 2023-12-23 13:16

Sector:
Download link #1:  https://[redacted].onion/QUAKER/PROOF/ 

Victim:   |  Group: 
US flag

dillarddoor.com 

Company logo
Ransomware Group:

Discovery Date: 2023-12-21 00:41
Estimated Attack Date: 2023-12-13

Sector:
Download link #1First established as a door company in the 1940s, Dillard Door has grown into one of the most successful security system providers in Tennessee today. In our 60-plus years of experience, we have earned a reputation for integrity, reliability and ingenuity. Simply stated, we do what we promise – and do it right. Rather than selling “quick-fix” products, we help companies develop complete security solutions, installing everything from entrance gates to security cameras to complete Access Control Systems – anything you need to protect your assets and ensure total control of your facility.Website: https://www.dillarddoor.comRevenue : $8.5MAddress: 788 East St Ste 102, Memphis, Tennessee, 38104, United StatesPhone Number: (901) 775-2143Download link #1: https://[redacted].onion/DILLARD/ecRYFdZ9JujR/DILLARD_PROOF_OF_HACK.zip 

Victim:   |  Group: 
GB flag

cts.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2023-12-21 00:41
Estimated Attack Date: 2023-12-16

Sector:
Download link #1CTS has undermined the priceless trust of its customers twice. Firstly, when the UK real estate market was paralyzed through their fault. And secondly, when they failed negotiations to keep their clients' data safe. Their disregard attitude to cyber security, as well as infinite greed, led to this situation. Initially, we had access just to one client regular VM. Terrible security vulnerabilities and network misconfigurations allowed us to gain access to the entire network in a few moments. How could they provide "Cyber Protection Shaped for Law"? On their website CTS states: Every minute and every decision matters and maximising reputation and minimising risk informs every decision made. If your goal is save your data and reputation, and minimize risks, the best decision will be to avoid the services of this company and switch to another MSP. They do not deserve to provide their services to the legal industry and should stay away from this business. The confidential data from 2 law firms is already being disclosed. What will happen next? We'll see.. Website: https://www.talbotslaw.co.uk/Revenue : $23.2MAddress: 30 Church St, Kidderminster, West Midlands, DY10 2AX, United KingdomPhone Number: (901) 775-2143Download link #1:https://[redacted].onion/TAL/RucUh1Jea2BF/TAL_PROOF_OF_HACK.zip Website: https://www.fenwickelliott.com/Revenue : $50.1MAddress: 71-91 Aldwych, London, Greater London, WC2B 4HN, United KingdomPhone Number: +44 2074211986Download link #1: https://[redacted].onion/FENWICKELLIOTT/rBCk7gfaXmF7/FENWICKELLIOTT_PROOF_OF_HACK.zip 

Victim:   |  Group: 
 flag

hunterbuildings.com 

Company logo
Ransomware Group:

Discovery Date: 2023-12-21 00:40
Estimated Attack Date: 2023-12-20

Sector:
Download link #1: https://[redacted].onion/HUNTER/68ZRg2b1oA20/ 

Victim:   |  Group: 
 flag

larlyn.com 

Company logo
Ransomware Group:

Discovery Date: 2023-12-21 00:40
Estimated Attack Date: 2023-12-20

Sector:
Download link #1: https://[redacted].onion/LARLYN/QqakRgUT3xcw/  

Victim:   |  Group: 
 flag

wkw-group.com 

Company logo
Ransomware Group:

Discovery Date: 2023-12-21 00:40
Estimated Attack Date: 2023-12-20

Sector:
Download link #1:  https://[redacted].onion/WKW/f8r49BmAqKir/ 

Victim:   |  Group: 
 flag

dbmgroup.com 

Company logo
Ransomware Group:

Discovery Date: 2023-12-21 00:40
Estimated Attack Date: 2023-12-20

Sector:
Download link #1: https://[redacted].onion/DBMG/kE0cZ6KmMsBN/ 

Victim:   |  Group: 
US flag

LAJOLLAGROUP 

Company logo
Ransomware Group:

Discovery Date: 2023-12-18 17:18

Sector:
Founded in 1993, La Jolla Group is an industry leading apparel and accessories company that specializes in building brands that inspire consumers. In today’s digitally-focused environment, it has never been easier to start a brand and never more difficult to scale. With a proven track record, robust infrastructure, and a specialized team, La Jolla Group is uniquely positioned to take your brand to the next level by providing custom solutions that meet your specific needs. Website: https://www.lajollagroup.com Revenue : $35.2M Address: 14350 Myford Rd Ste 100, Irvine, California, 92606, United States Phone Number: (949) 428-2800

