Ransomware Group intelligence
Ddosecret
ActiveTrack Ddosecret with 585 published victims and 4 known leak locations in a single intelligence view.
Overview
Ddosecret is tracked by Breach House as a ransomware group with 585 published victims.
Russian Federation is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 323 100.0%
- Pending 0 0.0%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Web location | Up checked 47m ago | data.ddosecrets.org |
| Leak location 3 | Web location | Up checked 47m ago | ddosecrets.org |
| Leak location 1 | Web location | Down checked 47m ago | https://data.ddosecrets.com/ |
| Leak location 2 | Web location | Down checked 47m ago | ddosecrets.com |
Top Activity Sectors (15)
- Not identified 231
- Public Sector 18
- Communication / Marketing 14
- Services 11
- Finance / Legal / Insurance 10
- Energy 7
- Telecommunications 3
- Manufacturing / Engineering 3
- IT 3
- Education 3
- NGOs / Associations 3
- Retail / E-commerce 2
- Hospitality / Food & Beverage / Tourism 1
- Transportation / Travel / Logistics 1
- Construction / Real Estate 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Ddosecret, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: ddosecret uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: ddosecret modifies Windows Registry Run keys to ensure ransomware execution upon system reboot.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: ddosecret disables antivirus tools and security software to prevent detection and hinder system recovery efforts.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: ddosecret deletes Volume Shadow Copies and backup files to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: ddosecret performs remote system discovery to map the victim network and identify high-value targets.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: ddosecret scans network shares to identify victim file structures and target directories for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: ddosecret exploits SMB/Windows Admin Shares to move laterally between networked victim machines.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: ddosecret exfiltrates victim data via encrypted C2 channels before demanding payment for decryption keys.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: ddosecret encrypts victim files using custom ransomware binaries, locking data for extortion demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: ddosecret invokes system recovery inhibition commands to prevent automatic restoration from backups.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (585)
Search, filter and paginate the victim timeline for Ddosecret. Showing 501–585 of 585.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Cook Islands registry idoHpypTWEmkw4 View details | Other | leaked | |||
|
Cook Islands registry refers to registry services in the Cook Islands, a South Pacific island nation in free association with New Zealand, with administrative offices in Avarua, Rarotonga. The registry serves government record-keeping functions; related public registry services include civil registration under the Ministry of Justice, and maritime registry operations that provide ship and yacht registration, flag-state functions, survey, certification, and seafarer training. In the business registry context, it also supports entity search and company-record administration. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Cook Islands registry idoHpypTWEmkw4 View details | Other | leaked | |||
|
Cook Islands registry refers to registry services in the Cook Islands, a South Pacific island nation in free association with New Zealand, with administrative offices in Avarua, Rarotonga. The registry serves government record-keeping functions; related public registry services include civil registration under the Ministry of Justice, and maritime registry operations that provide ship and yacht registration, flag-state functions, survey, certification, and seafarer training. In the business registry context, it also supports entity search and company-record administration. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Convex idH1NrQEoZOgIi View details | Other | leaked | |||
|
Convex is a San Francisco-based software company that provides a sales intelligence platform for commercial services teams. According to its company materials, it helps users reach decision-makers and win more deals across a large property dataset, positioning itself as an industry cloud platform for commercial services. The company describes its focus as supporting go-to-market teams in sectors such as HVAC, building automation, security, fire safety, elevators, electrical, and janitorial services. In threat-intelligence cataloging, Convex was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Convex idH1NrQEoZOgIi View details | Other | leaked | |||
|
Convex is a San Francisco-based software company that provides a sales intelligence platform for commercial services teams. According to its company materials, it helps users reach decision-makers and win more deals across a large property dataset, positioning itself as an industry cloud platform for commercial services. The company describes its focus as supporting go-to-market teams in sectors such as HVAC, building automation, security, fire safety, elevators, electrical, and janitorial services. In threat-intelligence cataloging, Convex was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Conti ransomware chats idW99hPOaWagbj View details | Other | leaked | |||
|
Conti ransomware was a Russia-based ransomware-as-a-service operation associated with the Wizard Spider group and known for targeting public and private organizations across sectors. It used double extortion, combining file encryption with threats to publish stolen data, and was active from late 2019 until the group’s shutdown in 2022. Conti was widely reported against healthcare, government, education, critical infrastructure, and business victims, with activity concentrated in North America and other regions. The item “Conti ransomware chats” refers to leaked internal communications from the Conti ecosystem rather than a sector-specific company or service. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Conti ransomware chats idW99hPOaWagbj View details | Other | leaked | |||
|
Conti ransomware was a Russia-based ransomware-as-a-service operation associated with the Wizard Spider group and known for targeting public and private organizations across sectors. It used double extortion, combining file encryption with threats to publish stolen data, and was active from late 2019 until the group’s shutdown in 2022. Conti was widely reported against healthcare, government, education, critical infrastructure, and business victims, with activity concentrated in North America and other regions. The item “Conti ransomware chats” refers to leaked internal communications from the Conti ecosystem rather than a sector-specific company or service. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Consulate General of Israel in Atlanta, United States idJnbruYJ0M45U View details | United States | Public Sector | leaked | ||
|
