Ransomware Group intelligence
Nightspire
ActiveTrack Nightspire with 348 published victims and 11 known leak locations in a single intelligence view.
Overview
Nightspire is tracked by Breach House as a ransomware group with 348 published victims.
United States is currently the most targeted country in this dataset.
11 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (11)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 11 | Onion service | Up checked 4h ago | nspirep7orjq73k2x2fwh2mxgh74vm2now6cdbnnxjk2f5wn34bmdxad.onion |
| Leak location 10 | Onion service | Up checked 4h ago | nspire7lugml7ybqyjaaxtsgrs4qn3fcon3lrjbih6wamttvdm5ke4qd.onion |
| Leak location 4 | Onion service | Down checked 4h ago | a2lyiiaq4n74tlgz4fk3ft4akolapfrzk772dk24iq32cznjsmzpanqd.onion |
| Leak location 5 | Onion service | Down checked 4h ago | a2lyiiaq4n74tlgz4fk3ft4akolapfrzk772dk24iq32cznjsmzpanqd.onion |
| Leak location 8 | Onion service | Down checked 4h ago | nspiremkiq44zcxjbgvab4mdedyh2pzj5kzbmvftcugq3mczx3dqogid.onion |
| Leak location 9 | Onion service | Down checked 4h ago | nspiremkiq44zcxjbgvab4mdedyh2pzj5kzbmvftcugq3mczx3dqogid.onion |
| Leak location 6 | Onion service | Down checked 4h ago | nspirebcv4sy3yydtaercuut34hwc4fsxqqv4b4ye4xmo6qp3vxhulqd.onion |
| Leak location 7 | Onion service | Down checked 4h ago | nspirebcv4sy3yydtaercuut34hwc4fsxqqv4b4ye4xmo6qp3vxhulqd.onion |
| Leak location 1 | Onion service | Down checked 4h ago | nspireyzmvapgiwgtuoznlafqvlyz7ey6himtgn5bdvdcowfyto3yryd.onion |
| Leak location 2 | Onion service | Down checked 4h ago | nspireyzmvapgiwgtuoznlafqvlyz7ey6himtgn5bdvdcowfyto3yryd.onion |
| Leak location 3 | Onion service | Down checked 4h ago | nspireyzmvapgiwgtuoznlafqvlyz7ey6himtgn5bdvdcowfyto3yryd.onion |
Top Activity Sectors (17)
- Not identified 118
- Services 36
- Manufacturing / Engineering 23
- Healthcare / Pharma 19
- Finance / Legal / Insurance 18
- IT 16
- Communication / Marketing 15
- Transportation / Travel / Logistics 14
- Construction / Real Estate 12
- Hospitality / Food & Beverage / Tourism 9
- Retail / E-commerce 7
- Education 7
- NGOs / Associations 7
- Energy 7
- Public Sector 7
- Agriculture / Food 4
- Telecommunications 3
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Nightspire, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: nightspire exploits valid domain accounts harvested during initial access to authenticate against remote systems.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1059.001 PowerShell Execution
What they do: nightspire executes PowerShell scripts to automate reconnaissance, privilege checks, and payload deployment across compromised hosts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: nightspire modifies Registry Run Keys and startup folders to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: nightspire disables or modifies security tools such as EDR agents and monitoring services to hinder detection and response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: nightspire deletes Volume Shadow Copies and backup directories via system commands to prevent recovery from snapshots.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: nightspire performs remote system discovery to identify exposed services, hosts, and potential lateral movement paths.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: nightspire uses SMB/Windows Admin Shares discovery to map network shares and identify high-value targets for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: nightspire uses SMB/Windows Admin Shares for lateral movement into additional machines within the victim network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: nightspire encrypts victim files using custom ransomware routines targeting business documents, databases, and backups.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: nightspire performs internal defacement by replacing victim files with ransom notes and altered content markers.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (3)
▼Software Nightspire has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery & enumeration
Exfiltration
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
[NSPIRE_MSG].txt