Victim:   |  Group: 
GB flag

CTS 

Company logo
Ransomware Group:

Discovery Date: 2023-12-16 14:29

Sector:
 Website: https://www.fenwickelliott.com/ Revenue : $50.1M Address: 71-91 Aldwych, London, Greater London, WC2B 4HN, United Kingdom Phone Number: +44 2074211986

Victim:   |  Group: 
BE flag

MEDIMARKET 

Company logo
Ransomware Group:

Discovery Date: 2023-12-15 15:30
Estimated Attack Date: 2023-11-28

Sector:
MEDI-MARKET is a new chain of pharmacies and parapharmacies offering, for the first time in Belgium, 1,000 m² dedicated to health. Our innovative concept offers customers personalized advice from specialists and a wide range of products in the health care, natural medicine, cosmetics, nutrition and baby care sectors. Website: www.medi-market.beRevenue : $164MAddress: 2 Blvd Anspach 2, Brussels, Brussels Capital, BelgiumPhone Number: +32 22260120

Victim:   |  Group: 
FR flag

ODALYS 

Company logo
Ransomware Group:

Discovery Date: 2023-12-15 15:30
Estimated Attack Date: 2023-11-28

Sector:
A key player in the holiday accommodation market, Odalys Vacances annually welcomes more than 2 million tourists to its holiday rentals in the most popular destinations. We offer a range of accommodation to suit all tastes, from mobile home campsites to ski chalets and holiday residences to holiday clubs, prestige residences, apartments and hotels in city centres. Holiday rentals by the beach, in the mountains, in the countryside... and even ski holiday rentals. Website: www.odalys-vacances.comRevenue : $151.1MAddress: 2 Rue De La Roquette Passage Du Cheval Blanc Cour De Mai, Paris, FrancePhone Number: +33 158565656

Victim:   |  Group: 
ES flag

CIE 

Company logo
Ransomware Group:

Discovery Date: 2023-12-15 15:30
Estimated Attack Date: 2023-12-07

Sector:
CIE Automotive is an industrial group specialised in supplying components and subassemblies for the automotive market. CIE Automotive focuses its activity on seven technologies — Aluminium, Forging, Stamping and Tube Welding, Machining, Plastic, Casting and Roof Systems. Website: www.cieautomotive.comRevenue : $3.6BAddress: 69 Alameda Mazarredo 8º, Bilbao, Basque Country, 48009, SpainPhone Number: +34 946054835

Victim:   |  Group: 
US flag

NNDOMAIN 

Company logo
Ransomware Group:

Discovery Date: 2023-12-15 15:29
Estimated Attack Date: 2023-12-07

Sector:
National Nail has been a proud part of the American building materials industry for over 50 years as a manufacturer and distributor of high-quality, innovative product and service solutions for the residential, commercial, and industrial construction industries. We partner with multiple national and global suppliers and distributors to serve the hardware wholesale, roofing wholesale, independent, chain, home center and STAFDA channels. Website: www.nationalnail.comRevenue : $678.9MAddress: 2964 Clydon Ave SW, Grand Rapids, Michigan, 49519, United StatesPhone Number: (616) 538-8000

Victim:   |  Group: 
DK flag

ISC 

Company logo
Ransomware Group:

Discovery Date: 2023-12-15 15:29
Estimated Attack Date: 2023-12-11

Sector:
ISC is an Engineering services company based in Denmark working worldwide to create value for our clients through innovative engineering solutions for offshore projects. ISC has been in Offshore Wind since we designed the world's first Offshore Substation almost 20 years ago. ISC provides engineering design service solutions within sectors such as Renewable Energy, Oil & Gas. Website: www.isc.dkRevenue : $60.1MAddress: 70 Borgergade, Esbjerg, Region Syddanmark, 6700, DenmarkPhone Number: +45 35278800

Victim:   |  Group: 
US flag

DILLARD 

Company logo
Ransomware Group:

