Ransomware Group intelligence
Ddosecret
ActiveTrack Ddosecret with 397 published victims and 4 known leak locations in a single intelligence view.
Overview
Ddosecret is tracked by Breach House as a ransomware group with 397 published victims.
Israel is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 47 14.6%
- Pending 276 85.4%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Web location | Up checked 2h ago | data.ddosecrets.org |
| Leak location 3 | Web location | Up checked 2h ago | ddosecrets.org |
| Leak location 2 | Web location | Down checked 2h ago | ddosecrets.com |
| Leak location 1 | Web location | Down checked 2h ago | https://data.ddosecrets.com/ |
Top Activity Sectors (15)
- Not identified 231
- Public Sector 18
- Communication / Marketing 14
- Services 11
- Finance / Legal / Insurance 10
- Energy 7
- Telecommunications 3
- Manufacturing / Engineering 3
- IT 3
- Education 3
- NGOs / Associations 3
- Retail / E-commerce 2
- Hospitality / Food & Beverage / Tourism 1
- Transportation / Travel / Logistics 1
- Construction / Real Estate 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Ddosecret, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: ddosecret uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: ddosecret modifies Windows Registry Run keys to ensure ransomware execution upon system reboot.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: ddosecret disables antivirus tools and security software to prevent detection and hinder system recovery efforts.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: ddosecret deletes Volume Shadow Copies and backup files to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: ddosecret performs remote system discovery to map the victim network and identify high-value targets.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: ddosecret scans network shares to identify victim file structures and target directories for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: ddosecret exploits SMB/Windows Admin Shares to move laterally between networked victim machines.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: ddosecret exfiltrates victim data via encrypted C2 channels before demanding payment for decryption keys.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: ddosecret encrypts victim files using custom ransomware binaries, locking data for extortion demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: ddosecret invokes system recovery inhibition commands to prevent automatic restoration from backups.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (397)
Search, filter and paginate the victim timeline for Ddosecret. Showing 201–300 of 397.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Roskomnadzor idlhLRc5rV5kWE View details | Other | pending | |||
|
Roskomnadzor is the Russian federal executive authority for supervision of communications, information technology, and mass media. Based in Moscow, it oversees telecommunications, electronic media, mass communications, personal data compliance, and related licensing and regulatory functions. The agency also plays a central role in enforcing internet-content controls and coordinating radio-frequency administration in Russia. In threat-intelligence catalogs, Roskomnadzor is tracked as a public-sector target under the broader other category. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | RKPLaw id1zcaxdDidrXl View details | Finance / Legal / Insurance | pending | |||
|
RKPLaw is a U.S.-based legal services firm serving the Finance, Legal, and Insurance sectors, with a business profile centered on professional legal support for clients in regulated industries. Publicly available industry references indicate that firms in this space commonly provide transactional, regulatory, and advisory services to insurers, policyholders, and related financial clients. RKPLaw was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | quiborax id5XpXrNZhNhQq View details | Other | pending | |||
|
Quiborax is a Chile-based industrial and minerals company that operates in the production and supply of boron-related products and other mineral-derived materials for commercial and industrial use. It is positioned in the broader natural-resources and materials space, with operations tied to Chile’s mining sector and export-oriented supply chains. In threat-intelligence catalogs, Quiborax is referenced as a ransomware victim entry rather than as a confirmed incident disclosure. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | PWC idM9mB4Q7SpPkq View details | Other | pending | |||
|
PwC, or PricewaterhouseCoopers, is a British multinational professional services network headquartered in London, England. It operates in more than 150 countries and serves clients through audit, tax, advisory, consulting, and related business services. The firm maintains a broad global office footprint and works across sectors including finance, technology, healthcare, energy, and public services. In threat-intelligence indexing, PwC is listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Public Chamber of the Krasnoyarsk idQ6s2nQQavOZI View details | Public Sector | pending | |||
|
The Public Chamber of the Krasnoyarsk Krai is a consultative civil society institution within the public sector of Russia, operating in the Krasnoyarsk Territory to analyze draft legislation and monitor government activities. It serves as an oversight body with consultative powers, helping citizens interact with government officials and local authorities to protect their rights and exercise public control over executive authorities. The chamber systematically participates in monitoring regional bills of high social significance and conducts public examination of local legislation. It was listed as a ransomware victim associated with the threat actor ddosecret. |
||||||
| Ransomware | PT Rea Kaltim Plantations and Group idc80ocEygCSKO View details | Services | pending | |||
|
PT REA Kaltim Plantations and Group is the Indonesian operating arm of R.E.A. Holdings plc, based in East Kalimantan with offices in Balikpapan and Jakarta. The company is engaged in oil-palm cultivation and the production and sale of crude palm oil and palm kernel products, with sustainability and forest-preservation messaging on its corporate site. Public business profiles also place it in the farming and plantations space within Indonesia’s broader services and food-production ecosystem. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | PSCB id1gsbqXljfXI9 View details | Other | pending | |||
|
PSCB is a Pakistan-based entity associated with the country’s software and IT-export ecosystem; the Pakistan Software Export Board is a government-owned body headquartered in Islamabad that promotes the national IT industry and supports IT, IT-enabled services, freelancers, and call centers engaged in exports. Its role includes market promotion and registration support for companies participating in Pakistan’s technology sector through the TechDestination/PSEB portal. In a threat-intelligence context, PSCB is recorded as operating in the Other sector. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Project Whispers idb0EVpjVgYmmr View details | Telecommunications | pending | |||
|
Project Whispers is a telecommunications-sector organization in the United Kingdom, a field that provides communications services such as network access, connectivity, and related infrastructure. Public references do not clearly identify its exact product lineup or operating footprint, so the company should be described conservatively as a telecoms entity rather than with unverified specifics. DDoSecrets, the source associated with the listing, is known for publishing data previously leaked on ransomware sites. Project Whispers was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Project Whispers idb0EVpjVgYmmr View details | Telecommunications | pending | |||
|
Project Whispers is a telecommunications-sector organization in the United Kingdom, a field that provides communications services such as network access, connectivity, and related infrastructure. Public references do not clearly identify its exact product lineup or operating footprint, so the company should be described conservatively as a telecoms entity rather than with unverified specifics. DDoSecrets, the source associated with the listing, is known for publishing data previously leaked on ransomware sites. Project Whispers was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Procuradoria-Geral da Fazenda Nacional idKPvQg7UpZZHi View details | Communication / Marketing | pending | |||
