Ransomware Group:  
Rhysida



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | External Information | Tools | Yara Rules | Ransom Note(s) | Activity | Worldmap | Victims (156)

Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.

The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.

The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.

After encryption, the ransomware appends the extension '.ryshida' to encrypted files.
Source: https://github.com/crocodyli/ThreatActors-TTPs


Sites

Title Available Last Visit FQDN Screenshot
Rhysida 🟢 2024-11-21 04:56:47.249975 rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion 📸
None 🟢 2024-11-21 04:57:07.337185 rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion 📸
None 🟢 2024-11-21 04:57:20.790217 rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion 📸
Rhysida 🟢 2024-11-21 04:57:34.871332 rhysidafc6lm7qa2mkiukbezh7zuth3i4wof4mh2audkymscjm6yegad.onion 📸

External information

Tools used

Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
PowerView AnyDesk Impacket NTDS Utility (ntdsutil) WinSCP
PsExec
Windows Event Utility (wevtutil)
WMIC

This information is provided by Ransomware-Tool-Matrix

Yara Rules

Ransom Note(s)

Activity over time

Worldmap

156 Victims

US flag

Bishop Ireton High School 

Company logo
Ransomware Group:

Discovery Date: 2024-11-20 20:17

Sector: Education
Bishop Ireton High School Bishop Ireton High School, a Catholic preparatory high school located in historic Alexandria, Va., began its proud heritage of academic excellence in 1964.

Victim:   |  Group: 
US flag

American Addiction Centers 

Company logo
Ransomware Group:

Discovery Date: 2024-11-16 10:45

Sector: Healthcare
American Addiction Centers American Addiction Centers was founded in 2007. Since that time, we have grown into the largest network of rehab facilities nationwide, with programs in California, Florida, Texas, Nevada, Massachusetts, Mississippi, New Jersey, and Rhode Island.

Group: 
US flag

Granite School District 

Company logo
Ransomware Group:

Discovery Date: 2024-11-09 10:50

Sector: Education
Granite School District The Granite School District is a public school district spread across central Salt Lake County, Utah, serving West Valley City, Millcreek, Taylorsville, South Salt Lake, and Holladay; Kearns and Magna Townships; and parts of West Jordan, Murray and Cottonwood Heights.

Victim:   |  Group: 
GB flag

Fylde Coast Academy Trust 

Company logo
Ransomware Group:

Discovery Date: 2024-11-05 11:23

Sector: Education
Fylde Coast Academy Trust Fylde Coast Academy Trust (FCAT) was established in 2012 by Fylde Coast Teaching School, a partnership of Blackpool Sixth Form College and Hodgson Academy, both Outstandin learning organisations recognised for their contribution to education on a national level.

Group: 
US flag

Hope Valley Recovery 

Company logo
Ransomware Group:

Discovery Date: 2024-11-01 13:37

Sector: Healthcare
Hope Valley Recovery Hope Valley Recovery is built around a non-judgmental, client-centered approach; where we assist and guide the client as they pave a path to recovery.

Victim:   |  Group: 
CA flag

De Rose Lawyers 

Company logo
Ransomware Group:

Discovery Date: 2024-10-25 13:19

De Rose Lawyers We are a knowledgeable litigation firm with over 40 years of combined experience, solely dedicated to the practice of personal injury law.

Victim:   |  Group: 
US flag

Easterseals 

Company logo
Ransomware Group:

Discovery Date: 2024-10-23 10:19

Sector: Healthcare
Easterseals Easterseals is leading the way to full equity, inclusion, and access through life-changing disability and community services.

Victim:   |  Group: 
US flag

Henry County Schools 

Company logo
Ransomware Group:

Discovery Date: 2024-10-15 19:45

Henry County Schools We strive to provide our students and families access to the most skilled professional educators available. We take pride in our offerings in the areas of academics, athletics, arts, and social/emotional supports.

Group: 
JP flag

Microworks 

Company logo
Ransomware Group:

Discovery Date: 2024-10-15 12:26

Sector: Not Found
Microworks Microworks Point of Sale Prism offers an ideal computer system for pizza delivery, restaurant management, and franchise food service.

Victim:   |  Group: 
US flag

Axis Health System 

Company logo
Ransomware Group:

Discovery Date: 2024-10-10 19:00

Sector: Healthcare
Axis Health System Axis Health System is a private, nonprofit healthcare organization established in 1960, providing healthcare to residents of Southwest & Western Colorado.

Victim:   |  Group: 
AU flag

Golden Age Nursing Home 

Company logo
Ransomware Group:

Discovery Date: 2024-10-03 07:13
Estimated Attack Date: 2024-08-09

Sector: Healthcare
Golden Age Nursing Home Golden Age Nursing Home is a Medicare-certified facility providing short- and long-term nursing and rehabilitative services.

Victim:   |  Group: 
CA flag

Plastics Plus 

Company logo
Ransomware Group:

Discovery Date: 2024-09-30 11:34
Estimated Attack Date: 2024-08-22

Plastics Plus Since our founding in 1990, Plastics Plus has emerged as a leader in the plastic resin distribution industry. As a privately held company, we've dedicated ourselves to mastering the distribution of thermoplastics, serving a wide range of industries with our expertise.

Victim:   |  Group: 
US flag

Shenango Area School District 

Company logo
Ransomware Group:

Discovery Date: 2024-09-26 21:06

Shenango Area School District The Shenango Area School District is located in southern Lawrence County, conveniently situated 45 miles north of Pittsburgh and 90 miles south of Erie. The district encompasses 25 square miles, which includes both Shenango Township and South New Castle Borough. More

Victim:   |  Group: 
AU flag

Daughterly Care 

Company logo
Ransomware Group:

Discovery Date: 2024-09-22 12:03
Estimated Attack Date: 2024-09-06

Sector: Healthcare
Daughterly Care Daughterly Care has been providing Consumer Directed Care for private clients for over 16 years.

Victim:   |  Group: 
US flag

Greene Acres Nursing Home 

Company logo
Ransomware Group:

Discovery Date: 2024-09-20 09:36

Sector: Healthcare
Greene Acres Nursing Home A recognized leader in the provision of superior rehabilitation and long term care services, Greene Acres Nursing Home is the largest non-profit, nursing home in Greene County.