Discovery Date: 2023-12-15 15:29
Estimated Attack Date: 2023-12-13

Sector:
First established as a door company in the 1940s, Dillard Door has grown into one of the most successful security system providers in Tennessee today. In our 60-plus years of experience, we have earned a reputation for integrity, reliability and ingenuity. Simply stated, we do what we promise – and do it right. Rather than selling “quick-fix” products, we help companies develop complete security solutions, installing everything from entrance gates to security cameras to complete Access Control Systems – anything you need to protect your assets and ensure total control of your facility.Website: www.dillarddoor.comRevenue : $8.5MAddress: 788 East St Ste 102, Memphis, Tennessee, 38104, United StatesPhone Number: (901) 775-2143

Victim:   |  Group: 
 flag

Dillard Door & Security 

Company logo
Ransomware Group:

Discovery Date: 2023-12-13 11:33

Sector:
First established as a door company in the 1940s, Dillard Door has grown into one of the most successful security system providers in Tennessee today. In our 60-plus years of experience, we have earned a reputation for integrity, reliability and ingenuity. Simply stated, we do what we promise – and do it right. Rather than selling “quick-fix” products, we help companies develop complete security solutions, installing everything from entrance gates to security cameras to complete Access Control Systems – anything you need to protect your assets and ensure total control of your facility.

Victim:   |  Group: 
DK flag

ISC Consulting Engineers 

Company logo
Ransomware Group:

Discovery Date: 2023-12-11 09:58

Sector:
ISC is an Engineering services company based in Denmark working worldwide to create value for our clients through innovative engineering solutions for offshore projects. ISC has been in Offshore Wind since we designed the world's first Offshore Substation almost 20 years ago. ISC provides engineering design service solutions within sectors such as Renewable Energy, Oil & Gas.

Victim:   |  Group: 
 flag

CIE Automotive 

Company logo
Ransomware Group:

Discovery Date: 2023-12-07 12:58

Sector:
CIE Automotive is an industrial group specialised in supplying components and subassemblies for the automotive market. CIE Automotive focuses its activity on seven technologies — Aluminium, Forging, Stamping and Tube Welding, Machining, Plastic, Casting and Roof Systems.

Victim:   |  Group: 
 flag

National Nail Corp 

Company logo
Ransomware Group:

Discovery Date: 2023-12-07 12:58

Sector:
National Nail has been a proud part of the American building materials industry for over 50 years as a manufacturer and distributor of high-quality, innovative product and service solutions for the residential, commercial, and industrial construction industries. We partner with multiple national and global suppliers and distributors to serve the hardware wholesale, roofing wholesale, independent, chain, home center and STAFDA channels.

Group: 
CA flag

FYIdoctors 

Company logo
Ransomware Group:

Discovery Date: 2023-11-28 11:35

Sector:
We started in 2008 as a small group of independent like-minded optometrists in Alberta. We were determined to provide excellent, personalized care first when many in our industry were putting profits over patients. Our values have helped us grow into Canada’s largest eye care provider with over 300 clinics coast-to-coast. Through it all, we've kept our patients first.

Victim:   |  Group: 
 flag

Axiom Construction & Consulting 

Company logo
Ransomware Group:

Discovery Date: 2023-11-28 11:35

Sector:
Axiom Construction and Consulting is a full-envelope architectural sheet-metal contractor and professional manager of construction services. We deliver a wide range of retail and commercial projects throughout Washington. To date, Axiom has completed over 130 projects that have consisted of over two million square feet of metal siding and roofing.

Group: 
BE flag

Medi-Market 

Company logo
Ransomware Group:

Discovery Date: 2023-11-28 11:35

Sector:
MEDI-MARKET is a new chain of pharmacies and parapharmacies offering, for the first time in Belgium, 1,000 m² dedicated to health. Our innovative concept offers customers personalized advice from specialists and a wide range of products in the health care, natural medicine, cosmetics, nutrition and baby care sectors.

Victim:   |  Group: 
 flag

Odalys Vacances 

Company logo
Ransomware Group:

Discovery Date: 2023-11-28 11:35

Sector:
A key player in the holiday accommodation market, Odalys Vacances annually welcomes more than 2 million tourists to its holiday rentals in the most popular destinations. We offer a range of accommodation to suit all tastes, from mobile home campsites to ski chalets and holiday residences to holiday clubs, prestige residences, apartments and hotels in city centres. Holiday rentals by the beach, in the mountains, in the countryside... and even ski holiday rentals.

Victim:   |  Group: 
 flag

Verhelst 

Company logo
Ransomware Group:

Discovery Date: 2023-11-21 17:44

Sector:
From shell construction to recycling of construction waste. From asphalt production to sand mining. From asbestos removal to soil remediation. Verhelst Group is a total partner for professional construction projects. A construction group with a unique approach and extensive construction expertise.

