Ransomware Group intelligence
Mindware
InactiveTrack Mindware with 13 published victims and 1 known leak locations in a single intelligence view.
Overview
Mindware is tracked by Breach House as a ransomware group with 13 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | dfpc7yvle5kxmgg6sbcp5ytggy3oeob676bjgwcwhyr2pwcrmbvoilqd.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (13)
Search, filter and paginate the victim timeline for Mindware.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | willsent id3384 View details | Other | — | ||
|
willsent is a company in the broad Other sector; publicly available threat-intelligence listings do not provide a verified business description, location, or product line. In this index entry, the name appears as a ransomware victim record rather than an operational profile. The associated threat actor is Mindware, a ransomware group tracked for targeting organizations across multiple sectors. The listing identifies willsent as a ransomware victim associated with Mindware. |
|||||
| Ransomware | welplaat id3383 View details | Other | — | ||
|
Welplaat is an organization in the Netherlands classified in the Other sector. Public threat-intelligence listings identify it as a victim name associated with a ransomware exposure event. No verified public source in the provided results describes its products, services, or operating footprint in detail. The listing was recorded under the Mindware ransomware group and should be read as a threat-intelligence reference, not a confirmed breach disclosure. |
|||||
| Ransomware | toshfarms id3382 View details | Agriculture / Food | — | ||
|
Tosh Farms is an agriculture and food business based in Henry, Tennessee, with operations in pig production across Tennessee and Kentucky. Its website says the company raises pigs on more than 18,000 acres and identifies Tosh Farms as the largest pork producer in Tennessee. Public business listings place its headquarters at 1586 Atlantic Avenue, Henry, Tennessee. It was listed as a ransomware victim associated with mindware. |
|||||
| Ransomware | thebureau id3381 View details | Other | — | ||
|
thebureau is a Miami-based cannabis packaging company that designs and manufactures specialty packaging and vape hardware. Its offerings include customizable jars, tubes, bags, boxes, and all-in-one vapes for cannabis brands. Public listings describe it as a full-service product development, sourcing, design, and production business in the packaging sector. It was listed as a ransomware victim associated with mindware. |
|||||
| Ransomware | smd id3380 View details | Other | — | ||
|
SMD is an Other-sector organization; public records in the available search results do not identify a more specific industry, location, or offering. In threat-intelligence indexing, it is best described by its company name and sector only, without adding unverified operational details. Mindware is a ransomware group first reported in 2022 and associated with double-extortion activity against organizations across multiple industries. SMD was listed as a ransomware victim associated with Mindware. |
|||||
| Ransomware | simpsonplastering id3379 View details | Other | — | ||
|
Simpson Plastering, LLC is an Alabama-based subcontractor headquartered in Birmingham, with a second office in Belmont, North Carolina. The company provides stucco, EIFS, plastering, panel installation, and custom wall finish services for owners, construction companies, and general contractors. Public business listings place its core operations in Birmingham and note service coverage across the Southeast. It was listed as a ransomware victim associated with mindware. |
|||||
| Ransomware | nottco id3378 View details | Other | — | ||
|
Nott Company is a U.S.-based industrial distributor and engineering supplier headquartered in Arden Hills, Minnesota, with multiple Midwest locations. It provides fluid power products and systems, industrial power transmission products and systems, custom rubber fabricated products, and material handling equipment. Company materials also describe hydraulic system design and OEM integration services. It was listed as a ransomware victim associated with mindware. |
|||||
| Ransomware | micropakkn id3377 View details | Agriculture / Food | — | ||
|
micropakkn is an entity operating within the Agriculture and Food sector, providing services relevant to grain, livestock, or crop production in the United States. While specific location details and full offerings are not publicly documented, the entity functions as part of the broader agricultural services landscape supporting food supply chains. The organization was listed as a ransomware victim associated with the Mindware threat actor, which claimed the incident on May 5, 2022. No official confirmation of data theft or breach specifics is available from primary sources, and the entity has not issued a formal public disclosure regarding the incident. This listing serves as a neutral record of the claimed association between micropakkn and the Mindware ransomware group. |
|||||
| Ransomware | mediuscorp id3376 View details | Services | — | ||
|
Mediuscorp is a Morgan Hill, California-based services company in the printing sector, operating from 15850 Concord Circle. It describes itself as an experienced provider of print production and related services, with offerings that include printing, finishing, packaging, kitting and assembly, fulfillment, and logo merchandise. The company also promotes customer communication through its sales and customer service teams and lists a local contact number and email on its site. It was listed as a ransomware victim associated with mindware. |
|||||
| Ransomware | diager id3375 View details | Other | — | ||
|
Diager is a French manufacturing company based in Poligny, in the Jura department of Bourgogne-Franche-Comté, France. It describes itself as a leading maker of professional tools, including drilling products, and says it manufactures nearly one million tools per year. Public company profiles also place Diager in the manufacturing sector and identify its headquarters in Poligny. Diager was listed as a ransomware victim associated with Mindware. |
|||||
| Ransomware | callinc id3374 View details | Services | — | ||
|
Callinc is a U.S. services company that appears to operate in cold calling, call center, or outbound sales support based on available business listings and service descriptions. In this sector, firms typically help clients with phone outreach, lead generation, and customer contact workflows. Publicly available information about its exact offerings and location is limited. It was listed as a ransomware victim associated with Mindware. |
|||||
| Ransomware | allwell id3373 View details | Other | — | ||
|
Allwell is a U.S. Medicare Advantage product offered through local health insurers under the Wellcare by Allwell brand. It operates in multiple states and provides Medicare Part C coverage, with some plans including prescription drug, dental, vision, hearing, and other supplemental benefits. Public plan information also shows member and provider support channels and a mailing address in Van Nuys, California. The company was listed as a ransomware victim associated with Mindware. |
|||||
| Ransomware | acorentacar id3372 View details | Other | — | ||
|
Aco Rent a Car is a car rental company that operates in the United States, with locations and airport service in Miami, Fort Lauderdale, Orlando, and other markets. Its website promotes low-cost rentals, shuttle-supported airport pickups, and a range of vehicle options for travelers. Public listings also place its headquarters in Florida, reflecting a regional rental operation with multiple pickup points. It was listed as a ransomware victim associated with mindware. |
|||||