Victim:   |  Group: 
US flag

Port of Seattle/Seattle-Tacoma International Airport (SEA) 

Company logo
Ransomware Group:

Discovery Date: 2024-09-18 12:10

Port of Seattle/Seattle-Tacoma International Airport (SEA)

Group: 
US flag

Qeco/coeq 

Company logo
Ransomware Group:

Discovery Date: 2024-09-10 09:37

Sector: Not Found
Qeco/coeq The Qualifications Evaluation Council of Ontario (confident-teacherQECO) was founded in 1969 by OECTA, ETFO (FWTAO & OPSTF at the time) and AEFO to provide, and to objectively administer, the evaluation of teacher qualifications for salary purposes.

Group: 
US flag

Pennsylvania State Education Association 

Company logo
Ransomware Group:

Discovery Date: 2024-09-09 22:06

Pennsylvania State Education Association PSEA is 178,000 members strong a community of education professionals who make a difference in the lives of Pennsylvania's students every day.

Group: 
GB flag

Stratford School Academy 

Company logo
Ransomware Group:

Discovery Date: 2024-09-08 06:37

Stratford School Academy We are a mixed, all ability, and non-faith school. Our purpose is to educate all the children in our diverse local community.

Victim:   |  Group: 
US flag

Project Hospitality 

Company logo
Ransomware Group:

Discovery Date: 2024-09-02 17:10

Project Hospitality

Victim:   |  Group: 
AU flag

White Mountain Backpacks 

Company logo
Ransomware Group:

Discovery Date: 2024-08-31 20:31

White Mountain Backpacks White Mountain Backpacks has been responsible for innovative design in performance backpacks for more than 30 years. More

Victim:   |  Group: 
US flag

Sports & Spine Orthopaedics 

Company logo
Ransomware Group:

Discovery Date: 2024-08-31 04:37

Sector: Healthcare
Sports & Spine Orthopaedics

Victim:   |  Group: 
IE flag

Corbally Gartland and Rappleyea 

Company logo
Ransomware Group:

Discovery Date: 2024-08-29 18:12

Corbally Gartland and Rappleyea Corbally, Gartland and Rappleyea, LLP is a full-service law firm based in Pleasant Valley and Millbrook, New York. We provide aggressive, ethical, cost-effective legal counsel and advocacy to people and businesses.

Group: 
US flag

NewsBank 

Company logo
Ransomware Group:

Discovery Date: 2024-08-26 09:26

NewsBank NewsBank, inc. has been a premiere provider of the world's largest repository of reliable information for more than 50 years.

Victim:   |  Group: 
US flag

Affordable Tools 

Company logo
Ransomware Group:

Discovery Date: 2024-08-26 01:32

Affordable Tools Our mission is to provide a positive buying experience offering low prices, fast shipping, and friendly customer service.

Victim:   |  Group: 
US flag

Kronick Moskovitz Tiedemann & Girard 

Company logo
Ransomware Group:

Discovery Date: 2024-08-22 16:11

Kronick Moskovitz Tiedemann & Girard

Victim:   |  Group: 
AU flag

Engedi 

Company logo
Ransomware Group:

Discovery Date: 2024-08-22 09:44

Sector: Not Found
Engedi Engedi is a community based, local Mackay organisation providing support to people with a disability.

Victim:   |  Group: 
US flag

Olympus Financial 

Company logo
Ransomware Group:

Discovery Date: 2024-08-21 11:54

Olympus Financial Olympus Financial is here to provide a smoother, faster, and more efficient mortgage journey.

Victim:   |  Group: 
US flag

Waynesboro Nurseries 

Company logo
Ransomware Group:

Discovery Date: 2024-08-19 19:37

Waynesboro Nurseries Waynesboro Nurseries is a major wholesale supplier for the Eastern United States with customers from Maine to Georgia.

Victim:   |  Group: 
US flag

Sterling Rope 

Company logo
Ransomware Group:

Discovery Date: 2024-08-16 15:27

Sterling Rope Founded in 1992, Sterling Rope Company has established itself as a leader in designing, developing and manufacturing high-performance ropes and life-safety products. More

Victim:   |  Group: 
US flag

Liberty Resources 

Company logo
Ransomware Group:

Discovery Date: 2024-08-15 12:31

Sector: Healthcare
Liberty Resources Liberty Resources, Inc., headquartered in Syracuse, New York, is one of Central New Yorks most diversified and trusted human service agencies.

Victim:   |  Group: 
US flag

The Washington Times 

Company logo
Ransomware Group:

Discovery Date: 2024-08-14 14:04

The Washington Times The Washington Times is an American conservative daily newspaper published in Washington, D.C. It covers general interest topics with an emphasis on national politics.

Victim:   |  Group: 
US flag

The White Center Community Development Association 

Company logo
Ransomware Group:

Discovery Date: 2024-08-13 18:20

The White Center Community Development Association The White Center CDA is a vibrant, evolving community organization guided by the White Center Neighborhood Action Plan and engaged in various core programs and partnership initiatives to benefit the White Center community.

Victim:   |  Group: 
US flag

Moser Wealth Advisors 

Company logo
Ransomware Group:

Discovery Date: 2024-08-11 11:03

Moser Wealth Advisors Based in Bellevue, Washington, Moser Wealth Advisors is a regionally owned and operated wealth management firm that combines a Certified Public Accounting firm and Registered Investment Advisor to deliver comprehensive financial planning solutions that incorporate sophisticated tax and investment advice to high net worth individuals, families and business owners.

Victim:   |  Group: 
US flag

Sumter County Sheriff 

Company logo
Ransomware Group:

Discovery Date: 2024-08-09 10:00

Sumter County Sheriff The Sumter County Sheriff's Office is founded on the principles of integrity, respect, honesty, and caring for others.

Victim:   |  Group: 
US flag

Bayhealth Hospital 

Company logo
Ransomware Group:

Discovery Date: 2024-08-07 17:17

Sector: Healthcare
Bayhealth Hospital Bayhealth is a technologically advanced not-for-profit healthcare system with nearly 4,000 employees and a medical staff of more than 450 physicians and 200 advanced practice clinicians.