|
A Procuradoria-Geral da Fazenda Nacional (PGFN) is a Brazilian federal body within the Advocacia-Geral da União, headquartered in Brasília, Distrito Federal. It represents the Union in tax matters and handles the judicial and administrative collection of tax and non-tax credits, while also providing legal advice to the Ministry of Finance. The agency offers taxpayer services through the Gov.br portal and the Regularize platform, with regional offices and remote support channels. In threat-intelligence listings, Procuradoria-Geral da Fazenda Nacional was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Private Office of Sheikh Hazza bin Zayed Al Nahyan idluW8nAUT1mid View details | Communication / Marketing | pending | |||
|
Private Office of Sheikh Hazza bin Zayed Al Nahyan is an Abu Dhabi-based office associated with Sheikh Hazza bin Zayed Al Nahyan, the Ruler’s Representative in the Al Ain Region of the Emirate of Abu Dhabi and a senior UAE royal figure. Public references indicate the office operates under the private-office brand in Abu Dhabi and presents services tied to business support, trade promotion, and investment facilitation within the broader communication and marketing context. Its work is positioned around relationship management and public-facing coordination rather than a consumer product business. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Prime Minister of Iraq's Office idqICUkiaJBj8X View details | Communication / Marketing | pending | |||
|
Prime Minister of Iraq's Office is the official media office of Iraq’s prime minister and commander-in-chief, based in Baghdad, where it handles government communication and public messaging. Public profiles describe it as a government administration organization that publishes statements, press materials, and official updates for the Iraqi prime minister’s office. In a threat-intelligence context, it is cataloged under the Communication / Marketing sector because of its public-facing communications role and outreach functions. The entity was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | President Donald Trump's Private Schedules.pdf idhTxJJJHU8ZDL View details | Communication / Marketing | pending | |||
|
President Donald Trump's Private Schedules.pdf is a Communication / Marketing-related item from the United States, presented as a PDF file title that implies private scheduling records associated with Donald Trump. Publicly available reporting in the search results connects Trump-related sensitive data claims to leaked or exposed information involving his security team and administration, rather than to a clearly identified operating company or service offering. In this index context, the entity is treated as a listed record under a threat-intelligence catalog rather than a verified business profile. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | President Donald Trump's Private Schedules.pdf idhTxJJJHU8ZDL View details | Communication / Marketing | pending | |||
|
President Donald Trump's Private Schedules.pdf is a Communication / Marketing-related item from the United States, presented as a PDF file title that implies private scheduling records associated with Donald Trump. Publicly available reporting in the search results connects Trump-related sensitive data claims to leaked or exposed information involving his security team and administration, rather than to a clearly identified operating company or service offering. In this index context, the entity is treated as a listed record under a threat-intelligence catalog rather than a verified business profile. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Port and Railway Projects Service of JSC UMMC id7xBAAyhQuUU6 View details | Transportation / Travel / Logistics | pending | |||
|
Port and Railway Projects Service of JSC UMMC is a transportation and logistics-related entity associated with JSC UMMC in Russia, a market where UMMC operates across industrial and infrastructure-linked businesses. Based on its name, the service is involved in port and railway project support, indicating offerings tied to rail logistics, terminal access, and transport infrastructure coordination. In threat-intelligence catalogs, it appears as a ransomware victim entry within the Transportation / Travel / Logistics sector. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Popov Files idDyRtvg6K1am0 View details | Other | pending | |||
|
Popov Files is identified in threat-intelligence indexes as an entity in the **Other** sector, with no verified public profile available in the provided sources. Based on the name alone, it may refer to an organization, project, or file collection rather than a conventional commercial brand, but the available evidence does not support a more specific description. DDoSecrets has published datasets taken from ransomware leak sites, where attackers had already posted victim material. Popov Files was listed as a ransomware victim associated with **ddosecret**. |
||||||
| Ransomware | Polar Branch of the Russian Federal Research Institute of Fisheries and Oceanography idaMy2pagN6Udj View details | Russian Federation | Education | pending | ||
|
The Polar Branch of the Russian Federal Research Institute of Fisheries and Oceanography, also known as PINRO named after N.M. Knipovich, is a Russian fisheries research institute based in Murmansk, Russia. It operates as part of VNIRO and conducts marine research to support fisheries management, including studies used to estimate allowable catches and assess commercial fish, invertebrates, algae, and marine mammals. The branch is part of the country’s public-sector scientific infrastructure for marine and fisheries science. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Planatol idptbiC0Y9WMLK View details | Other | pending | |||
|
Planatol GmbH is a German manufacturer and supplier of adhesives and application systems, with headquarters in Rohrdorf, Bavaria, Germany. The company describes itself as one of the leading global suppliers of adhesive products and application systems, serving industrial customers since 1932. Public company profiles also place it in the chemical products sector and list its address in Rohrdorf, Germany. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Phoenix Program interviews idOLOzFapUL3Ze View details | Communication / Marketing | pending | |||
|
Phoenix Program interviews is presented as a Communication/Marketing entity in the United States, with publicly available materials tied to Phoenix-based marketing and communications interview guidance and related career content. The name suggests a business or program focused on interview preparation, recruiting, or marketing communications rather than a consumer-facing product, but no authoritative public company profile was available in the search results to confirm a more specific operational description. In this context, the listing type indicates a ransomware victim entry associated with the threat actor ddosecret. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Petroworks idUwRW5ijFIDkM View details | Other | pending | |||
|
Petroworks Oil&Gas Sdn Bhd is a public company headquartered in Petaling Jaya, Selangor, Malaysia, operating within the oil and gas industry since its founding in 2013. The firm provides support activities for oil and gas operations, including drilling services, maintenance, reconditioning, and equipment rental for the oil sector. As a small enterprise with 2-10 employees, it focuses on aftermarket solutions and operational support for the energy industry. Petroworks was listed as a ransomware victim associated with the threat actor ddosecret, underscoring vulnerabilities in the Malaysian energy sector. |
||||||
| Ransomware | Petrofort iduw49K1v9Sfqz View details | Other | pending | |||
|
Petrofort is a company listed in the **Other** sector; public-source search results do not provide a reliable, official company profile with clear details on its exact offerings or operating structure. Based on the name alone, it appears to be a corporate entity rather than an individual, but the available sources do not support a more specific business description without risking invention. The safest factual characterization is therefore limited to its sector classification and the fact that it is identifiable as a company name used in threat-intelligence indexing. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Perceptics idPvJI8T01Yn9M View details | Other | pending | |||
