Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us
Search v2
before

Prefix a filter with + to require it, or - to exclude it — e.g. +country:us only shows US victims, -country:us hides them. Mix several with free-text words; everything is combined with AND (so hospital +country:us -group:lockbit3 means: text "hospital", country is US, group is not lockbit3). Repeating + on the same field is OR'd together (+country:us +country:ca → US or Canada); repeating - excludes all of them. Wrap multi-word values in quotes, e.g. +sector:"public sector". infostealer, press and multipleclaims take a bare +/- with no value: +infostealer / -infostealer filter on infostealer data, while +press searches press articles only and -press hides press coverage; +multipleclaims restricts to victims claimed by more than one group (cross-referenced) and -multipleclaims keeps only single-claim victims; +campaign:fortibleed / -campaign:fortibleed filter on domains found in the FortiBleed leaked-credential dataset; +ioc:<value> searches IOCs only (no -ioc: form) and returns the group(s) that value belongs to — <value> can be a literal indicator (hash, email, wallet, IP, domain, ...) or a group's slug, and it takes over the whole search, ignoring every other term/filter; a query starting with CVE- (e.g. CVE-2023-4966, or a partial id like CVE-2024) searches vulnerabilities only and returns the group(s) known to exploit it; before:/after: take a date directly with no +/- prefix, as shown below.

+country:only this country — opens a picker
-country:exclude this country — opens a picker
+group:only this group — opens a picker
-group:exclude this group — opens a picker
+website:example.comonly this website
+sector:only this sector — opens a picker
-sector:exclude this sector — opens a picker
+infostealerhas infostealer data
-infostealerno infostealer data
+presssearch press articles only
-presshide press coverage
+multipleclaimsclaimed by more than one group (cross-ref only)
-multipleclaimsclaimed by a single group only
+campaign:fortibleeddomain found in the FortiBleed dataset
-campaign:fortibleeddomain not in the FortiBleed dataset
+ioc:IOC value or group slug — searches IOCs only, returns the group
after:2025-01-01discovered/attacked on or after
before:2026-01-01discovered/attacked on or before
No victims found

No results matched this query. Try removing a filter or broadening a term.

Press Coverage 1
Dyfed-Powys Police
2026-09-14

La police de Dyfed-Powys (Pays de Galles) a été victime d'une cyberattaque détectée le 14 septembre, qui a perturbé certains de ses systèmes non urgents, notamment les contacts en ligne et les e-mails. Les services d'urgence (lignes 999 et 101) sont toutefois restés opérationnels tout au long de l'incident. L'enquête, menée par l'unité régionale contre le crime organisé Tarian, tente toujours de déterminer l'origine de l'attaque et si un ransomware a été utilisé. Si aucune preuve ne montre que des données du public ont été compromises, la police enquête toujours pour savoir si des informations concernant son personnel ont été consultées. L'Information Commissioner's Office (l'autorité de protection des données au Royaume-Uni) a été informée de la situation.

Read article