Ransomware Group intelligence
Barracuda
ActiveTrack Barracuda with 18 published victims and 3 known leak locations in a single intelligence view.
Overview
Barracuda is tracked by Breach House as a ransomware group with 18 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 3 33.3%
- Pending 4 44.4%
- Deleted 2 22.2%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 3h ago | qr6uopkqxmq254osyct3oibil32xp3qsimkkbqdscsrsb4zqbagnifad.onion |
| Leak location 2 | Onion service | Up checked 3h ago | uvm6hk4wwstfddja5z5htgtlehmfyflffijz6iozsuqyacyibzxefkqd.onion |
| Leak location 1 | Onion service | Up checked 3h ago | darkfoxaqhfpxkrbt7vxns2z2u2k72sgmqbzeorupaiottw3ecm2wgyd.onion |
Top Activity Sectors (6)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Barracuda, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: Barracuda leverages local accounts harvested from credential dumps to gain initial access and persist execution on victim machines.
What that means: Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1059.001 PowerShell Execution
What they do: Barracuda executes ransomware payload logic via encoded PowerShell commands to stage encryption routines across compromised hosts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Barracuda disables security tools by terminating antivirus processes and modifying Windows Defender service configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1083 File and Directory Discovery Discovery
What they do: Barracuda performs file and directory discovery using PowerShell globbing to identify critical system and user data folders.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Barracuda uses network share discovery to locate victim file servers and map accessible storage paths for encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Barracuda moves laterally through SMB/Windows Admin Shares using stolen credentials to encrypt additional networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1560.001 Archive via Utility Collection
What they do: Barracuda archives stolen data using utility-based collection commands before exfiltration to its command-and-control infrastructure.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: Barracuda encrypts discovered files and directories with custom symmetric encryption, appending its own勒索 note to each affected file.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Barracuda inhibits system recovery by deleting Volume Shadow Copy snapshots and disabling backup restore mechanisms via built-in Windows tools.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Barracuda performs internal defacement by replacing system icons and web content with ransom notices to increase disruption.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (18)
Search, filter and paginate the victim timeline for Barracuda. Showing 1–18 of 18.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | i2i-systems id32793 View details | Türkiye | IT | pending | ||
|
i2i-systems.com operates within the IT sector and is identified as a ransomware victim within a threat-intelligence index. The entity is associated with the threat actor Barracuda, with operational context linked to Turkey. This listing type categorizes the organization based on its documented relationship to a ransomware incident involving Barracuda. The description maintains neutrality regarding specific incident details, avoiding assumptions about data stolen, ransom demands, or breach confirmation. It serves as a factual catalog entry reflecting the entity's status in cyber threat intelligence records. i2i-systems.com was listed as a ransomware victim associated with Barracuda. |
||||||
| Ransomware | i2i-systems id32793 View details | Türkiye | IT | pending | ||
|
This is one of the most poorly secured companies we have ever encountered. Over the course of a week, we analyzed the infrastructure and moved freely across their network. The infrastructure lacked proper security configurations, and the IT department showed a complete disregard for the data. As a result of the attack, 693 gigabytes of data were exfiltrated. We downloaded the complete source code for the following projects: Caplan DataGov-Dev-Docker DDR DDR-Veriskop DFE-Dev Kangal-Dev SDD-DEV-DOCKER SDD-MAIN commonprojects.zip Copycat.zip CopycatLive.zip datacat.war datagov.war Kangal-Dev.zip Kangal-Master.zip [email protected] smartdq.war The volume of exfiltrated source code totaled 44 gigabytes. The data includes a full snapshot of the latest releases from the development repository. i2i-systems has a direct connection to the information security company Veriskop; therefore, this breach directly affects them as well. In addition, i2i-systems engaged in joint projects with partners such as Vodafone, Etiya, Bouygues, Freedom Mobile, and others; this is evidenced by the Linux servers located within the i2i-systems infrastructure: 1864654005 backup_Veriskop-SQA1.local_2026-08-31_203808.tar.gz 3292962897 copycat2019.i2isystems.local_critical_backup_2026-08-31_19-30-29.tar.gz 18422354 critical_backup_bouygues_fcbs_batch2.local_20260830_221815.tar.gz 2231188487 