Victim:   |  Group: 
 flag

Maryville Academy 

Company logo
Ransomware Group:

Discovery Date: 2024-08-05 07:42

Maryville Academy Maryville is a child care organization rooted in Catholic social teaching and dedicated to the preservation of the dignity of children at every age.

Victim:   |  Group: 
 flag

Ranney School 

Company logo
Ransomware Group:

Discovery Date: 2024-08-04 15:45

Sector: Not Found
Ranney School Ranney School is unique in our area. We are the only Age 3 through Grade 12 independent, co-ed, secular college preparatory school in Monmouth County, NJ.

Victim:   |  Group: 
US flag

City of Columbus, Ohio 

Company logo
Ransomware Group:

Discovery Date: 2024-07-31 10:17

City of Columbus, Ohio

Victim:   |  Group: 
US flag

New Jersey City University 

Company logo
Ransomware Group:

Discovery Date: 2024-07-27 16:41

New Jersey City University

Victim:   |  Group: 
GE flag

Computer Networking Solutions 

Company logo
Ransomware Group:

Discovery Date: 2024-07-27 10:43

Sector: Technology
Computer Networking Solutions Computer Networking Solutions, dba LightSpeed DataLinks (LDL) is a small business located in Columbus, Georgia. LDL has been in business since 1998 and is an active Cisco reseller.

Victim:   |  Group: 
US flag

Community Care Alliance 

Company logo
Ransomware Group:

Discovery Date: 2024-07-26 22:16

Sector: Healthcare
Community Care Alliance Community Care Alliance is a unified human service agency integrating resources, supports and programs to strengthen families.

Victim:   |  Group: 
 flag

LawDepot 

Company logo
Ransomware Group:

Discovery Date: 2024-07-23 09:45

LawDepot

Victim:   |  Group: 
 flag

Queens County Public Administrator 

Company logo
Ransomware Group:

Discovery Date: 2024-07-20 20:17

Queens County Public Administrator There is a Public Administrator in every county in the City of New York.

Victim:   |  Group: 
MX flag

Law Offices of the Public Defender - New Mexico 

Company logo
Ransomware Group:

Discovery Date: 2024-07-19 04:39

Law Offices of the Public Defender - New Mexico As the state's largest law firm, we represent low-income people facing criminal charges in New Mexico.

Victim:   |  Group: 
 flag

Gandara Center 

Company logo
Ransomware Group:

Discovery Date: 2024-07-17 21:10

Sector: Healthcare
Gandara Center Gandara Center was founded in Springfield in 1977 to advocate and provide for equal and culturally competent services in behavioral health for the Hispanic community.

Victim:   |  Group: 
 flag

Goede, DeBoest & Cross, PLLC. 

Company logo
Ransomware Group:

Discovery Date: 2024-07-15 16:13

Goede, DeBoest & Cross, PLLC. Since its founding, the firm has grown to a mid-size law firm where the partners have a genuine camaraderie and a dynamic and young vibe amongst its staff. There is a team mentality, a family atmosphere and a shared desire to help clients.

Group: 
 flag

BrownWinick 

Company logo
Ransomware Group:

Discovery Date: 2024-07-14 08:41

BrownWinick 1951, a tax-law specialty firm opened its doors in downtown Des Moines, Iowa. Its modest size hid lofty ambitions: to help its clients build on a strong foundation, and to put businesses from Iowa, the Midwest and around the country on a powerful footing for growth and competitive success.

Group: 
 flag

MYC Media 

Company logo
Ransomware Group:

Discovery Date: 2024-07-07 07:37

Sector: Not Found
MYC Media MYC Media is your national creative agency providing full-service marketing to businesses looking to expand their brand�s reach and make an impact.

Victim:   |  Group: 
 flag

DRM Resources 

Company logo
Ransomware Group:

Discovery Date: 2024-06-29 21:46

Sector: Not Found
DRM Resources DRM Resources exists to create synergistic teams that unify diverse skill sets to envision new concepts and execute on them.

Victim:   |  Group: 
 flag

Erivan Gecom Inc 

Company logo
Ransomware Group:

Discovery Date: 2024-06-22 20:53

Erivan Gecom Inc Founded in 1981 by Pierre Lajeunesse, the company was first known under the sole name of Erivan. At that time, the company was working in civil engineering and construction of large-scale concrete jobs.

Victim:   |  Group: 
 flag

Production Machine & Enterprises 

Company logo
Ransomware Group:

Discovery Date: 2024-06-16 16:01

Production Machine & Enterprises Since 1978, Production Machine & Enterprises (PM&E) has specialized in the CNC machining of parts from non-ferrous castings to bar stock.

Victim:   |  Group: 
DE flag

CETOS Services 

Company logo
Ransomware Group:

Discovery Date: 2024-06-16 16:01

Sector: Not Found
CETOS Services CETOS Services AG is an integrated IT service provider specializing in software packaging, software distribution and IT support.

Victim:   |  Group: 
US flag

Kiemle-Hankins 

Company logo
Ransomware Group:

Discovery Date: 2024-06-15 20:23

Kiemle-Hankins Kiemle-Hankins and Birclar have been leaders in industrial maintenance for over 80 years, and together, we are one of the most trusted companies in the industry.

Victim:   |  Group: 
US flag

California Rice Exchange 

Company logo
Ransomware Group:

Discovery Date: 2024-06-08 13:52

California Rice Exchange California Rice is The Environmental Crop. Nearly 230 wildlife species rely on Sacramento rice fields for food and a restimg place.

Victim:   |  Group: 
CA flag

Rob's Whole Health Pharmacy 

Company logo
Ransomware Group:

Discovery Date: 2024-05-30 21:26

Sector: Healthcare
Rob's Whole Health Pharmacy

Victim:   |  Group: 
US flag

ICC 

Company logo
Ransomware Group:

Discovery Date: 2024-05-22 21:15

Sector: Not Found
ICC ICC is a structured cabling solutions manufacturer of copper & fiber optic connectivity products for commercial & residential applications More

Victim:   |  Group: 
GB flag

Widdop & Co. 