|
Perceptics is a Knoxville, Tennessee-based company in the appliances, electrical, and electronics manufacturing industry, with a focus on vehicle-recognition technology. Its website says it delivers LPR cameras and vehicle recognition software for tolling, border security, and transportation agencies, and company profiles also describe products for commodity tracking and automated tolling. The company presents itself as a provider of software and hardware designed to improve recognition accuracy and operational efficiency. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Patron Papers idmLov5qgmPgQG View details | Other | pending | |||
|
Patron Papers is an entity associated with the library sector, likely involved in patron-driven services or acquisitions based on its name and sector alignment. While specific location and detailed offerings remain unconfirmed in publicly available sources, the organization appears to operate within the Other sector classification. The entity's activities may relate to library patron management or collection development, as suggested by similar industry terms like patron-driven acquisitions. Patron Papers was listed as a ransomware victim associated with the threat actor ddosecret, marking its inclusion in threat-intelligence records regarding cyber incidents. |
||||||
| Ransomware | Patriot Front audio idaamRZDx0H0Ap View details | Other | pending | |||
|
Patriot Front audio is a recorded-audio collection associated with Patriot Front, a U.S.-based neo-Nazi organization with chapters around the country. DDoSecrets describes the material as audio files from Patriot Front's Discord server, and its Patriot Front archive also includes videos, photos, documents, and chat messages from the same organization. The listing falls in the Other sector and reflects publicly shared leaked records rather than a conventional commercial product or service. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Patriot Front idZurM4cspWztV View details | Other | pending | |||
|
Patriot Front is a Texas-based white supremacist organization founded in 2017 by Thomas Ryan Rousseau after the Charlottesville Unite the Right rally. It is active in the United States and is known for propaganda distribution, including flyering, banner drops, stencil campaigns, and vandalism targeting public and private property. Public reporting describes the group as one of the most active white supremacist organizations in the country. In threat-intelligence context, Patriot Front was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Parler idO75yuJC6oFKs View details | Other | leaked | |||
|
Parler is a U.S.-based social media platform that serves creators, brands, and communities with tools for audience engagement and free-expression-focused networking. It has operated from Nevada and Tennessee and was reported in 2024 to be based in Plano, Texas, following ownership changes and a planned relaunch. Parler belongs to the broader alternative social media sector and is positioned as a platform for direct connection and community building. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Parler idO75yuJC6oFKs View details | Other | leaked | |||
|
Parler is a U.S.-based social media platform that serves creators, brands, and communities with tools for audience engagement and free-expression-focused networking. It has operated from Nevada and Tennessee and was reported in 2024 to be based in Plano, Texas, following ownership changes and a planned relaunch. Parler belongs to the broader alternative social media sector and is positioned as a platform for direct connection and community building. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Paramilitary Leaks id4GoZdi8rH7dV View details | Other | leaked | |||
|
Paramilitary Leaks is a leak collection in the Other sector that aggregates material from paramilitary groups and militias, including chat logs, recordings, and related documents. Public reporting on the dataset describes it as part of Distributed Denial of Secrets’ archives, with records spanning U.S. militia activity and internal communications. The material is presented as a searchable disclosure resource rather than an operating business, and its location is identified with the United States in public descriptions. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Paramilitary Leaks id4GoZdi8rH7dV View details | Other | leaked | |||
|
Paramilitary Leaks is a leak collection in the Other sector that aggregates material from paramilitary groups and militias, including chat logs, recordings, and related documents. Public reporting on the dataset describes it as part of Distributed Denial of Secrets’ archives, with records spanning U.S. militia activity and internal communications. The material is presented as a searchable disclosure resource rather than an operating business, and its location is identified with the United States in public descriptions. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | PacoLeaks idba3Lyf8pzpNJ View details | Other | pending | |||
|
PacoLeaks appears in threat-intelligence catalogs as an entity in the **Other** sector, with no reliable public evidence in the provided results describing a specific product, service, or operating location. The name does not map cleanly to a clearly identified company in the search material, so the safest description is a neutral placeholder entry for an indexed victim label rather than a fully profiled business. DDoSecrets is a transparency-focused collective that publishes material previously leaked by ransomware operators, spanning victims across multiple sectors. PacoLeaks was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | OSCE Vienna idBLDDyjnTUvpH View details | Other | pending | |||
|
OSCE Vienna refers to the Secretariat of the Organization for Security and Co-operation in Europe, a multilateral intergovernmental organization headquartered in Vienna, Austria. The OSCE is the world’s largest regional security organization and works on stability, peace, democracy, conflict prevention, and confidence-building across Europe, North America, and Asia. Its Vienna offices support diplomatic, administrative, and operational coordination for the organization. In threat-intelligence catalogs, it was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Oryx Resources idVIY0jDiDArVo View details | Other | pending | |||
|
Oryx Resources Limited is a UK-registered company with a registered office in London, England. Public business profiles for related Oryx entities describe operations in energy-sector infrastructure and adjacent oil, gas, and utilities activities, placing the name within a broader industrial and commercial context. For cataloging purposes, the listing is classified under the **Other** sector because the available public record does not provide a single definitive operating industry for this specific entity. It was listed as a ransomware victim associated with **ddosecret**. |
||||||
| Ransomware | Op Cyber Toufan idTWQBG5ebrueS View details | IT | pending | |||
|
Op Cyber Toufan is an IT-sector organization associated with Israel and appears in cyber threat reporting as part of the broader Cyber Toufan activity set. Public analysis describes Cyber Toufan as a threat actor focused on Israeli organizations, using credential abuse, exposed remote access, lateral movement, and data-leak operations against targeted environments. Available reporting indicates the group has targeted organizations in or linked to Israel, with operations involving unauthorized access and public disclosure of stolen or disrupted data. Op Cyber Toufan was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Office of Industrial Economics, Thailand idg9d6iNTqH6k3 View details | Thailand | Manufacturing / Engineering | pending | ||
|
The Office of Industrial Economics (OIE) is a Thai government agency based in Bangkok that serves as the official compiler of manufacturing sector statistics and industrial production data. It tracks industrial indices and supports policy work on Thailand’s manufacturing and engineering economy, including restructuring priority industries and improving productivity. OIE also publishes sector data covering 75 industrial groups and related industrial trends. In threat-intelligence listings, Office of Industrial Economics, Thailand was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Office of Industrial Economics, Thailand idg9d6iNTqH6k3 View details | Thailand | Manufacturing / Engineering | pending | ||