NightSpire Encryption Notice Your internal servers and backup & virtual infrastructure have been fully compromised. All your files encrypted by NIGHTSPIRE Ransomware. You have 72 hours to respond. The initial payment for decryption and file deletion is 30000 USD in Bitcoin. This amount is based on your annual revenue, and this is notably less amount than all of your past hard work and effort to develop all of your products. However, the amount can be renegotiated depending on the circumstances. Our Discount Service Includes: - If you respond within 48 hours, we will provide you 30% discount as service. - If you respond within 24 hours, we will provide you 50% discount as service. "The faster you pay, the lower the ransom." That's our motto. Failure to cooperate will result in public disclosure. We possess a complete list of files and document samples that serve as proof of the access. You can see the decryption demo video and the list of copied files on our website. ------------------- About NightSpire – Cooperate: The Win-Win Resolution ------------------- Full Decryption Tool + Instructions: Universal binary decrypts all affected systems in hours. Data Deletion Proof: Timestamped logs, blockchain-verified wipe certificates—your data erased forever. Secrecy Assurances: No traces online; we expunge all references post-deal. Bonus: Security Audit Report: Detailed breach vector analysis + fixes, valued at $50K+ from legit firms. Payment Flexibility: Crypto (BTC We Offer), staged if needed—processed by our financial team. NightSpire isn't a lone hacker in a basement. We're a structured syndicate with standard operating procedures, support desks, recruiters, and analysts—like a Fortune 500 but optimized for cyber efficiency. Our reputation demands we deliver: victims who pay get results, building trust for mutual long-term gains. Non-payment erodes that, but cooperation upholds it. Security researchers and reputation confirm, we're a fully fledged cyber group... built to monetize. We honor deals to ensure repeat business across the ecosystem. --------------------------- WHAT HAPPENS IF YOU DON'T PAY ------------------------------- - The hacked news about your company will be posted on our Onion site. - Source codes of your all software products will be open source. - Your clients and partners may be notified about the data breach. - The data may be shared or sold to third parties. - You will permanently lose access to your encrypted data. - We will not provide any decryption tools or support. ----------------------------------------- CAUTION --------------------------------------------- >>> Important – Do Not DO NOT modify files. DO NOT use third-party tools. Unncessary activities cause permanent loss of your data. AES-256/RSA-4096 = impossible without our key. >>> WARNING – NO INTERMEDIARIES Do NOT use recovery or negotiation companies. They are middlemen who profit from deception. For example: They charged victims $1M Secretly negotiated with us for $200K Kept $800K for themselves. Contacting us directly = 5× lower cost. Middlemen only steal from you. Deal direct. Pay less. Resolve faster. >>> IMPORTANT – INSURANCE NOTICE Do NOT involve your cyber insurance company directly. They will sabotage negotiations to avoid paying the full policy amount. If your coverage is $10M, they will offer us $100K. We will reject it. They will refuse to increase. Result: no payment, full data leak, total damage — for you. If you anonymously inform us of your insurance limits and terms, we will NOT exceed that amount in negotiations. This guarantees: • Fast resolution • Data deletion • Full decryption • No public leak Silence only benefits the insurer. Transparency benefits you. Choose wisely. >>> CONSEQUENCES OF DATA LEAK If your data is leaked: • Government fines (GDPR, compliance, tax authorities) • Lawsuits from clients and partners • Criminal abuse of employee and customer identities • Bank fraud, loan fraud, money laundering • FBI investigations and legal exposure • Competitor espionage and business sabotage • Employee poaching and loss of trade secrets • Permanent reputation destruction Your company will bleed money, clients, trust, and stability. Statistics: 2 out of 3 companies shut down within 6 months after a major data breach. The cost of recovery is hundreds of times higher than the ransom. Paying is faster. Cheaper. Safer. Your reputation took years to build. It takes minutes to destroy. Read more about the GDRP legislation:: https://en.wikipedia.org/wiki/General_Data_Protection_Regulation https://gdpr.eu/what-is-gdpr/ https://gdpr-info.eu/ -------------------------------------------- How to Contact Us --------------------------------------------- >>> Using qTox Chat App Our qTox ID: 038F61A270B8094E713E4815C4FA5086E4AD3A021575C6F90EE65A0C123D3E3BF6926C3B59EA Our qTox ID: 8D663FD10BF662930F4C076CBF95FACFCC4ABD8F1A5E328DE75D0B0237A74E1AE1E0C5C37E7F >>> Using Tor Browser: 1. Download Tor Browser: https://www.torproject.org/ 2. Install Tor Browser: • Windows: Run the installer, launch Tor Browser, and click Connect. • macOS: Open the downloaded .dmg file, drag Tor Browser to Applications, launch it, and click Connect. • Linux: Extract the downloaded package, run ./start-tor-browser.desktop, and click Connect. • Android: Install from Google Play or torproject.org, open the app, and tap Connect. • iOS (iPhone): Install Onion Browser from the App Store, open it, and tap Connect. 3. Access the under link once connected. http://nspire7lugml7ybqyjaaxtsgrs4qn3fcon3lrjbih6wamttvdm5ke4qd.onion Login with UUID "[snip]" and password "[snip]". 4. Also introduce you to our blog site where you can learn more about us through the link below. http://nspirep7orjq73k2x2fwh2mxgh74vm2now6cdbnnxjk2f5wn34bmdxad.onion/ >>> On Mail Proton Mail: [email protected] Onion Mail: [email protected] Contact us and verify with UUID "[snip]". ----------------------------------------------------- FAQ ------------------------------------------------------ Proof? Preview + Free sample decrypts. Safe tool? Universal, tested. Data gone? Solid proof. Future attacks? Pay = gone forever + fixes. Team NightSpire.
readme.txt
Dear Management,
If you are reading this message, it means that:
- your network infrastructure has been compromised,
- sensetive data was leaked,
- files are encrypted
--------------------------------------------------------------------------
The best and only thing you can do is to contact us
to settle the matter before any losses occurs.
Onion Site:
http://nspireyzmvapgiwgtuoznlafqvlyz7ey6himtgn5bdvdcowfyto3yryd.onion
Proton Mail:
[email protected]
--------------------------------------------------------------------------
1. THE FOLLOWING IS STRICTLY FORBIDDEN
1.1 EDITING FILES.
Renaming files could DAMAGE the
cipher and decryption will be impossible.
1.2 USING THIRD-PARTY SOFTWARE.
Trying to recover with any software
can also break the cipher and
file recovery will become a problem.
--------------------------------------------------------------------------------------------------
2. EXPLANATION OF THE SITUATION
2.1 WHAT HAPPENED
We encrypted your workstations and servers to make the fact of the intrusion visible and to prevent you from hiding sensetive data leaks.
We have already downloaded a huge amount of sensetive data and analyzed it. Now its fate is up to you, it will either be deleted or sold, or shared with the media.
2.2 VALUABLE DATA WE USUALLY STEAL:
- Databases, legal documents, personal information.
- Audit reports.
- Audit SQL database
- Any financial documents (Statements, invoices, accounting, transfers etc.).
- Work files and corporate correspondence.
- Any backups.
- Confidential documents.
2.3 TO DO LIST (best practies)
- Contact us as soon as possible.
- Contact us only in our live chat, otherwise you can run into scammers.
- Purchase our decryption tool and decrypt your files. There is no other way to do this.
- Realize that dealing with us is the shortest way to success and secrecy.
- Give up the idea of using decryption help programs, otherwise you will destroy the system permanently.
- Avoid any third-party negotiators and recovery groups. They can become the source of leaks.
--------------------------------------------------------------------------------------------------
3. POSSIBLE DECISIONS
3.1 NOT MAKING THE DEAL
- After 5 days starting tomorrow your leaked data will be Disclosed or sold.
- We will also send the data to all interested supervisory organizations and the media.
- Decryption key will be deleted permanently and recovery will be impossible.
- Losses from the situation can be measured based on your annual budget.
3.2 MAKING THE WIN-WIN DEAL
- You will get the only working Decryption Tool and the how-to-use Manual.
- You will get our guarantees (with log provided) of non-recovarable deletion of all your leaked data.
- You will get our guarantees of secrecy and removal of all traces related to the deal in the Internet.
- You will get our security report on how to fix your security breaches.