Company logo
Ransomware Group:

Discovery Date: 2024-05-18 14:55

Widdop & Co. Widdop Data System Program and SQL Databases for Sale!!!Widdop & Co, a family-owned wholesale gifts and home decor supplier, is selling the source code of their Widdop Data System program and relevant SQL databases for April 29, 2024. These databases contain all suppliers and buyers with contact details, the company's financial flows, and algorithms for discounts and margins. By buying these databases and software, you are buying a turnkey ready-made business. More

Victim:   |  Group: 
US flag

Surrey Place Healthcare & Rehabilitation 

Company logo
Ransomware Group:

Discovery Date: 2024-05-15 12:49

Sector: Healthcare
Surrey Place Healthcare & Rehabilitation Surrey Place Healthcare & Rehabilitation is a 74-bed Skilled Nursing facility in Bradenton, Florida. More

Victim:   |  Group: 
BR flag

Unimed Vales do Taquari e Rio Pardo 

Company logo
Ransomware Group:

Discovery Date: 2024-05-08 16:35

Sector: Healthcare
Unimed Vales do Taquari e Rio Pardo We are the largest healthcare cooperative in the world.

Group: 
AR flag

Lopez Hnos 

Company logo
Ransomware Group:

Discovery Date: 2024-05-02 14:14

Lopez Hnos Lopez Hnos is a leading company dedicated to offer a wide range of products in three business units: bicycles, bike parts and motorcycle parts with distribution throughout Argentina.

Group: 
IT flag

CDSHotels 

Company logo
Ransomware Group:

Discovery Date: 2024-04-26 00:26

CDSHotels For thirty years our friendly staff, professionalism and attention to detail make CDSHotels a leader in the hospitality world.

Victim:   |  Group: 
SV flag

Ministerio de Desarrollo Local 

Company logo
Ransomware Group:

Discovery Date: 2024-04-23 18:23

Ministerio de Desarrollo Local The Ministry of Local Development is the government entity in charge of bringing investment and infrastructure works to the country's municipalities. More

Victim:   |  Group: 
US flag

Hernando County 

Company logo
Ransomware Group:

Discovery Date: 2024-04-12 06:01

Hernando County

Victim:   |  Group: 
US flag

Oki Golf 

Company logo
Ransomware Group:

Discovery Date: 2024-04-12 00:15

Oki Golf Oki Golf is a collection of 11 Seattle area golf courses, including The Golf Club at Newcastle, providing championship golf course layouts and outstanding course conditions to players of all skill levels.

Victim:   |  Group: 
MY flag

Malaysian Industrial Development Finance 

Company logo
Ransomware Group:

Discovery Date: 2024-04-07 16:24

Malaysian Industrial Development Finance MIDF, established in 1960 and based in Kuala Lumpur, is a financial development institution to modernize Malaysia's manufacturing industries.

Victim:   |  Group: 
AE flag

Seven Seas Technology 

Company logo
Ransomware Group:

Discovery Date: 2024-04-03 01:29

Sector: Technology
Seven Seas Technology Seven Seas Technology has chosen a collaborative, multi-cloud strategy that puts customers first by partnering with most of the major technology vendors. We help our customers innovate their processes, create valuable connections and rapport with their business and increase their productivity.

Group: 
MX flag

El Debate 

Company logo
Ransomware Group:

Discovery Date: 2024-03-26 23:52

Sector: Not Found
El Debate El Debate is a Mexican newspaper published by El Debate S.A. de C.V. of Culiacan, Sinaloa.

Victim:   |  Group: 
US flag

MarineMax 

Company logo
Ransomware Group:

Discovery Date: 2024-03-20 23:56

MarineMax

Victim:   |  Group: 
US flag

Kolbe Striping 

Company logo
Ransomware Group:

Discovery Date: 2024-03-20 08:47

Sector: Construction
Kolbe Striping Kolbe Striping offers both durable and lasting pavement marking as well as temporary markings designed to suit your needs.

Victim:   |  Group: 
US flag

Brooks Tropicals 

Company logo
Ransomware Group:

Discovery Date: 2024-03-12 11:43

Brooks Tropicals Brooks Tropicals grows its popular Caribbean Red papayas in several Caribbean locales.

Victim:   |  Group: 
US flag

Ann & Robert H. Lurie Children's Hospital of Chicago 

Company logo
Ransomware Group:

Discovery Date: 2024-02-27 11:40

Sector: Healthcare
Ann & Robert H. Lurie Children's Hospital of Chicago Ann & Robert H. Lurie Children's Hospital of Chicago provides superior pediatric care in a setting that offers the latest benefits and innovations in medical technology, research and family-friendly design.

Victim:   |  Group: 
US flag

Ironrock 

Company logo
Ransomware Group:

Discovery Date: 2024-02-26 23:45

Sector: Construction
Ironrock Ironrock is a manufacturer of high quality indoor/outdoor unglazed ceramic quarry tile, and architectural thin brick.

Group: 
IT flag

ASP BasilicataASM MateraIRCCS CROB 

Company logo
Ransomware Group:

Discovery Date: 2024-02-15 12:16

Sector: Healthcare
ASP BasilicataASM MateraIRCCS CROB ...

Victim:   |  Group: 
PE flag

CNPC Peru S.A. 

Company logo
Ransomware Group:

Discovery Date: 2024-02-01 03:01

Sector: Energy
CNPC Peru S.A. CNPC Peru S.A., formerly known as Petrobras Energia Peru S.A., operates in the country since 1993.

Victim:   |  Group: 
US flag

Lee Spring 

Company logo
Ransomware Group:

Discovery Date: 2024-01-13 11:50

Lee Spring Lee Spring manufactures and distributes mechanical springs, wire forms, stampings and fourslide parts worldwide.

Victim:   |  Group: 
CH flag

The Lutheran World Federation 

Company logo
Ransomware Group:

Discovery Date: 2024-01-06 01:22

The Lutheran World Federation

Victim:   |  Group: 
GB flag

Aspiration Training 

Company logo
Ransomware Group:

Discovery Date: 2024-01-01 13:06

Sector: Education
Aspiration Training Aspiration Training is an award-winning specialist training provider, delivering qualifications in Dental, Adult Care and Early Years for over 20 years.