The Consulate General of Israel to the Southeastern United States is Israel’s diplomatic mission based in Atlanta, Georgia, serving the public sector through consular services, diplomatic outreach, and representation of the State of Israel in the region. Its jurisdiction covers Alabama, Georgia, Kentucky, Mississippi, North Carolina, South Carolina, and Tennessee, and it also supports community affairs and public diplomacy work. In Atlanta, the consulate provides appointment-based consular services and related information for residents and visitors within its area of responsibility. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Consulate General of Israel in Atlanta, United States idJnbruYJ0M45U View details | United States | Public Sector | leaked | ||
|
The Consulate General of Israel to the Southeastern United States is Israel’s diplomatic mission based in Atlanta, Georgia, serving the public sector through consular services, diplomatic outreach, and representation of the State of Israel in the region. Its jurisdiction covers Alabama, Georgia, Kentucky, Mississippi, North Carolina, South Carolina, and Tennessee, and it also supports community affairs and public diplomacy work. In Atlanta, the consulate provides appointment-based consular services and related information for residents and visitors within its area of responsibility. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Constellis.zip idntRpsLOoBwCq View details | Other | leaked | |||
|
Constellis.zip is an entity listed in the **Other** sector; based on its name, no reliable public business profile is available from the provided sources to confirm a specific location or offerings. In threat-intelligence catalogs, such entries are typically treated as named targets rather than as fully profiled organizations when public corporate details are limited. The listing format indicates a ransomware-victim record associated with a leak or disclosure ecosystem, but it does not itself establish the scope of any incident. It was listed as a ransomware victim associated with **ddosecret**. |
||||||
| Ransomware | Constellis.zip idntRpsLOoBwCq View details | Other | leaked | |||
|
Constellis.zip is an entity listed in the **Other** sector; based on its name, no reliable public business profile is available from the provided sources to confirm a specific location or offerings. In threat-intelligence catalogs, such entries are typically treated as named targets rather than as fully profiled organizations when public corporate details are limited. The listing format indicates a ransomware-victim record associated with a leak or disclosure ecosystem, but it does not itself establish the scope of any incident. It was listed as a ransomware victim associated with **ddosecret**. |
||||||
| Ransomware | CitizenGo & HatzeOir databases idy7caho3X3QGy View details | NGOs / Associations | leaked | |||
|
CitizenGO is a Madrid-based advocacy organization associated with Fundación CitizenGO, a nonprofit platform that runs online campaigns, petition tools, member registration, donations, and related site support for its community. Public materials describe its work as international and focused on advocacy across multiple countries, placing it within the NGOs/Associations sector. HazteOir is a related Spanish advocacy brand historically connected to CitizenGO and used in its organizational and campaign activities. The CitizenGO & HatzeOir databases entry was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | CitizenGo & HatzeOir databases idy7caho3X3QGy View details | NGOs / Associations | leaked | |||
|
CitizenGO is a Madrid-based advocacy organization associated with Fundación CitizenGO, a nonprofit platform that runs online campaigns, petition tools, member registration, donations, and related site support for its community. Public materials describe its work as international and focused on advocacy across multiple countries, placing it within the NGOs/Associations sector. HazteOir is a related Spanish advocacy brand historically connected to CitizenGO and used in its organizational and campaign activities. The CitizenGO & HatzeOir databases entry was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Chinga La Migra idZU48qyTapqfw View details | Other | leaked | |||
|
Chinga La Migra is a U.S.-based activist and solidarity campaign centered on immigration enforcement, with public references connecting it to organizing, advocacy, and community support around immigrant rights. Its name is a Spanish-language protest phrase meaning, in context, opposition to border and immigration policing, and it is used in the United States as a political slogan rather than a commercial service. Public descriptions associate the project with advocacy-oriented events and messaging aimed at immigrant communities and anti-ICE organizing. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Chinga La Migra idZU48qyTapqfw View details | Other | leaked | |||
|
Chinga La Migra is a U.S.-based activist and solidarity campaign centered on immigration enforcement, with public references connecting it to organizing, advocacy, and community support around immigrant rights. Its name is a Spanish-language protest phrase meaning, in context, opposition to border and immigration policing, and it is used in the United States as a political slogan rather than a commercial service. Public descriptions associate the project with advocacy-oriented events and messaging aimed at immigrant communities and anti-ICE organizing. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Chinese Ministry of Commerce idT85SxJGgltY5 View details | Retail / E-commerce | leaked | |||
|
The Chinese Ministry of Commerce (MOFCOM) is an executive department of the State Council of the People's Republic of China, headquartered in Beijing. It is responsible for formulating policies on foreign trade, export and import regulations, foreign direct investments, consumer protection, and market competition, while negotiating bilateral and multilateral trade agreements. MOFCOM regulates domestic and foreign trade, works to attract foreign investment, and helps Chinese companies abroad, including overseeing e-commerce development and WTO implementation. The ministry was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Chinese Ministry of Commerce idT85SxJGgltY5 View details | Retail / E-commerce | leaked | |||
|
The Chinese Ministry of Commerce (MOFCOM) is an executive department of the State Council of the People's Republic of China, headquartered in Beijing. It is responsible for formulating policies on foreign trade, export and import regulations, foreign direct investments, consumer protection, and market competition, while negotiating bilateral and multilateral trade agreements. MOFCOM regulates domestic and foreign trade, works to attract foreign investment, and helps Chinese companies abroad, including overseeing e-commerce development and WTO implementation. The ministry was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Chamber of Mines of South Africa idpAL89RBeYh6Z View details | South Africa | Other | leaked | ||
|
The Chamber of Mines of South Africa was a South African mining-industry employers’ organisation based in South Africa, serving member companies and promoting their interests in the sector. It operated as an industry body focused on representing and supporting mining employers, and it later changed its name to Minerals Council South Africa. In threat-intelligence catalogs, the entity is associated with the other sector classification in South Africa. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Chamber of Mines of South Africa idpAL89RBeYh6Z View details | South Africa | Other | leaked | ||
