Ransomware Group intelligence
Devman
InactiveTrack Devman with 207 published victims and 3 known leak locations in a single intelligence view.
Overview
Devman is tracked by Breach House as a ransomware group with 207 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | qljmlmp4psnn3wqskkf3alqquatymo6hntficb4rhq5n76kuogcv7zyd.onion |
| Leak location 2 | Onion service | Unknown | devmanblggk7ddrtqj3tsocnayow3bwnozab2s4yhv4shpv6ueitjzid.onion |
| Leak location 3 | Onion service | Unknown | wugurgyscp5rxpihef5vl6b6m5ont3b6sezhl7boboso2enib2k3q6qd.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (207)
Search, filter and paginate the victim timeline for Devman.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Crystal Coast Pain Management id26099 View details | United States | Services | ||
|
SSN, medical data, medical cards |
|||||
| Ransomware | ENCOMPASS-INC id26083 View details | United States | Finance / Legal / Insurance | ||
|
Finance documents, clients PII |
|||||
| Ransomware | woodwardoralsurgery.com id26006 View details | Svalbard and Jan Mayen | Healthcare / Pharma | ||
|
Patient data, med cards |
|||||
| Ransomware | wjnklaw.com id26003 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] N/A |
|||||
| Ransomware | consultaegis.com id25906 View details | United States | Transportation / Travel / Logistics | ||
|
The data contains materials of national security including BIO laboratory facilities blue prints, and infromation regardless US army nitroglycerin supply chain. |
|||||
| Ransomware | zallc.org id25905 View details | United States | Finance / Legal / Insurance | ||
|
PII data, SSN´s financial and audit reports. |
|||||
| Ransomware | ***vandenberg.com id25887 View details | United States | Other | ||
|
Client data, HR data |
|||||
| Ransomware | **ps.net id25886 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | tiw-group.com id25882 View details | Svalbard and Jan Mayen | Services | ||
|
[AI generated] TIW Group is a specialist software firm with over 30 years of experience in developing solutions for the insurance industry. Their flagship product, ALIS, provides end-to-end solutions for life insurance and annuity processing. Additionally, they provide business process automation, legacy modernization, and risk compliance management services. Their digital solutions help businesses to streamline operations and improve business efficiency. |
|||||
| Ransomware | z*l*c.o*g id25881 View details | United States | Finance / Legal / Insurance | ||
|
PII data, SSN´s financial and audit reports. |
|||||
| Ransomware | twi-group.com id25859 View details | United States | Transportation / Travel / Logistics | ||
|
[AI generated] TWI Group is a specialized freight forwarder and logistics provider that primarily focuses on the trade show industry. The company provides a wide range of services, including domestic and international transportation, on-site handling, customs clearance, and more. Based in Nevada, USA, TWI operates globally reaching more than 180 countries. They are recognized for their expertise in managing logistics for all sizes of trade show exhibits. |
|||||
| Ransomware | c*n**lta**i*.com id25834 View details | United States | Transportation / Travel / Logistics | ||
|
The data contains materials of national security including BIO laboratory facilities blue prints, and infromation regardless US army nitroglycerin supply chain. |
|||||
| Ransomware | cs.at id25831 View details | Austria | Finance / Legal / Insurance | ||
|
Insurance data, Hr data, client data |
|||||
| Ransomware | **.at id25808 View details | Austria | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | ****cr*nem*ds.c*m id25734 View details | Svalbard and Jan Mayen | Healthcare / Pharma | ||
|
Patient data, medical cards clinic records |
|||||
| Ransomware | ***-gr*up.com id25733 View details | Svalbard and Jan Mayen | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | automax.com id25668 View details | India | Communication / Marketing | ||
|
[AI generated] AutoMax.com is a leading used car dealership group in the US. Known for its wide range of high-quality pre-owned vehicles, AutoMax.com provides affordable options with comprehensive auto inspection and warranty. They offer financing options for all credit situations. The company is committed to delivering excellent customer service through its knowledgeable and friendly staff. |
|||||
| Ransomware | Syrmasgs id25667 View details | India | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | ***m*sic.fi id25666 View details | Finland | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.****law.com id25665 View details | United States | Finance / Legal / Insurance | ||
|
No additional victim description available. |
|||||
| Ransomware | ***om****s-***.com id25664 View details | United States | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | www.mims.com id25663 View details | Senegal | Healthcare / Pharma | ||
|