--------------------------------------------------------------------------------------------------
4. HOW TO CONTACT US
4.1 Download and install TOR Browser https://torproject.org
4.2 Go to our contact form website at http://nspireyzmvapgiwgtuoznlafqvlyz7ey6himtgn5bdvdcowfyto3yryd.onion/contact.php
4.3 You can request sample files chat to review leaked data samples.
4.4 In case TOR Browser is restricted in your area use VPN services.
4.5 All leaked Data samples will be Disclosed in 7 Days if you remain silent.
4.6 Your Decryption keys will be permanently destroyed at the moment the leaked Data is Disclosed.
--------------------------------------------------------------------------------------------------
5. RESPONSIBILITY
5.1 Breaking critical points of this offer will cause:
- Deletion of your decryption keys.
- Immediate sale or complete Disclosure of your leaked data.
- Notification of government supervision agencies, your competitors and clients.
--------------------------------------------------------------------------------------------------
readme_2.txt
Hi, Your hotel is hacked! Your servers and files are locked and copied. =================================== REMEMBER! We also locked files in OneDrive. And we did not change the extensions of files in OneDrive. =================================== You cannot decrypt yourself without our key, even you're using third party software or from help of security companies. Please do not waste your time. Your files will be easily decrypted with pay. Never worry. We're waiting here with UUID [snip] Method * : [email protected] Method 1 : Our qTox ID 3B61CFD6E12D789A439816E1DE08CFDA58D76EB0B26585AA34CDA617C41D5943CDD15DB0B7E6 Method 2 : Browse our Onion Site with Tor Browser http://nspiremkiq44zcxjbgvab4mdedyh2pzj5kzbmvftcugq3mczx3dqogid.onion http://a2lyiiaq4n74tlgz4fk3ft4akolapfrzk772dk24iq32cznjsmzpanqd.onion We're waiting here with UUID [snip]
nightspire_readme.txt
-Your sensetive data are stolen and encrypted! If you pay within 3 days, we will decrypt it and also, we will not public your data. After that we will public this situation and all data. -DO NOT MODIFY FILES YOURSELF. -DO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA. -YOU MAY DAMAGE YOUR FILES, IT WILL RESULT IN PERMANENT DATA LOSS. -YOUR DATA IS STRONGLY ENCRYPTED, YOU CAN NOT DECRYPT IT WITHOUT OUR HELP. CONTACT US: Onion Mail : [email protected] qTox ID: 3B61CFD6E12D789A439816E1DE08CFDA58D76EB0B26585AA34CDA617C41D5943CDD15DB0B7E6 http://a2lyiiaq4n74tlgz4fk3ft4akolapfrzk772dk24iq32cznjsmzpanqd.onion http://nspiremkiq44zcxjbgvab4mdedyh2pzj5kzbmvftcugq3mczx3dqogid.onion Send this message first "NSPIRE[snip]" when contact with us, so to make sure it's you.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (348)
Search, filter and paginate the victim timeline for Nightspire. Showing 1–100 of 348.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Transportes Montejo S.A.S. id32399 View details | Colombia | Transportation / Travel / Logistics | — | |
|
www.transportesmontejo.com operates within the transportation, travel, and logistics sector, serving regional and commercial mobility needs in Spain. The entity provides services aligned with freight coordination, passenger movement, and supply chain logistics for the Montejo region and broader Iberian markets. As a ransomware victim indexed under threat actor nightspire, this listing reflects a cybersecurity incident classification within the threat-intelligence catalog. The description avoids speculative details regarding data exfiltration, ransom demands, or confirmed breach specifics, adhering to neutral analytical standards. This entry documents the association between the organization, its sector context, and the attributed threat actor for catalog and intelligence purposes. |
|||||
| Ransomware | Transportes Montejo S.A.S. id32399 View details | Colombia | Transportation / Travel / Logistics | — | |
|
Data is not available now. |
|||||
| Ransomware | Easyoga id32367 View details | Taiwan, Province of China | Retail / E-commerce | — | |
|
shop.easyoga.com operates within the retail and e-commerce sector, serving customers in Taiwan (country: TW). The entity functions as an online commerce platform, providing retail offerings and e-commerce services to its clientele. This listing type identifies shop.easyoga.com as a ransomware victim within the threat-intelligence index. The association with threat actor nightspire underscores the cybersecurity vulnerabilities affecting retail and e-commerce infrastructure in the region. The entry serves as a documented reference point for monitoring ransomware incidents across commercial sectors. |
