Ransomware Group intelligence
Bavacai
ActiveTrack Bavacai with 16 published victims and 1 known leak locations in a single intelligence view.
Overview
Bavacai is tracked by Breach House as a ransomware group with 16 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (16)
Search, filter and paginate the victim timeline for Bavacai.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Elken Sdn Bhd id28830 View details | Malaysia | Retail / E-commerce | ||
|
MLM / health & beauty products company. ~16k emails extracted. |
|||||
| Ransomware | Bandeirante Supermercados id28831 View details | Brazil | Retail / E-commerce | ||
|
Brazilian supermarket chain. |
|||||
| Ransomware | Strategic Imports id28832 View details | Australia | Retail / E-commerce | ||
|
Australian auto parts/batteries importer. Brands: Strategic Imports, Auto Parts Now, Discount Batteries Now. User: bstuart (Brad Stuart). QNAP NAS (CACHEDEV1_DATA). |
|||||
| Ransomware | Magnolia (Israel) id28833 View details | Israel | Retail / E-commerce | ||
|
Israeli jewelry company. Silver & accessories, participates in Vicenza jewelry fair (2025/2026). Sells via buyme.co.il gift cards. ~38k files, invoices in Hebrew (SI/IN/OV prefix). |
|||||
| Ransomware | Trimble Inc / Gerrard Inc id28834 View details | United States | IT | ||
|
Technology company Trimble (trimble.com) and Gerrard Inc (gerrardinc.com). ~18 Trimble email addresses. |
|||||
| Ransomware | Atencio Engineering id28835 View details | United States | Manufacturing / Engineering | ||
|
Civil engineering & land surveying firm. Services: site plans, boundary surveys, OWTS (septic) design, fire line design, elevation certificates, flood plain analysis. Clients in Las Animas County, Pueblo County, Florence CO area. |
|||||
| Ransomware | SIT Group / Robusta id28836 View details | Italy | Manufacturing / Engineering | ||
|
Italian company SIT Group (sitgroup.it) and Bulgarian Robusta (robusta.bg). Also abv.bg emails. |
|||||
| Ransomware | Desert Christian Schools (DCS) id28837 View details | United States | Education | ||
|
K-12 Christian school affiliated with First Baptist Church of Lancaster, CA. ADP payroll, DCFS childcare program, City of Lancaster Water Safety program. Financial docs: P&L, Balance Sheet, Trial Balance, 1099s. School Board minutes 2025. |
|||||
| Ransomware | CourtSmart id28838 View details | United States | IT | ||
|
Court technology company. Domain courtsmart.com / COURTSMART2. Dev server: dev-rich20.courtsmart.com. Connections to JIS.org, nashville.org. |
|||||
| Ransomware | Hathcock (Personal) id28839 View details | Other | |||
|
Personal comprehensive reports. Individuals: Noel Ray Hathcock, Trinity John Hathcock. |
|||||
| Ransomware | ActionAid / TACOSA id28840 View details | United Kingdom | NGOs / Associations | ||
|
NGO sector. Domains: actionaid.org, tacosa.org.za, immigration.go.tz. |
|||||
| Ransomware | Palmers Relocations id28841 View details | United Kingdom | Transportation / Travel / Logistics | ||
|
Australian international removals & relocation company. FIDI accredited, ISO 9001:2015 certified. Services: household moves, storage, customs, immigration (IMMI/VEVO). Operates Melbourne area (Pascoe Vale, Dandenong, Caulfield). |
|||||
| Ransomware | Académie de Montpellier / CSJM id28842 View details | France | Education | ||
|
French public school network. Domain CSJM.BEZIERS, part of Académie de Montpellier (ac-montpellier.fr). Occitanie region (laregion.fr). Teacher and admin staff credentials. |
|||||
| Ransomware | Colegio María Inmaculada (CMI) id28843 View details | Costa Rica | Education | ||
|
Catholic school in Moravia, Costa Rica. Domain cmi.local / mariainmaculada.ed.cr. Servers: CMI-DC01, CMI-APP, CMI-HTTP2, main-server1/2. |
|||||
| Ransomware | CEAGESP / Netfeirasp id28844 View details | Brazil | Agriculture / Food | ||
|
Brazilian produce wholesale market network. Domain netfeirasp.ceagesp (CEAGESP). Also demarchibrasil.com.br accounts. |
|||||
| Ransomware | Raycolighting id28845 View details | United Kingdom | Manufacturing / Engineering | ||
|
Organization with 2 emails extracted. Domain: raycolighting.com |
|||||