Ransomware Group intelligence

ImNotAVillain

Active

Track ImNotAVillain with 2 published victims and 1 known leak locations in a single intelligence view.

BREACH HOUSE ALERTS
Want an alert every time a new ransomware post is published?
Choose the feeds and the countries you care about — we email you when they move.
Victims 2 Known published victims in this dataset
First discovered 2026-09-24 Earliest victim discovery date
Last discovered 2026-09-24 Latest victim discovery date
Inactive since 0 days Days since the latest known victim
Top country United Kingdom 1 victims
Known locations 1 Leak or negotiation infrastructure tracked

Overview

ImNotAVillain is tracked by Breach House as a ransomware group with 2 published victims.

United Kingdom is currently the most targeted country in this dataset.

1 known leak locations are currently associated with this group.

Leak Status Distribution

  • Leaked 0 0.0%
  • Pending 2 100.0%
  • Deleted 0 0.0%

Top Countries

Interactive distribution based on the currently visible victims list.

Top Countries
Distribution

    Known Leak Locations (1)

    Label Type Availability Links
    Leak location 1 Onion service Unknown o6rtgcjdjqyimjxexpejddhdfbehsjn4fcsazfkgwydeb27gqhtdntyd.onion

    Top Activity Sectors (1)

    Victims (2)

    Search, filter and paginate the victim timeline for ImNotAVillain. Showing 1–2 of 2.

    Type Target Discovered Country Business Category Intel Link Leak status
    Ransomware Revolut id33143 View details United Kingdom Finance / Legal / Insurance pending
    Ransomware Italy id33144 View details Italy — pending