|
The Office of Industrial Economics (OIE) is a Thai government agency based in Bangkok that serves as the official compiler of manufacturing sector statistics and industrial production data. It tracks industrial indices and supports policy work on Thailand’s manufacturing and engineering economy, including restructuring priority industries and improving productivity. OIE also publishes sector data covering 75 industrial groups and related industrial trends. In threat-intelligence listings, Office of Industrial Economics, Thailand was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | odebrecht id77zCzdKCWZrZ View details | Other | pending | |||
|
Odebrecht S.A., now officially known as Novonor, is a Brazilian multinational conglomerate headquartered in Salvador, Bahia, Brazil. The company specializes in engineering, construction, chemicals, and petrochemicals, with operations spanning the Americas, Caribbean, Africa, Europe, and the Middle East. It has built major infrastructure projects including power plants, railroads, ports, and airports such as Miami International Airport. Odebrecht operates in twenty-eight countries and is active in mining, oil and gas, and agroindustrial sectors. The firm was listed as a ransomware victim associated with the threat actor ddosecret. |
||||||
| Ransomware | Oculus id5k5WKtdsQK3g View details | Other | pending | |||
|
Oculus is a virtual reality brand and enterprise software offering associated with Meta Platforms in the United States, focused on VR headsets, collaboration tools, and business use cases. Its business products have included Oculus for Business and Quest for Business, which were designed to support workplace deployment, device management, and VR collaboration. In public descriptions, Oculus has been presented as part of Meta’s Reality Labs effort to build VR and AR hardware and software. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Oath Keepers id38Vucx0kJU84 View details | Other | pending | |||
|
Oath Keepers is an American far-right anti-government militia group founded in 2009 and associated with extremist political activity. It is based in the United States and is known for recruiting among current and former military and law-enforcement personnel, while operating as an organized activist and paramilitary network. Public reporting describes the group as one of the country’s larger extremist anti-government movements. Oath Keepers was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Nusantara Regas idW1BgpCRnsNp9 View details | United States | Energy | pending | ||
|
Nusantara Regas is a joint venture in the Oil & Energy sector, headquartered in Central Jakarta, Indonesia, that specializes in natural gas services and LNG infrastructure. The company manages the construction and operation of a regasification terminal in West Java, providing gas storage, transportation, procurement, and sales to power plants and other buyers. It operates a Floating Storage Regasification Unit (FSRU) in Jakarta Bay that receives LNG from carriers and regasifies it for delivery. Nusantara Regas is affiliated with PT Pertamina Persero and PT Gas Company Tbk, responsible for operating FSRU assets in the Gulf waters of Jakarta. The company was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Nuclear Power Production and Development Company of Iran idE1A3388a2iT0 View details | Energy | pending | |||
|
Nuclear Power Production and Development Company of Iran is an Iranian state-owned energy company in Tehran that operates within the country’s nuclear-power sector. According to its official profile, it handles the study, construction, safe operation, and electricity sale activities related to nuclear power plants, and it supports research, investment, supervision, and commercial work in nuclear energy. The company is also tied to Iran’s nuclear-fuel cycle and the Bushehr Nuclear Power Plant, reflecting its role in national nuclear development and power generation. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | NSA Report on Russia Spearphishing.pdf idancHUAgCNtWx View details | Russian Federation | Other | pending | ||
|
NSA Report on Russia Spearphishing.pdf is a U.S. National Security Agency report on Russian spearphishing activity, focused on cyber operations against election infrastructure and related targets. The document describes attempts to compromise a voting software supplier and to use that access to target local election officials, placing it in the broad Other sector and in RU-linked reporting context. As a threat-intelligence index entry, it is treated as an entity associated with cyber incident exposure rather than as a commercial offering or service. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | NPO VS id5ACyCFVTJMaW View details | Other | pending | |||
|
NPO VS is a nonprofit organization operating in the Other sector, focused on serving the public good through regional or national initiatives rather than generating profit. As a nonprofit entity, it addresses social, cultural, environmental, or humanitarian issues such as education, health, or poverty alleviation, relying on donations, grants, and membership dues for funding. The organization functions without profit motives, reinvesting surplus income into its mission while maintaining tax-exempt status and accountability to donors and the public. NPO VS was listed as a ransomware victim associated with the threat actor ddosecret. |
||||||
| Ransomware | New Granada Energy Corporation idmYPKnaDXaM9Y View details | Energy | pending | |||
|
New Granada Energy Corporation Sucursal Colombiana is a Colombia-based oil and gas company headquartered in Bogotá, D.C., with operations in the hydrocarbons sector. Public company profiles describe it as an upstream energy business involved in geophysical, geological, and related exploration services for oil and gas, and in producing energy products. As a Colombian energy operator, it appears in industry and contract records connected to exploration and development activity in the country. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Neocom_Geoservice idMNqsFg14ucLU View details | Other | pending | |||
|
Neocom_Geoservice is a business associated with the Other sector in the United States, a broad category that can include non-industrial or cross-sector services. Publicly available source material in this query does not provide enough verified detail to identify its exact offerings, so any narrower description would be speculative. In threat-intelligence listings, the name is used as an entity identifier rather than a confirmed statement about the scope or impact of any incident. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Nauru Police Force idJiej6OBuwN3h View details | Other | pending | |||
|
The Nauru Police Force is the national law enforcement agency of Nauru, operating under the command of the Commissioner of Police to deliver safety and preserve public order. Its duties include taking lawful measures to preserve the peace, prevent crime, and protect property, as defined by the Nauru Police Force Act 1972. The force has launched specialized initiatives to enhance response capabilities for survivors of domestic violence and gender-based offenses. It collaborates with the Australian Federal Police through the Nauru–Australia Policing Partnership to strengthen front-line capabilities and address transnational crime. The Nauru Police Force was listed as a ransomware victim associated with the threat actor ddosecret. |
||||||
| Ransomware | Myanmar_Financials idfA9jPpdYiraT View details | Finance / Legal / Insurance | pending | |||
|
Myanmar_Financials refers to a Myanmar-based financial-sector entity associated with finance, legal, and insurance services in the country’s regulated financial system. Myanmar’s sector includes banks, microfinance, and insurance providers, with reforms expanding oversight and market development under the Central Bank of Myanmar. Public sector references describe the country’s financial services market as including banking and insurance activities, alongside broader legal and regulatory modernization. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Myanmar Investments idadP58WnudYq3 View details | Finance / Legal / Insurance | pending | |||
|