|||||
| Ransomware | Easyoga id32367 View details | Taiwan, Province of China | Retail / E-commerce | — | |
|
Data is not available now. |
|||||
| Ransomware | Truckworx id32368 View details | United States | Transportation / Travel / Logistics | — | |
|
Truckworx.com operates within the United States transportation, travel, and logistics sector, providing services aligned with freight management and supply chain operations. As cataloged in this threat-intelligence index under the ransomware victim listing type, the entity is associated with threat actor Nightspire. This designation reflects the cybersecurity classification of the affected organization within the index's analytical framework. The description remains neutral regarding specific incident details, as confirmed specifics are not publicly disclosed by the entity itself. |
|||||
| Ransomware | Truckworx id32368 View details | United States | Transportation / Travel / Logistics | — | |
|
- Financial records- Accounting records- Tax records- Business operations documents- Legal/corporate records |
|||||
| Ransomware | Victory Personal Care, Inc id31959 View details | United States | — | — | |
|
Data is not available now. |
|||||
| Ransomware | Vi***** Pe****** C***, Inc id31908 View details | — | — | ||
|
Data is not available now. |
|||||
| Ransomware | T****w**x id31809 View details | — | — | ||
|
Data is not available now. |
|||||
| Ransomware | eas**** id31656 View details | United Kingdom | IT | — | |
|
Eas**** is an IT company based in the United Kingdom, providing various services to its clients. As an IT firm, eas**** likely offers a range of solutions, including software development, networking, and cybersecurity. It was listed as a ransomware victim associated with nightspire. |
|||||
| Ransomware | eas**** id31656 View details | United Kingdom | IT | — | |
|
Data is not available now. |
|||||
| Ransomware | Tianji Auto Care Service Company id31650 View details | Türkiye | Transportation / Travel / Logistics | — | |
|
Tianji Auto Care Service Company operates in the transportation sector, providing auto care services in Turkey. As a company in the travel and logistics industry, it plays a role in supporting the movement of people and goods. Tianji Auto Care Service Company was listed as a ransomware victim associated with nightspire. |
|||||
| Ransomware | Tianji Auto Care Service Company id31650 View details | Türkiye | Transportation / Travel / Logistics | — | |
|
Data is not available now. |
|||||
| Ransomware | T***w**x id31459 View details | United States | IT | — | |
|
T***w**x is an IT company based in the United States, providing various IT services and solutions. The company operates in the IT sector, offering its services to clients across the country. T***w**x is listed as a ransomware victim associated with nightspire. |
|||||
| Ransomware | T***w**x id31459 View details | United States | IT | — | |
|
Data is not available now. |
|||||
| Ransomware | The Mountain id30988 View details | United Kingdom | Transportation / Travel / Logistics | — | |
|
The Mountain Company is a travel company based in the United Kingdom, operating in the transportation and logistics sector, offering various travel services. The company provides travel packages and itineraries, catering to different client needs. The Mountain Company was listed as a ransomware victim associated with nightspire. |
|||||
| Ransomware | The Mountain id30988 View details | United Kingdom | Transportation / Travel / Logistics | — | |
|
- HR & Payroll Data- Financial & Accounting Records- Payment & Credit Card Data- Customer & CRM Data- Orders & Supply Chain Data- SharePoint & Business Application Data |
|||||
| Ransomware | Kates Nussman Ellis Earle & Landolfi LLP id30989 View details | United States | Services | — | |
|
Katesnussman.com is a services company based in the United States, offering various services to its clients. The company operates in the services sector, providing support to its customers. Katesnussman.com was listed as a ransomware victim associated with nightspire. |
|||||
| Ransomware | Kates Nussman Ellis Earle & Landolfi LLP id30989 View details | United States | Services | — | |
|
Data is not available now. |
|||||
| Ransomware | Akribis Systems Pte Ltd id30975 View details | Singapore | Manufacturing / Engineering | — | |
|