[AI generated] Mims.com is an online resource for medical professionals used mainly in Asia-Pacific and Middle East regions. It provides latest drug information and medical news, with a database featuring information about thousands of prescription medications. It also offers feature articles, opinion pieces and continuing medical education (CME) activities. It's extensively used by doctors, pharmacists, nurses and students. |
|||||
| Ransomware | www.saundersandsaunders.com id25662 View details | United States | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Tvgoiania id25654 View details | Brazil | Communication / Marketing | ||
|
[AI generated] Tvgoiania is a media and news company based in Goiânia, Brazil. It provides a platform for local news, events, and updates significant to the Goiania area. The company offers a variety of media content in the form of live shows, news broadcasts, publications, and web content. Tvgoiania operates primarily in Portuguese language. |
|||||
| Ransomware | NSSF id25653 View details | Svalbard and Jan Mayen | Retail / E-commerce | ||
|
NSSF is a retail and e-commerce entity associated with Sweden, a market where online commerce is widely used across consumer and business sales channels. Sweden’s retail sector is characterized by strong e-commerce adoption and modern payment and platform infrastructure, supporting digital storefronts and transaction processing. In that context, NSSF fits within a sector focused on online merchandising, customer ordering, and commerce operations. It was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | klhindustries.com id25459 View details | United States | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | pronaca.com id25454 View details | Svalbard and Jan Mayen | Communication / Marketing | ||
|
Financial, contracts HR data |
|||||
| Ransomware | consigaz.com.br id25453 View details | Brazil | Energy | ||
|
[AI generated] Consigaz is a Brazilian company that specializes in the distribution of Liquefied Petroleum Gas (LPG) for both industrial and residential use. They offer services such as cooking gas delivery and installation of gas systems for businesses. The company is committed to safety and environmental responsibility, using advanced technology for efficient gas handling and distribution. Consigaz operates across several Brazilian states. |
|||||
| Ransomware | sealbeachca.gov id25452 View details | United States | Other | ||
|
Datatheft 300gb of data stollen includes gov documents, deeds and much more |
|||||
| Ransomware | sealbeachpd.com id25451 View details | United States | Other | ||
|
data theft, evidence, officers personal information police reports, DEA open cases information |
|||||
| Ransomware | ******m*di*al.com id25450 View details | United States | Healthcare / Pharma | ||
|
Patients data, plastic operations data, SSNs |
|||||
| Ransomware | ****t*lc*a*tpm.com id25449 View details | Svalbard and Jan Mayen | Healthcare / Pharma | ||
|
Financial, patients data, HR data |
|||||
| Ransomware | s***p.com id25448 View details | Svalbard and Jan Mayen | Other | ||
|
Case data, atourney client data, hr data |
|||||
| Ransomware | Intonu.com id25180 View details | United States | Finance / Legal / Insurance | ||
|
Financial, Hr documents, claims |
|||||
| Ransomware | oppor**nity*****.org id25179 View details | United States | Healthcare / Pharma | ||
|
Patients data, financial data |
|||||
| Ransomware | Jennings SD id25178 View details | United States | Finance / Legal / Insurance | ||
|
Financial data, HR data |
|||||
| Ransomware | sharinc.org id25177 View details | United States | Finance / Legal / Insurance | ||
|
Financial, Custommer data |
|||||
| Ransomware | kavi.fi id25092 View details | Finland | Other | ||
|
HR data |
|||||
| Ransomware | i**o**.us id25091 View details | United States | Finance / Legal / Insurance | ||
|
Financial, Hr documents, claims |
|||||
| Ransomware | ***ind***es.com id25090 View details | United States | Other | ||
|
Hr data, client data |
|||||
| Ransomware | Clínica Dávila id25016 View details | Chile | Healthcare / Pharma | ||
|
Patients' full records, HIV test results, IDs. Throughout a long waiting period, and despite a vast number of phone calls and emails sent by our team to the hospital, we have seen no action from the clinic to resolve the issue - knowing that the HIV tests could potentially change the lives of people whose relatives, friends, and workplaces will... |
|||||
| Ransomware | k*v*.fi id25005 View details | Finland | Other | ||
|
HR data |
|||||
| Ransomware | transrocamar.com id24989 View details | Spain | Finance / Legal / Insurance | ||
|
Financial, Client IDS |
|||||
| Ransomware | British Holiday & Home Parks Association Ltd id24988 View details | United Kingdom | NGOs / Associations | ||
|
Passport scans, Financial |
|||||
| Ransomware | consult*****.c** id24956 View details | United States | Finance / Legal / Insurance | ||
|
Financial, HR data |
|||||
| Ransomware | *n**e-ai id24955 View details | China | Other | ||