Myanmar Investments operates within the Finance, Legal, and Insurance sectors in Myanmar, providing investment advisory services and facilitating compliance with the country’s investment and insurance regulations. The entity supports both local and foreign investors seeking market access, particularly in the insurance industry, which is governed by the Insurance Business Law of 1996 and related regulatory frameworks. It assists clients in navigating licensing requirements, capital thresholds, and policy obligations under the Myanmar Investment Law. Myanmar Investments was listed as a ransomware victim associated with the threat actor ddosecret. |
||||||
| Ransomware | MVTEC id8U8UWoELVbmd View details | Other | pending | |||
|
MVTec Software GmbH is a German technology company based in Munich that develops hardware-independent software for machine vision. Its products are used across demanding imaging and inspection environments, including semiconductor production, quality control, metrology, medicine, and surveillance. The company operates internationally and maintains regional offices and support locations in Europe, North America, and Asia. In threat-intelligence catalogs, MVTec is listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | MSpy idVKqp6YHmEH4k View details | Other | pending | |||
|
MSpy is a parental control and monitoring software brand that helps users track activity on mobile devices and computers, including location, messages, calls, and app use. Its website describes the service as a way for parents to review a child’s device activity through an online account, and its LinkedIn profile lists its primary location in Edinburgh, Scotland. The company operates in the Other sector and markets subscription-based monitoring tools for iPhone and Android devices. MSpy was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Moustass leaks idvZUAzyshxFFt View details | Other | leaked | |||
|
Moustass leaks is listed in the Other sector and appears in a DDoSecrets publication of materials tied to ransomware leak activity. The record is presented as a leak-related entry rather than a conventional company profile, so its public-facing description centers on the indexed data set rather than on products or services. No verified location or commercial offering is provided in the available source record. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Moustass leaks idvZUAzyshxFFt View details | Other | leaked | |||
|
Moustass leaks is listed in the Other sector and appears in a DDoSecrets publication of materials tied to ransomware leak activity. The record is presented as a leak-related entry rather than a conventional company profile, so its public-facing description centers on the indexed data set rather than on products or services. No verified location or commercial offering is provided in the available source record. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Mosekspertiza idE1NXlF5Z1xLA View details | Other | pending | |||
|
Mosekspertiza appears to be a Russia-based organization in the Other sector, but the available record does not identify its public offerings or operating profile with certainty. Because the name is presented without corroborating business details, the safest description is a neutral catalog entry for an entity in a non-specified sector. In threat-intelligence context, it is indexed as a ransomware victim associated with the ddosecret threat actor. The listing does not, by itself, establish the scope or validity of any compromise, only that Mosekspertiza was associated with ddosecret in the index. |
||||||
| Ransomware | MO Proud Boys videos id2HnfCpTcfSVR View details | Communication / Marketing | pending | |||
|
MO Proud Boys videos is an entity name that suggests media or promotional video activity in the Communication / Marketing sector, but no authoritative public business profile was available in the search results to confirm a precise location or service line. In threat-intelligence catalogs, such names are typically indexed as the identified organization tied to an incident record, even when public-facing operational details are limited. The available results show only that Proud Boys is a far-right extremist group, which is unrelated to any verified corporate description for this listing. The listing was recorded as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | MK Brokers idp3aOD4f7ijc3 View details | Other | pending | |||
|
MK Brokers JSC is a Bulgarian investment company licensed by the Bulgarian Financial Supervision Commission and based in Sofia. It provides access to Bulgarian and international financial markets and offers brokerage services for clients seeking trading and investment support. Public business listings also identify it as a privately held financial services firm operating from 8 Tsar Osvoboditel Blvd. in Sofia. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Ministry of Foreign Affairs of Cambodia idmALLjKbvJUok View details | Public Sector | pending | |||
|
The Ministry of Foreign Affairs and International Cooperation of Cambodia is the country’s public-sector foreign affairs authority, based in Phnom Penh. It represents Cambodia in international relations, manages diplomatic missions abroad, and provides visa services and related consular support. The ministry operates as a central government body serving Cambodia’s external relations and international cooperation priorities. In threat-intelligence listings, it was named as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Ministry of Culture of the Russian Federation idPLWTSVnoHT8U View details | Russian Federation | Public Sector | pending | ||
|
The Ministry of Culture of the Russian Federation is a federal executive body in Moscow, Russia, responsible for national policy and legal regulation in culture, the arts, historical and cultural heritage, cinematography, archives, copyright, and related state services. It also oversees protection of cultural heritage and state supervision in this sphere. As a public sector institution, it serves the cultural administration of the Russian Federation and supports the country’s cultural policy and heritage management. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Ministry of Communications and IT of Azerbaijan idHxiyayQ1xw2J View details | Communication / Marketing | pending | |||
|
The Ministry of Communications and Information Technologies of the Republic of Azerbaijan is a central executive body based in Baku that sets and implements state policy for communications and information technology. It oversees telecommunications, postal services, radio spectrum use, and related regulatory and control functions for state agencies, businesses, and individuals in Azerbaijan. As a government-sector organization, it sits within the country’s communications and IT landscape and supports development and oversight of digital infrastructure and services. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Mining Secrets idr0SinIEnF5T1 View details | Other | pending | |||
|
Mining Secrets appears to be a business in the broad Other sector, with public threat-intelligence references identifying it as a ransomware victim rather than describing a consumer-facing brand or product line. Available reporting does not clearly establish its operating location or commercial offerings, so those details should be treated cautiously until confirmed by first-party sources. In ransomware contexts, victims are often named on leak or disclosure channels after an extortion event involving their systems or data. Mining Secrets was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | MilicoLeaks idDKh2HRlNv7Dy View details | Other | pending | |||
|
MilicoLeaks is indexed as a ransomware-related victim entry in the threat-intelligence record, with its sector classified as Other. Public sources in the search results do not provide enough verified detail to identify its offerings or operating profile with confidence, so no further business description is stated here. The name is preserved as listed for catalog consistency and analyst reference. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Metropolitan Police Department DC idHYjhgiG8kFjb View details | Public Sector | pending | |||
|
Metropolitan Police Department DC is the police agency for Washington, DC, in the United States, and it serves the city as a public sector law enforcement organization. It provides patrol, emergency response, investigations, and community policing services across the District. As a municipal public safety agency, it operates within government service delivery rather than a commercial market. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Metprom Group idFbKCZckIQXln View details | Communication / Marketing | pending | |||
|
Metprom Group is a Russia-based company with an online presence in the communication and marketing sector, and available company materials identify Metprom as a business operating in Russia and abroad. Its public website describes the firm as providing integrated project support for mining and metals companies, while other directory data characterizes Metprom Group as active across EPC, industrial, and related business services. In this catalog, the entity is indexed for cyber-risk monitoring under a ransomware-victim listing. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | McLanahan Russia id4JdmvLj3vgC8 View details | Russian Federation | Other | pending | ||
|
McLanahan Russia is the Russia-based local entity associated with McLanahan, a company known for industrial processing equipment and related solutions. In this catalog context, it is classified in the Other sector and is identified as operating in Russia (RU). The name suggests an industrial and equipment-related business presence rather than a consumer brand, but publicly available details in the search results are limited. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | mashoil.ru idEeMfysGofkQo View details | Energy | pending | |||
|
mashoil.ru is associated with the Russian energy sector, which covers oil, gas, electricity, and related industrial activity in Russia. Public reporting on the energy vertical describes MashOil in the context of Russian oil-and-gas cyber incidents, indicating it operates in an energy-related business environment rather than as a general consumer brand. The domain name suggests a company tied to oil operations, but available public results do not provide enough verified detail to state more about its products or geographic footprint without overreaching. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Marathon Group idcSsYY3kneYdK View details | Services | pending | |||
|
Marathon Group is a U.S.-based services company headquartered in Houston, Texas, and its business profile indicates an insurance focus. Its website says the company was formed in 2000 to provide high-quality Vehicle Service Contract administration for direct marketing, while its public profiles describe it as a vertically integrated service contract provider offering administration, financing, marketing, and insurance protection. In industry directories, Marathon Group is also associated with insurance operations and related service offerings. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Manafort texts idQXEkSyR8X8q2 View details | Other | pending | |||
|
Manafort texts is a U.S.-based leaked-texts item in the other sector, centered on alleged text messages obtained from the phone of Paul Manafort’s daughter and later circulated online. The material is described as a set of messages rather than an operating company or product offering, so its catalog profile is best understood as a data-leak record tied to personal communications. The listing appears in Distributed Denial of Secrets coverage of ransomware-related disclosures and associated publications. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Macron leaks idKFY5iRKHkR7m View details | Other | pending | |||
|
Macron leaks refers to the 2017 leak of stolen materials linked to Emmanuel Macron’s presidential campaign in France, a politically sensitive disclosure rather than a commercial service or product. Reporting on the incident describes a coordinated operation that combined hacking, disinformation, and the release of roughly 15 GB of data, including emails, shortly before the French election. In threat-intelligence catalogs, the name is used as an incident label for a leak event rather than a traditional organization profile. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | LLC Capital idXQRWeiqnDkFA View details | Services | pending | |||
|
LLC Capital appears in a services-sector context, but publicly available source material in this search set does not provide a reliable company profile, operating location, or offerings sufficient for a precise description. In the absence of an authoritative first-party profile, the safest characterization is that it is a business entity identified by name as LLC Capital and categorized under Services. This listing is used here as a threat-intelligence record rather than a verified corporate profile. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | LINESTAR idYm3FUmwYl667 View details | Other | pending | |||
|
LINESTAR is a utility supply and energy services company headquartered in Houston, Texas, providing integrity, maintenance, and construction services to the midstream and downstream energy markets. The company also operates utility tool and equipment supply operations across Canada, serving the Power Utility market with strategic warehouse locations in multiple provinces. LINESTAR delivers a full suite of infrastructure support services to energy clients, combining operational expertise with industry-specific equipment solutions. The organization was listed as a ransomware victim associated with the threat actor ddosecret. |
||||||
| Ransomware | LeakyMails idtjsbTh3hsDG5 View details | Other | pending | |||
|
LeakyMails is a listed ransomware victim in the Other sector; the available source set does not identify a verified public profile, offering, or headquarters for the company. In threat-intelligence catalogs, such entries are used to document organizations whose data was exposed or published in connection with ransomware activity, without asserting the scope of any incident. DDoSecrets is a nonprofit archive that publishes data already leaked by ransomware operators, and its materials span multiple sectors. LeakyMails was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | LAPD Headshots idq2nbr6df8Inq View details | Other | pending | |||
|
LAPD Headshots is a collection of over 9,000 headshots of officers in the Los Angeles Police Department, located in Los Angeles, California, within the public sector. The offering consists of photographic personnel records maintained by the Department, which were later exposed in a suspected data incident. This listing was identified as a ransomware victim associated with the threat actor ddosecret, which published the data as part of a broader transparency initiative. The incident involved sensitive materials linked to law enforcement personnel and private individuals, though no official breach confirmation or stolen data types have been publicly disclosed by the affected entity. |
||||||
| Ransomware | Kazakhstan Ministry of Energy idsJqumdxxXHUq View details | Energy | leaked | |||
|
The Kazakhstan Ministry of Energy is the central executive body of the Republic of Kazakhstan responsible for state policy and regulation across the energy sector. Based in Astana, it oversees oil and gas, petrochemicals, hydrocarbon transport, electricity, heat supply, uranium mining, nuclear energy, renewables, and related environmental and green-economy functions. As a national ministry, it manages policy, coordination, and supervision for key parts of Kazakhstan’s energy system. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Kazakhstan Ministry of Energy idsJqumdxxXHUq View details | Energy | leaked | |||
|
The Kazakhstan Ministry of Energy is the central executive body of the Republic of Kazakhstan responsible for state policy and regulation across the energy sector. Based in Astana, it oversees oil and gas, petrochemicals, hydrocarbon transport, electricity, heat supply, uranium mining, nuclear energy, renewables, and related environmental and green-economy functions. As a national ministry, it manages policy, coordination, and supervision for key parts of Kazakhstan’s energy system. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Kallias and Associates idVaW4gSe90gsp View details | Other | pending | |||
|
Kallias and Associates is a Cypriot firm based in Nicosia, Cyprus, listed as a chartered accountants practice. Public business listings describe it as offering accounting, taxation, business assurance, insolvency, and related advisory services to local and international clients. The firm’s office is recorded at Gr. Xenopoulos Street, Office 202, Nicosia 1061. In this threat-intelligence index, it was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Jones Day idTVcPgs8VT0Na View details | Other | pending | |||
|