Akribis Sys is a company based in Singapore, operating in the manufacturing and engineering sector. The company likely provides specialized systems and services to clients in its industry. Akribis Sys was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | Akribis Systems Pte Ltd id30975 View details | Singapore | Manufacturing / Engineering | — | |
|
- All Motor Designs- CAD Files- Employee & HR Sensitive Data- Legal & Compliance- Machine Details |
|||||
| Ransomware | Thai Seng International Co. Ltd id30976 View details | Thailand | Manufacturing / Engineering | — | |
|
Thaiseng.co.th is a Thailand-based company operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Thaiseng.co.th was listed as a ransomware victim associated with nightspire. |
|||||
| Ransomware | Thai Seng International Co. Ltd id30976 View details | Thailand | Manufacturing / Engineering | — | |
|
- Administration documents from Thaiseng International Co, Ltd- Marketing data which includes client information. |
|||||
| Ransomware | MKS Transformator id30977 View details | Türkiye | Manufacturing / Engineering | — | |
|
MKS Ltd is a company operating in the manufacturing and engineering sector, based in Turkey. The company likely provides various services and products related to its sector. MKS Ltd was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | MKS Transformator id30977 View details | Türkiye | Manufacturing / Engineering | — | |
|
- Accounting / Finance Documents- Projects Data, Purchasing / Procurement Documents- Quality / Document Control- Maintenance, and HR documents- Production / Manufacturing Data |
|||||
| Ransomware | OPTIDEA GmbH id30978 View details | Switzerland | IT | — | |
|
Optidea is an IT company based in Switzerland, offering various services in the IT sector. The company operates in the Swiss market, providing solutions to its clients. Optidea was listed as a ransomware victim associated with nightspire. |
|||||
| Ransomware | OPTIDEA GmbH id30978 View details | Switzerland | IT | — | |
|
- Internal Document- Financial & HR Documents- Design Data |
|||||
| Ransomware | Furama Bukit Bintang id30979 View details | Malaysia | Hospitality / Food & Beverage / Tourism | — | |
|
Furama Bukit Bintang is a hotel located in the heart of Kuala Lumpur, Malaysia, offering accommodations and services to the hospitality and tourism sector. As part of the Food & Beverage and Tourism industry, it provides various amenities to its guests. Furama Bukit Bintang was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | Furama Bukit Bintang id30979 View details | Malaysia | Hospitality / Food & Beverage / Tourism | — | |
|
- Executive Data- HR Data and Documents- Data for IT Department |
|||||
| Ransomware | K. Venkatesh, Co id30980 View details | India | IT | — | |
|
Cavenkatesh.com is an Indian entity operating in the IT sector, providing various services. The company is based in India and offers services related to the IT industry. Cavenkatesh.com was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | K. Venkatesh, Co id30980 View details | India | IT | — | |
|
- Internal Documents |
|||||
| Ransomware | Wings Argo Private Limited id30981 View details | India | Agriculture / Food | — | |
|
Wings Projects Agro operates in the agriculture and food sector in India, providing various offerings to its clients. The company is involved in activities related to the agricultural industry, catering to the needs of the food sector. Wings Projects Agro was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | Wings Argo Private Limited id30981 View details | India | Agriculture / Food | — | |
|
Wings Production DB |
|||||
| Ransomware | KSL Dirtworks LLC id30982 View details | United States | Construction / Real Estate | — | |
|
KSL Dirtworks operates in the construction and real estate sector in the United States, providing various services. The company is involved in dirt work and other construction-related activities. KSL Dirtworks was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | KSL Dirtworks LLC id30982 View details | United States | Construction / Real Estate | — | |
|
- HR Documents- Financial Documents- Contracts- Bids & Proposals- Project Documents- Office Documents- Construction Standards- Insurance Documents |
|||||
| Ransomware | Diffusion de Produits Inoxydables id30983 View details | France | IT | — | |
|
dpinox.fr is a French company operating in the IT sector, providing various services to its clients. As an IT company, dpinox.fr likely offers a range of services including software development, consulting, and technology solutions. dpinox.fr was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | Diffusion de Produits Inoxydables id30983 View details | France | IT | — | |