|
The Chamber of Mines of South Africa was a South African mining-industry employers’ organisation based in South Africa, serving member companies and promoting their interests in the sector. It operated as an industry body focused on representing and supporting mining employers, and it later changed its name to Minerals Council South Africa. In threat-intelligence catalogs, the entity is associated with the other sector classification in South Africa. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Central Bank of Russia idcpX5geTZi1or View details | Russian Federation | Finance / Legal / Insurance | leaked | ||
|
The Central Bank of Russia, also known as the Bank of Russia, is the central bank of the Russian Federation and is headquartered in Moscow. It serves as the country’s monetary authority, protecting the ruble and ensuring price stability while issuing cash, overseeing payment systems, and regulating banking activity. Its public functions include monetary policy, foreign exchange control, financial-market supervision, and support for the stability of Russia’s financial system. In threat-intelligence records, Central Bank of Russia was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Central Bank of Russia idcpX5geTZi1or View details | Russian Federation | Finance / Legal / Insurance | leaked | ||
|
The Central Bank of Russia, also known as the Bank of Russia, is the central bank of the Russian Federation and is headquartered in Moscow. It serves as the country’s monetary authority, protecting the ruble and ensuring price stability while issuing cash, overseeing payment systems, and regulating banking activity. Its public functions include monetary policy, foreign exchange control, financial-market supervision, and support for the stability of Russia’s financial system. In threat-intelligence records, Central Bank of Russia was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Cellebrite and MSAB idCBgV9DDHpOpB View details | Other | leaked | |||
|
Cellebrite is an Israel-based digital intelligence and investigative analytics company headquartered in Petah Tikva. It provides mobile forensics, data extraction, and analytics solutions used by public and private organizations for investigations and data security. The company describes its platform as supporting digital forensics, investigations, and intelligence workflows across many countries. In threat-intelligence catalogs, Cellebrite and MSAB are listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Cellebrite and MSAB idCBgV9DDHpOpB View details | Other | leaked | |||
|
Cellebrite is an Israel-based digital intelligence and investigative analytics company headquartered in Petah Tikva. It provides mobile forensics, data extraction, and analytics solutions used by public and private organizations for investigations and data security. The company describes its platform as supporting digital forensics, investigations, and intelligence workflows across many countries. In threat-intelligence catalogs, Cellebrite and MSAB are listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Casolaro Files idqqWE2r6TCw3j View details | Energy | leaked | |||
|
Casolaro Files refers to a collection of documents presented by Distributed Denial of Secrets as part of a Venezuela/U.S. energy-sector matter, describing materials said to relate to companies and individuals connected to that industry. DDoSecrets’ article listing identifies it among recently published files and frames it as an energy-sector disclosure tied to Venezuela, not as an operating energy company. In threat-intelligence catalogs, Casolaro Files is therefore treated as a named victim entry within the Energy sector and associated with public leak activity. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Casolaro Files idqqWE2r6TCw3j View details | Energy | leaked | |||
|
Casolaro Files refers to a collection of documents presented by Distributed Denial of Secrets as part of a Venezuela/U.S. energy-sector matter, describing materials said to relate to companies and individuals connected to that industry. DDoSecrets’ article listing identifies it among recently published files and frames it as an energy-sector disclosure tied to Venezuela, not as an operating energy company. In threat-intelligence catalogs, Casolaro Files is therefore treated as a named victim entry within the Energy sector and associated with public leak activity. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Capital Legal Services idyKl4oSD2IgPU View details | Finance / Legal / Insurance | leaked | |||
|
Capital Legal Services is a professional-services business operating in the Finance, Legal, and Insurance space, serving clients that need legal and related advisory support in a regulated environment. Publicly available materials do not provide a definitive company profile or location for this exact entity, so its business can only be described conservatively from the name and sector context. As a legal-sector organization, it would be expected to handle sensitive client and matter-related information. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Capital Legal Services idyKl4oSD2IgPU View details | Finance / Legal / Insurance | leaked | |||
|
Capital Legal Services is a professional-services business operating in the Finance, Legal, and Insurance space, serving clients that need legal and related advisory support in a regulated environment. Publicly available materials do not provide a definitive company profile or location for this exact entity, so its business can only be described conservatively from the name and sector context. As a legal-sector organization, it would be expected to handle sensitive client and matter-related information. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Cablegate idqyaehxnCz5y2 View details | Other | leaked | |||
|
Cablegate is an organization in the Other sector; available public context does not provide enough detail to verify its location or specific offerings from the name alone. The name suggests a corporate or project-related entity rather than a consumer brand, but no reliable source in the provided record identifies its business model, geography, or service portfolio. In threat-intelligence catalogs, such entries are often recorded with limited public-facing company detail when the victim name appears in leak or disclosure datasets. Cablegate was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Cablegate idqyaehxnCz5y2 View details | Other | leaked | |||
|
Cablegate is an organization in the Other sector; available public context does not provide enough detail to verify its location or specific offerings from the name alone. The name suggests a corporate or project-related entity rather than a consumer brand, but no reliable source in the provided record identifies its business model, geography, or service portfolio. In threat-intelligence catalogs, such entries are often recorded with limited public-facing company detail when the victim name appears in leak or disclosure datasets. Cablegate was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Bradley Foundation idDT68VEAbYkb3 View details | NGOs / Associations | leaked | |||
|
The Lynde and Harry Bradley Foundation is a private, independent grantmaking organization based in Milwaukee, Wisconsin, in the United States. It supports nonprofit and civic initiatives through philanthropy, with program areas that include constitutional order, free markets, civil society, and informed citizens. As a foundation, it operates in the NGOs and associations sector and funds organizations rather than providing consumer products or services. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Bradley Foundation idDT68VEAbYkb3 View details | NGOs / Associations | leaked | |||
|
The Lynde and Harry Bradley Foundation is a private, independent grantmaking organization based in Milwaukee, Wisconsin, in the United States. It supports nonprofit and civic initiatives through philanthropy, with program areas that include constitutional order, free markets, civil society, and informed citizens. As a foundation, it operates in the NGOs and associations sector and funds organizations rather than providing consumer products or services. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Boy Scouts of America idHjvbPvnLSPcu View details | United States | Other | leaked | ||
|
Boy Scouts of America, now known as Scouting America, is a U.S.-based youth organization headquartered in the United States. It provides scouting programs and character-building activities for children and teens, including outdoor skills, camping, hiking, leadership development, and community service. Its offerings span age-based programs such as Cub Scouting, Scouts BSA, Venturing, and Sea Scouting. In a threat-intelligence listing, Boy Scouts of America was recorded as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Boy Scouts of America idHjvbPvnLSPcu View details | United States | Other | leaked | ||
|
Boy Scouts of America, now known as Scouting America, is a U.S.-based youth organization headquartered in the United States. It provides scouting programs and character-building activities for children and teens, including outdoor skills, camping, hiking, leadership development, and community service. Its offerings span age-based programs such as Cub Scouting, Scouts BSA, Venturing, and Sea Scouting. In a threat-intelligence listing, Boy Scouts of America was recorded as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Bob Otto emails idMfPxiRKOtMWF View details | Other | leaked | |||
|
Bob Otto emails refers to a hack entry published by Distributed Denial of Secrets (ddosecret), describing hacked emails from Robert Otto, a senior U.S. State Department official. The item is categorized in the Other sector and is associated with the United States, reflecting a leaked-email style disclosure rather than an operating business profile. In this context, the listing catalogs an incident involving personal or official correspondence attributed to Otto, with no public business offerings described in the source entry. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Bob Otto emails idMfPxiRKOtMWF View details | Other | leaked | |||
|
Bob Otto emails refers to a hack entry published by Distributed Denial of Secrets (ddosecret), describing hacked emails from Robert Otto, a senior U.S. State Department official. The item is categorized in the Other sector and is associated with the United States, reflecting a leaked-email style disclosure rather than an operating business profile. In this context, the listing catalogs an incident involving personal or official correspondence attributed to Otto, with no public business offerings described in the source entry. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | BlueLeaks idauxWVyadom2i View details | Other | leaked | |||
|
BlueLeaks is a large trove of internal U.S. law-enforcement and public-safety materials that was published online in 2020 and is widely associated with police, fusion-center, and related government records. The collection was released by Distributed Denial of Secrets (DDoSecrets) and drew on data reportedly obtained from a third-party web services environment used by law-enforcement portals in the United States. Its contents include internal bulletins, reports, emails, manuals, and other operational documents spanning multiple agencies and years. BlueLeaks is listed here as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | BlueLeaks idauxWVyadom2i View details | Other | leaked | |||
|
BlueLeaks is a large trove of internal U.S. law-enforcement and public-safety materials that was published online in 2020 and is widely associated with police, fusion-center, and related government records. The collection was released by Distributed Denial of Secrets (DDoSecrets) and drew on data reportedly obtained from a third-party web services environment used by law-enforcement portals in the United States. Its contents include internal bulletins, reports, emails, manuals, and other operational documents spanning multiple agencies and years. BlueLeaks is listed here as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Blagoveshchensk City Administration idW8CpjcaWukGU View details | Public Sector | leaked | |||
|
Blagoveshchensk City Administration is the municipal government of Blagoveshchensk, the administrative center of Amur Oblast in Russia, on the Amur River opposite Heihe, China. It provides public administration and related municipal services for the city, including governance, public services, and local administration functions. The city’s official investment profile also places the administration in the public sector, alongside responsibilities tied to public safety, social security, and municipal management. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Blagoveshchensk City Administration idW8CpjcaWukGU View details | Public Sector | leaked | |||
|
Blagoveshchensk City Administration is the municipal government of Blagoveshchensk, the administrative center of Amur Oblast in Russia, on the Amur River opposite Heihe, China. It provides public administration and related municipal services for the city, including governance, public services, and local administration functions. The city’s official investment profile also places the administration in the public sector, alongside responsibilities tied to public safety, social security, and municipal management. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Bangkok Airways idKMR6eIzUQCBx View details | Other | leaked | |||
|
Bangkok Airways Public Company Limited is a regional airline based in Bangkok, Thailand, operating scheduled services to destinations within Thailand and across Southeast Asia. The airline offers full-service flights with in-flight meals, 20kg baggage allowance, and seat selection for domestic and international routes. It is known as Asia's Boutique Airline and holds a 4-Star certification for quality of seats, amenities, and service standards. Bangkok Airways was listed as a ransomware victim associated with the threat actor ddosecret. |
||||||
| Ransomware | Bangkok Airways idKMR6eIzUQCBx View details | Other | leaked | |||
|
Bangkok Airways Public Company Limited is a regional airline based in Bangkok, Thailand, operating scheduled services to destinations within Thailand and across Southeast Asia. The airline offers full-service flights with in-flight meals, 20kg baggage allowance, and seat selection for domestic and international routes. It is known as Asia's Boutique Airline and holds a 4-Star certification for quality of seats, amenities, and service standards. Bangkok Airways was listed as a ransomware victim associated with the threat actor ddosecret. |
||||||
| Ransomware | Banco de Poupança e Crédito id9zEQterP4HbK View details | Finance / Legal / Insurance | leaked | |||
|
Banco de Poupança e Crédito is Angola’s largest state-owned commercial bank, headquartered in Luanda and operating branches across the country. It provides full-service banking for individuals, businesses, and public-sector clients, with offerings that include deposits, lending, payments, and other retail and corporate financial services. The bank is a major institution in Angola’s finance sector and has historically played a central role in the country’s banking system. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Banco de Poupança e Crédito id9zEQterP4HbK View details | Finance / Legal / Insurance | leaked | |||
|
Banco de Poupança e Crédito is Angola’s largest state-owned commercial bank, headquartered in Luanda and operating branches across the country. It provides full-service banking for individuals, businesses, and public-sector clients, with offerings that include deposits, lending, payments, and other retail and corporate financial services. The bank is a major institution in Angola’s finance sector and has historically played a central role in the country’s banking system. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Bahamas Registry idZhcniwkIcULG View details | Other | leaked | |||
|
Bahamas Registry refers to a government-run registry service in The Bahamas that supports business and corporate administration. The Bahamas has a fully digital Corporate Administrative Registry Services portal for incorporating companies, filing corporate documents, paying annual fees, and obtaining certified copies, while maritime registry services are also offered through related online systems. In this context, the entity is categorized in the other sector and is associated with official registry functions rather than a private commercial brand. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Bahamas Registry idZhcniwkIcULG View details | Other | leaked | |||
|
Bahamas Registry refers to a government-run registry service in The Bahamas that supports business and corporate administration. The Bahamas has a fully digital Corporate Administrative Registry Services portal for incorporating companies, filing corporate documents, paying annual fees, and obtaining certified copies, while maritime registry services are also offered through related online systems. In this context, the entity is categorized in the other sector and is associated with official registry functions rather than a private commercial brand. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | AssangeLeaks idvofQTFLez96d View details | Other | leaked | |||
|
AssangeLeaks is listed in threat-intelligence coverage as a sector-Other entity in the United States, but the available sources do not identify a clear operating business, product line, or public-facing offering for it. In this context, the name is treated as an indexed victim record rather than a verified commercial organization, so no additional operational details can be stated with confidence. Public reporting on DDoSecrets describes it as a transparency-focused collective that republishes material already exposed by ransomware actors or other leak sources. AssangeLeaks was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | AssangeLeaks idvofQTFLez96d View details | Other | leaked | |||
|
AssangeLeaks is listed in threat-intelligence coverage as a sector-Other entity in the United States, but the available sources do not identify a clear operating business, product line, or public-facing offering for it. In this context, the name is treated as an indexed victim record rather than a verified commercial organization, so no additional operational details can be stated with confidence. Public reporting on DDoSecrets describes it as a transparency-focused collective that republishes material already exposed by ransomware actors or other leak sources. AssangeLeaks was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Arron Banks idos2c61DsmCFL View details | Finance / Legal / Insurance | leaked | |||
|
Arron Banks is a British businessman associated with the insurance and wider financial-services sector in the United Kingdom. Public profiles and reporting describe him as a founder and investor in insurance businesses, with interests spanning insurance, financial services, and related ventures. His commercial activity has been linked to the UK market, including insurance brokerage and other finance-related holdings. In threat-intelligence records, Arron Banks was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Arron Banks idos2c61DsmCFL View details | Finance / Legal / Insurance | leaked | |||
|
Arron Banks is a British businessman associated with the insurance and wider financial-services sector in the United Kingdom. Public profiles and reporting describe him as a founder and investor in insurance businesses, with interests spanning insurance, financial services, and related ventures. His commercial activity has been linked to the UK market, including insurance brokerage and other finance-related holdings. In threat-intelligence records, Arron Banks was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | ArianTel id9Msd4GUCEe6j View details | Other | leaked | |||
|
ArianTel is an Iranian telecommunications provider that offers mobile service and related communications services. Public profiles describe it as a mobile service operator and a provider of telecom offerings such as SIM cards and internet packages, with operations associated with Iran. Open-source reporting also links ArianTel to Iran’s broader communications and surveillance environment. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | ArianTel id9Msd4GUCEe6j View details | Other | leaked | |||
|
ArianTel is an Iranian telecommunications provider that offers mobile service and related communications services. Public profiles describe it as a mobile service operator and a provider of telecom offerings such as SIM cards and internet packages, with operations associated with Iran. Open-source reporting also links ArianTel to Iran’s broader communications and surveillance environment. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aqaba Company for Ports Operation & Management, Jordan idHJMPPSztR8Bx View details | Services | leaked | |||
|
Aqaba Company for Ports Operation & Management is a public company based in Aqaba, Jordan, in the maritime services sector, with headquarters in Aqaba and a reported workforce of 1,001-5,000 employees. It operates port activities and manages port facilities and services connected to the Port of Aqaba, supporting cargo handling and related maritime operations. The company is described as a governmental body for establishing, developing, maintaining, and operating port activities, and community-development materials note that the New Port is fully operational under its management. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aqaba Company for Ports Operation & Management, Jordan idHJMPPSztR8Bx View details | Services | leaked | |||
|
Aqaba Company for Ports Operation & Management is a public company based in Aqaba, Jordan, in the maritime services sector, with headquarters in Aqaba and a reported workforce of 1,001-5,000 employees. It operates port activities and manages port facilities and services connected to the Port of Aqaba, supporting cargo handling and related maritime operations. The company is described as a governmental body for establishing, developing, maintaining, and operating port activities, and community-development materials note that the New Port is fully operational under its management. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Appin Uncensored idFRQqwqi9n6hq View details | Other | leaked | |||
|
Appin Uncensored appears to refer to Appin, an Indian company described as a cyber-espionage firm that provided hacking services to governments, private investigators, and corporate clients. Reuters and later summaries characterize it as an educational startup that evolved into a private hacking and intelligence operation serving high-end clients. Public reporting places the company in India, but available sources do not provide a clear consumer-facing product or ordinary commercial offerings for this listing. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Appin Uncensored idFRQqwqi9n6hq View details | Other | leaked | |||
|
Appin Uncensored appears to refer to Appin, an Indian company described as a cyber-espionage firm that provided hacking services to governments, private investigators, and corporate clients. Reuters and later summaries characterize it as an educational startup that evolved into a private hacking and intelligence operation serving high-end clients. Public reporting places the company in India, but available sources do not provide a clear consumer-facing product or ordinary commercial offerings for this listing. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Andrew Tate's War Room videos idVRC3ImxbER18 View details | Other | leaked | |||
|
Andrew Tate's War Room videos refers to a collection of in-person meeting, dinner, and event recordings tied to Andrew Tate's War Room, an all-male networking group. Reporting and the indexed description characterize the group as a paid membership community that promotes self-discipline, motivation, confidence, and business or social networking, with participation fees reported at about $8,000 per year and coverage focused on its UK-linked activities. The material on the index concerns the videos themselves rather than a separate company service, so the listing is best understood as an Other-sector target associated with a media archive and private group activity. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Andrew Tate's War Room videos idVRC3ImxbER18 View details | Other | leaked | |||
|
Andrew Tate's War Room videos refers to a collection of in-person meeting, dinner, and event recordings tied to Andrew Tate's War Room, an all-male networking group. Reporting and the indexed description characterize the group as a paid membership community that promotes self-discipline, motivation, confidence, and business or social networking, with participation fees reported at about $8,000 per year and coverage focused on its UK-linked activities. The material on the index concerns the videos themselves rather than a separate company service, so the listing is best understood as an Other-sector target associated with a media archive and private group activity. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Andrew Tate's The Real World (Hustler's University) id5fi6VXQ8QgSg View details | Education | leaked | |||
|
Andrew Tate's The Real World, formerly known as Hustler's University, is an online education platform in the Education sector that offers courses on e-commerce, drop shipping, stocks, crypto, and copywriting, taught by millionaire professors to over 155,000 members worldwide. The platform provides access to a network of 240,000 professionals, expert training, direct mentorship, and tested strategies for scaling businesses to 7+ figures. It operates as a global digital learning application focused on wealth creation methods, requiring about 2 hours of daily focus work to potentially earn between 1 million and 10 million dollars. The Real World was listed as a ransomware victim associated with the threat actor ddosecret, which breached the platform on November 25, 2024, exposing user data. |
||||||
| Ransomware | Andrew Tate staff chats iddH898lnsHOTs View details | Other | leaked | |||
|
Andrew Tate staff chats refers to chat logs and related internal communications from Andrew Tate’s subscription-based online course service, The Real World, formerly known as Hustler’s University. The platform operates in the education and training space and is associated with Andrew Tate’s online business activity. Public reporting describes the service as a paid membership offering that includes training and community chat channels, with the leaked material drawn from those staff and user chat environments. It is categorized in the Other sector and is associated with the United Kingdom. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Andrew Tate staff chats iddH898lnsHOTs View details | Other | leaked | |||
|
Andrew Tate staff chats refers to chat logs and related internal communications from Andrew Tate’s subscription-based online course service, The Real World, formerly known as Hustler’s University. The platform operates in the education and training space and is associated with Andrew Tate’s online business activity. Public reporting describes the service as a paid membership offering that includes training and community chat channels, with the leaked material drawn from those staff and user chat environments. It is categorized in the Other sector and is associated with the United Kingdom. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Alliance Coal idNpmhXgw9RWP5 View details | Other | leaked | |||
|
Alliance Coal, commonly associated with Alliance Resource Partners, is a U.S. coal company headquartered in Tulsa, Oklahoma. It operates in the coal sector and describes itself as a leading producer in the Eastern United States, supplying utility, industrial, and steelmaking customers with coal. The company’s business centers on coal mining, production, and marketing, with additional energy-related assets in its broader portfolio. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Alliance Coal idNpmhXgw9RWP5 View details | Other | leaked | |||
|
Alliance Coal, commonly associated with Alliance Resource Partners, is a U.S. coal company headquartered in Tulsa, Oklahoma. It operates in the coal sector and describes itself as a leading producer in the Eastern United States, supplying utility, industrial, and steelmaking customers with coal. The company’s business centers on coal mining, production, and marketing, with additional energy-related assets in its broader portfolio. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | ALET idHi1pXQsys7uJ View details | Other | leaked | |||
|
ALET LTD is a UK-registered company based in Pontypool, Torfaen, Wales, with its registered office at 14 Museum Court. Companies House lists it as an active private limited company, but the available filing record does not describe its products, services, or operating sector in detail. In this catalog context, ALET is therefore identified conservatively as a business entity from the United Kingdom without further operational specifics. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | ALET idHi1pXQsys7uJ View details | Other | leaked | |||
|
ALET LTD is a UK-registered company based in Pontypool, Torfaen, Wales, with its registered office at 14 Museum Court. Companies House lists it as an active private limited company, but the available filing record does not describe its products, services, or operating sector in detail. In this catalog context, ALET is therefore identified conservatively as a business entity from the United Kingdom without further operational specifics. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | AKP id4hALqNOjDUvb View details | Other | leaked | |||
|
AKP is a UK-based company in the Other sector with headquarters in Great Yarmouth, England, and it presents itself as a precision engineering business. Its public materials describe technical manufacturing services such as CNC milling and related engineering support for customers across the region and beyond. The company is associated online with AKP Ltd in Great Yarmouth, which advertises precision engineering capabilities and a long-standing industry presence. AKP was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | AKP id4hALqNOjDUvb View details | Other | leaked | |||
|
AKP is a UK-based company in the Other sector with headquarters in Great Yarmouth, England, and it presents itself as a precision engineering business. Its public materials describe technical manufacturing services such as CNC milling and related engineering support for customers across the region and beyond. The company is associated online with AKP Ltd in Great Yarmouth, which advertises precision engineering capabilities and a long-standing industry presence. AKP was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Airman Teixeira Leaks idQZCJZdBCHHI5 View details | Other | leaked | |||
|
Airman Teixeira Leaks refers to the publicly circulated set of classified document images and transcripts attributed to U.S. Airman Jack Teixeira, who posted them to Discord channels. The material is associated with Teixeira, a member of the Massachusetts Air National Guard’s 102nd Intelligence Wing in the United States, and the listing itself does not describe a commercial company, product line, or public-facing service. As a threat-intelligence catalog entry, it is best understood as a leak-themed entity in the broader other sector rather than an operating business. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Airman Teixeira Leaks idQZCJZdBCHHI5 View details | Other | leaked | |||
|
Airman Teixeira Leaks refers to the publicly circulated set of classified document images and transcripts attributed to U.S. Airman Jack Teixeira, who posted them to Discord channels. The material is associated with Teixeira, a member of the Massachusetts Air National Guard’s 102nd Intelligence Wing in the United States, and the listing itself does not describe a commercial company, product line, or public-facing service. As a threat-intelligence catalog entry, it is best understood as a leak-themed entity in the broader other sector rather than an operating business. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Agencia Nacional de Hidrocarburos idPLiOIvx7rtzi View details | Other | leaked | |||
|
Agencia Nacional de Hidrocarburos (ANH) is a Colombian public authority based in Bogotá that oversees the country’s hydrocarbons sector. Its mandate includes the integral administration of the nation’s hydrocarbon reserves and promoting the optimal, sustainable use of petroleum and gas resources. The agency also publishes sector information and operates public-facing services from its main office in the capital. In threat-intelligence listings, it was named as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Agencia Nacional de Hidrocarburos idPLiOIvx7rtzi View details | Other | leaked | |||
|
Agencia Nacional de Hidrocarburos (ANH) is a Colombian public authority based in Bogotá that oversees the country’s hydrocarbons sector. Its mandate includes the integral administration of the nation’s hydrocarbon reserves and promoting the optimal, sustainable use of petroleum and gas resources. The agency also publishes sector information and operates public-facing services from its main office in the capital. In threat-intelligence listings, it was named as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Afghanistan Papiere id5IUn8KXtEJC8 View details | Other | leaked | |||
|
Afghanistan Papiere is an Afghanistan-based entity in the Other sector, and the name is commonly used in reference to Afghan papers or document collections rather than a clearly identified commercial brand. Public material tied to the phrase “Afghanistan Papiere” points to published or reported Afghanistan-related documents, indicating an information or document-oriented subject rather than a standard industrial or consumer offering. In a threat-intelligence catalog, the listing identifies the entity by name and sector only, without asserting operational details beyond available public context. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Afghanistan Papiere id5IUn8KXtEJC8 View details | Other | leaked | |||
|
Afghanistan Papiere is an Afghanistan-based entity in the Other sector, and the name is commonly used in reference to Afghan papers or document collections rather than a clearly identified commercial brand. Public material tied to the phrase “Afghanistan Papiere” points to published or reported Afghanistan-related documents, indicating an information or document-oriented subject rather than a standard industrial or consumer offering. In a threat-intelligence catalog, the listing identifies the entity by name and sector only, without asserting operational details beyond available public context. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aerogas idMAkIpx7Xb2UA View details | Energy | leaked | |||
|
Aerogas is an energy-sector company associated with the supply of rare and specialty gases and chemicals. Public business profiles describe Aerogas GmbH as based in Mülheim an der Ruhr, Germany, and serving customers worldwide. Other corporate listings also link AEROGAS to gas-related engineering activity in the Moscow region, indicating the name may be used by more than one entity. In threat-intelligence context, Aerogas was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aerogas idMAkIpx7Xb2UA View details | Energy | leaked | |||
|
Aerogas is an energy-sector company associated with the supply of rare and specialty gases and chemicals. Public business profiles describe Aerogas GmbH as based in Mülheim an der Ruhr, Germany, and serving customers worldwide. Other corporate listings also link AEROGAS to gas-related engineering activity in the Moscow region, indicating the name may be used by more than one entity. In threat-intelligence context, Aerogas was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aerial Surveillance Footage idqHDEVQVSIrsX View details | Other | leaked | |||
|
Aerial Surveillance Footage is a name used for footage captured from aircraft, helicopters, or drones for aerial surveillance, including monitoring properties, events, public spaces, and law-enforcement operations. In commercial and public-safety settings, this type of service supports real-time observation, incident review, and broad-area situational awareness. The listing suggests an entity associated with this material in the Other sector and reflects a name tied to aerial video or surveillance operations rather than a narrowly defined industry profile. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aerial Surveillance Footage idqHDEVQVSIrsX View details | Other | leaked | |||
|
Aerial Surveillance Footage is a name used for footage captured from aircraft, helicopters, or drones for aerial surveillance, including monitoring properties, events, public spaces, and law-enforcement operations. In commercial and public-safety settings, this type of service supports real-time observation, incident review, and broad-area situational awareness. The listing suggests an entity associated with this material in the Other sector and reflects a name tied to aerial video or surveillance operations rather than a narrowly defined industry profile. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | ACPeds idTyjvzWWVgu4Z View details | Other | leaked | |||
|
ACPeds is a pediatric healthcare provider in the United States, operating in the broader medical services sector and serving children and families through pediatric care. Public reporting about similarly named pediatric practices indicates this type of organization offers outpatient clinical services and related child health support. In threat-intelligence indexing, ACPeds is treated as an Other-sector entity because the available records do not provide a more specific industry classification. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | ACPeds idTyjvzWWVgu4Z View details | Other | leaked | |||
|
ACPeds is a pediatric healthcare provider in the United States, operating in the broader medical services sector and serving children and families through pediatric care. Public reporting about similarly named pediatric practices indicates this type of organization offers outpatient clinical services and related child health support. In threat-intelligence indexing, ACPeds is treated as an Other-sector entity because the available records do not provide a more specific industry classification. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Achinsk City Government idNnORqNVT53Rd View details | Public Sector | leaked | |||
|
Achinsk City Government is the municipal administration for Achinsk, a city in Krasnoyarsk Krai, Russia, on the Chulym River west of Krasnoyarsk. As a public sector body, it provides local government services and administration for the city and its residents. In threat-intelligence contexts, municipal governments are tracked as targets because they support essential public services and civic operations. Achinsk City Government was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Achinsk City Government idNnORqNVT53Rd View details | Public Sector | leaked | |||
|
Achinsk City Government is the municipal administration for Achinsk, a city in Krasnoyarsk Krai, Russia, on the Chulym River west of Krasnoyarsk. As a public sector body, it provides local government services and administration for the city and its residents. In threat-intelligence contexts, municipal governments are tracked as targets because they support essential public services and civic operations. Achinsk City Government was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | 29 Leaks idqH9vKaAnQhiF View details | Other | leaked | |||
|
29 Leaks is a DDoSecrets collection associated with ransomware-leaked material from organizations in the Other sector, based on the United States. DDoSecrets describes its disclosures as data already published by ransomware actors, assembled from dark web leak sites and shared for transparency and research purposes. The index reflects a broader set of publicly surfaced corporate and institutional leaks rather than a single operational business profile. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aban Offshore ida15lJWGaoM4G View details | Other | leaked | |||
|
Aban Offshore Limited is an Indian offshore drilling contractor headquartered in Chennai, India, and one of the private sector’s largest players in offshore drilling. The company provides drilling and oilfield services to the oil and gas industry and operates assets such as jack-up rigs, semi-submersible rigs, drill ships, and related offshore production units. Aban Offshore was incorporated in 1986 and went public in 1988, and it describes itself as a global offshore drilling services provider. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Accent Capital idwC7jUI7UuTGg View details | Other | leaked | |||
|
Accent Capital is a private investment firm based in the Republic of Cyprus that says it invests in high-quality assets with growth potential tied to global economic and demographic trends. Its public website presents the company as an investment business focused on identifying opportunities with long-term value, while associated records show a separate Accent Capital Plc incorporated in 2019 to provide external funding support for the Accent Group. In catalog and threat-intelligence contexts, Accent Capital may therefore appear as a financial-services or investment-related entity rather than a broad operating company. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | 29 Leaks idqH9vKaAnQhiF View details | Other | leaked | |||
|
29 Leaks is a DDoSecrets collection associated with ransomware-leaked material from organizations in the Other sector, based on the United States. DDoSecrets describes its disclosures as data already published by ransomware actors, assembled from dark web leak sites and shared for transparency and research purposes. The index reflects a broader set of publicly surfaced corporate and institutional leaks rather than a single operational business profile. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Aban Offshore ida15lJWGaoM4G View details | Other | leaked | |||
|
Aban Offshore Limited is an Indian offshore drilling contractor headquartered in Chennai, India, and one of the private sector’s largest players in offshore drilling. The company provides drilling and oilfield services to the oil and gas industry and operates assets such as jack-up rigs, semi-submersible rigs, drill ships, and related offshore production units. Aban Offshore was incorporated in 1986 and went public in 1988, and it describes itself as a global offshore drilling services provider. It was listed as a ransomware victim associated with ddosecret. |
||||||
| Ransomware | Accent Capital idwC7jUI7UuTGg View details | Other | leaked | |||
|
Accent Capital is a private investment firm based in the Republic of Cyprus that says it invests in high-quality assets with growth potential tied to global economic and demographic trends. Its public website presents the company as an investment business focused on identifying opportunities with long-term value, while associated records show a separate Accent Capital Plc incorporated in 2019 to provide external funding support for the Accent Group. In catalog and threat-intelligence contexts, Accent Capital may therefore appear as a financial-services or investment-related entity rather than a broad operating company. It was listed as a ransomware victim associated with ddosecret. |
||||||