Jones Day is an American multinational law firm headquartered in Washington, D.C., with a long-standing presence in major business and government centers. Founded in 1893, it serves clients through a global network of more than 2,500 lawyers across 40 offices on five continents, advising on litigation, transactions, and disputes. The firm’s Washington office focuses on matters involving the federal government, while its New York office serves banks, private equity firms, and blue-chip companies. Jones Day was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Jhonlin Group idet3kwJE2E2F2 View details | Services | pending | |||
|
Jhonlin Group is an Indonesia-based company with headquarters in Batulicin, South Kalimantan, and corporate profiles describe it as a holding-company enterprise operating from that location. Public business listings also associate the Jhonlin name with broad commercial activities across manufacturing, food and beverage, mining, and agro-industrial operations in Indonesia. Available sources do not provide a single consolidated product catalogue, but they indicate a diversified group structure tied to multiple operating businesses. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Jeb Bush Emails idWRmQYTtuM48z View details | Other | pending | |||
|
Jeb Bush Emails refers to a political archive from the United States, comprising over 1.5 million emails released by the Jeb Bush campaign in 2015 and extending back to 1999. The collection was made available for historical research into an opaque area of politics but was subsequently removed from the campaign website after errors were realized. The archive includes constituent data that was initially unredacted, prompting the campaign to issue a redacted version to protect sensitive information like Social Security numbers. This entity was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Italian State Police idwTJVUtHGi5nQ View details | Italy | Public Sector | pending | ||
|
Italian State Police is the Polizia di Stato, Italy’s civilian national police force and a public-sector agency based in Italy. It serves under the Ministry of the Interior and handles public order, law enforcement, investigations, and other state security duties. The force also supports citizen-facing administrative services and broader policing functions across the country. In a threat-intelligence context, this entry identifies Italian State Police as a ransomware victim listing associated with ddosecret. |
||||||
| Ransomware | Israel Ministry of Justice id1HxRkXJ03HjO View details | Israel | Public Sector | leaked | ||
|
Israel Ministry of Justice is an Israeli government ministry in the public sector, based in Jerusalem, and responsible for overseeing the country’s judicial system and related justice administration. It functions as one of the key administrative ministries of the Government of Israel and provides public-facing legal and governance services through its official channels. In the threat-intelligence index, the Israel Ministry of Justice was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Israel Ministry of Justice id1HxRkXJ03HjO View details | Israel | Public Sector | leaked | ||
|
Israel Ministry of Justice is an Israeli government ministry in the public sector, based in Jerusalem, and responsible for overseeing the country’s judicial system and related justice administration. It functions as one of the key administrative ministries of the Government of Israel and provides public-facing legal and governance services through its official channels. In the threat-intelligence index, the Israel Ministry of Justice was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Israel Ministry of Defense id1wLEkws6RG7B View details | Israel | Public Sector | leaked | ||
|
The Israel Ministry of Defense is Israel’s government defense department, based in Tel Aviv, responsible for protecting the state from internal and external military threats. It oversees core defense functions and supports the country’s security posture through military coordination, defense policy, and related public-sector services. The ministry also backs defense innovation, industry support, and export control activities through affiliated bodies and programs. In threat-intelligence listings, it was recorded as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Israel Ministry of Defense id1wLEkws6RG7B View details | Israel | Public Sector | leaked | ||
|
The Israel Ministry of Defense is Israel’s government defense department, based in Tel Aviv, responsible for protecting the state from internal and external military threats. It oversees core defense functions and supports the country’s security posture through military coordination, defense policy, and related public-sector services. The ministry also backs defense innovation, industry support, and export control activities through affiliated bodies and programs. In threat-intelligence listings, it was recorded as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Iron_March ideEKqoFpmelXK View details | Other | pending | |||
|
Iron_March is an entity categorized under the sector Other, with no verified location, specific offerings, or operational details publicly available. The name appears in various fictional contexts, including game zones and strategic operations, but no real-world corporate or organizational profile has been confirmed for Iron_March in this context. Due to the lack of authoritative data, Iron_March is described generally based on its name and sector classification without inventing facts. It was listed as a ransomware victim associated with the threat actor ddosecret, though no official breach notification or incident specifics have been disclosed by the affected entity. |
||||||
| Ransomware | Integrity Initiative idXF1oRIbXMwWx View details | Other | pending | |||
|
Integrity Initiative is a UK-based organization associated with work on public-interest advocacy and anti-corruption themes, operating in the broader “Other” sector rather than a traditional commercial industry. Public-facing descriptions linked to Integrity Initiatives International indicate activity around convening experts and advancing integrity-focused initiatives, with a global rather than purely local scope. Available references place the organization’s base in the United States for the International counterpart, but the queried Integrity Initiative name is commonly associated with UK-based civic and policy work. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Innwa Bank idUGfUS0hUuUbJ View details | Finance / Legal / Insurance | pending | |||
|
Innwa Bank is a private financial institution operating in Myanmar, providing banking services including deposits, loans, and payment solutions to individuals and businesses within the Finance sector. As part of Myanmar's banking landscape dominated by state-owned and private banks, Innwa Bank offers essential financial offerings to support local commerce and investment activities. The bank serves clients across the Finance, Legal, and Insurance sectors with tailored financial products designed for the region's underdeveloped but reforming market. Innwa Bank was listed as a ransomware victim associated with the threat actor ddosecret, reflecting its inclusion in recent cyber-threat intelligence reports on ransomware incidents in the Finance sector. |
||||||
| Ransomware | India Bulls idPMU3Y435Agro View details | India | Other | pending | ||
|
Indiabulls Limited is an India-based publicly listed company headquartered in Gurgaon, Haryana, with operations in real estate development and financial services. Its business activities have also included related offerings such as housing finance, securities broking, digital payments, and construction equipment leasing. The group has served Indian customers through property, lending, and market-linked financial products. It operates in the country under the Indiabulls name across multiple business lines. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | INAFOR idvk0h4FN5r4GU View details | Other | pending | |||
|
INAFOR is Nicaragua’s national forestry institute, a government body based in Nicaragua that manages forest resources and supports forestry oversight. Public descriptions indicate it works on forest management planning, logging control, and related sector monitoring and services. As a public-sector institution, its role centers on administration and protection of the country’s forests rather than commercial production. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | IDF (Ganosec) idq7CS5PGZhkBf View details | Other | pending | |||
|