etiya-mobile-test-01.local_backup_20260831_213207.tar.gz 20546323810 freedom-mobile1-critical-vault.tar.gz 1050673952 freedom-mobile2-secrets-20260830-232814.tar.gz 721661 maya-redhat7-9_2026-08-30_233036.tar.gz 22966288270 ol8-10-innobi_full_backup_20260831_022640.tar.gz 529695763 veriskop-db-critical-backup-2026-08-31_234418.tar.gz 13012999372 veriskop-fiziksel-yedek-20260831023535.tar.gz 309528511 veriskop-oracle-critical-backup-2026-08-31_203340.tar.gz 633604141 veriskop-rhel-7.local_critical_backup.tar.gz 4878999722 Veriskoptest01.local_backup_20260831_213236.tar.gz 238487575 Veriskoptest02.local_critical_backup_20260831_213052.tar.gz 33936543608 veriskoptest03_critical_backup_2026-08-31.tar.gz We have extracted absolutely all critical data from these infrastructure Linux systems and created a snapshot of the databases. In addition, i2i-systems recently launched a joint project with Turk Telekom—we have downloaded the database containing all their customers. The data will be published soon... | Severity: HIGH | Size: 643 GB | Status: selling | 300000$ |
||||||
| Ransomware | Skyline Implants & Periodontics id32035 View details | United States | Services | deleted | ||
|
skylineperio.com operates within the Services sector based in the United States, providing professional and technical services to clients. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim linked to the Barracuda threat actor. The listing reflects observed security events associated with this organization without disclosing specific breach details, data exfiltration specifics, or financial impact. This entry serves to document the relationship between skylineperio.com and Barracuda within cybersecurity threat reporting frameworks, aiding defenders in contextualizing potential risks. The description adheres strictly to verified index associations and avoids speculation regarding incident mechanics or outcomes. |
||||||
| Ransomware | Skyline Implants & Periodontics id32035 View details | United States | Services | deleted | ||
|
Full personal and servers files dumps from Skyline Implants & Periodontics company. The data files contain: medical documents of patients (including MRI scans of various parts of the body — files with the .dcm extension), personal photos, and the personal data of the doctor, Scott Ferguson, as well as documents from the company Skyline Implants & Periodontics — in particular, information on equipment and pharmaceutical procurement and other related materials. | Severity: HIGH | Size: 800 GB | Status: free | FREE |
||||||
| Ransomware | Namyang Industrial Co., Ltd. id32036 View details | Korea, Republic of | IT | leaked | ||
|
n yi.co.kr operates within the IT sector and is located in South Korea. The entity functions as a digital organization providing technology-focused services, aligning with its classification within cybersecurity threat indexing frameworks. As a ransomware victim, n yi.co.kr is documented within this threat-intelligence index due to its association with the Barracuda threat actor. This listing reflects the entity's position in incident records without disclosing unverified technical details, data specifics, or financial impact. The entry serves to catalog the relationship between the organization and the identified threat actor for analytical and defensive reference purposes. |
||||||
| Ransomware | Namyang Industrial Co., Ltd. id32036 View details | Korea, Republic of | IT | leaked | ||
|
Selling fresh full database dumps of company Namyang Industrial Co., Ltd. (renamed to Namyang Nexmo). Infrastructure dump, not website! There information about employers, manufacturing, parts, clients, partners and etc. Total lines (csv format): 17 641 181. | Severity: HIGH | Size: 2.51 GB | Status: free | FREE |
||||||
| Ransomware | Clinical Associates of the Finger Lakes (CAFL) id32037 View details | United States | Healthcare / Pharma | pending | ||
|
clinassoc.com operates within the United States healthcare and medicine sector, providing clinical association and related healthcare services. As a healthcare organization, it handles sensitive patient and operational information, making it a relevant target within threat-intelligence monitoring frameworks. This listing identifies clinassoc.com as a ransomware victim associated with Barracuda, reflecting the entity's inclusion in cybersecurity intelligence records tied to this threat actor. The description remains factual and neutral, avoiding invented details regarding breach scope, data impact, ransom terms, or confirmed incident specifics. The record serves as a structured catalog entry for threat-intelligence analysis and sector-focused risk monitoring. |
||||||
| Ransomware | Clinical Associates of the Finger Lakes (CAFL) id32037 View details | United States | Healthcare / Pharma | pending | ||
|
The company mishandled its clients' and employees' data, which is why it was leaked. We extracted all files and documents from the infrastructure. These documents included children's medical records, personal information of parents and employees, a full dump of all emails from the mail server, and much more. Target website: https://www.clinassoc.com/ | Severity: HIGH | Size: 447 GB | Status: selling | $1000 |