Victim:   |  Group: 
 flag

Petersen Health Care 

Company logo
Ransomware Group:

Discovery Date: 2023-11-21 17:44

Sector:
It is the mission of each Petersen Health Care facility to be great community partners. All Petersen Health Care homes are encouraged to host community activities and participate in fundraisers for the good of the community and local organizations. Petersen Health Care is recognized as a leader in the industry for community participation.

Victim:   |  Group: 
 flag

Paul Stuart 

Company logo
Ransomware Group:

Discovery Date: 2023-11-21 17:44

Sector:
Paul Stuart has lasted the test of time being one of the only remaining haberdashers on Madison Avenue. We credit our continued success to the desire to stay true to our roots while innovating with the times. Renowned for expert craftsmanship, thoughtful design using materials and fabrics sourced from the finest mills around the world, Paul Stuart combines Savile Row, Old Hollywood and classic New York to create timeless American classics with contemporary sophistication.

Victim:   |  Group: 
UY flag

GEOCOM 

Company logo
Ransomware Group:

Discovery Date: 2023-11-06 11:28

Sector:
GEOCOM Uruguay SA provides global solutions, with certified quality, applying state of the art IT technologies that are best suited to the demands and needs of its customers with the ongoing goal of exceeding their expectations.

Group: 
BE flag

MultiMasters 

Company logo
Ransomware Group:

Discovery Date: 2023-11-06 11:28

Sector:
The Multi Masters Group is a renowned and versatile company offering multiple services in a number of locations in Belgium. The Multi Masters Group is an evolution of the public com pany Cleaning Masters, which was founded in 1988 as a family cleaning business. Within a short period of time it grew into one of Belgium’s top 5 business support companies. In 2004, Cleaning Masters joined the Samsic Group, a European leader in the field of services. Since we are also part of AAFM, the leading European cooperation platform for business support services, we can provide customised solutions for our clients at a European level.

Victim:   |  Group: 
RO flag

UTI Group 

Company logo
Ransomware Group:

Discovery Date: 2023-11-06 11:28

Sector:
For 26 years, UTI, one of the most important and innovative companies in Romania, has stood for excellence, technology, trust and a strong commitment to quality. Over the last years, UTI has created a domestic reputation of approaching projects that have a decisive contribution to increasing the quality and safety of life. The company’s vision to become a vital part of the people’s life is grounded on the extensive solutions portfolio.

Victim:   |  Group: 
 flag

SCS SpA 

Company logo
Ransomware Group:

Discovery Date: 2023-10-16 19:06

Sector:
Today the Canavesana Servizi company manages hygiene services in 57 municipalities, dealing in particular with waste collection, separate waste collection and soil hygiene. The expansion of the user base has brought significant advantages in the rationalization of the service, encouraging greater collaboration between the participating municipalities.

Group: 
 flag

OmniVision Technologies 

Company logo
Ransomware Group:

Discovery Date: 2023-10-16 19:06

Sector:
Since being founded in 1995 OMNIVISION has been at the leading-edge of technology, developing and delivering advanced digital imaging, analog, and touch & display solutions for multiple applications across several industries. As a global fabless semiconductor organization, our award-winning innovative technologies have enabled smoother human/machine interfacing solutions within the automotive, medical, security & surveillance, computing, mobile phone, and emerging technology spaces.

Victim:   |  Group: 
 flag

The Hurley Group 

Company logo
Ransomware Group:

Discovery Date: 2023-10-07 13:07

Sector:
Based in New Haven, Connecticut, The Hurley Group is a real estate development and property management firm that specializes in properties throughout New Haven and Fairfield counties.

Group: 
 flag

Cornerstone Projects Group 

Company logo
Ransomware Group:

Discovery Date: 2023-10-05 15:37

Sector:
Cornerstone Projects Group offers commercial clients an unrivaled service and a commitment founded on the simple principle of stewardship: lead in the development, architecture and construction of real estate investments by serving the individual needs of each client.

Group: 
SK flag

RICOR Global Limited 

Company logo
Ransomware Group:

Discovery Date: 2023-10-05 15:37

Sector:
Ricor Global Limited continues to evolve as a major international player in the automotive industry and beyond. Supplying a wide range of both OEM and Tier one customers, our expertise is in the supply of metal stampings, tube manipulation and assemblies throughout the vehicle structure. With seven facilities in the UK, Poland and Slovakia and an office and tooling facilities in China and supplying products globally, Ricor has an established international footprint which is well situated to support its customers on a worldwide basis.