|
SRC, Client data |
|||||
| Ransomware | ****s*oc****.com id24954 View details | Spain | Finance / Legal / Insurance | ||
|
Financial, Client IDS |
|||||
| Ransomware | Culinary Jet Concierge id24937 View details | France | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | beausejourco-op.crs id24880 View details | Canada | Finance / Legal / Insurance | ||
|
Financial, HR |
|||||
| Ransomware | d*v***.cl id24879 View details | Chile | Healthcare / Pharma | ||
|
Patients full records, HIV tests results, ID's |
|||||
| Ransomware | Axion50plus id24859 View details | Canada | Finance / Legal / Insurance | ||
|
Financial, HR data, Client data |
|||||
| Ransomware | Jet ******** id24858 View details | France | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Productos Lácteos Flor de Aragua CA id24806 View details | VZ | Communication / Marketing | ||
|
HR data, clients data, Financial data |
|||||
| Ransomware | a**o*50*****.org id24805 View details | Canada | Finance / Legal / Insurance | ||
|
Financial, HR data, Client data |
|||||
| Ransomware | b**u**jou***-**.crs id24804 View details | Canada | Finance / Legal / Insurance | ||
|
Financial, HR |
|||||
| Ransomware | DXS SYSTEMS id24782 View details | United Kingdom | Services | ||
|
[AI generated] N/A |
|||||
| Ransomware | CANCER id24760 View details | Brazil | Finance / Legal / Insurance | ||
|
Financial data, clients data |
|||||
| Ransomware | ***-***tems.*** id24759 View details | United Kingdom | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Quezon Power id24719 View details | Philippines | Energy | ||
|
Employee data, hr info, projects, Work logs of the power plants, Scada SRC |
|||||
| Ransomware | Hopital La Rabta id24718 View details | Tunisia | Healthcare / Pharma | ||
|
[AI generated] Hopital La Rabta is a major hospital located in Tunis, Tunisia. It provides a wide array of medical services to the Tunisian population. The hospital prides itself on its team of highly skilled and dedicated medical professionals who utilize advanced medical equipment to effectively diagnose and treat diseases. It offers surgical services, specialty medicine, emergency care, and outpatient services. |
|||||
| Ransomware | Hopital ** ***** id24697 View details | Tunisia | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | C*NC*R id24696 View details | Brazil | Finance / Legal / Insurance | ||
|
Financial data, clients data |
|||||
| Ransomware | www.digital****.com id24695 View details | United States | IT | ||
|
Data theft 80gb |
|||||
| Ransomware | Village Santé Saint Joseph Hospital id24662 View details | France | Healthcare / Pharma | ||
|
patient data |
|||||
| Ransomware | fassic.org id24661 View details | France | Finance / Legal / Insurance | ||
|
Financial Records, Med cards, Hr documents |
|||||
| Ransomware | Inter care id24660 View details | United States | Healthcare / Pharma | ||
|
Full quickbooks dump, patients data, and financial data |
|||||
| Ransomware | solidere id24553 View details | Lebanon | Construction / Real Estate | ||
|
[AI generated] Solidere, short for Société Libanaise de Développement et Reconstruction, is a Lebanese joint stock company responsible for the reconstruction, development, and management of Beirut’s Central District. Created in 1994, the firm is entrusted with restoring Beirut's historical buildings, attracting investments, and promoting tourism. It effectively serves as a private real estate company, but granted with governmental powers for urban development. |
|||||
| Ransomware | hopital-*********.com id24542 View details | France | Healthcare / Pharma | ||
|
Financial data, medical records |
|||||
| Ransomware | f***i*.o*g id24541 View details | France | Finance / Legal / Insurance | ||
|
Financial Records, Med cards, Hr documents |
|||||
| Ransomware | arko.no id24540 View details | Norway | Other | ||
|
Datatheft Client DB |
|||||
| Ransomware | S**** Saint ****** id24539 View details | France | Healthcare / Pharma | ||
|
Financial data, medical cards |
|||||
| Ransomware | cpasch.com id24418 View details | United States | Other | ||
|
Ransom: 200gb 150k |
|||||
| Ransomware | n*w*****.com id24367 View details | Other | |||
|
Ransom: 200gb 220k |
|||||
| Ransomware | ravand.com id24366 View details | Canada | Other | ||
|
Ransom: 75k 50gb |
|||||
| Ransomware | Abdulhadi Hospital id24329 View details | Jordan | Healthcare / Pharma | ||
|
Ransom: ecaretest.com 350k 246gb |
|||||
| Ransomware | newhorizonsmedical.org id24328 View details | United States | Healthcare / Pharma | ||
|
Ransom: 90k 236gb |
|||||
| Ransomware | www.eastersealsnei.org id24327 View details | United States | Other | ||
|
Ransom: 550k 280gb |
|||||
| Ransomware | m*tt**ca**r**.**.it id24326 View details | Other | |||
|
Ransom: 75k 50gb |
|||||
| Ransomware | c*a*c*.c*m id24325 View details | Other | |||
|
Ransom: 200gb 150k |
|||||
| Ransomware | a*f*o.us id24324 View details | Other | |||
|
Ransom: 250k 200gb |
|||||
| Ransomware | gsccca.org id24124 View details | United States | Other | ||
|
Ransom: 500gb 400k |
|||||
| Ransomware | procure.com id24122 View details | United States | Communication / Marketing | ||
|
Ransom: data theft 40gb 120K |
|||||
| Ransomware | future.com.bo id24003 View details | Bolivia, Plurinational State of | Other | ||
|
Ransom: 200k 120gb |
|||||
| Ransomware | mcchemical.com id23997 View details | United States | Manufacturing / Engineering | ||
|
mcchemical.com is the website of MidContinental Chemical Company, Inc. (MCC), a US-based manufacturer headquartered in Olathe, Kansas. The company produces and distributes petroleum additives designed to improve the performance of fuels and lubricating oils in vehicles, equipment, and machinery. MCC has operated since 1994 and supports research and product development alongside sales, marketing, and supply chain functions. In threat-intelligence listings, mcchemical.com was identified as a ransomware victim associated with devman. |
|||||
| Ransomware | MCC id24581 View details | United States | Manufacturing / Engineering | ||
|
Ransom: 200k 80gb |
|||||
| Ransomware | f*t*r*.com.** id23936 View details | Other | |||
|
Ransom: 300k 120gb |
|||||
| Ransomware | ****clinic.com.** id23935 View details | Healthcare / Pharma | |||
|
Ransom: 210k 145gb |
|||||
| Ransomware | ctfc.cat id23814 View details | Spain | Other | ||
|
Ransom: 248000 30gb of files exfiltrated |
|||||
| Ransomware | omniumint.com id23787 View details | United States | Other | ||
|
Omnium International is an independent professional services firm focused on project management, commercial management, contract management, cost consultancy, quantity surveying, and dispute resolution. Its website says it serves clients across Dubai, Abu Dhabi, Saudi Arabia, the UK, Europe, and Cyprus, with international offices supporting its work. Available directory and company listings place Omnium International in the business services category and identify the firm as headquartered outside the US, while this index lists omniumint.com under a US ransomware victim entry. It was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | omniumint id24580 View details | United States | Other | ||
|
Ransom: 1.2million 1.2 tb and one very interesting email |
|||||
| Ransomware | www.oucru.org id23621 View details | Viet Nam | Other | ||
|
Ransom: 500k 120gb |
|||||
| Ransomware | www.heitech.com.my id23583 View details | Malaysia | IT | ||
|
Ransom: 500k 60gb |
|||||
| Ransomware | m*c*e*ic*l.com id23553 View details | Other | |||
|
Ransom: 50gb 100k |
|||||
| Ransomware | o*c*u.o** id23541 View details | Other | |||
|
Ransom: 500k 120gb |
|||||
| Ransomware | juntalocal.cdmx.gob.mx id23540 View details | Mexico | Other | ||
|
Ransom: 60gb 300k |
|||||
| Ransomware | h*tel*ys*e*s.pl id23451 View details | Other | |||
|
Ransom: data theft 400k |
|||||
| Ransomware | fhw.org id23438 View details | United States | Other | ||
|
Ransom: 700k 120gb |
|||||
| Ransomware | h*i**c*.c*m.my id23437 View details | Other | |||
|
Ransom: 500k 60gb |
|||||
| Ransomware | r*p**fl*wa*ps.com id23436 View details | Other | |||
|
Ransom: oracle theft 200k |
|||||
| Ransomware | g*e*g*o**l.com id23435 View details | Other | |||
|
Ransom: oracle theft 400k |
|||||
| Ransomware | pharmaciedesalizes.fr id23173 View details | France | Healthcare / Pharma | ||
|
pharmaciedesalizes.fr appears to be a French pharmacy-related healthcare site in the healthcare/pharma sector, reflecting the role of pharmacies in France’s broader healthcare system. In France, pharmacies dispense prescription and over-the-counter medicines and provide health advice and other patient-facing services within the national health framework. The site is therefore best understood as part of France’s healthcare and pharmaceutical services environment, with a local presence in France. It was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | pharmaciedesalize.com.fr id24579 View details | France | Healthcare / Pharma | ||
|
Ransom: 50k 80gb |
|||||
| Ransomware | www.o****m*nt.com id23161 View details | Other | |||
|
Ransom: 1400000 USD |
|||||
| Ransomware | EMBASY OF BOLIVIA DC id23127 View details | Bolivia, Plurinational State of | Other | ||
|
Ransom: 200k 400gb |
|||||
| Ransomware | regionalurology.com id23126 View details | United States | Other | ||
|
Ransom: 200k 300gb |
|||||
| Ransomware | ****** embassy D.C id23065 View details | Other | |||
|
Ransom: 200000 USD |
|||||
| Ransomware | r******urology.com id22964 View details | Other | |||
|
Ransom: 250k 300gb |
|||||
| Ransomware | forestry.gov.jm id22963 View details | Jamaica | Other | ||
|
Ransom: 200000 USD |
|||||
| Ransomware | naturmaelk.dk id22832 View details | Denmark | Other | ||
|
Naturmælk is a Danish dairy company based in Tinglev, South Denmark, that is owned by the farmers who supply its milk. It operates as an organic dairy and produces milk and dairy products with an emphasis on sustainability, transparency, climate, biodiversity, and animal welfare. Company information and contact details identify Naturmælk as a small, ambitious mejeri serving the Danish market. Naturmælk (naturmaelk.dk) was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | naturmaelk id24578 View details | Denmark | Other | ||
|
Ransom: 550000 USD |
|||||
| Ransomware | teeuwissen.com id22790 View details | Netherlands | Other | ||
|
Ransom: 370k 80gb |
|||||
| Ransomware | www.hameshakem.co.il id22787 View details | Israel | Other | ||
|
Ransom: 6kk 400gb exfiltrated |
|||||
| Ransomware | www.profimetrics.com id22707 View details | Portugal | Communication / Marketing | ||
|
Ransom: 50000 USD |
|||||
| Ransomware | e***.o*g id22706 View details | Other | |||
|
Ransom: 50000 USD |
|||||
| Ransomware | t*t*a**o**.com id22704 View details | Other | |||
|
Ransom: 500000 USD |
|||||
| Ransomware | a**h*y*in*er**t**nal.c*m id22703 View details | Other | |||
|
Ransom: 150000 USD |
|||||
| Ransomware | www.wrapex.ca id22660 View details | Canada | Other | ||
|
Wrapex Industrial Services Incorporated is a Canadian industrial services company based in Alberta, with locations in Edmonton, Rocky Mountain House, and Lloydminster. It provides industrial insulation, glycol tracing, utilidor, scaffolding, shrink wrapping, and access solutions for construction, maintenance, and turnaround projects across western Canada. Public company descriptions also place it in the construction sector and identify it as a private firm serving energy, petrochemical, pulp, and paper clients. It was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | wrapex id24577 View details | Canada | Other | ||
|
Ransom: 780000 USD |
|||||
| Ransomware | pestbusters.com.sg id22644 View details | Singapore | Other | ||
|
PestBusters Singapore is a Singapore-based pest control company that provides pest control services not in connection with agriculture. Company records also note secondary construction-installation activity, and its office is registered at 139 Cecil Street, #05-01 YSY Building, Singapore. Its website describes it as one of Singapore’s leading providers of pest control services, with NEA-compliant protocols and services for residential and commercial clients. In threat-intelligence indexing, pestbusters.com.sg was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | www.braswellsvc.com id22643 View details | United States | Other | ||
|
Braswell Services LLC is a Texas-based U.S. company operating in support services and logistics, with business lines that include procurement, manufacturing, kitting, transportation, and storage-related services. Public company listings also describe it as serving vehicle and industrial needs, including components, accessories, and related repair or freight activities. The company is associated with New Boston and the Hooks, Texas area, reflecting a regional operational footprint in the United States. In the threat-intelligence index, Braswell Services was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | braswellsvc id24576 View details | United States | Other | ||
|
Ransom: 120000 USD | Note: 300gb exfiltrated |
|||||
| Ransomware | busaba.com id22642 View details | United Kingdom | Other | ||
|
Busaba.com is the website of Busaba Eathai Limited, a London-based Thai restaurant group in the UK hospitality sector. The company presents itself as a modern Bangkok dining brand built around Thai cooking, with restaurant services and a customer-facing privacy policy that references bookings, enquiries, offers and events. Public company data places Busaba Eathai Limited in London, England, and classifies it as a licensed restaurant business. It was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | busaba id24575 View details | United Kingdom | Other | ||
|
Ransom: 580000 USD |
|||||
| Ransomware | www.chicagobotanic.org id22641 View details | United States | Other | ||
|
Chicago Botanic Garden is a nonprofit public garden in Glencoe, Illinois, in the United States, centered on a 385-acre landscape with 27 to 28 themed gardens and related visitor areas. It offers seasonal walks, tram tours, a café, a garden shop, plant information resources, membership, and educational programs, classes, and workshops for visitors and members. The site supports garden visits, learning activities, and plant discovery through collections, plant profiles, and conservation-related content. It was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | chicagobotanic id24574 View details | United States | Other | ||
|
Ransom: 590000 USD |
|||||
| Ransomware | r3consulting.com id22640 View details | United States | Services | ||
|
r3consulting.com is the website of R3 Government Solutions, a professional services company based in Arlington, Virginia, United States. The firm says it provides services and solutions that help agencies address difficult staffing and organizational challenges, with work in federal human capital, human resources, and training. Company listings also place it in the Services sector and describe it as a US-based business with offices in Arlington and Marco Island. It was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | r3consulting id24573 View details | United States | Services | ||
|
Ransom: 350000 USD | Note: 400gb stollen |
|||||
| Ransomware | ncgllc.com id22639 View details | United States | Services | ||
|
Ransom: 100000 USD |
|||||
| Ransomware | n**u***e**.dk id22638 View details | Other | |||
|
Ransom: 590000 USD |
|||||
| Ransomware | sacada.org id22637 View details | United States | Other | ||
|
Ransom: 100000 USD |
|||||
| Ransomware | promisedland.com.tw/h21 million USD...Time Remaining:---BUY Files id22416 View details | Taiwan, Province of China | Communication / Marketing | ||
|
1000000 USD |
|||||
| Ransomware | www.shimaogroup.com id22415 View details | China | Services | ||
|
91000000 USD |
|||||
| Ransomware | www.p***e*u**h***.us id22414 View details | United States | Other | ||
|
1700000 USD |
|||||
| Ransomware | www.s*i***gr*u*.com id22156 View details | Other | |||
|
91000000 USD |
|||||
| Ransomware | promisedland.com.tw id22109 View details | Taiwan, Province of China | Communication / Marketing | ||
|
1000000 USD |
|||||
| Ransomware | www.pure-chemical.com id22108 View details | India | Manufacturing / Engineering | ||
|
5000000 USD |
|||||
| Ransomware | ruff.com.br id21529 View details | Brazil | Other | ||
|
1000000 USD |
|||||
| Ransomware | www.diethelmtravel.com id21528 View details | Thailand | Transportation / Travel | ||
|
www.diethelmtravel.com is the website of DTH Travel, formerly Diethelm Travel, a Thailand-based destination management company in the transportation and travel sector. The company provides tailor-made holidays, inbound travel services, and destination management across Asia, serving leisure and business travelers from its Bangkok base. Public directory and company materials describe a long-standing regional travel operator with offices and local partnerships in multiple Asian markets. It was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | diethelmtravel id24572 View details | Thailand | Transportation / Travel | ||
|
1800000 USD |
|||||
| Ransomware | kw****.tw id21482 View details | Taiwan, Province of China | Other | ||
|
1000000 USD |
|||||
| Ransomware | pr*****.tw id21481 View details | Taiwan, Province of China | Communication / Marketing | ||
|
1050000 USD |
|||||
| Ransomware | b*u*l*****.tw id21480 View details | Taiwan, Province of China | Other | ||
|
1100000 USD |
|||||
| Ransomware | ***.c*m.tw id21479 View details | Taiwan, Province of China | Other | ||
|
6000000 USD |
|||||
| Ransomware | pt.elis.com id21252 View details | Portugal | Other | ||
|
4000000 USD |
|||||
| Ransomware | pt.e*i*.com id21228 View details | Other | |||
|
4000000 USD |
|||||
| Ransomware | mol.go.th id21207 View details | Thailand | Other | ||
|
15000000 USD |
|||||
| Ransomware | eehc.gov.eg id21156 View details | Egypt | Other | ||
|
2270000 USD |
|||||
| Ransomware | solidere.com id21129 View details | Lebanon | Other | ||
|
Solidere is a Lebanese real estate company based in Beirut, with its headquarters in the Beirut Central District. The company’s stated objective is to acquire real estate properties and to finance and execute infrastructure works in the Beirut Central area, supporting redevelopment and related urban projects. Its website, solidere.com, serves as the company’s corporate presence and information channel. In threat-intelligence listings, solidere.com was associated with a ransomware victim entry tied to devman. |
|||||
| Ransomware | www.e***.gov.eg id21128 View details | Other | |||
|
2270000 USD |
|||||
| Ransomware | sol*d*r*.com id21108 View details | Other | |||
|
7250000 USD |
|||||
| Ransomware | Hong Kong Victim id20983 View details | Hong Kong | Other | ||
|
(To be disclosed)... |
|||||
| Ransomware | China Harbour Engineering Company id20982 View details | China | Manufacturing / Engineering | ||
|
450000 USD |
|||||
| Ransomware | TBD HONG KONG id20981 View details | Hong Kong | Other | ||
|
TBD... |
|||||
| Ransomware | c****gl*b*.com id20980 View details | Other | |||
|
1000000 USD |
|||||
| Ransomware | takachiho.co.jp id20979 View details | Japan | Other | ||
|
1000000 USD |
|||||
| Ransomware | elematec.com id20978 View details | Japan | Other | ||
|
Elematec Corporation is a Japan-based integrated service company in the electronics industry, headquartered in Tokyo, Japan. It describes itself as providing electronics-related services supported by a long-established client base and on-site capabilities, with offices and group operations across Japan and overseas. The company’s corporate information and network pages show a global business footprint spanning Asia and the Americas. Elematec.com was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | elematec id24571 View details | Japan | Other | ||
|
10000000 USD |
|||||
| Ransomware | gotec.com id20977 View details | Switzerland | Other | ||
|
GOTEC Group is a specialist in surface treatment and bonding-agent coating for rubber, metal, and plastic parts, with a global industrial footprint across Europe, the Americas, and Asia. Its headquarters are in Wülfrath, Germany, and the company operates production and sales locations in multiple countries, including Switzerland-related business activity. Public company profiles describe GOTEC as a supplier to automotive and industrial customers, focused on coating and adhesion solutions for technical components. The domain gotec.com was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | gotec id24570 View details | Switzerland | Other | ||
|
6450000 USD |
|||||
| Ransomware | NSSF KENYA /nssf.zip - first samle /nssfwriteup.html - writeup id20517 View details | Kenya | Other | — | |
|
NSSF Kenya is Kenya’s National Social Security Fund, a public-sector social security institution based in Kenya that administers social protection services for workers and employers. In threat-intelligence catalogs, it is referenced with related sample or writeup labels such as nssf.zip and nssfwriteup.html, which are used to index the incident record rather than describe the organization’s operations. The listing places the entity in the “Other” sector and frames it as a ransomware-related target in Kenya. It was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | DHL THAILAND id20391 View details | Thailand | Other | — | |
|
TBD |
|||||
| Ransomware | lantro.com id20373 View details | Japan | Other | — | |
|
1.1 million USD |
|||||
| Ransomware | dmbarone.com id20251 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
130k USD |
|||||
| Ransomware | Gobierno del Estado de Colima id20238 View details | Mexico | Other | — | |
|
TBD |
|||||
| Ransomware | www.nijar.es id20217 View details | Spain | Other | — | |
|
TBD |
|||||
| Ransomware | www.paragonradiology.com id20200 View details | United States | Other | — | |
|
200k USD |
|||||
| Ransomware | netstar.co.za id20199 View details | South Africa | Other | — | |
|
Netstar is a South African company in the transport and security technology space, best known for vehicle tracking and stolen-vehicle-recovery services. It says it pioneered the industry in South Africa in 1994 and provides nationwide customer support from offices in Midrand and other locations across the country. The company also references business and personal contact services through its website and branded regional offices. In threat-intelligence records, netstar.co.za was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | netstar id24569 View details | South Africa | Other | — | |
|
1.2 million USD |
|||||
| Ransomware | NSSF KENYA id20137 View details | Kenya | Other | — | |
|
4.5 million USD |
|||||
| Ransomware | TBD KOREA id20135 View details | Korea, Republic of | Other | — | |
|
TBD |
|||||
| Ransomware | TBD HONK KONG id20134 View details | Hong Kong | Other | — | |
|
TBD |
|||||
| Ransomware | TBD GREECE id20133 View details | Greece | Other | — | |
|
TBD |
|||||
| Ransomware | TOHO-CO id20132 View details | Japan | Other | — | |
|
120k |
|||||
| Ransomware | TBD KENYA id20131 View details | Kenya | Other | — | |
|
TBD |
|||||
| Ransomware | piriou.vn id20130 View details | Viet Nam | Other | — | |
|
Piriou Vietnam is a shipbuilding company based in Ho Chi Minh City, Vietnam, with operations also associated with Long An province. It builds medium-sized aluminum and steel vessels to European standards, emphasizing high added value and competitive pricing. Company materials describe it as PIRIOU VIETNAM, formerly SEAS South East Asia Shipyard, and place it in the ship and boat building sector. The entity was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | piriou id24568 View details | Viet Nam | Other | — | |
|
383K USD |
|||||
| Ransomware | tvgoiania.com.br id19966 View details | Brazil | Other | — | |
|
80K USD |
|||||
| Ransomware | Pienaar Brothers id19959 View details | South Africa | Other | — | |
|
590K USD |
|||||
| Ransomware | Victim from Japan id19958 View details | Japan | Other | — | |
|
TBD |
|||||
| Ransomware | dailynews.co.th id19944 View details | Thailand | Other | — | |
|
dailynews.co.th is the online edition of Daily News, a Thai-language daily newspaper based in Bangkok and distributed nationwide. Its website publishes general news coverage for Thailand, including latest news, breaking stories, sports, entertainment, health, and current affairs. The publication describes itself as an internet daily newspaper offering broad news analysis and up-to-date reporting for readers in Thailand. In threat-intelligence listings, dailynews.co.th appears as a ransomware victim associated with devman, with Thailand recorded as the country and Other as the sector. |
|||||
| Ransomware | DAILY NEWS THAILAND id24567 View details | Thailand | Other | — | |
|
375K USD |
|||||
| Ransomware | gmanetwork.com id19934 View details | Philippines | Telecommunications | — | |
|
gmanetwork.com is the official website of GMA Network, Inc., a Philippine media and broadcasting company based in Quezon City, Metro Manila. GMA Network operates television and radio services and presents news, entertainment, and corporate information through its public web presence. The company describes itself as the Philippines' leading broadcast network, with a broad portfolio of programs and media-related businesses. In threat-intelligence catalogs, gmanetwork.com was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | GMA NETWORK id24566 View details | Philippines | Telecommunications | — | |
|
2.5 million USD |
|||||
| Ransomware | https://www.gmanetwork.com/news/ id19933 View details | Philippines | Other | — | |
|
https://www.gmanetwork.com/news/ is the official news portal of GMA Network, one of the largest television and media networks in the Philippines, delivering latest Philippine and international news coverage. The site offers real-time updates on politics, business, science, technology, and entertainment, serving audiences across the Philippines and globally. It operates from Quezon City and is recognized as a leading and trusted source for broadcast and digital news in the country. The portal was listed as a ransomware victim associated with the threat actor devman. |
|||||
| Ransomware | https://pestbusters.com.sg/ id19740 View details | Singapore | Other | — | |
|
PestBusters is one of Singapore's leading providers of pest control services, combining expertise with rigorous, NEA-compliant protocols for residential and commercial clients. For over 30 years, the company pioneered high-quality pest control in Singapore, delivering excellent service with compliance to environmental health and safety standards. As Asia's leading pest management experts, PestBusters offers innovative and comprehensive pest management services across the region. The company was listed as a ransomware victim associated with the threat actor devman. |
|||||
| Ransomware | pestbusters id24564 View details | Singapore | Other | — | |
|
100K USD |
|||||
| Ransomware | smvthailand.com id19685 View details | Thailand | Other | — | |
|
375K USD |
|||||
| Ransomware | Chinese Healthcare Organisation id19680 View details | China | Healthcare / Pharma | — | |
|
TBD |
|||||
| Ransomware | Singapour Factory id19679 View details | Singapore | Manufacturing / Engineering | — | |
|
TBD |
|||||
| Ransomware | South African IT firm id19652 View details | South Africa | Other | — | |
|
TBD |
|||||
| Ransomware | South African Hr company id19651 View details | South Africa | Services | — | |
|
TBD |
|||||
| Ransomware | dovesit.co.za id19650 View details | South Africa | Other | — | |
|
550k USD |
|||||
| Ransomware | EU victim id19342 View details | Other | — | ||
|
(To be discoled) |
|||||
| Ransomware | China Harbour Engeneiring Company FILE SAMPLE 1 avaliable /CHEC/CHECsample.zip id19326 View details | China | Services | — | |
|
China Harbour Engineering Company Ltd. (CHEC) is a Beijing-based Chinese services and infrastructure contractor founded in 1980 and part of China Communications Construction Company Ltd. It provides EPC, BOT, and PPP services across marine engineering, dredging and reclamation, roads and bridges, railways, airports, and related civil works. The company also supports public and private sector infrastructure projects with equipment supply and installation and broader engineering services. China Harbour Engeneiring Company FILE SAMPLE 1 avaliable /CHEC/CHECsample.zip was listed as a ransomware victim associated with devman. |
|||||
| Ransomware | Premier Meats South Africa id19268 View details | South Africa | Communication / Marketing | — | |
|
(90k USD) |
|||||
| Ransomware | Feel Four id19267 View details | Singapore | Other | — | |
|
60k USD |
|||||
| Ransomware | Singapour Victim id19266 View details | Singapore | Other | — | |
|
(To be discoled) |
|||||
| Ransomware | Honk Kong Victim id19265 View details | Hong Kong | Other | — | |
|
(To be discoled) |
|||||
| Ransomware | China Harbour Engeneiring Company id19264 View details | China | Services | — | |
|
450k USD |
|||||
| Ransomware | FEELFOUR id19143 View details | Singapore | Other | — | |
|
70k USD |
|||||
| Ransomware | Med institute id19142 View details | Education | — | ||
|
Price -Soon |
|||||
| Ransomware | Bangkok Electronics Co., Ltd id19141 View details | Thailand | Services | — | |
|
200k USD |
|||||
| Ransomware | Tawasol id19140 View details | Egypt | Other | — | |
|
150k USD |
|||||
| Ransomware | Dubai Company id19010 View details | United Arab Emirates | Services | — | |
|
Different Locker |
|||||
| Ransomware | Texas Construction Firm id19009 View details | United States | Construction / Real Estate | — | |
|
Name disclosed soon |
|||||
| Ransomware | Optimax Technology id19008 View details | Taiwan, Province of China | IT | — | |
|
Pending |
|||||
| Ransomware | doumen.fr id19007 View details | France | Other | — | |
|
Still in negotiation |
|||||