|
- Bank account details- Digital certificate- Financial records- Employee/HR records- Customer and supplier data- Contracts and quotations |
|||||
| Ransomware | TFG Benefits, Inc. id30984 View details | United States | Finance / Legal / Insurance | — | |
|
Tfgbenefits is a US-based company operating in the finance, legal, and insurance sector, providing various benefits and services to its clients. The company is headquartered in the United States and offers a range of financial and insurance products. Tfgbenefits was listed as a ransomware victim associated with nightspire. |
|||||
| Ransomware | TFG Benefits, Inc. id30984 View details | United States | Finance / Legal / Insurance | — | |
|
- Employee PII- Payroll- Benefits- Financials- Client HR- Identity Docs |
|||||
| Ransomware | Auto Royal Company id30774 View details | Italy | Transportation / Travel / Logistics | — | |
|
Autoroyalcompany.it operates in the transportation and logistics sector in Italy, providing services to facilitate the movement of goods and people. As a company in this sector, it plays a crucial role in the country's economy. Autoroyalcompany.it was listed as a ransomware victim associated with nightspire. |
|||||
| Ransomware | Auto Royal Company id30774 View details | Italy | Transportation / Travel / Logistics | — | |
|
More than 100GB of SQLInfinity Database |
|||||
| Ransomware | Cedar Crest College id30557 View details | United States | Education | — | |
|
Cedarcrest College is a private liberal arts college located in the United States, offering a range of academic programs to students. As an educational institution, it provides various courses and degree programs in different fields. Cedarcrest College was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | Cedar Crest College id30557 View details | United States | Education | — | |
|
Data is not available now. |
|||||
| Ransomware | Webosphere id30524 View details | India | IT | — | |
|
Webosphere.in is an Indian IT company, presumably offering various information technology services. The company operates in the IT sector, providing services to clients in India. Webosphere.in was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | Webosphere id30524 View details | India | IT | — | |
|
-SQL Database- Source Code |
|||||
| Ransomware | PCCC Realty LLC id30357 View details | United States | Construction / Real Estate | — | |
|
PCCC Realty LLC operates in the construction and real estate sector in the United States, providing various services related to property development and management. As a company in this sector, PCCC Realty LLC is involved in activities such as property acquisition, construction, and leasing. PCCC Realty LLC was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | PCCC Realty LLC id30357 View details | United States | Construction / Real Estate | — | |
|
Data is not available now. |
|||||
| Ransomware | Grupo Riquelme id30026 View details | Paraguay | Transportation / Travel / Logistics | — | |
|
Gruporiquelme.com is a company operating in the transportation, travel, and logistics sector in Paraguay. The company likely provides services such as cargo transportation, travel arrangements, and logistics management. Gruporiquelme.com was listed as a ransomware victim associated with nightspire |
|||||
| Ransomware | Grupo Riquelme id30026 View details | Paraguay | Transportation / Travel / Logistics | — | |
|
- Full Database Backup- Banking & Financial Data- Accounting & Ledger Records- Customer Databases- HR / Workforce Data- User, Role & Permission data- ERP & Critical Business Application Data |
|||||
| Ransomware | Artistic Smiles id30072 View details | United States | NGOs / Associations | — | |
|
Data is not available now. |
|||||
| Ransomware | legendsmn(Blue Ox, Paul Bunyan, Lumberjack Electric) id29988 View details | United States | Retail / E-commerce | — | |
|
Data is not available now. |
|||||
| Ransomware | dean cosmetic dentistry id29989 View details | United States | Healthcare / Pharma | — | |
|
Data is not available now. |
|||||
| Ransomware | Guy E******* & F*******, P.A id29948 View details | Finance / Legal / Insurance | — | ||
|
Data is not available now. |
|||||
| Ransomware | Central Texas ***** ***** id29949 View details | Energy | — | ||
|
Data is not available now. |
|||||
| Ransomware | Ri***** Co**** Europe S.r.l. id29950 View details | Retail / E-commerce | — | ||