Victim:   |  Group: 
JO flag

Abdali Hospital 

Company logo
Ransomware Group:

Discovery Date: 2023-12-26 01:30

Sector:
Abdali Hospital Abdali Hospital is a 200-bed multi-specialty hospital with the mission to provide best practice patient-centred care and promote research and education.

Victim:   |  Group: 
ZA flag

Tshwane University of Technology 

Company logo
Ransomware Group:

Discovery Date: 2023-12-26 01:30

Sector:
Tshwane University of Technology Tshwane University of Technology is a higher education institution in South Africa that came into being through a merger of three technikons - Technikon Northern Gauteng, Technikon North-West and Technikon Pretoria.

Victim:   |  Group: 
 flag

Kauno Technologijos Universitetas 

Company logo
Ransomware Group:

Discovery Date: 2023-12-19 04:14

Sector:
Kauno Technologijos Universitetas KTU offers 5 study programmes in computer sciences.

Victim:   |  Group: 
 flag

Grupo Jose Alves 

Company logo
Ransomware Group:

Discovery Date: 2023-12-12 03:54

Sector:
Grupo Jose Alves

Victim:   |  Group: 
 flag

Insomniac Games 

Company logo
Ransomware Group:

Discovery Date: 2023-12-12 02:41

Sector:
Insomniac Games Insomniac Games, Inc. is an American video game developer based in Burbank, California.

Victim:   |  Group: 
 flag

Holding Slovenske elektarne 

Company logo
Ransomware Group:

Discovery Date: 2023-12-10 05:42

Sector:
Holding Slovenske elektarne

Victim:   |  Group: 
 flag

Hse 

Company logo
Ransomware Group:

Discovery Date: 2023-12-10 04:10

Sector:
Hse

Victim:   |  Group: 
QA flag

Qatar Racing and Equestrian Club 

Company logo
Ransomware Group:

Discovery Date: 2023-12-09 19:12

Sector:
Qatar Racing and Equestrian Club Established in 1975 Qatar Racing and Equestrian Club is mandated with representing, promoting and advancing equine and equestrian initiatives from grassroots programs to the international arena.

Victim:   |  Group: 
 flag

Travian Games 

Company logo
Ransomware Group:

Discovery Date: 2023-12-08 08:41

Sector:
Travian Games Travian Games is one of the world's leading PC games companies, based in Munich.

Victim:   |  Group: 
 flag

Tcman 

Company logo
Ransomware Group:

Discovery Date: 2023-12-08 07:10

Sector:
Tcman Tcman was born with the vocation to provide real solutions to the need to improve the management of industrial assets.

Victim:   |  Group: 
 flag

King Edward VII's Hospital 

Company logo
Ransomware Group:

Discovery Date: 2023-11-29 11:41

Sector:
King Edward VII's Hospital Unique files are presented to your attention! Data from the Royal Family! A large amount of patient and employee data. Sale in one lot!!King Edward VII's Hospital is an independent charitable hospital with a proud history of Royal Patronage, discreetly located within London's Harley Street medical district.

Victim:   |  Group: 
TH flag

Bangkok University 

Company logo
Ransomware Group:

Discovery Date: 2023-11-27 23:28

Sector:
Bangkok University Bangkok University has operated since 1962, is one of the oldest and largest private, non-profit universities in Thailand.

Victim:   |  Group: 
 flag

NC Central University 

Company logo
Ransomware Group:

Discovery Date: 2023-11-27 22:02

Sector:
NC Central University North Carolina Central University (NCCU), a distinguished institution nestled in the heart of Durham, North Carolina, has earned national acclaim for its unwavering commitment to academic excellence, groundbreaking research opportunities and remarkable achievements in securing grants for innovative projects.

Victim:   |  Group: 
CN flag

Energy China 

Company logo
Ransomware Group:

Discovery Date: 2023-11-24 20:49

Sector:
Energy China China Energy Engineering Corporation or Energy China, is a Chinese state-owned energy conglomerate, with headquarters in Chaoyang District, Beijing.

Victim:   |  Group: 
 flag

St Edmund's College & Prep School 

Company logo
Ransomware Group:

Discovery Date: 2023-11-21 11:45

Sector:
St Edmund's College & Prep School Located in 400 acres of beautiful Hertfordshire countryside, St Edmund's College and Prep School is a safe, stimulating environment for students aged 3-18, with boarding available from age 11.

Victim:   |  Group: 
GB flag

British Library 

Company logo
Ransomware Group:

Discovery Date: 2023-11-20 07:09

Sector:
British Library The British Library is a research library in London that is the national library of the United Kingdom. It is one of the largest libraries in the worl.

Victim:   |  Group: 
 flag

MHM Health 

Company logo
Ransomware Group:

Discovery Date: 2023-11-11 14:44

Sector:
MHM Health MHM Health is dedicated to help our partner Independent Physician Associations remain independent as the healthcare industry transitions to value-based care.

Victim:   |  Group: 
IT flag

Azienda Ospedaliera Universitaria Integrata di Verona 

Company logo
Ransomware Group:

Discovery Date: 2023-11-10 07:10

Sector:
Azienda Ospedaliera Universitaria Integrata di Verona The Verona Integrated University Hospital Company is a hospital facility that is part of the Veneto Health Service, based in the city of Verona and is one of the largest hospitals in Italy.

Victim:   |  Group: 
MY flag

Indah Water Konsortium 

Company logo
Ransomware Group:

Discovery Date: 2023-11-07 22:15

Sector:
Indah Water Konsortium Indah Water Konsortium, a company owned by Minister of Finance Incorporated, is Malaysia's national sewerage company which has been entrusted with the tasks of developing and maintaining a modern and efficient sewerage system for all Malaysians.

Victim:   |  Group: 
 flag

Mount St. Mary's Seminary 

Company logo
Ransomware Group:

Discovery Date: 2023-11-06 13:08

Sector:
Mount St. Mary's Seminary Mount St. Mary's Seminary is the oldest division of the Athenaeum. The seminary has as its mission the preparation of candidates for the Catholic priesthood�a gift of God and the fruit of an integrated approach to formation.