IDF (Ganosec) refers to the Israel Defense Forces, the national military of Israel, operating in the Other sector with a primary focus on defending the country's borders and security interests. The entity provides comprehensive defense offerings, including ground, air, and intelligence operations across regions such as the Negev, Arava, and Eilat. In this context, IDF (Ganosec) is identified as having been compromised by an Indonesian hacker group known as Ganosec Team, which published data under the ddosecret platform. The listing neutrally states that IDF (Ganosec) was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | IDF (Anonymous For Justice) idLaQNbpNPROvk View details | Other | pending | |||
|
IDF (Anonymous For Justice) is associated with the Israeli military justice system, which the IDF says includes the Military Advocate General’s Corps, the Military Police Criminal Investigation Division, and military courts. The Military Advocate General’s Corps provides legal advice and helps enforce military and criminal law across the IDF, making the entity part of a defense and government context in Israel. In cyber-threat-intelligence catalogs, it is treated as an Other-sector organization rather than a commercial business. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Identity Evropa Discord logs idv9o26b6VcUSu View details | Other | pending | |||
|
Identity Evropa Discord logs refers to leaked chat records tied to Identity Evropa, a U.S.-based white supremacist organization active from 2016 to 2019. The logs capture internal Discord communications used for organizing, coordination, and discussion among members of the group. Distributed Denial of Secrets describes the material as a leak of Identity Evropa’s Discord chat logs, while reporting on the leak places the organization in the context of extremist activity on U.S. campuses and online. The listing is categorized in the Other sector and associated with ddosecret. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Icebreaker idCQpNbFDZqiay View details | Other | leaked | |||
|
Icebreaker appears in a ransomware-victim index under the Other sector, indicating an organization listed in connection with a leak or extortion event rather than a specific industry profile. Publicly available index data does not provide a verified location, business description, or offering details for Icebreaker, so any further operational characterization would be speculative. The entity is therefore best described as a named organization recorded in threat-intelligence tracking for ransomware exposure. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Icebreaker idCQpNbFDZqiay View details | Other | leaked | |||
|
Icebreaker appears in a ransomware-victim index under the Other sector, indicating an organization listed in connection with a leak or extortion event rather than a specific industry profile. Publicly available index data does not provide a verified location, business description, or offering details for Icebreaker, so any further operational characterization would be speculative. The entity is therefore best described as a named organization recorded in threat-intelligence tracking for ransomware exposure. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | IAEC id4vhR075hAgx8 View details | Other | leaked | |||
|
IAEC is a Kolkata, West Bengal-based company founded in 1949 and focused on air and pollution control technology. Its profile describes a long-running industrial business built around environmental control systems and related technology for commercial and industrial use. Public references consistently place the company in Kolkata, India, and identify it with the broader industrial engineering and environmental equipment space. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | IAEC id4vhR075hAgx8 View details | Other | leaked | |||
|
IAEC is a Kolkata, West Bengal-based company founded in 1949 and focused on air and pollution control technology. Its profile describes a long-running industrial business built around environmental control systems and related technology for commercial and industrial use. Public references consistently place the company in Kolkata, India, and identify it with the broader industrial engineering and environmental equipment space. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Hunter Biden emails idwdalkwStAUTO View details | Other | pending | |||
|
Hunter Biden emails is a limited-distribution dataset in the other sector, associated with an alleged copy of Hunter Biden’s laptop content circulated online. Distributed Denial of Secrets describes it as approximately 128,500 emails allegedly from the laptop, primarily dated between 2009 and 2019, and published on its site in January 2024. The listing centers on email material rather than a company profile, office location, or commercial offerings, so it is best understood as a data collection entry. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Hofeller Files idy0Q4cWYCItUo View details | Other | pending | |||
|
The Hofeller Files is a digital archive of computer files saved on the hard drives of Thomas Hofeller, a prominent Republican redistricting strategist in the United States. It serves as a public repository where Hofeller's daughter published a link to her copy of the files, making records on voting patterns and demographic data accessible online. The archive offers evidence of how political operatives used Census data and racial information to influence redistricting and democracy. This collection is sectored as Other and functions as an encyclopedic resource on modern Republican gerrymandering strategies. The Hofeller Files was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Heritage Foundation idKIxW36CBjhtz View details | NGOs / Associations | pending | |||
|
The Heritage Foundation is a nonprofit research and educational think tank based in Washington, DC. Founded in 1973, it develops and promotes conservative public policy focused on free enterprise, limited government, individual freedom, traditional American values, and national defense. It operates in the NGOs/associations sector and is known for policy analysis, advocacy, and communications aimed at U.S. decision-makers. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | HBGary iduRpiuu48vYjn View details | Other | pending | |||
|
HBGary is a U.S.-based technology security company known for providing malware detection, analysis, and incident-response tools for enterprise and government customers. Public descriptions also note that HBGary Federal was a related entity focused on U.S. federal clients, while HBGary Inc. served broader commercial security needs. The company’s services centered on cyber defense and intelligence-oriented security products rather than consumer software. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | HART idjjDDBFWeRDvl View details | Other | pending | |||
|
HART is an entity in the Other sector based in the United States, with public details about its offerings not clearly established in the available sources. Its name appears in a threat-intelligence context rather than a business-profile context, so the most reliable description is limited to sector and geography. Available reporting does not provide enough authoritative detail to define its services without speculation. HART was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Harita Group idD6xcRud7k2NP View details | Services | pending | |||
|
Harita Group is an Indonesian conglomerate with operations in natural resources and related services, including aluminum, coal, nickel, palm oil, and timber products. Its businesses span mining, smelting, refining, shipping, and other operational support activities, with a major footprint in Indonesia. The group is widely associated with industrial and commodity supply chains rather than a single consumer brand. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Hacking Team idNUqMQ4a0Fpn7 View details | Other | pending | |||
|
Hacking Team is a Milan-based Italian technology company known for developing and selling offensive intrusion and surveillance software, including tools marketed to governments and law enforcement. It gained notoriety for its Remote Control System and for operating in the broader cyber-surveillance sector. The company has also been widely reported as having been acquired and later rebranded under the Memento Labs name. In threat-intelligence catalogs, Hacking Team is listed as a ransomware victim associated with ddosecret. |
||||||