Group: 
 flag

UTC Overseas 

Company logo
Ransomware Group:

Discovery Date: 2023-09-27 16:07

Sector:
Utc Overseas Inc. provides freight forwarding services. The Company offers a variety of services including ocean and air freight, project logistics, trucking, cargo insurance, customs brokerage, and warehousing.

Victim:   |  Group: 
 flag

Unitex Textile Rental Services 

Company logo
Ransomware Group:

Discovery Date: 2023-09-27 16:07

Sector:
For more than 100 years, our family-run business has been leading the way in the medical uniform and linen rental industry. Today, we’re the largest family-owned healthcare service provider in the country. Because our family is involved in every inch of the business, our unflagging attention to detail results in a clear advantage for you and your business. Now in our 4th generation, we continue to provide our clients the kind of quality, cleanliness and service that has become the unrivaled standard. We don’t make idle promises; we don’t cut corners; we always strive to exceed expectations. That is, simply, the way this family business has always been run. And because we closely watch and refine and improve every inch of our business every day, when it comes to laundry, linen and uniforms, Unitex Healthcare Laundry Services gives you a competitive advantage.

Victim:   |  Group: 
 flag

Orthum Bau 

Company logo
Ransomware Group:

Discovery Date: 2023-09-26 17:38

Sector:
Our vision is to be not just a construction company, but a dynamic, powerful and innovative force in the construction industry, built on a solid foundation for your success. Our construction projects are much more than just buildings – they are living, breathing creations that are brought to life with the highest construction quality, flexibility and timeliness. Every day we guarantee smooth construction progress and strive to make each project better than the last.

Victim:   |  Group: 
 flag

Astro Lighting 

Company logo
Ransomware Group:

Discovery Date: 2023-09-26 17:38

Sector:
Astro specialises predominantly in wall and ceiling lighting, and has achieved a wide reputation as the leading supplier of bathroom lighting in the UK.

Victim:   |  Group: 
AU flag

DM Civil 

Company logo
Ransomware Group:

Discovery Date: 2023-09-21 10:06

Sector:
DM Civil provides tailored, sustainable civil contracting solutions to many of Australia’s leading companies. A privately owned company established in 1976 by Reg Toohey, Tony Spanjers and his late brother Eric Spanjers. Since then, we have grown to be one of Western Australia’s most trusted and respected civil contractors. We offer a diverse range of civil construction capabilities: • Water Infrastructure • Pipelines • Land Development • Trenchless technology • Mining Infrastructure • Trencher Hire & Services We consistently align ourselves with industry best practice and guarantee the delivery of client focussed construction solutions.

Victim:   |  Group: 
 flag

Bacon Universal 

Company logo
Ransomware Group:

Discovery Date: 2023-09-20 14:30

Sector:
Bacon Universal Company, Inc. has proudly served Hawaii's Construction Industry for more than 60 years.

Victim:   |  Group: 
 flag

Spuncast 

Company logo
Ransomware Group:

Discovery Date: 2023-09-20 14:30

Sector:
Spuncast, Inc was founded in 1976 and is headquartered in Watertown, Wisconsin. The company provides centrifugal castings and offers stainless steel tubing products, such as hydraulic cylinders.

Victim:   |  Group: 
AU flag

Peacock Bros 

Company logo
Ransomware Group:

Discovery Date: 2023-09-19 11:36

Sector:
Peacock Bros. Pty Ltd, Australian-owned and operated since 1888, has grown into one of the ANZ region’s largest providers of Data Management and Printing Solutions with branches in Melbourne, Sydney, Brisbane, Perth, Adelaide and Auckland. Manufacturers of high quality barcode and colour labels, we also work with the best technology brands to provide exceptional products, solutions and support for all your supply chain needs: - Barcode labels, Tags and Colour Labels - Thermal Printing, Ribbons & Applicator Systems - ID Card Services - Scanning & Mobile Computing - Wireless Infrastructure & Networking Solutions - Customized Software Solutions - Project Management & Engineering - Authorized Service & Support.

Victim:   |  Group: 
 flag

Wardlaw Claims Service 

Company logo
Ransomware Group:

Discovery Date: 2023-09-11 15:56

Sector:
Wardlaw Claims Service is an industry-leading claims management and risk solutions firm founded in 1965. Today, we remain one of the largest privately held IA firms in the industry. No large conglomerates here! Our clients experience personalized services tailored to the nature of their risk management needs. Our services range from Daily & Catastrophe Field Adjusting in Residential and Commercial Property to Desk Adjusting, Auto Appraisal, Casualty & Liability, Emergency Services Invoice Reviews and more. We use industry leading claims technology to best serve our clients and their policyholders with INTEGRITY, ACCURACY & EXCELLENCE.

Victim:   |  Group: 
 flag

Levine Bagade Han 

Company logo
Ransomware Group:

Discovery Date: 2023-09-11 14:35

Sector:
Levine Bagade Han LLP is an intellectual property law practice in Palo Alto, CA. We work closely with fast-moving clients who care about their intellectual property. Though we have experience in other areas, we focus on IP. Strategy, invention disclosure management, patent prosecution, portfolio management, due diligence (client and investor based), licensing, litigation strategy… We help you with IP strategy that matches your company's business objectives. We use our experience to guide clients through IP mazes and minefields. At our core, we strive to create a client-centered practice that is unique to the intellectual property legal field.

Group: 
GB flag

Leekes 

Company logo
Ransomware Group:

Discovery Date: 2023-09-11 14:35

Sector:
Retailer of homeware and home furnishing products. The company is a family owned chain of home department stores selling furniture and accessories plus conservatories, orangeries, windows, doors, kitchen and bathroom products through online and offline stores in South Wales, United Kingdom.

Victim:   |  Group: 
 flag

My Insurance Broker 

Company logo
Ransomware Group:

Discovery Date: 2023-09-11 14:35

Sector:
Founded in 2008, My Insurance Broker is a Canadian community-dedicated brokerage.

Victim:   |  Group: 
CA flag

Unimarketing 

Company logo
Ransomware Group:

Discovery Date: 2023-09-11 14:35

Sector:
Unimarketing is a company that operates in the Information Technology and Services industry. It employs 21-50 people and has $10M-$25M of revenue. The company is headquartered in Chicoutimi, Quebec, Canada.

Victim:   |  Group: 
 flag

Geo Tek 

Company logo
Ransomware Group:

Discovery Date: 2023-09-08 14:35

Sector:
Incorporated in 1997, GeoTek is a full service consulting engineering firm specializing in geotechnical engineering, construction materials testing, special inspections, and environmental consulting. GeoTek is founded on the principal of providing strong business partnerships with clients by demonstrating a committed passion for those who demand technical advice and responsive customer service that adds value to the client's project.

Group: 
 flag

Custom Powder Systems 

Company logo
Ransomware Group:

Discovery Date: 2023-09-08 13:07

Sector:
Custom Powder Systems is actually a containment company, so as a containment company, we offer many different solutions for customers.

Victim:   |  Group: 
 flag

JSS Almonds 

Company logo
Ransomware Group:

Discovery Date: 2023-09-08 13:07

Sector:
JSS Almonds is a grower and processor of whole and natural California Almonds. Our facility specializes in shelled and inshell almonds. JSS Almonds serves over 15000 acres and specializes in natural, whole, and brown skin almond processing.

Group: 
 flag

atWork Office Furniture 

Company logo
Ransomware Group:

Discovery Date: 2023-09-08 11:37

Sector:
atWork offers wide selection of office furniture, design services, installation.

Victim:   |  Group: 
IN flag

BRiC Partnership 

Company logo
Ransomware Group:

Discovery Date: 2023-09-08 11:37

Sector:
BRiC is a consulting engineering firm with offices located in Belleville, Illinois; Evansville, Indiana; Springfield, Illinois; and Kirkwood, Missouri. While the four principals have been providing engineering services since the 1980's, BRiC Partnership was formed in 2002.

Victim:   |  Group: 
 flag

TORMAX USA 

Company logo
Ransomware Group:

Discovery Date: 2023-09-07 11:30

Sector:
TORMAX USA Inc. is committed to providing exceptional services with highly qualified technical advisers and service technicians on automatic door systems since 1997.

Victim:   |  Group: 
 flag

West Craft Manufacturing 

Company logo
Ransomware Group:

Discovery Date: 2023-09-07 11:30

Sector:
West Craft Manufacturing Inc. is an industry leader in the production of custom hydraulic cylinders and pneumatic cylinders for a diverse range of industries. We are specialized in designing and manufacturing custom hydraulic cylinders as per your specifications.

Victim:   |  Group: 
 flag

Trimaran Capital Partners 

Company logo
Ransomware Group:

Discovery Date: 2023-09-07 11:30

Sector:
Led by Managing Partners Jay R. Bloom and Dean C. Kehler and Managing Director Michael G. Maselli, Trimaran Capital Partners ("Trimaran") is a private New York-based investment firm based in New York founded in 1998.

Victim:   |  Group: 
 flag

Specialised Management Services 

Company logo
Ransomware Group:

Discovery Date: 2023-09-07 09:57

Sector:
Specialised Management Services Ltd (SMS) was formed in 1999 predominately as a service and support company to the oil and gas industry.

Group: 
CA flag

Maxxd Trailers 

Company logo
Ransomware Group:

Discovery Date: 2023-09-05 17:35

Sector:
MAXXD is a subsidiary of Maxey Trailers Mfg. Inc., a Texas company in business since 1999. The company began as a one man shop and has grown to an operation of 70 employees who produce 5,000 trailers annually for clients across the U.S. and Canada.

Victim:   |  Group: 
 flag

MINEMAN Systems 

Company logo
Ransomware Group:

Discovery Date: 2023-09-05 17:35

Sector:
MINEMAN IS THE TRUSTED INDUSTRY STANDARD FOR THE MARKETING OF CONCENTRATES AND METALS FROM MINING.

Victim:   |  Group: 
FR flag

Promotrans 

Company logo
Ransomware Group:

Discovery Date: 2023-09-05 17:35

Sector:
Promotrans is a company that operates in the Professional Training & Coaching industry. It employs 251-500 people and has $25M-$50M of revenue. The company is headquartered in Paris, Île-de-france, France.

Victim:   |  Group: 
 flag

Seymours 

Company logo
Ransomware Group:

Discovery Date: 2023-09-05 17:35

Sector:
Surrey estate agents Seymours have six offices in Surrey located in Ripley, Guildford, Burpham, Woking and West Byfleet, one being a specialist letting & management operation dealing with properties for sale

Victim:   |  Group: 
 flag

Marfrig Global Foods 

Company logo
Ransomware Group:

Discovery Date: 2023-09-05 16:03

Sector:
Established in 2000, Marfrig Global Foods processes beef products. They have processing locations in various countries and regions.

Victim:   |  Group: 
 flag

Barsco 

Company logo
Ransomware Group:

Discovery Date: 2023-09-05 11:26

Sector:
Texas located Heating, Ventilation, Air Conditioning, and Refrigeration wholesale supplier. Since 1934 and under many names Barsco has been atop the HVAC/R industry. Centered in Dallas, Barsco operates across the North, East, and Central Texas frontiers.

Victim:   |  Group: 
 flag

Foroni SPA 

Company logo
Ransomware Group:

Discovery Date: 2023-09-05 11:26

Sector:
Foroni S.p.A. is a fully integrated manufacturer of Nickel based and Specialty alloys in a wide range of chemistries for a variety of industrial applications.

Victim:   |  Group: 
DK flag

Hornsyld Købmandsgaard 

Company logo
Ransomware Group:

Discovery Date: 2023-09-05 11:26

Sector:
Hornsyld Købmandsgaard is a company that operates in the Farming industry. It employs 21-50 people and has $10M-$25M of revenue. The company is headquartered in Hornsyld, Region Midtjylland, Denmark.

Victim:   |  Group: 
FR flag

Lagarde Meregnani 

Company logo
Ransomware Group:

Discovery Date: 2023-09-05 11:26

Sector:
Lagarde Meregnani. BUILDING FINISHING COMPANY. Lagarde Meregnani works on new construction or renovation sites in painting and decoration, floor coverings and wall coverings, facade renovation, exterior insulation, tiles and earthenware, etc.Whether it concerns construction sites for professionals or private individuals, Lagarde Meregnani manages all trades and thus coordinates interventions as well as possible, in the Grand Est and throughout France.

Victim:   |  Group: 
CA flag

Balcan 

Company logo
Ransomware Group:

Discovery Date: 2023-09-04 17:29

Sector:
Founded in 1967 and headquartered in Montreal, Canada, Balcan is a manufacturer and distributor of technical films and flexible packaging.

Victim:   |  Group: 
 flag

Barco Uniforms 

Company logo
Ransomware Group:

Discovery Date: 2023-09-04 17:29

Sector:
Founded in 1929, Barco Uniforms is a leader of design innovation in the premium professional apparel industry, offering award-winning premium uniforms that elevate and honor the individuals in the healthcare, enterprise, and food service industries.

Victim:   |  Group: 
 flag

Alberto Couto Alves 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:50

Sector:
ACA Engenharia & Construção operates in a wide range of areas from Roads and Infrastructures, Buildings to the production of Bituminous mixtures, Concrete and Aggregates.

Victim:   |  Group: 
 flag

Agoravita 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:50

Sector:
Since 1999, Agoravita has supported companies in their infrastructure projects and IT services, digital communications, software development and training, which form the basis of their digital transition.

Victim:   |  Group: 
 flag

American Meteorological Society 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:50

Sector:
The American Meteorological Society, founded in 1919, is a global community committed to advancing weather, water, and climate science and service.

Victim:   |  Group: 
 flag

Biocair International 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:50

Sector:
Biocair is a global GDP logistics specialist with over 35 years of experience in the pharmaceutical, biotechnology and life sciences sectors.

Victim:   |  Group: 
 flag

Confartigianato Federimpresa FC 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:50

Sector:
Confartigianato Federimpresa FC is a company that operates in the Financial Services industry.

Victim:   |  Group: 
 flag

ScanSource 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:50

Sector:
Founded in 1992, ScanSource, Inc is an international distributor of technology products and solutions, focusing on point-of-sale (POS), payments, barcode, physical security, unified communications and collaboration, cloud and telecom services.

Victim:   |  Group: 
 flag

CWS 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:48

Sector:
CWS Srl is a company that operates in the Information Technology and Services industry.

Victim:   |  Group: 
 flag

Hawa Sliding Solutions 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:48

Sector:
Hawa AG has been producing sliding solutions for creative building culture for more than 50 years. It is well-known as a premium provider of sliding fitting systems for equipment, room partitioning, shop fronts and facades.

Victim:   |  Group: 
 flag

Imagination 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:48

Sector:
Imagination is an independent experience company with 12 offices worldwide. We specialise in designing experiences which change how people feel, think and act.

Victim:   |  Group: 
 flag

Italkraft 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:48

Sector:
Headquartered in Miami, Florida, we provide our customers with Italian Design kitchen, bathroom and closet cabinetry of the highest standard and style.

Victim:   |  Group: 
US flag

Michigan Production Machining 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:48

Sector:
Michigan Production Machining, Inc. manufactures induction heat treating supplies. The company offers precision machined ferrous and non-ferrous forgings and castings to the automotive industry. Michigan Production Machining operates in the United States.

Victim:   |  Group: 
 flag

Novobit 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:48

Sector:
Novobit AG is a well-established and fully independent company that develops and manufactures a wide range of fiber optic products for the global market.

Victim:   |  Group: 
IT flag

Artemide 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:46

Sector:
Artemide, headquartered in Lombardy, Italy, is a company that specializes in the design, manufacturing, and retail of residential light fixtures.

Victim:   |  Group: 
 flag

Reyes Automotive Group 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:46

Sector:
Reyes Automotive Group is a minority owned Joint Venture (or JV) that is comprised of two companies with a combined 120 years of manufacturing experience.

Victim:   |  Group: 
 flag

Rotomail Italia SpA 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:46

Sector:
Rotomail Italia SpA is a company that operates in the Printing industry.

Victim:   |  Group: 
 flag

Phoenix Taxis 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:46

Sector:
Phoenix Taxis are Northumberland's largest taxi company, operating a service throughout the North East dedicated to quality vehicles and reliable customer service.

Victim:   |  Group: 
 flag

Wasserstrom 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:46

Sector:
The Wasserstrom Company, headquartered in Columbus, Ohio and founded in 1902, is a restaurant supplier and distributor of foodservice supplies and equipment. They sell products, such as kitchen supplies and catering supplies, from industry manufacturers.

Victim:   |  Group: 
US flag

Americold 

Company logo
Ransomware Group:

Discovery Date: 2023-07-20 12:46

Sector:
AmeriCold Logistics LLC is a major temperature controlled warehousing and transportation company based in Atlanta, Georgia, United States. It is in the business of modern commercialized temperature-controlled warehousing for the storage of perishable goods.

Victim:   |  Group: