Ransomware Group intelligence
Dark Project
ActiveTrack Dark Project with 38 published victims and 1 known leak locations in a single intelligence view.
Overview
Dark Project is tracked by Breach House as a ransomware group with 38 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | darkprn3d3udnhpuxknsrhft3376lrz5tenhgkrxge5hxqe46pkbrwid.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (38)
Search, filter and paginate the victim timeline for Dark Project. Showing 1–38 of 38.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Long-Lewis Automotive Group id31290 View details | United States | Retail / E-commerce | ||
|
Longlewis.com is a US-based company operating in the retail and e-commerce sector, offering various products and services to its customers. As an e-commerce platform, it provides a range of shopping options, likely including automotive and other retail products. Longlewis.com was listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | Long-Lewis Automotive Group id31290 View details | United States | Retail / E-commerce | ||
|
About Long-Lewis Automotive Group The Long-Lewis Auto Group is Alabama’s largest automotive retailer, with origins tracing back to a hardware store founded in Bessemer, Alabama, in 1887. It became one of the nation's very first Ford dealerships in 1915 and operates multiple dealerships across the state. Following a successful cyberattack on Long Lewis, more than 500 GB of confidential information was stolen. More than 15,000 records containing personal data of the organization’s customers and employees, important financial and banking documents, and other valuable company information were compromised. Currently, Long Lewis lost control of more than 650,000 files. |
|||||
| Ransomware | The Metropolitan Entertainment & Convention Authority id31252 View details | United States | NGOs / Associations | ||
|
Omahameca.org is a non-governmental organization based in the United States, operating in the sector of NGOs and associations. The organization likely provides various services and support to its community. Omahameca.org was listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | The Metropolitan Entertainment & Convention Authority id31252 View details | United States | NGOs / Associations | ||
|
About MECA Omaha MECA is a organization that manages public event venues in Omaha, Nebraska, including the CHI Health Center, Charles Schwab Field, and The RiverFront. Established in 2000, it plays a crucial role in hosting world-class events and fostering community engagement through its facilities. As a result of a successful cyberattack on the company, MECA suffered damage; more than 500 GB of confidential information was stolen, specifically the company’s customer data, important financial documents, and the personal data of the organization’s employees. About 100 000 files are not secured by domain for now. Download here: http://667k2ck7qlzoqt52i6dq7evcfzko2ezfrhgv6zziccjet2cc653kvbid.onion/ |
|||||
| Ransomware | Laurel Institutes id31254 View details | United States | Education | ||
|
Laurel University, located in the United States, is an educational institution providing various academic programs. As part of the education sector, it offers courses and services to students. Laurel University was listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | Laurel Institutes id31254 View details | United States | Education | ||
|
About Laurel Institutes Laurel Institutes offers focused education and professional certifications across various fields, including business, healthcare, trades, cosmetology, and culinary arts. The institution emphasizes hands-on training and small class sizes to foster student engagement and skill development. Their programs are designed to prepare students for successful careers in industries they are passionate about. With multiple campuses and online options, Laurel Institutes aims to connect students with local employers and provide resources for career advancement. A "Laurel Institutes" company suffered a cyberattack that led to the theft of approximately 50+ GB of sensitive data. Exposed files include financial confidential papers, bank records and medical personal information. Personal data of more than 1,000 students and staff members was leaked Download here: http://tjaaioz32salcoj63ttxra6nfqggwbcezkzpwnhyoiwq5tuimzmsb3qd.onion |
|||||
| Ransomware | Ohio Living Home Health & Hospice id31257 View details | United States | Healthcare / Medicine | ||
|
Ohio Living is a not-for-profit healthcare organization based in the United States, providing a range of services including senior living communities, home health, and hospice care. The organization operates in the state of Ohio, offering various healthcare and medical services to its community. Ohio Living was listed as a ransomware victim associated with Dark Project |
|||||
| Ransomware | Ohio Living Home Health & Hospice id31257 View details | United States | Healthcare / Medicine | ||
|
About Ohio Living Founded in 1922, Ohio Living is an experienced not-for-profit provider of life plan communities and services in Ohio. Due to cyberattack at least 600Gb of sensitive data leaked in "Ohio Living Home Health & Hospice" in April 2026. It known that at least 5000 files with personal data were stolen, among whole it contained employee records, driver licenses, patient personal documents including photos, medical records, social security numbers, insurance information, also files with confidential company financial information and bank records covering period for 2022-2026. Download here: http://3i5px2hibsyityv6jixnqba35yz25jekbwwumjdxjqzt3euqsygjx5id.onion/ |