Victim:   |  Group: 
 flag

SMH Group 

Company logo
Ransomware Group:

Discovery Date: 2023-11-05 11:31

Sector:
SMH Group In 2022, the SMH Group was born, with all the individual offices having their original names prefixed with 'SMH'.

Victim:   |  Group: 
 flag

GO! Handelsschool Aalst 

Company logo
Ransomware Group:

Discovery Date: 2023-11-02 10:12

Sector:
GO! Handelsschool Aalst GO! Handelsschool Aalst is een milieubewuste school in het centrum van Aalst en streeft naar hoogstaand onderwijs op maat in een open sfeer.

Victim:   |  Group: 
 flag

Northwest Eye Care Professionals 

Company logo
Ransomware Group:

Discovery Date: 2023-10-14 07:11

Sector:
Northwest Eye Care Professionals Serving Clackamas and the surrounding communities in Vancouver and Beaverton, we offer comprehensive eye health services for all members of your family as well as specialty services.

Victim:   |  Group: 
 flag

Southern Arkansas University 

Company logo
Ransomware Group:

Discovery Date: 2023-10-09 02:53

Sector:
Southern Arkansas University Southern Arkansas University offers personalized tour visits, faculty and staff who invest in student success, and a caring campus community. More

Victim:   |  Group: 
 flag

Camara Municipal de Gondomar 

Company logo
Ransomware Group:

Discovery Date: 2023-10-06 01:13

Sector:
Camara Municipal de Gondomar Discover Gondomar, a land of historical echoes, where the long history of generations attests to the identity of this Municipality.

Victim:   |  Group: 
DO flag

General Directorate of Migration of the Dominican Republic 

Company logo
Ransomware Group:

Discovery Date: 2023-10-04 01:16

Sector:
General Directorate of Migration of the Dominican Republic

Victim:   |  Group: 
BR flag

Federal University of Mato Grosso do Sul 

Company logo
Ransomware Group:

Discovery Date: 2023-10-02 01:17

Sector:
Federal University of Mato Grosso do Sul The Federal University of Mato Grosso do Sul, is a public university located in the state of Mato Grosso do Sul in Brazil.

Victim:   |  Group: 
IT flag

Istituto Prosperius 

Company logo
Ransomware Group:

Discovery Date: 2023-09-26 13:17

Sector:
Istituto Prosperius Villa Cherubini reopens with a new facility within the Prosperius Institute health complex, established founded by Prof. Mario Bigazzi back in 1973.

Victim:   |  Group: 
KW flag

Ministry Of Finance (Kuwait) 

Company logo
Ransomware Group:

Discovery Date: 2023-09-25 14:42

Sector:
Ministry Of Finance (Kuwait) Ministry of Finance is one of the governmental bodies of Kuwait and part of the cabinet.

Victim:   |  Group: 
 flag

Ort Harmelin College of Engineering 

Company logo
Ransomware Group:

Discovery Date: 2023-09-23 02:46

Sector:
Ort Harmelin College of Engineering Ort Harmelin College of Engineering is an innovative technological college located in the heart of the hi-tech area, Sapir in Netanya.

Group: 
 flag

Holon Institute of Technology 

Company logo
Ransomware Group:

Discovery Date: 2023-09-22 11:44

Sector:
Holon Institute of Technology HIT Holon Institute of Technology, is a well-established unique and multidisciplinary academic institution, which manages to maintain its young spirit as well as its dynamic and contemporary nature.

Victim:   |  Group: 
 flag

Singing River Health System 

Company logo
Ransomware Group:

Discovery Date: 2023-09-10 05:37

Sector:
Singing River Health System Singing River Health System is both a mission-driven provider of health services and one of the largest employers on the Mississippi Gulf Coast.

Victim:   |  Group: 
AU flag

Core Desktop 

Company logo
Ransomware Group:

Discovery Date: 2023-09-10 05:37

Sector:
Core Desktop Core Desktop is a Microsoft Tier 1 CSP Partner delivering key IT managed solutions that merge legacy technology with innovative cloud solutions.

Victim:   |  Group: 
DK flag

IT-Center Syd 

Company logo
Ransomware Group:

Discovery Date: 2023-09-09 11:37

Sector:
IT-Center Syd IT Center South is an operations center for an administrative IT service community consisting of several state-owned educational institutions spread over 11 land registers around the region of Southern Denmark. More

Victim:   |  Group: 
 flag

Prince George's County Public Schools 

Company logo
Ransomware Group:

Discovery Date: 2023-08-25 07:10

Sector:
Prince George's County Public Schools Prince George's County Public Schools (PGCPS), one of the nation's 20th largest school districts, has 201 schools and centers, more than 133,000 students and nearly 20,000 employees.

Victim:   |  Group: 
 flag

Prospect Medical Holdings 

Company logo
Ransomware Group:

Discovery Date: 2023-08-24 08:38

Sector:
Prospect Medical Holdings

Victim:   |  Group: 
US flag

Pierce College 

Company logo
Ransomware Group:

Discovery Date: 2023-08-21 23:39

Sector:
Pierce College Pierce College creates quality educational opportunities for a diverse community of learners to thrive in an evolving world.

Victim:   |  Group: 
IT flag

Municipality of Ferrara 

Company logo
Ransomware Group:

Discovery Date: 2023-08-16 10:06

Sector:
Municipality of Ferrara Ferrara is a city and comune in Emilia-Romagna, northern Italy, capital city of the Province of Ferrara.

Victim:   |  Group: 
AR flag

National Institute of Social Services for Retirees and Pensioners 

Company logo
Ransomware Group:

Discovery Date: 2023-08-12 09:07

Sector:
National Institute of Social Services for Retirees and Pensioners

Victim:   |  Group: 
AU flag

Optimum Health Solutions 

Company logo
Ransomware Group:

Discovery Date: 2023-08-09 11:01

Sector:
Optimum Health Solutions Optimum Health Solutions is Australia's leading preventative health company.

Victim:   |  Group: 
 flag

Ramtha 

Company logo
Ransomware Group:

Discovery Date: 2023-08-09 07:01

Sector:
Ramtha The teachings of Ramtha are a unique science.