||||||
| Ransomware | VR Advogados id31727 View details | Brazil | Finance / Legal / Insurance | pending | ||
|
VR Advogados is a law firm based in Brazil, operating in the finance and legal sector, providing a range of services to clients. As a legal services provider, VR Advogados likely handles sensitive client information. VR Advogados was listed as a ransomware victim associated with Barracuda |
||||||
| Ransomware | VR Advogados id31727 View details | Brazil | Finance / Legal / Insurance | pending | ||
|
VR Advogados, a Brazilian law firm, neglected its clients’ personal data, violating laws regarding data storage and confidentiality—they posted and shared all of their clients’ documents, passport information, and powers of attorney via a Discord server. We hacked it. Now we have 3,000 documents belonging to all of their clients—passports, powers of attorney, declarations, personal and work-related correspondence, and more. The firm hasn’t responded to us for three days; if this continues, we’ll start selling the data. | Status: upcoming | Size: 10 GB | Starts at $30000.00 |
||||||
| Ransomware | Ferrell \ Skyline Implants & Periodontics \ Dr. Scott Ferguson id31366 View details | United States | Healthcare / Pharma | deleted | ||
|
Ferrell Skyline Implants & Periodontics, led by Dr. Scott Ferguson, is a US-based healthcare and medicine provider specializing in implants and periodontics. The practice offers various dental services, catering to patients in the US. Ferrell Skyline Implants & Periodontics operates within the healthcare sector, providing medical services to its patients. It was listed as a ransomware victim associated with Barracuda. |
||||||
| Ransomware | Ferrell \ Skyline Implants & Periodontics \ Dr. Scott Ferguson id31366 View details | United States | Healthcare / Pharma | deleted | ||
|
Full personal and servers files dumps from Skyline Implants & Periodontics company. The data files contain: medical documents of patients (including MRI scans of various parts of the body — files with the .dcm extension), personal photos, and the personal data of the doctor, Scott Ferguson, as well as documents from the company Skyline Implants & Periodontics — in particular, information on equipment and pharmaceutical procurement and other related materials. | Status: free | Size: 800 GB | Now free |
||||||
| Ransomware | Micro-Comm Inc. id31353 View details | United States | IT | leaked | ||
|
Micro-comm.com is an IT company based in the US, offering various services within the information technology sector. As a US-based entity, micro-comm.com operates within the IT industry, providing services to its clients. Micro-comm.com was listed as a ransomware victim associated with Barracuda. |
||||||
| Ransomware | Micro-Comm Inc. id31353 View details | United States | IT | leaked | ||
|
Micro-Comm, Inc. is an industrial automation company based in Olathe, Kansas, that provides water and wastewater control systems, manufacturing control panels, micro-controllers, and SCADA software. [http://www.micro-comm-inc.com]. Tree of all files: https://www.filemail.com/d/vpqdvykqwssupsw. Files count: 894 963, documents type: maps, schemes, personal employers information, personal citizens information, work photos, emails, partners personal information | Status: selling | Size: 643 GB | Starting at $30000.00 |
||||||
| Ransomware | Namyang Industrial Co., Ltd. \ NAMYANG NEXMO id31354 View details | Korea, Republic of | Telecommunications | leaked | ||
|
Nynexmo.com is a telecommunications company based in Korea, offering various services in the sector. The company operates in the telecommunications industry, providing essential services. Nynexmo.com was listed as a ransomware victim associated with Barracuda |
||||||
| Ransomware | Namyang Industrial Co., Ltd. \ NAMYANG NEXMO id31354 View details | Korea, Republic of | Telecommunications | leaked | ||
|
Selling fresh full database dumps of company Namyang Industrial Co., Ltd. (renamed to Namyang Nexmo). Infrastructure dump, not website! There information about employers, manufacturing, parts, clients, partners and etc. Total lines (csv format): 17 641 181. | Status: selling | Size: 2.51 GB | Starting at $40000.00 |
||||||
| Ransomware | RS Automation Co., Ltd. id31355 View details | China | Manufacturing / Engineering | pending | ||
|
Cable-peeler.com is a company operating in the manufacturing and engineering sector, based in China. The company likely provides products or services related to cable peeling, a process used in various industrial applications. Cable-peeler.com was listed as a ransomware victim associated with Barracuda |
||||||
| Ransomware | RS Automation Co., Ltd. id31355 View details | China | Manufacturing / Engineering | pending | ||
|
Full dump of all files from the servers and developers personal files and NAS. Legal documents, letters, drawings, assembly, C, and C++ source codes. Official manufacturer website: rsautomation.co.kr | Status: upcoming | Size: 637 GB | Starts at $50000.00 |
||||||