|||||
| Ransomware | Labpharma id31259 View details | Mexico | Healthcare / Pharma | ||
|
Labpharmacorp.com operates in the healthcare and pharmaceutical sector, providing services in Mexico. The company is involved in various activities related to pharmaceuticals and healthcare. Labpharmacorp.com was listed as a ransomware victim associated with Dark Project |
|||||
| Ransomware | Labpharma id31259 View details | Mexico | Healthcare / Pharma | ||
|
Labpharmacorp Labpharma is a Clinical Laboratory in Miami dedicated to delivering dependable, high-quality laboratory services for clinical trials and research. About Labpharma Labpharma is a laboratory data company supporting clinical research trials. Company offers Local and Central Laboratory testing and data management. Standard Services: Laboratory Manual (electronic and hardcopy), kit production, door to door shipping (IATA certified), research trained and certified (CGP certified), while testing menu includes the following disciplines: Hematology, Clinical Chemistry, Immunochemistry, Infectious Disease, Hemostasis, and Toxicology. From end to end all samples are barcode, tracked and managed to ensure reliable laboratory services for research studies. Download here: http://t2ru74fbgut26xnagtrl4ajeh5vqytrl6cpr6cubmr6sqdxk5guh5mqd.onion/ |
|||||
| Ransomware | Ruhrpumpen id31261 View details | Germany | Manufacturing / Engineering | ||
|
Ruhrpumpen is a German-based company operating in the manufacturing and engineering sector, specializing in the design and production of pumps and related systems. The company offers a range of products and services to various industries, including oil and gas, power generation, and water treatment. Ruhrpumpen is headquartered in Germany and serves a global customer base. It was listed as a ransomware victim associated with Dark Project |
|||||
| Ransomware | Ruhrpumpen id31261 View details | Germany | Manufacturing / Engineering | ||
|
About Ruhrpumpen Ruhrpumpen is a leading global manufacturer of highly engineered centrifugal and reciprocating pumps. A sophisticated cyberattack in the company's network led to a massive data breach. As a result of the incident, approximately 1 TB of data was leaked, including confidential personal and financial information. |
|||||
| Ransomware | Thermo King id31263 View details | United States | Manufacturing / Engineering | ||
|
Thermo King is a leading manufacturer of temperature control systems for the transportation industry, based in the United States. The company provides a range of products and services to the manufacturing and engineering sectors. Thermo King was listed as a ransomware victim associated with Dark Project |
|||||
| Ransomware | Thermo King id31263 View details | United States | Manufacturing / Engineering | ||
|
Due to cyberattack on Genesis more than 70 Gb of company data was stolen. Leakage contains big amount of sensitive data such as company's customers data, bank and financial information documents. About 10 000 files are not secured by THERMO KING for now. Download here: http://wjcml4mxpcvsmjxm33zhjb46nzutxk6g3f5w23fopgpwj6pqjcidiyqd.onion |
|||||
| Ransomware | Storer Transportation and Storer Coachways id31265 View details | United States | Transportation / Travel / Logistics | ||
|
Storerbus is a transportation company based in the United States, operating in the sector of Transportation, Travel, and Logistics. The company provides various services related to bus transportation. Storerbus was listed as a ransomware victim associated with Dark Project |
|||||
| Ransomware | Storer Transportation and Storer Coachways id31265 View details | United States | Transportation / Travel / Logistics | ||
|
The company "Storer Transportation" and "Storer Coachways" was attacked, resulting in the theft of more than 50,000 folders (240+ GB) of the company’s confidential information, including more than 1,500 pieces of employee personal data, financial and banking documents, credit card information and a large amount of confidential incident data. Download here: http://pokttabd2hod47ladeeoin22wmq4remyo3wshwvxfuhgqygcbezq2qqd.onion |
|||||
| Ransomware | Genesis Engineering Group id31267 View details | United States | Manufacturing / Engineering | ||
|
Genesis Engineering Group is a US-based company operating in the manufacturing and engineering sector, providing various services and products to its clients. As a key player in its industry, the company focuses on delivering innovative solutions. Genesis Engineering Group was listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | Genesis Engineering Group id31267 View details | United States | Manufacturing / Engineering | ||
|
Due to cyberattack on Genesis more than 75Gb of company personal data was stolen. Leakage contains big amount of sensitive data such as personal emlpoyes documents, company's customers data, bank and financial information documents. About 50 000 files are not secured by Genesis for now. Download here: http://x2jz63qemhcbhyskzt3pie757oicdkctk2rh5dpykmxsw2yoayeqs5yd.onion/ |
|||||
| Ransomware | Mayco International id31269 View details | United States | Finance / Legal / Insurance | ||
|
Maycoin International is a financial services company based in the US, operating in the finance, legal, and insurance sectors. The company provides various financial solutions to its clients. Maycoin International was listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | Mayco International id31269 View details | United States | Finance / Legal / Insurance | ||
|
About Mayco International At least 2Tb of sensitive data were exfiltrated from the company’s control following a cyberattack. The compromised dataset leaked from Mayco internatioins company infrastructure includes internal organizational documents, proprietary technical schemas, employee personally identifiable information, and a substantial volume of financial records. |
|||||
| Ransomware | Sutherland Packaging id31271 View details | United Kingdom | Manufacturing / Engineering | ||
|
Sutherland Packaging is a company based in the United Kingdom, operating in the manufacturing and engineering sector. The company likely provides packaging solutions to various industries. Sutherland Packaging was listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | Sutherland Packaging id31271 View details | United Kingdom | Manufacturing / Engineering | ||
|
About SPI Sutherland Packaging LLC is a leading manufacturer specializing in creative digitally printed full-color point-of-purchase displays for brands worldwide. The company offers a range of services including digital printing, retail packaging, and turnkey fulfillment, focusing on delivering custom-blended solutions that meet client demands. With over 50 years of experience, Sutherland Packaging is trusted by global brands for its high-quality and cost-effective solutions. Due to cyberattack on Sutherland Packaging more than "200" Gb of company data was stolen. Leakage contains big amount of sensitive data such as company's customers data, bank and financial information documents. About 250 000 files are not secured by Sutherland Packaging for now. |
|||||
| Ransomware | Brainhunter Companies LLC. and Brainhunter Systems Ltd. id31273 View details | United States | IT | ||
|
Brainhunter is an IT company based in the US, offering various services. The company operates in the information technology sector, providing solutions to its clients. Brainhunter was listed as a ransomware victim associated with Dark Project |
|||||
| Ransomware | Brainhunter Companies LLC. and Brainhunter Systems Ltd. id31273 View details | United States | IT | ||
|
About Brainhunter Companies LLC. and Brainhunter Systems Ltd. Founded in 1995, Brainhunter is an employment agency providing staffing and recruiting services to engineers, information technology, healthcare, and industrial sectors. Brainhunter also offers workplace management products, solutions and consulting, payroll and compliance services, and more. Brainhunter is headquartered in Toronto, Ontario. As a result of the attack on Brainhunter, more than 160 GB of the company's confidential data was stolen, including banking and financial documents, as well as the personal data of employees and customers. At this time, approximately 320,000 files remain unprotected by Brainhunter Foundation. |
|||||
| Ransomware | Leviton id31275 View details | United States | Manufacturing / Engineering | ||
|
Leviton is a US-based company operating in the manufacturing and engineering sector, offering a range of products and solutions. The company is headquartered in the United States and provides various electrical and networking components. Leviton was listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | Leviton id31275 View details | United States | Manufacturing / Engineering | ||
|
About Leviton Founded in 1906 and headquartered in Melville, New York, Leviton is a privately held global provider of electrical wiring devices, data center connectivity solutions, and lighting energy management systems. A major cyber attack has resulted in the Leviton company losing control over its entire repository of sensitive data, totaling approximately 1.4 terabytes. The massive breach exposed a wide range of highly confidential information, including internal financial records, proprietary project schematics and working documents, as well as the personal data of employees. Additionally, a significant quantity of other unclassified but highly sensitive information was exfiltrated in the breach, painting a stark picture of a total system compromise. |
|||||
| Ransomware | The Family Medicine Clinic id31277 View details | United States | Healthcare / Medicine | ||
|
Family Medicine Clinic New Iberia is a healthcare provider based in the US, offering medical services to patients in the region. As a healthcare provider, the clinic is likely to handle sensitive patient information. It was listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | The Family Medicine Clinic id31277 View details | United States | Healthcare / Medicine | ||
|
About FMC The Family Medicine Clinic (Louisiana) suffered a serious cyberattack, which resulted in the encryption of a vast data archive and left the company without access to its own online systems. The leak of more then 250Gb FMC medical data encompasses a wide range of document types, including patient registration forms, lab test results, treatment plans, prescription records, and personal insurance information. In addition, employee personnel files were leaked, along with the full names, home addresses, and Social Security numbers of hundreds of customers. Download here: http://x4emye5homuwkrvrfaoql53hc5spbazkvcw3m4pv6jaj5tjqmjizleqd.onion |