Victim:   |  Group: 
ID flag

United Tractors 

Company logo
Ransomware Group:

Discovery Date: 2023-08-03 09:07

Sector:
United Tractors United Tractors is a heavy equipment distribution company headquartered in Jakarta, Indonesia.

Victim:   |  Group: 
 flag

ESMOD 

Company logo
Ransomware Group:

Discovery Date: 2023-07-28 22:06

Sector:
ESMOD ESMOD, founded by master tailor Alexis Lavigne, has been one of the most prestigious fashion universities in the world since the first students crossed its threshold in 1841.

Victim:   |  Group: 
 flag

ESKA Erich Schweizer 

Company logo
Ransomware Group:

Discovery Date: 2023-07-28 16:12

Sector:
ESKA Erich Schweizer ESKA is a leading German manufacturer of all types of fuses and passive components.

Victim:   |  Group: 
IR flag

Rouzbeh Educational Complex 

Company logo
Ransomware Group:

Discovery Date: 2023-07-28 10:11

Sector:
Rouzbeh Educational Complex The industry in which Rouzbeh Educational Complex operates is educational institution. The country where Rouzbeh Educational Complex is located is Iran, while the company's headquarters is in Tehran.

Victim:   |  Group: 
IT flag

University of Salerno 

Company logo
Ransomware Group:

Discovery Date: 2023-07-26 09:04

Sector:
University of Salerno The University of Salerno is a university located in Fisciano and in Baronissi, Italy. Its main campus is located in Fisciano while the Faculty of Medicine is located in Baronissi.

Victim:   |  Group: 
GB flag

University of the West of Scotland 

Company logo
Ransomware Group:

Discovery Date: 2023-07-25 07:02

Sector:
University of the West of Scotland

Victim:   |  Group: 
 flag

Axity 

Company logo
Ransomware Group:

Discovery Date: 2023-07-22 12:05

Sector:
Axity Axity is one of the leading IT companies in Latin America and home to the best talent.

Victim:   |  Group: 
 flag

Lumberton Independent School District 

Company logo
Ransomware Group:

Discovery Date: 2023-07-19 11:06

Sector:
Lumberton Independent School District Lumberton Independent School District is a public school district based in Lumberton, Texas. In addition to Lumberton, the district serves the city of Rose Hill Acres.

Victim:   |  Group: 
US flag

Stephen F. Austin State University 

Company logo
Ransomware Group:

Discovery Date: 2023-07-17 13:11

Sector:
Stephen F. Austin State University Stephen F. Austin State University is a public university in Nacogdoches, Texas. More

Victim:   |  Group: 
 flag

IRIS Informatique 

Company logo
Ransomware Group:

Discovery Date: 2023-07-17 13:11
Estimated Attack Date: 2023-06-19

Sector:
IRIS Informatique IRIS Informatique is a team of experts with many areas of expertise: Helpdesk, IT Logistics, IT Repair and Recycling, delegation of IT resources, etc. More

Victim:   |  Group: 
 flag

ICT-College 

Company logo
Ransomware Group:

Discovery Date: 2023-07-17 13:11

Sector:
ICT-College ICT-College's experienced staff are always available to help and answer questions. More

Victim:   |  Group: 
 flag

Caterham High School 

Company logo
Ransomware Group:

Discovery Date: 2023-07-14 21:01

Sector:
Caterham High School Caterham High is a community school that serves a richly diverse area of East London, with many ethnic groups and languages represented. More

Victim:   |  Group: 
 flag

The Big Life group 

Company logo
Ransomware Group:

Discovery Date: 2023-07-14 02:05

Sector:
The Big Life group Big Life is in the business of changing lives. We fight inequality by working with people and places to create opportunities and inspire change. More

Victim:   |  Group: 
IT flag

Citta Nuova 

Company logo
Ransomware Group:

Discovery Date: 2023-07-10 13:07

Sector:
Citta Nuova Citta Nuova is an Italian publishing house established in Rome in 1959. More

Victim:   |  Group: 
KE flag

Kenya Bureau Of Standards 

Company logo
Ransomware Group:

Discovery Date: 2023-07-07 03:01

Sector:
Kenya Bureau Of Standards The Kenya Bureau of Standards (KEBS) has remained the premier government agency for the provision of Standards, Metrology and Conformity Assessment (SMCA) services since its inception in 1974. More

Victim:   |  Group: 
 flag

Ayuntamiento de Arganda City Council 

Company logo
Ransomware Group:

Discovery Date: 2023-07-03 11:04

Sector:
Ayuntamiento de Arganda City Council Located in the southeast of the Community of Madrid, 25 kilometers from Madrid capital, Arganda del Rey can boast of having an extremely interesting natural environment, since part of its municipal district is included in the 'Parque Regional del Sureste', as well as having large green areas and particular ecosystems of remarkable environmental richness. More

Victim:   |  Group: 
 flag

Hollywood Forever 

Company logo
Ransomware Group:

Discovery Date: 2023-07-03 10:06

Sector:
Hollywood Forever Hollywood Forever is a full-service funeral home, crematory, cemetery, and cultural events center in the heart of Hollywood. More

Victim:   |  Group: 
 flag

BM GROUP POLYTEC S.p.A. 

