Ransomware Group intelligence
BrainCipher
ActiveTrack BrainCipher with 95 published victims and 8 known leak locations in a single intelligence view.
Overview
BrainCipher is tracked by Breach House as a ransomware group with 95 published victims.
United States is currently the most targeted country in this dataset.
8 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (8)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 3h ago | vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion |
| Leak location 6 | Onion service | Down checked 3h ago | 77nrxelcwh47yikvpaz2rvtsten4sen2elybo5r5st6wlxsbitv255qd.onion |
| Leak location 8 | Onion service | Down checked 3h ago | p6wmotxzvg34tdmpwm4beqgrcyp5iys43snkccsahnw74la3k3xx6pad.onion |
| Leak location 7 | Onion service | Down checked 3h ago | cuuhrxbg52c5agytmtjpwfu7mrs4xtaitc4mukkiy2kqdxeqbcmuhaid.onion |
| Leak location 5 | Onion service | Down checked 3h ago | 4ldgw2wuidqu5ef3rzx4byonf3y7rdnh43jiw2z4sbtjiwic6gkov7yd.onion |
| Leak location 4 | Onion service | Down checked 3h ago | zktnif5vckhmz5tyrukp5bamatbfhkxjnb23rspsanyzywcrx3bvtqad.onion |
| Leak location 3 | Onion service | Down checked 3h ago | brain4zoadgr6clxecixffvxjsw43cflyprnpfeak72nfh664kqqriyd.onion |
| Leak location 2 | Onion service | Down checked 3h ago | mybmtbgd7aprdnw2ekxht5qap5daam2wch25coqerrq2zdioanob34ad.onion |
Top Activity Sectors (13)
- Not identified 14
- Services 12
- Manufacturing / Engineering 12
- IT 10
- Finance / Legal / Insurance 7
- Communication / Marketing 7
- Healthcare / Pharma 6
- Construction / Real Estate 3
- Transportation / Travel / Logistics 2
- Retail / E-commerce 2
- Agriculture / Food 1
- Public Sector 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue BrainCipher, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: BrainCipher executes PowerShell scripts to stage payloads, disable defenses, and propagate across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: BrainCipher leverages registry run keys and startup folders to maintain persistence after reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: BrainCipher disables antivirus tools and security processes to prevent detection and ensure encryption completes successfully.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: BrainCipher inserts junk code into its malware binaries to evade static analysis and signature-based detection.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: BrainCipher deletes Volume Shadow Copies and backup files via system commands to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: BrainCipher uses network share discovery to locate victim file shares and identify high-value directories for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: BrainCipher moves laterally through SMB/Windows Admin Shares to compromise additional hosts within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: BrainCipher exfiltrates stolen data over C2 channels before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: BrainCipher encrypts victim files using its ransomware payload, targeting business documents and backups to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: BrainCipher calls system recovery inhibitors to block restore processes and harden its impact phase.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
[id].README_2.txt
ATTENTION: YOUR DATA HAS BEEN LOCKED! Dear representatives of the company, We are compelled to inform you that your information system has been successfully breached by our group. All your data, including financial reports, customer databases, internal documentation, correspondence, and even backup files, have been encrypted using state-of-the-art cryptographic algorithms. Without our unique decryption key, restoring access to this data is impossible. We strongly advise against attempting to resolve this issue independently, as any such attempts may result in irreversible data loss. Your company is now in an extremely vulnerable position. Disclosure or destruction of the data may lead to serious consequences, including: Financial losses: Leakage of confidential information can result in lawsuits, fines, and compensation claims. Moreover, your competitors may exploit this data to gain an unfair advantage in the market. Reputational damage: Loss of trust from clients and partners may negatively impact your business. News of the cyberattack will spread quickly, and your brand may become associated with unreliability and an inability to protect data. Legal consequences: Violation of data protection laws (e.g., GDPR, CCPA, or other regional regulations) may lead to significant fines and audits by regulatory authorities. This may also necessitate a mandatory restructuring of your data processing procedures. Operational issues: Lack of access to critical systems may lead to a complete halt in your company�s operations. This could affect not only you but also your customers, partners, and suppliers. ADDITIONAL RISKS AND THREATS: Legal consequences for company leadership: If we decide to disclose the data, it may lead to criminal charges against your company�s management for negligence and violation of data protection rules. You personally may be held accountable, and your career could be at risk. Media and public opinion: We collaborate with various media outlets and are ready to provide them with part of your data for public exposure. Information about your inability to protect data will become public knowledge, leading to further reputational damage. Mass lawsuits from clients and partners: We have prepared anonymous instructions for your clients and partners affected by the leak. These instructions will help them file class-action lawsuits against your company. We understand the importance of the stolen information for your organization. Currently, all data is in our possession. We are ready to discuss the terms of transferring the decryption key and guarantee the complete deletion of all copied data after receiving payment. We also offer an alternative: ignoring this message will either lead to the public leakage of data through our special portal on the Dark Web or result in its complete destruction. *** Brain Cipher Leaks: http://vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion/ *** PLEASE NOTE: Any contact with law enforcement agencies or data recovery companies will be considered a violation of our agreement. If we discover that you are collaborating with third parties, this will immediately lead to the following actions: Key deletion: all decryption keys will be irrevocably deleted. Public leak: We will release part of the data on public resources to ensure maximum reputational damage. Increased recovery cost: The price for decryption will double, and the timeframe for providing the key will be extended. Legal consequences for leadership: We will pass information about your collaboration with law enforcement to the media and regulatory bodies, leading to additional legal and reputational problems. We understand that this is a difficult situation and would like to offer you a way to resolve it. For this purpose, we provide clear instructions for data recovery. Please note that time is limited. If we do not receive a response within 72 hours, the cost of recovery will increase, and the likelihood of data preservation will significantly decrease. WHY YOU SHOULD CONTACT US DIRECTLY? Guaranteed security: We guarantee the complete deletion of all data copies after receiving payment. Professional approach: We use cutting-edge technologies to ensure reliable encryption and decryption of data. Confidentiality: Our communication channels are fully anonymous, and we do not share information with third parties. Flexibility: We are ready to discuss payment terms and provide additional time for decision-making. No risks: Cooperation with us is the only way to avoid a public data leak and irreversible data loss. Protection from legal consequences: We will ensure that information about your company does not fall into the hands of law enforcement or the media if you meet our requirements. ======================================== To contact us, follow these instructions: 1.Download and install Tor Browser (https://www.torproject.org/download/) 2.Go to our support page: http://braincgksuixxkpkme7zlpkh7u47oryxx574d74ws4eal4t2mxyahbqd.onion (This page can take up to 30 minutes to load.) 3.Enter your encryption ID: [snip] We will provide further instructions on payment and data recovery. After confirming payment, we will transfer a unique decryption key that will allow you to restore access to all your files. We strongly recommend acting quickly and professionally! Any delays or attempts to ignore this message may lead to irreversible consequences. We are ready to cooperate and ensure a secure resolution to this issue. Email to support: [email protected] Welcome to BrainCipher!
How To Restore Your Files.txt
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\Welcome to Brain Cipher Ransomware!\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\Dear managers!\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\If you're reading this, it means your systems have been hacked and encrypted and your data stolen.\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\The most proper way to safely recover your data is through our support. We can recover your systems within 4-6 hours.\\\\\\ \\\\\\\\\\\\\In order for it to be successful, you must follow a few points:\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\1.Don't go to the police, etc.\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\\2.Do not attempt to recover data on your own.\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\\\3.Do not take the help of third-party data recovery companies.\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\\\\\\\\\In most cases, they are scammers who will pay us a ransom and take a % for themselves.\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\\\\\\If you violate any 1 of these points, we will refuse to cooperate with you!!!\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ \\ \\ ATTENTION!!! If you do not contact us within 48 hours, we will post the record on our website: \\ \\ \\ http://vkvsgl7lhipjirmz6j5ubp3w3bwvxgcdbpi3fsbqngfynetqtw4w5hyd.onion/ \\ \\ \\ \\ 3 steps to data recovery: \\ \\ \\ 1. Download and install Tor Browser (https://www.torproject.org/download/) \\ \\ 2. Go to our support page: http://mybmtbgd7aprdnw2ekxht5qap5daam2wch25coqerrq2zdioanob34ad.onion \\ ******* This page can take up to 30 minutes to load. \\ \\ 3. Enter your encryption ID: [snip] \\ \\ \\ Email to support: [email protected] \\ \\ \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ _ _ | | (_) | |__ _ __ __ _ _ _ __ | '_ \| '__/ _` | | '_ \ | |_) | | | (_| | | | | | |_.__/|_| \__,_|_|_| |_| ,--""-. (_,=- ) `---#{ `}
[id].README.txt
***
Welcome to Brain Cipher Ransomware!
***
Dear managers!
If you're reading this, it means your systems have been hacked and encrypted and your data stolen.
***
The most proper way to safely recover your data is through our support. We can recover your systems within 4-6 hours.
In order for it to be successful, you must follow a few points:
1.Don't go to the police, etc.
2.Do not attempt to recover data on your own.
3.Do not take the help of third-party data recovery companies.
In most cases, they are scammers who will pay us a ransom and take a for themselves.
***
If you violate any 1 of these points, we will refuse to cooperate with you!!!
3 steps to data recovery:
1. Download and install Tor Browser (https://www.torproject.org/download/)
2. Go to our support page: http://mybmtbgd7aprdnw2ekxht5qap5daam2wch25coqerrq2zdioanob34ad.onion
3. Enter your encryption ID: [snip]
Email to support: [email protected]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (95)
Search, filter and paginate the victim timeline for BrainCipher. Showing 1–95 of 95.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | icot.es id32358 View details | Spain | IT | ||
|
icot.es is an entity operating within the IT sector located in Spain. The platform serves as a threat-intelligence index entity, cataloging cybersecurity incidents and associated actors across sectors and geographies. Within this catalog, icot.es is classified as a ransomware victim, with its listing connected to threat actor BrainCipher. This designation reflects its inclusion in intelligence records documenting ransomware-related activity and its geographic and sectoral context. The entry provides neutral, factual context for threat-intelligence analysis and monitoring. |
|||||
| Ransomware | icot.es id32358 View details | Spain | IT | ||
|
[AI generated] N/A |
|||||
| Ransomware | aeiconsultants.com id32359 View details | United States | Services | ||
|
aeiconsultants.com operates within the Services sector and is headquartered in the United States, providing professional consulting and advisory services. The entity is cataloged within this threat-intelligence index as a ransomware victim linked to the threat actor BrainCipher. This listing reflects the organization's inclusion in verified cyber incident records tied to this specific adversary group. The description maintains neutrality regarding incident details, focusing solely on the entity's sector, geographic presence, and its association with the indexed threat actor. Users of this catalog can reference this entry for situational awareness regarding ransomware activity in the Services sector within the US. |
|||||
| Ransomware | aeiconsultants.com id32359 View details | United States | Services | ||
|
[AI generated] N/A |
|||||
| Ransomware | syc.es id32360 View details | Spain | Finance / Legal / Insurance | ||
|
syc.es operates within the Finance, Legal, and Insurance sectors and is situated in Spain. The entity is documented in this threat-intelligence index specifically as a ransomware victim associated with the threat actor BrainCipher. Its classification reflects the sector-relevant exposure profile observed in the indexed intelligence record. This entry provides neutral context regarding the entity's operational domain and its documented relationship to the specified threat actor without disclosing unverified incident details. The listing type underscores its status within the ransomware victim category of this intelligence catalog. |
|||||
| Ransomware | syc.es id32360 View details | Spain | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | Adviesbureau De Beuckelaer BV id32361 View details | Netherlands | Services | ||
|
Adviesbureau De Beuckelaer BV operates within the Services sector and is headquartered in the Netherlands. The organization provides advisory and professional services, contributing to its classification within service-oriented industries that are frequently targeted by cyber threats. This listing type identifies the entity as a ransomware victim associated with the threat actor BrainCipher. The entry reflects the threat-intelligence index's documentation of this specific incident relationship without disclosing unverified technical details or confirmed breach specifics. The association underscores the ongoing cybersecurity risks faced by service sector organizations in European markets. |
|||||
| Ransomware | Adviesbureau De Beuckelaer BV id32361 View details | Netherlands | Services | ||
|
[AI generated] N/A |
|||||
| Ransomware | ahadandco.com id32362 View details | United Arab Emirates | Services | ||
|
ahadandco.com operates within the Services sector and is located in the United Arab Emirates. The entity provides professional services aligned with its geographic and industry positioning. According to the threat-intelligence index, ahadandco.com has been formally listed as a ransomware victim linked to the threat actor BrainCipher. This classification reflects aggregated cyber-threat intelligence data without confirming specific incident details such as data exfiltration scope or operational impact. The listing serves to inform stakeholders about associated security risks within this sector and region. |
|||||
| Ransomware | ahadandco.com id32362 View details | United Arab Emirates | Services | ||
|
[AI generated] N/A |
|||||
| Ransomware | sago.com id32363 View details | United States | IT | ||
|
sago.com operates within the IT sector and is situated in the United States, providing technology-focused services and solutions to clients. The entity is formally listed within the threat-intelligence index as a ransomware victim associated with the threat actor BrainCipher. This classification reflects the cybersecurity context in which the organization was identified. No specific incident details, such as breach confirmation, data theft specifics, or financial impact, are included per strict factual guidelines. The listing serves to document the relationship between sago.com and BrainCipher for threat monitoring and intelligence purposes. |
|||||
| Ransomware | sago.com id32363 View details | United States | IT | ||
|
[AI generated] Sago is a market research and insights company headquartered in the United States. It specializes in connecting brands and researchers with qualified participants for qualitative and quantitative research studies, including focus groups, online surveys, and in-depth interviews. Formerly known as Schlesinger Group, Sago serves clients across various industries seeking consumer and professional insights to inform business decisions. |
|||||
| Ransomware | crmeyer.com id32364 View details | Germany | Services | ||
|
crmeyer.com operates within the Services sector and is based in Germany. The entity represents a business organization whose infrastructure was impacted by a ransomware attack linked to the threat actor BrainCipher. This listing type identifies crmeyer.com within the threat-intelligence index as a ransomware victim connected to this specific adversary group. The description focuses on the entity's sector, geographic origin, and its documented association with the threat actor without elaborating on unverified technical details or incident specifics. This catalog entry provides neutral context for threat researchers and security professionals monitoring adversary activity across sectors. |
|||||
| Ransomware | crmeyer.com id32364 View details | Germany | Services | ||
|
[AI generated] N/A |
|||||
| Ransomware | ccsperfusion.com id32365 View details | United States | Healthcare / Pharma | ||
|
CCS Perfusion.com operates within the United States healthcare and medicine sector, providing services aligned with clinical and medical workflows. The entity is cataloged in the threat-intelligence index under the ransomware victim listing type, associated with the threat actor BrainCipher. This designation contextualizes its exposure within a cyber threat landscape affecting healthcare organizations. The description avoids speculative details regarding data, impact metrics, or confirmed breach specifics, maintaining strict neutrality and factual accuracy consistent with threat-intelligence documentation standards. |
|||||
| Ransomware | ccsperfusion.com id32365 View details | United States | Healthcare / Pharma | ||
|
[AI generated] CCS Perfusion is a US-based company operating in the medical and healthcare industry, specializing in perfusion services and cardiovascular surgery support. The company provides clinical perfusion professionals who operate heart-lung bypass machines during open-heart surgeries. It serves hospitals and surgical centers, ensuring patient safety during cardiopulmonary bypass procedures. The company operates within the United States healthcare sector. |
|||||
| Ransomware | windiam.com id30757 View details | IT | |||
|
Windiam.com operates within the IT sector, providing various services. The company is based in the United States. Windiam.com was listed as a ransomware victim associated with BrainCipher. |
|||||
| Ransomware | windiam.com id30757 View details | IT | |||
|
[AI generated] N/A |
|||||
| Ransomware | windiam.com id30757 View details | Belgium | IT | ||
|
[AI generated] N/A |
|||||
| Ransomware | robroy.com id30380 View details | United States | Manufacturing / Engineering | ||
|
Robroy.com is a US-based company operating in the manufacturing and engineering sector, providing various products and services. The company is involved in the design, manufacture, and supply of electrical and electronic components. Robroy.com was listed as a ransomware victim associated with BrainCipher |
|||||
| Ransomware | robroy.com id30380 View details | United States | Manufacturing / Engineering | ||
|
[AI generated] Rob Roy Industries, operating through robroy.com, is a US-based manufacturer specializing in electrical conduit systems and enclosures. The company produces PVC-coated steel conduit, fiberglass conduit, and industrial enclosures used in corrosive and hazardous environments. Headquartered in Verona, Pennsylvania, Rob Roy serves industries such as oil and gas, chemical processing, wastewater treatment, and utilities, providing durable electrical protection solutions across North America. |
|||||
| Ransomware | iac-intl.com id30381 View details | United States | Manufacturing / Engineering | ||
|
IAC Intl operates in the manufacturing and engineering sector, providing services in the United States. The company's expertise lies in its ability to deliver innovative solutions to its clients. IAC Intl was listed as a ransomware victim associated with BrainCipher |
|||||
| Ransomware | iac-intl.com id30381 View details | United States | Manufacturing / Engineering | ||
|
[AI generated] N/A |
|||||
| Ransomware | digitaldynamics.com id30160 View details | United States | IT | ||
|
Digitaldynamics.com is an IT company based in the United States, providing various IT services. The company operates in the IT sector, offering services to clients. Digitaldynamics.com was listed as a ransomware victim associated with BrainCipher |
|||||
| Ransomware | digitaldynamics.com id30160 View details | United States | IT | ||
|
[AI generated] N/A |
|||||
| Ransomware | goldenstateortho.com id30161 View details | United States | Healthcare / Pharma | ||
|
Goldenstateortho.com is a healthcare service provider based in the United States, specializing in orthopedic care. The company offers various medical services to patients in need of orthopedic treatment. Goldenstateortho.com was listed as a ransomware victim associated with BrainCipher. |
|||||
| Ransomware | goldenstateortho.com id30161 View details | United States | Healthcare / Pharma | ||
|
[AI generated] Golden State Ortho appears to be an orthopedic medical practice or orthopedic supply company based in the United States, likely California given the "Golden State" reference. It operates in the healthcare industry, potentially offering orthopedic surgical services, prosthetics, orthotics, or related medical products and patient care. Specific verified details about this company are limited, so full operational details cannot be confirmed with certainty. |
|||||
| Ransomware | printronix.com id30162 View details | United States | Manufacturing / Engineering | ||
|
Printronix is a US-based company operating in the manufacturing and engineering sector, offering various products and services. The company is involved in the design, manufacture, and distribution of industrial printing solutions. Printronix was listed as a ransomware victim associated with BrainCipher |
|||||
| Ransomware | printronix.com id30162 View details | United States | Manufacturing / Engineering | ||
|
[AI generated] Printronix is a US-based company specializing in industrial printing solutions. Founded in 1974 and headquartered in Irvine, California, it manufactures line matrix printers, thermal printers, and related accessories primarily for enterprise and industrial environments. Its products serve industries such as manufacturing, logistics, and supply chain management, offering high-volume, mission-critical printing capabilities used in warehouses and distribution centers worldwide. |
|||||
| Ransomware | paipharma.com id30136 View details | Brazil | Healthcare / Pharma | ||
|
Paipharma.com operates in the healthcare and pharmaceutical sector, providing services in Brazil. The company's offerings cater to the needs of the Brazilian healthcare market. Paipharma.com was listed as a ransomware victim associated with BrainCipher |
|||||
| Ransomware | paipharma.com id30136 View details | Brazil | Healthcare / Pharma | ||
|
[AI generated] N/A |
|||||
| Ransomware | eggetttax.ca id30099 View details | Canada | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | sterlinggloballtd.com id30100 View details | United Kingdom | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | themintgaming.com id30005 View details | IT | |||
|
[AI generated] N/A |
|||||
| Ransomware | alu-rex.com id29918 View details | Austria | Manufacturing / Engineering | ||
|
[AI generated] Alu-Rex is a Canadian company specializing in the manufacturing of gutter protection systems and accessories. Based in Quebec, Canada, the company produces aluminum-based products designed to prevent debris from clogging eavestroughs. Their product lines include continuous hanger systems and gutter guards primarily marketed to roofing and eavestrough installation professionals across North America. |
|||||
| Ransomware | anglomoil.com id29923 View details | United Kingdom | — | ||
|
[AI generated] Anglomoil is an Australian company specialising in the manufacture and supply of lubricants and associated products. Operating in the industrial and automotive lubricant sector, it serves mining, transport, agriculture, and general industry markets. Headquartered in Australia, the company produces engine oils, greases, hydraulic fluids, and specialty lubricants, distributing products nationally and to select international markets. |
|||||
| Ransomware | squamish.net id29543 View details | Canada | IT | ||
|
[AI generated] squamish.net appears to be an internet service provider and telecommunications company operating in Squamish, British Columbia, Canada. It offers broadband internet connectivity and related services to residential and business customers in the Squamish region. The company serves as a local ISP, providing connectivity solutions to the Sea-to-Sky Corridor area of British Columbia, positioning itself within the Canadian telecommunications and internet services industry. |
|||||
| Ransomware | sheppadviser.com.au id29304 View details | Australia | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | ice.org.uk id29062 View details | United Kingdom | Construction / Real Estate | ||
|
[AI generated] ICE, the Institution of Civil Engineers, is a UK-based professional membership organisation founded in 1818. It supports civil engineers worldwide through qualifications, knowledge sharing, policy influence, and professional development. Headquartered in London, it operates across infrastructure, construction, and engineering sectors. ICE sets industry standards, accredits engineering programmes, and advocates for sustainable infrastructure development globally. |
|||||
| Ransomware | flbgroup.com id28382 View details | United Kingdom | Manufacturing / Engineering | ||
|
[AI generated] N/A |
|||||
| Ransomware | kisnet.co.jp id28383 View details | Japan | IT | ||
|
[AI generated] Kisnet Co., Ltd. is a Japanese internet service provider based in Japan. The company offers broadband and network connectivity services primarily to residential and business customers. Operating within the telecommunications and ISP industry, Kisnet provides internet access solutions in the Japanese market. The company is part of Japan's regional ISP sector, delivering reliable network infrastructure and related services to its subscriber base. |
|||||
| Ransomware | nwlr.ca id28384 View details | Canada | Transportation / Travel / Logistics | ||
|
[AI generated] N/A |
|||||
| Ransomware | liteline.com id28385 View details | United States | Manufacturing / Engineering | ||
|
[AI generated] Liteline is a Canadian lighting manufacturer and distributor based in Ontario, Canada. The company specializes in designing and supplying innovative LED lighting solutions for residential and commercial applications. Its product portfolio includes recessed lighting, track lighting, and decorative fixtures. Liteline is known for combining energy-efficient technology with modern design, serving contractors, architects, and consumers across North America through various retail and wholesale channels. |
|||||
| Ransomware | westonconsulting.com id28386 View details | United States | Construction / Real Estate | ||
|
[AI generated] N/A |
|||||
| Ransomware | exceldor.ca id28387 View details | Canada | Agriculture / Food | ||
|
[AI generated] Exceldor is a Canadian agricultural cooperative specializing in poultry production and processing. headquartered in Quebec, Canada, the company produces and distributes chicken and turkey products under various brands. It operates processing facilities across Quebec and Ontario, supplying retail, foodservice, and industrial customers throughout Canada. Exceldor is one of the largest poultry cooperatives in the country, known for its focus on quality and sustainable farming practices. |
|||||
| Ransomware | soundinsurance.ca id28388 View details | Canada | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | endeavourautomotive.co.uk id28389 View details | United Kingdom | Retail / E-commerce | ||
|
[AI generated] Endeavour Automotive is a UK-based car dealership group operating across England. The company sells new and used vehicles from multiple mainstream and premium brands, including Ford, Nissan, and others. It also provides vehicle servicing, parts, and aftersales support. Operating within the automotive retail industry, Endeavour Automotive runs several dealership locations primarily in the south and east of England. |
|||||
| Ransomware | eworldme.com id28390 View details | United Arab Emirates | IT | ||
|
[AI generated] N/A |
|||||
| Ransomware | bridgeway-consulting.co.uk id28391 View details | United Kingdom | Transportation / Travel / Logistics | ||
|
[AI generated] N/A |
|||||
| Ransomware | fsbgroup.ca id23495 View details | Canada | Services | ||
|
[AI generated] N/A |
|||||
| Ransomware | semag.fr id23494 View details | France | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | axxia.fr id23493 View details | France | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | oxfordcounty.ca id23238 View details | Canada | Public Sector | ||
|
[AI generated] Oxford County represents the best of both worlds: urban communities full of life, entertainment, and commerce; and rural areas that are rich in natural resources, history, and farming communities. Located in the heart of Southwestern Ontario, it is home to several thriving communities. As a municipality, its mission is to provide public services that enhance the quality of life for its citizens. |
|||||
| Ransomware | cdom.org id23237 View details | United States | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | bmsi.org id22432 View details | United States | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | bw-lv.de id21518 View details | Germany | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | VIRTUALWEB.US id21409 View details | United States | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | jorgefernandez.es id21369 View details | Spain | Communication / Marketing | ||
|
[AI generated] "Jorgefernandez.es" is a Spain-based company engaged in the distribution of home improvement materials and tools. Their vast catalog includes supplies for plumbing, heating, electrical, lumber, and tools. They cater to individual consumers and also supply to professional building and construction businesses. In addition to product sales, they provide customer service and support. |
|||||
| Ransomware | Pulmonary Physicians of South Florida Clinics | Data security breach! id19736 View details | United States | Healthcare / Pharma | ||
|
Pulmonary Physicians of South Florida Clinics is a healthcare group in South Florida offering Pulmonary, Critical Care, and Sleep Medicine services across Miami-Dade, Broward, and Monroe counties. The organization provides state-of-the-art diagnosis and treatment for lung diseases, along with accredited Sleep Disorder Diagnostic Centers for conditions like Obstructive Sleep Apnea. It operates in multiple hospitals throughout the region, serving patients with experienced and highly qualified physicians. The clinic was listed as a ransomware victim associated with the threat actor BrainCipher, as discovered by Ransomware.live on May 5, 2025. |
|||||
| Ransomware | Pulmonary Physicians of South Florida Clinics id19739 View details | United States | Healthcare / Pharma | ||
|
[AI generated] N/A |
|||||
| Ransomware | neatem.fr | Update! id19735 View details | France | Other | ||
|
neatem.fr is the website of Neatem, an information services company based in Croissy-Beaubourg, Île-de-France, France. Company profiles describe Neatem as providing IT infrastructure, support services, system security, cloud hosting, and related technical engineering services. Its stated activity also includes engineering and technical studies in computing, alongside services in the information technology domain. In threat-intelligence records, neatem.fr was listed as a ransomware victim associated with BrainCipher. |
|||||
| Ransomware | neatem.fr id19738 View details | France | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | mbmdubai.com id19734 View details | United Arab Emirates | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | ddecor.com id19733 View details | India | IT | ||
|
[AI generated] D'Decor is a leading home decor company known for its innovative and stylish range of home furnishings. Originating from India, it's recognized globally for curtains, upholfurniture fabrics, bed and bath linen. D'Decor aims to blend traditional craftsmanship with innovative technology, offering an extensive collection of designs to cater to a wide variety of tastes. |
|||||
| Ransomware | ruizre.es id19732 View details | Spain | Construction / Real Estate | ||
|
[AI generated] Ruizre.es is a real estate company based in Valencia, Spain that specializes in property rentals and sales. They provide a variety of services including assessment, property management, purchase and sale of properties, rental management, and property investment consultation. They pride themselves in helping their clients navigate the complex real estate market with ease. |
|||||
| Ransomware | soundtransit.org id19731 View details | United States | Communication / Marketing | ||
|
[AI generated] Sound Transit, operating under the domain "soundtransit.org", is a mass transit agency serving the Seattle, Washington, USA, metropolitan area. Founded in 1996, it offers public transit services including bus, light rail, and commuter rail services throughout King, Pierce, and Snohomish counties. Its major transportation systems include Link Light Rail, Sounder Commuter Rail, and ST Express buses. |
|||||
| Ransomware | valedolobo.com id19730 View details | Portugal | Hospitality / Food & Beverage / Tourism | ||
|
[AI generated] "Valedolobo.com" is the online platform for the Vale do Lobo resort located in Portugal's Algarve region. Specializing in luxury experiences, it features multiple leisure facilities including two 18-hole golf courses, a wellness center, and various restaurants. It offers properties for sale or rent for vacation purposes, making it a premier destination for tourists. |
|||||
| Ransomware | edisoft.es id19729 View details | Spain | Services | ||
|
[AI generated] Edisoft is a Spanish technological company specializing in development and implementation of software systems for businesses. They offer solutions in areas such as ERP (Enterprise Resource Planning), CRM (Customer Relationship Management), business intelligence, and eCommerce. They also provide IT consulting, training, and ongoing technical support for clients. Their goal is to help businesses improve their efficiency and productivity through innovative technology solutions. |
|||||
| Ransomware | iycsa.com.co id19728 View details | Colombia | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Rhode Island Department of Humain Services id16290 View details | United States | Services | ||
|
Provides support and resources for health, financial aid, and social services in Rhode Island. |
|||||
| Ransomware | Modern Dental Group Limited id16157 View details | Hong Kong | Healthcare / Pharma | ||
|
[AI generated] Modern Dental Group Limited is a global dental service provider headquartered in Hong Kong. The company specializes in the production and distribution of dental prosthetic devices and related services. It operates a network of facilities across multiple countries, offering products like crowns, bridges, and orthodontic devices to dental professionals, emphasizing quality and innovation. |
|||||
| Ransomware | Estar Seguros, S.A. id16002 View details | Mexico | Communication / Marketing | ||
|
[AI generated] Estar Seguros, S.A. is an insurance company that specializes in providing a range of insurance products and services. It focuses on offering tailored solutions to meet the diverse needs of its clients, including auto, home, and life insurance. The company is known for its customer-centric approach, competitive pricing, and reliable coverage options, aiming to deliver peace of mind and financial protection. |
|||||
| Ransomware | Cristal y Lavisa S.A. de C.V. id16001 View details | Mexico | Communication / Marketing | ||
|
[AI generated] Cristal y Lavisa S.A. de C.V. is a Mexican company specializing in the production and distribution of glass products. Known for its high-quality glassware, the company serves various industries, including construction, automotive, and consumer goods. With a focus on innovation and customer satisfaction, Cristal y Lavisa has established a strong presence in the domestic and international markets. |
|||||
| Ransomware | Deloitte UK id15858 View details | United Kingdom | Services | ||
|
[AI generated] Deloitte UK is a leading professional services firm, part of the global Deloitte network. It offers audit, consulting, financial advisory, risk management, and tax services across various industries. Known for its expertise and innovation, Deloitte UK helps clients solve complex business challenges. It emphasizes diversity, inclusion, and sustainability in its operations and corporate culture. |
|||||
| Ransomware | Royce Corporation id15810 View details | United States | Manufacturing / Engineering | ||
|
[AI generated] Royce Corporation is a global trading company specializing in the distribution and marketing of industrial raw materials and chemicals. The company serves a diverse range of industries, including metallurgy, electronics, and energy. Known for its strong supply chain management and strategic partnerships, Royce Corporation aims to deliver quality products and services to meet the evolving needs of its clients worldwide. |
|||||
| Ransomware | G-ONE AUTO PARTS DE MÉXICO, S.A. DE C.V. id15797 View details | Mexico | Manufacturing / Engineering | ||
|
[AI generated] G-ONE Auto Parts de México, S.A. de C.V. is a company based in Mexico specializing in the distribution and sale of automotive parts. It caters to a wide range of vehicles, providing high-quality components and accessories to meet the needs of both individual customers and businesses. The company is known for its commitment to customer satisfaction and reliable service within the automotive industry. |
|||||
| Ransomware | COOPERATIVA TELEFONICA DE CALAFATE LTD. id15290 View details | Argentina | Communication / Marketing | ||
|
[AI generated] COOPERATIVA TELEFONICA DE CALAFATE LTD. is a telecommunications cooperative based in El Calafate, Argentina. It provides a range of services including telephony, internet, and other communication solutions to the local community. As a cooperative, it operates with a focus on member needs and community development, emphasizing service quality and accessibility. |
|||||
| Ransomware | G-One Auto Parts de México S.A. de C.V. id15289 View details | Mexico | Manufacturing / Engineering | ||
|
[AI generated] G-One Auto Parts de México S.A. de C.V. is a Mexican company specializing in the distribution and sale of automotive parts. It focuses on providing high-quality components for various vehicle makes and models, serving both retail and wholesale markets. The company is known for its customer-centric approach, competitive pricing, and extensive inventory, catering to the needs of automotive professionals and enthusiasts alike. |