|||||
| Ransomware | Rocky Mount Recyclers id31279 View details | United States | Other | ||
|
Rmrnc.com is an online presence in the other sector, operating in the United States. The entity provides various offerings, although specific details are not readily available. Rmrnc.com was listed as a ransomware victim associated with Dark Project |
|||||
| Ransomware | Rocky Mount Recyclers id31279 View details | United States | Other | ||
|
Due to cyberattack on Rocky Mount Recyclers more than 40Gb of company personal data was stolen. Leakage contains big amount of sensitive data such as personal emlpoyes documents, company's customers data, bank and financial information documents. About 12,000 files are not secured by RMR for now. Download here: http://2zl5qc3mqap7vziqfis65oyjcgdiedigoequxbqsn6uwian7ieozvoqd.onion/ |
|||||
| Ransomware | The Miller Group id31281 View details | United Kingdom | Construction / Real Estate | ||
|
Miller Group is a construction and real estate company based in the United Kingdom, operating in the sector of construction and property development. The company offers various services including construction, property development, and management. Miller Group is listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | The Miller Group id31281 View details | United Kingdom | Construction / Real Estate | ||
|
About The Miller Group The Miller Group refers to The Miller Group - Multiplex Division, a retail display manufacturer with operations spanning Dupo, Illinois and Richmond, Virginia As a result of the cyberattack, the company lost control of 500 GB of confidential data, including: employees’ Social Security numbers, email addresses, home addresses, and ZIP codes—plain Excel spreadsheets; financial documents in PDF format—budgets, transactions, and internal reports; complete project drawings—working diagrams and perspective sketches. |
|||||
| Ransomware | TSC Logistics id31283 View details | Philippines | Transportation / Travel / Logistics | ||
|
TSC Logistics is a logistics and transportation services provider based in the Philippines, offering a range of services to support the movement of goods. The company operates within the transportation and logistics sector, catering to various industries. TSC Logistics was listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | TSC Logistics id31283 View details | Philippines | Transportation / Travel / Logistics | ||
|
About TSC Logistics TSC Logistics specializes in providing advanced transportation solutions that prioritize speed and cost-effectiveness for their clients. A cyberattack has resulted in the exfiltration of nearly 600 gigabytes of highly sensitive data, exposing a vast trove of internal records. The compromised material includes personal employee documents, confidential company financial records, invoices, taxpayer statements, and extensive client information. More than 10,000 PDF files have been leaked, containing unredacted Social Security numbers, driver’s licenses, payroll records, and other protected identifiers, raising the spectre of widespread identity theft and regulatory scrutiny. |
|||||
| Ransomware | Reid Electric Service, Inc id31285 View details | United States | Construction / Real Estate | ||
|
Reidelectricservice.com is a company operating in the construction and real estate sector in the United States. The company likely provides electrical services, given its name. Reidelectricservice.com was listed as a ransomware victim associated with Dark Project |
|||||
| Ransomware | Reid Electric Service, Inc id31285 View details | United States | Construction / Real Estate | ||
|
About Reid Electric Service, Inc At Reid Electric Service, Inc. we realize the safety, and reliability of your electrical system is important to you. We take pride in exceeding your expectations to perform work on your electrical system on time, safely and on budget. Reid Electric Service, Inc has suffered a cyberattack on its service systems, resulting in the theft of approximately 50 GB of sensitive data. The breached information includes employees' personal data and detailed architectural plans of clients' buildings. |
|||||
| Ransomware | Mile Bluff Medical Center id31286 View details | United States | Healthcare / Medicine | ||
|
Mile Bluff is a healthcare provider based in the United States, offering medical services to patients. As a part of the healthcare sector, Mile Bluff plays a crucial role in providing medical care and support. Mile Bluff was listed as a ransomware victim associated with Dark Project. |
|||||
| Ransomware | Mile Bluff Medical Center id31286 View details | United States | Healthcare / Medicine | ||
|
About Mile Bluff Medical Center Located in Mauston, Wisconsin, Mile Bluff Medical center has been in operation since 1912. Its services include acute emergency care, as well as long term nursing and rehabilitation A "Mile Bluff Medical Center" company suffered a cyberattack leading to the theft of over 550 GB of sensitive data. Exposed files include a full SQL database backup, employee records, confidential company financial information, bank records, patients' personal documents, Social Security numbers, medical records, medical histories, and surgical records. As a result, the personal data of more than 25,000 patients and staff members was leaked. Download here: http://7iphetz64a7iihcpwr3nirjioghyt6lrku62gu4z7f3zo7rcz5qrgvad.onion/ |
|||||