Company logo
Ransomware Group:

Discovery Date: 2023-07-03 01:02

Sector:
BM GROUP POLYTEC S.p.A. Polytec is the merger of two leading companies in automation, robotics , renewable energy and plant engineering, an internationally renowned company operating in the field of system integration, specializing in solutions and platforms that combine robotics, artificial intelligence, process automation and software to help manufacturing companies achieve the technological transformation they need to become smart factories. More

Victim:   |  Group: 
 flag

Enfield Grammar School 

Company logo
Ransomware Group:

Discovery Date: 2023-06-29 21:00

Sector:
Enfield Grammar School Enfield Grammar School is a boys' Comprehensive school and sixth form with academy status, founded in 1558, situated in Enfield Town in the London Borough of Enfield in North London. Documents Data Catalog: 18 GB, 76 Files 20% Not sold data was uploaded, data hunters, enjoy More

Victim:   |  Group: 
 flag

Western National Group 

Company logo
Ransomware Group:

Discovery Date: 2023-06-29 01:36

Sector:
Western National Group Experts in the Western US multifamily real estate industry, Western National Group is an outstanding curator of investment opportunities, a team of industry-leading builders, and an accredited property management company. More

Victim:   |  Group: 
 flag

Alberta Newsprint 

Company logo
Ransomware Group:

Discovery Date: 2023-06-28 20:57

Sector:
Alberta Newsprint Founded in 1989, Alberta Newsprint is a manufacturer of premium newsprint and high bright paper. Documents Data Catalog: 28 GB, 45 785 Files 40% Not sold data was uploaded, data hunters, enjoy More

Victim:   |  Group: 
 flag

iMatica 

Company logo
Ransomware Group:

Discovery Date: 2023-06-27 14:05

Sector:
iMatica iMatica was born in 2001 in Girona and we have expanded throughout the peninsula to provide more and better service. The specialty of the house is the implementation of business management software, also called ERP or billing and accounting program. Documents Data Catalog: 717 GB, 568 473 Files 90% Not sold data was uploaded, data hunters, enjoy More

Victim:   |  Group: 
DE flag

Hochschule Kaiserslautern 

Company logo
Ransomware Group:

Discovery Date: 2023-06-27 00:08

Sector:
Hochschule Kaiserslautern The Kaiserslautern University of Applied Sciences is a Hochschule (University of Applied Sciences) with 3 campuses located in Kaiserslautern, Germany, in Pirmasens, Germany and in Zweibrucken, Germany. Documents Data Catalog: 241 GB, 294 254 Files 40% Not sold data was uploaded, data hunters, enjoy More

Victim:   |  Group: 
 flag

Fassi Gru S.p.A. 

Company logo
Ransomware Group:

Discovery Date: 2023-06-26 14:02

Sector:
Fassi Gru S.p.A. Fassi Gru S.p.A. - Loader cranes manufacturer since 1965. Fassi Gru is the market leader among Italian producers. Its product range and sales numbers place it among the top producers of hydraulic cranes in the world. Documents Data Catalog: 490 GB, 1 120 626 Files 100% All files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: 
 flag

Avannubo 

Company logo
Ransomware Group:

Discovery Date: 2023-06-21 21:03

Sector:
Avannubo Global provider of technological services with an official license for IP telephony, mobile phones and Internet access. Documents Data Catalog: 165Gb, 198760 Files 100% All files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: 
DE flag

SAPROS 

Company logo
Ransomware Group:

Discovery Date: 2023-06-20 20:11

Sector:
SAPROS Sapros is a manufacturer, and supplier of food products like salads, vegetables, fruit and high-quality antipasti. Documents 100% All files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: 
AT flag

EDER 

Company logo
Ransomware Group:

Discovery Date: 2023-06-18 20:00

Sector:
EDER The EDER group of companies includes the brick plants in Peuerbach and Weibern, four ready-mixed concrete plants in Upper Austria, Systembau Eder with prefabricated stairs, constructive concrete components and double-wall systems for industrial building construction and its own vehicle fleet. Documents 100% All files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: 
 flag

Tyconz 

Company logo
Ransomware Group:

Discovery Date: 2023-06-18 00:05

Sector:
Tyconz Founded in 2011, TYCONZ has become one of the most experienced SAP-certified consultancy firms. Documents 100% All files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: 
AT flag

Ziegelwerk Eder 

Company logo
Ransomware Group:

Discovery Date: 2023-06-17 07:00

Sector:
Ziegelwerk Eder In 1996, the Upper Austrian family company EDER built a state-of-the-art brick factory in Freital near Dresden. Documents 100% All files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: 
 flag

Koper Automatisering 

Company logo
Ransomware Group:

Discovery Date: 2023-06-15 11:01

Sector:
Koper Automatisering Koper Automatisering specializes in the development of specialized software for the food industry and floriculture. Documents 100% All files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: 
 flag

Paris High School 

Company logo
Ransomware Group:

Discovery Date: 2023-06-12 06:58

Sector:
Paris High School Paris High School is a learning community dedicated to developing well-rounded, productive, engaged citizens in a safe and supportive environment. More

Victim:   |  Group: 
US flag

Northeastern State University 

Company logo
Ransomware Group:

Discovery Date: 2023-06-12 05:00

Sector:
Northeastern State University Northeastern State University is a public university with its main campus in Tahlequah, Oklahoma. More

Victim:   |  Group: 
CL flag

Ejercito de Chile 

Company logo
Ransomware Group:

Discovery Date: 2023-06-10 00:04

Sector:
Ejercito de Chile The Army of Chile is the branch of the Armed Forces of Chile in charge of the land defense of Chile, whose mission is to maintain the external security, sovereignty and territorial integrity of the Republic. More

Victim:   |  Group: 
 flag

Haemokinesis 

Company logo
Ransomware Group:

Discovery Date: 2023-06-05 11:27

Sector:
Haemokinesis Haemokinesis specializes in research and development, laboratory systems, sales and distribution of immunohematology products. Documents 100% all files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: 
CH flag

Amstutz Produkte 

Company logo
Ransomware Group:

Discovery Date: 2023-06-05 11:26

Sector:
Amstutz Produkte AMSTUTZ PRODUKTE AG is a leading Swiss manufacturer of chemicals and technical equipment for chemical applications. Documents 100% all files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: 
 flag

The Thomas Hardye School 

Company logo
Ransomware Group:

Discovery Date: 2023-06-05 11:26

Sector:
The Thomas Hardye School The Thomas Hardye School is a secondary academy school in Dorchester, Dorset, England. It is also part of the DASP group. Documents 100% all files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: 
 flag

Collectivite Territoriale de Martinique 

Company logo
Ransomware Group:

Discovery Date: 2023-06-05 11:25

Sector:
Collectivite Territoriale de Martinique The territorial collectivity of Martinique is a single French territorial collectivity that succeeds the overseas department and region of Martinique in all their rights and obligations on January 1, 2016. Documents 100% all files was uploaded to public access, data hunters, enjoy More

Victim:   |  Group: