Ransomware Group intelligence
Hive
InactiveTrack Hive with 209 published victims and 3 known leak locations in a single intelligence view.
Overview
Hive is tracked by Breach House as a ransomware group with 209 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 1h ago | hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion |
| Leak location 3 | Onion service | Down checked 1h ago | hiveapi4nyabjdfz2hxdsr7otrcv6zq6m4rk5i2w7j64lrtny4b7vjad.onion |
| Leak location 1 | Onion service | Down checked 1h ago | hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion |
Top Activity Sectors (16)
- Not identified 111
- Services 20
- Healthcare / Pharma 13
- Education 12
- Communication / Marketing 10
- Manufacturing / Engineering 8
- IT 7
- Public Sector 6
- Finance / Legal / Insurance 5
- Energy 4
- Telecommunications 3
- Transportation / Travel / Logistics 3
- Construction / Real Estate 2
- Agriculture / Food 2
- Hospitality / Food & Beverage / Tourism 1
- NGOs / Associations 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Hive, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: hive uses PowerShell scripts to execute malicious commands and deploy payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: hive disables security tools like antivirus software and monitoring agents to evade detection during attacks.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: hive deletes Volume Shadow Copies and backup directories to prevent data recovery and increase pressure.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1049 System Network Connections Discovery Discovery
What they do: hive queries system network connections to map active services and identify high-value targets for encryption.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1120 Peripheral Device Discovery Discovery
What they do: hive discovers peripheral devices to locate sensitive data requiring encryption before ransomware deployment.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1135 Network Share Discovery Discovery
What they do: hive performs network share discovery to identify accessible SMB shares for lateral movement and victim data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: hive leverages SMB/Windows Admin Shares for lateral movement across networked hosts within victim environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: hive exfiltrates stolen victim data via encrypted C2 channels to enable double extortion tactics.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: hive encrypts victim files using strong symmetric cryptography to maximize impact and ransom demand.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: hive invokes system recovery inhibition commands to prevent automated backups or remediation processes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (22)
▼Software Hive has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (1)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1q4frmv39nmvdsxjnen8jm7ykgz68w7p38v5pry9 |
bitcoin | $584,731 | 2 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
HOW_TO_DECRYPT.txt
Your network has been breached and all data were encrypted.
Personal data, financial reports and important documents are ready to disclose.
To decrypt all the data and to prevent exfiltrated files to be disclosed at
http://hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion/
you will need to purchase our decryption software.
Please contact our sales department at:
http://hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion/
Login: [snip]
Password: [snip]
To get an access to .onion websites download and install Tor Browser at:
https://www.torproject.org/ (Tor Browser is not related to us)
Follow the guidelines below to avoid losing your data:
- Do not delete or reinstall VMs. There will be nothing to decrypt.
- Do not modify, rename or delete *.key files. Your data will be
undecryptable.
- Do not modify or rename encrypted files. You will lose them.
- Do not report to the Police, FBI, etc. They don't care about your business.
They simply won't allow you to pay. As a result you will lose everything.
- Do not hire a recovery company. They can't decrypt without the key.
They also don't care about your business. They believe that they are
good negotiators, but it is not. They usually fail. So speak for yourself.
- Do not reject to purchase. Exfiltrated files will be publicly disclosed.
hive.txt
Your network has been breached and all data were encrypted.
Personal data, financial reports and important documents are ready to disclose.
To decrypt all the data and to prevent exfiltrated files to be disclosed at
http://hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion/
you will need to purchase our decryption software.
Please contact our sales department at:
http://hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion/
Login: [snip]
Password: [snip]
To get an access to .onion websites download and install Tor Browser at:
https://www.torproject.org/ (Tor Browser is not related to us)
Follow the guidelines below to avoid losing your data:
- Do not modify, rename or delete *.key.rrumj files. Your data will be
undecryptable.
- Do not modify or rename encrypted files. You will lose them.
- Do not report to the Police, FBI, etc. They don't care about your business.
They simply won't allow you to pay. As a result you will lose everything.
- Do not hire a recovery company. They can't decrypt without the key.
They also don't care about your business. They believe that they are
good negotiators, but it is not. They usually fail. So speak for yourself.
- Do not reject to purchase. Exfiltrated files will be publicly disclosed.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (209)
Search, filter and paginate the victim timeline for Hive. Showing 1–100 of 209.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | R C Stevens Construction id5262 View details | Construction / Real Estate | — | ||
|
As commercial construction specialists in Orlando, we provide new construction and renovation services with an emphasis on design/build. R. C. Stevens is qualified to design and construct any type of commercial construction project in Orlando. We offer all of the necessary resources to meet each client’s specific project needs for design and construction services related to manufacturing/industrial, commercial, healthcare, financial, religious, and renovations. At. R. C. Stevens, the spirit of innovation can be found in each and every Orlando commercial construction project we do. Every team member at R.C. Stevens strives daily to uphold the founding principles of quality and integrity as having long been a company tradition since 1926. |
|||||
| Ransomware | G.W. Becker id5227 View details | Communication / Marketing | — | ||
|
***** DATA IS COMING SOON **** G.W. Becker, Inc. is a full service, single source, provider of choice for quality overhead crane products and solutions. Family owned since 1980, we have grown from a local overhead crane parts supplier to a recognized industry leader offering a full spectrum of overhead crane related products and services throughout North America. Proud to be an Executive Member of the Crane Manufacturer’s Association of America, we design and manufacture custom overhead cranes, hoists and components to CMAA Specifications (Class “A” through “F”) or AIST Technical Report #6. We utilize our knowledgeable in-house team of mechanical, structural and electrical engineers to offer application assistance, custom design engineering and manufacturing of overhead crane products with our customers’ needs first and foremost. Empowered with highly trained and qualified technicians, G.W. Becker, Inc. provides self-performing installations, inspections and field service repairs for all makes and models of overhead cranes; providing compliance with local regulations and ensuring a safe and productive material handling operation. Staying true to our mission and values, we strive to understand our customers’ needs and deliver specialized expertise and long-term planning solutions for the unique challenges of purchasing and maintaining overhead crane and hoist equipment. |
|||||
| Ransomware | Consulate Health Care id5197 View details | Healthcare / Pharma | — | ||
|
Consulate Health Care is a leading provider of senior healthcare services, specializing in post-acute care. We offer services ranging from comprehensive short-term rehabilitation and transitional care to Alzheimer’s and dementia care. Consulate Health Care began as a small provider in Cheswick, PA with a strong focus on patient needs. We haven’t waivered from that focus, which has strengthened our family and allows us to sustain jobs in many communities, create rigorous systems of care and deploy technology that makes it easier to understand patient needs. Even as we’ve grown to provide services across 5 states, it’s the little things we do while fulfilling our mission statement of "Providing Service with Our Hearts and Hands" that really makes the difference. From visiting with our patients while they eat, to pulling up the sheets to just the right height, our employees care for patients like family, not because it’s their job, but because it’s their calling. |
|||||
| Ransomware | Centro Médico Virgen De La Caridad id5163 View details | Healthcare / Pharma | — | ||
|
Grupo Centro Médico Virgen de la Caridad, a private health company with its own identity that was born in 1981 in the city of Cartagena, where it is headquartered, currently has 2 hospitals (Cartagena and Caravaca), 20 polyclinics, 23 physiotherapy clinics and 16 dental clinics , which are distributed throughout different parts of the Region of Murcia and Orihuela Costa. In addition, the group has 1 aesthetic clinic (Cartagena), plus 1 Ophthalmological clinic (Cartagena). The health entity that is committed to global, close, accessible and highly qualified care, is made up of more than 600 professionals (including health, administrative and patient care personnel) whose purpose is to offer a wide range of services on a daily basis under the better and more complete health care. All our centers are equipped with the most advanced technology, an essential support, which together with our highly qualified human capital, has made us, over almost 40 years of activity, a benchmark in private medicine in the Region of Murcia. We welcome you to Grupo Centro Médico Virgen de la Caridad, where new challenges are not a problem but a challenge for growth and improvement in private healthcare . |
|||||
| Ransomware | Camst Group id5160 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
Camst Group is a company that specializes in restaurant services. It offers catering & banqueting, restaurant & bars, catering at the fair, and collective cater. |
|||||
| Ransomware | MHMR Authority Of Brazos Valley id4956 View details | Public Sector | — | ||
|
The MHMR Authority of Brazos Valley is a public non-profit community MHMR center. Through the Texas Department of State Health Services and Texas Department of |
|||||
| Ransomware | Alvaria id4952 View details | United States | IT | — | |
|
Alvaria, (pronounced: ahl-vahr-ee-uh), a global leader delivering optimized customer experience and workforce engagement software and cloud services technology solutions. |
|||||
| Ransomware | Interface id4938 View details | United States | Other | — | |
|
**** 30% OF THE DATA IS COMING SOON **** Interface, Inc. is a global flooring company specializing in carbon neutral carpet tile and resilient flooring. Stocks: NASDAQ: TILE Equity: IF6N.F, IF6N.BE, IF6N.HA |
|||||
| Ransomware | North Idaho College id4934 View details | Education | — | ||
|
Founded in 1933, North Idaho College is a community college in Coeur d'Alene, Idaho. |
|||||
| Ransomware | Innovative Education Management id4933 View details | Education | — | ||
|
Innovative Education Management (IEM) has been successfully developing and operating California charter schools since 1998 |
|||||
| Ransomware | Dixons Allerton Academy id4932 View details | Education | — | ||
|
Dixons Allerton Academy (formerly Rhodesway Academy) is a coeducational all-through school and sixth form located in Allerton area of the City of Bradford, in the English county of West Yorkshire. |
|||||
| Ransomware | City Of Huntsville, Texas id4931 View details | Public Sector | — | ||
|
Huntsville Texas is a city in the Texas Hill Country. |
|||||
| Ransomware | JAKKS Pacific Inc id4914 View details | Communication / Marketing | — | ||
|
JAKKS Pacific, Inc. is a multi-brand company that, since 1995, has been designing, developing, producing and marketing toys, leisure products and writing instruments for children and adults around the world. The company has become a top six U.S. player in the toys and leisure products sector through product development, licensing agreements and strategic acquisitions. We believe our growth strategy is unique and built upon a concentrated effort to spread earnings across all four quarters. We have accomplished that by expanding and 'counter-seasonalizing' our product lines, adding new retail outlets and leveraging our product development and merchandising expertise on products with staying power. About JAKKS Pacific, Inc. JAKKS Pacific, Inc. is a leading designer, manufacturer and marketer of toys and consumer products sold throughout the world, with its headquarters in Santa Monica, California. JAKKS Pacific’s popular proprietary brands include: Fly Wheels®, Perfectly Cute®, ReDo Skateboard Co.®, X Power Dozer®, Disguise®, Weee-Do™ and a wide range of entertainment-inspired products featuring premier licensed properties. Through JAKKS Cares, the company’s commitment to philanthropy, JAKKS is helping to make a positive impact on the lives of children. Visit us at www.jakks.com and follow us on Instagram (@jakkstoys), Twitter (@jakkstoys) and Facebook (JAKKS Pacific). |
|||||
| Ransomware | JAKKS Pacific Inc id4914 View details | United States | Communication / Marketing | — | |
|
JAKKS Pacific, Inc. is a multi-brand company that, since 1995, has been designing, developing, producing and marketing toys, leisure products and writing instruments for children and adults around the world. The company has become a top six U.S. player in the toys and leisure products sector through product development, licensing agreements and strategic acquisitions. We believe our growth strategy is unique and built upon a concentrated effort to spread earnings across all four quarters. We have accomplished that by expanding and 'counter-seasonalizing' our product lines, adding new retail outlets and leveraging our product development and merchandising expertise on products with staying power. About JAKKS Pacific, Inc. JAKKS Pacific, Inc. is a leading designer, manufacturer and marketer of toys and consumer products sold throughout the world, with its headquarters in Santa Monica, California. JAKKS Pacific’s popular proprietary brands include: Fly Wheels®, Perfectly Cute®, ReDo Skateboard Co.®, X Power Dozer®, Disguise®, Weee-Do™ and a wide range of entertainment-inspired products featuring premier licensed properties. Through JAKKS Cares, the company’s commitment to philanthropy, JAKKS is helping to make a positive impact on the lives of children. Visit us at www.jakks.com and follow us on Instagram (@jakkstoys), Twitter (@jakkstoys) and Facebook (JAKKS Pacific). |
|||||
| Ransomware | Stolle Machinery id4913 View details | Manufacturing / Engineering | — | ||
|
**** ALL BLUEPRINTS OF ALL PRODUCT LINES WILL BE AVAILABLE SOON **** Stolle is the world's leading supplier of two piece can and end-making machinery for the global canmaking industry. Our high speed machines can be found in can plants around the world performing the value-added functions of the canmaking process. |
|||||
| Ransomware | Mark-Taylor id4845 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Expand Group id4844 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KNOX College id4782 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | INTERSPORT France id4742 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Guilford College id4661 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Norman Public Schools id4646 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hydro-Gear & Agri-Fab id4608 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | LCMH id4581 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MCCROSSAN id4559 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | APM Terminals id4542 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TCQ id4538 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ROYAL GATEWAY CO., LTD id4537 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cornwell Quality Tools id4535 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Landi Renzo id4456 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Tata Power id4388 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Município De Loures id4306 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mansfield Independent School District (MISD) id4263 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Southwell, Inc. id4251 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hendry Regional Medical Center id4244 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | JANMARINI id4242 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TAKAO-UK id4241 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GFG id4240 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TSMTU id4239 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BHARBERT id4219 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Sigmund Software id4211 View details | United States | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | New York Racing Association id4200 View details | United States | NGOs / Associations | — | |
|
No additional victim description available. |
|||||
| Ransomware | Bell Technical Solutions id4187 View details | Canada | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | FONTAINEBLEAU id4182 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | California-Oregon Telecommunications Company id4098 View details | United States | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | Eurocell id4072 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | NCG Medical id4058 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Altice International id4014 View details | Netherlands | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Baton Rouge General id4011 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Reiter Affiliated Companies id3973 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | WOOTTON ACADEMY TRUST id3963 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TriState HVAC Equipment id3952 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | ENN Group id3903 View details | China | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | CIMEX id3876 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Weidmueller id3875 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Empress EMS id3867 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | LaVan & Neidenberg id3834 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Carrolls Irish Gifts id3797 View details | Ireland | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Behavioral Health System id3793 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | FMT id3792 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CITY-FURNITURE id3791 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | RALLYE-DOM id3790 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SANDO id3775 View details | Spain | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | RTVCM id3774 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AdaptIT id3773 View details | South Africa | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Exela Technologies id3772 View details | United States | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | APETITO id3771 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | GROUP4 AUSTRALIA id3770 View details | Australia | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Authentic Brands Group id3769 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Yurtiçi Kargo id3733 View details | Türkiye | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Hamlyns Limited id3732 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | DIRECTFERRIES id3731 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | MHIRE id3730 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CAN.COM id3729 View details | Netherlands | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | AUM id3728 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KDE id3727 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | YURTICIKARGO id3726 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Massy Distribution Limited id3725 View details | Jamaica | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | WWSTEELE id3724 View details | United States | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||
| Ransomware | NETWORK4CARS id3723 View details | Netherlands | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | AG id3720 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rocky id3708 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SuperAlloy Industrial Co., Ltd. id3694 View details | United Kingdom | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||
| Ransomware | Diskriter id3693 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Alphapointe id3682 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Arte Radiotelevisivo Argentino (Artear) id3680 View details | Argentina | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Goodman Campbell Brain & Spine id3610 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | G&P Projects And Systems S.A. id3565 View details | Brazil | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Caracol TV id3564 View details | Colombia | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Travira Air id3550 View details | Indonesia | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | XEIAD id3549 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | SOUCY id3540 View details | Canada | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Guardian Fueling Technologies id3539 View details | United States | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | ChemStation International id3538 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | GUARDFUEL id3537 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | NUAIRE id3536 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | IGHQ id3535 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Yachiyo Of America id3533 View details | Japan | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | RateGain id3517 View details | India | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | SPORTPLAZA id3487 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | EIITNET id3482 View details | United States | Other | — | |
|
No additional victim description available. |
|||||