|||||
| Ransomware | Berridge Manufacturing Co. id15033 View details | United States | Manufacturing / Engineering | ||
|
[IA generated] Berridge Manufacturing Co. specializes in the production of high-quality metal roofing and siding products. Established in 1970, the company is known for its innovative design and engineering, offering a wide range of metal panels, architectural products, and portable roll-forming machines. Berridge is committed to sustainability and provides solutions for both residential and commercial applications. |
|||||
| Ransomware | K&S Tool & Mfg Co. id15030 View details | United States | Services | ||
|
[IA generated] K&S Tool & Mfg Co. is a company specializing in precision manufacturing and tooling services. They offer a range of services including CNC machining, custom tool making, and engineering support. Known for high-quality craftsmanship and reliability, K&S serves various industries by providing tailored solutions that meet specific client needs. Their commitment to innovation ensures they stay at the forefront of manufacturing technology. |
|||||
| Ransomware | Basilio Advogados id15029 View details | Brazil | Finance / Legal / Insurance | ||
|
[IA generated] Basilio Advogados is a prominent law firm based in Brazil, known for its expertise in various legal areas including corporate law, litigation, and arbitration. The firm is recognized for delivering high-quality legal services with a focus on client needs and strategic solutions. Its team of experienced lawyers is committed to providing personalized and effective legal advice to both domestic and international clients. |
|||||
| Ransomware | CHRISTODOULOS G. VASSILIADES & CO. LLC id15028 View details | Cyprus | Finance / Legal / Insurance | ||
|
[IA generated] CHRISTODOULOS G. VASSILIADES & CO. LLC is a prominent law firm based in Cyprus, specializing in corporate and commercial law. The firm offers a wide range of services, including legal consultancy for international business transactions, tax planning, intellectual property, and dispute resolution. Known for its expertise and client-focused approach, the firm serves a diverse clientele, including multinational corporations and individuals. |
|||||
| Ransomware | hanwa.co.th id14409 View details | Thailand | Manufacturing / Engineering | ||
|
Hanwa Co., Ltd. (Thailand) is a subsidiary of Hanwa Co., Ltd., a Japan-based global trading company. Established to expand Hanwa’s operations in Southeast Asia, this firm specializes in trading a diverse range of products including steel, metals, food, petroleum, and chemicals. Leveraging its parent company's extensive network, Hanwa Thailand aims to provide comprehensive trading solutions and foster strong business relationships in the region. |
|||||
| Ransomware | rmn.fr id14045 View details | France | Communication / Marketing | ||
|
Réunion des Musées Nationaux-Grand Palais (RMN-GP) is a French cultural institution dedicated to managing and promoting national museums and monuments. It organizes exhibitions, publishes art books, and oversees museum shops and cafes. RMN-GP plays a crucial role in preserving and showcasing France's cultural heritage to a global audience. |
|||||
| Ransomware | ghanare.com id14043 View details | Ghana | Communication / Marketing | ||
|
Ghanare.com is an online platform dedicated to providing comprehensive real estate services in Ghana. It connects buyers, sellers, and renters with property listings, including residential, commercial, and land options. The platform aims to simplify the property search process, offering detailed property information, images, and contact details to facilitate seamless transactions. |
|||||
| Ransomware | beinlaw.co.il - Prof. Bein & Co. id13934 View details | Israel | Finance / Legal / Insurance | ||
|
Prof. Bein & Co., accessible via beinlaw.co.il, is a reputable law firm based in Israel. It specializes in various legal fields, offering expert services in commercial law, real estate, litigation, and intellectual property. The firm is known for its professional approach, experienced team, and commitment to providing tailored legal solutions to meet the unique needs of its clients. |
|||||
| Ransomware | tiendasmacuto.com id13869 View details | Venezuela, Bolivarian Republic of | Retail / E-commerce | ||
|
Tiendasmacuto.com is an online retail store specializing in outdoor and adventure gear. They offer a wide range of products including backpacks, tents, sleeping bags, and hiking accessories. The company focuses on high-quality, durable items suitable for camping, trekking, and other outdoor activities. Customer service and satisfaction are key priorities, ensuring a reliable shopping experience. |
|||||
| Ransomware | fabamaq.com id13794 View details | Argentina | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | cyceron.fr id13793 View details | France | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Sherbrooke Metals id13464 View details | United States | Manufacturing / Engineering | ||
|
No additional victim description available. |
|||||
| Ransomware | Apex Global | Big leak outlooks - 2tb. id13463 View details | Netherlands | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Cole Technologies Group id13462 View details | United States | IT | ||
|
No additional victim description available. |
|||||
| Ransomware | Family Wealth Advisors Ltd. id13461 View details | Israel | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Mars 2 LLC id13460 View details | United States | Services | ||
|
No additional victim description available. |
|||||
| Ransomware | Indonesia Terkoneksi id13220 View details | Indonesia | Other | ||
|
More important than money, only honor. |
|||||