|
Data is not available now. |
|||||
| Ransomware | B****S I******t***l id29906 View details | Finance / Legal / Insurance | — | ||
|
Data is not available now. |
|||||
| Ransomware | Sheraton Miramar Resort El Gouna id29907 View details | Egypt | Hospitality / Food & Beverage / Tourism | — | |
|
Data is not available now. |
|||||
| Ransomware | G**** R****l*e id29908 View details | Construction / Real Estate | — | ||
|
Data is not available now. |
|||||
| Ransomware | Silsbee Police Department id29857 View details | United States | Education | — | |
|
Court Information |
|||||
| Ransomware | K****** County. Mi**e**ta id29858 View details | United States | Public Sector | — | |
|
Data is not available now. |
|||||
| Ransomware | WaxWorks Inc id29859 View details | United States | IT | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Blue Nile Medical Center id29860 View details | United States | Healthcare / Pharma | — | |
|
More than 3000+ Patient's EHR Records |
|||||
| Ransomware | Pattono S.r.l id29809 View details | Italy | Manufacturing / Engineering | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Sierra West Jewelers id29810 View details | United States | Retail / E-commerce | — | |
|
Data is not available now. |
|||||
| Ransomware | GRIP Outreach For Youth id29684 View details | United States | NGOs / Associations | — | |
|
- Financial & Accounting Records- Sensitive Employee- Youth Participant & Child Protection Records- Governance & Legal Documents |
|||||
| Ransomware | Unique Litho, Inc id29685 View details | United States | Manufacturing / Engineering | — | |
|
Data is not available now. |
|||||
| Ransomware | A*** G*** A*S* id29686 View details | Agriculture / Food | — | ||
|
Data is not available now. |
|||||
| Ransomware | ASIA STRATEGIC id29687 View details | Finance / Legal / Insurance | — | ||
|
Data is not available now. |
|||||
| Ransomware | First Mutual Holdings id29643 View details | Zimbabwe | Finance / Legal / Insurance | — | |
|
- Internal Database |
|||||
| Ransomware | Krum Public Library id29645 View details | United States | Education | — | |
|
- Financial Documents- HR Data- Supervisor's Information |
|||||
| Ransomware | basatamfi id29505 View details | Egypt | Other | — | |
|
Data is not available now. |
|||||
| Ransomware | Red-Line id29358 View details | United States | Other | — | |
|
- QuickBooks Files- Scanned tax returns- Proposal, Contrats- QuickBooks automated backups |
|||||
| Ransomware | Qua****Pro id29359 View details | IT | — | ||
|
Data is not available now. |
|||||
| Ransomware | la familia adualt day center id29360 View details | United States | Healthcare / Pharma | — | |
|
Data is not available now. |
|||||
| Ransomware | Pat**** S.r.l id29361 View details | Other | — | ||
|
Data is not available now. |
|||||
| Ransomware | Si**** West J******* id29362 View details | Retail / E-commerce | — | ||
|
Data is not available now. |
|||||
| Ransomware | Bresme Madrid S.L. id29363 View details | Spain | IT | — | |
|
Data is not available now. |
|||||
| Ransomware | Papa John's Egypt id29364 View details | Egypt | Hospitality / Food & Beverage / Tourism | — | |
|
- Banking & Financial Records- Personal data- Critical POS Data |
|||||
| Ransomware | Rawaj Consumer Finance id29365 View details | Egypt | Finance / Legal / Insurance | — | |
|
- Sales Related Documents- Human Resources- Sensitive Employee Records- Email and SMS Data |
|||||
| Ransomware | Ueno Fine Chemicals Industry id29366 View details | Thailand | Manufacturing / Engineering | — | |
|
Ueno Fine Chemicals Industry Ltd. is a Japan-based manufacturing company with operations in Thailand and other markets, and its English site presents the company’s business profile and product information. The company develops and manufactures chemical products and LCP-related materials, with research, production, and quality-control functions across its operations. Its Thailand business is described as serving food additives and chemical products, reflecting a broader industrial and engineering-oriented manufacturing footprint. It was listed as a ransomware victim associated with nightspire. |
|||||
| Ransomware | Ueno Fine Chemicals Industry (Thailand), Ltd. id29996 View details | Thailand | Manufacturing / Engineering | — | |
|
- Financial & Accounting Records- Human Resources- Sales & Marketing |
|||||
| Ransomware | Vantage Energy LLC id29235 View details | United States | Other | — | |
|
Data is not available now. |
|||||
| Ransomware | C***r*o T**uc**n* id29236 View details | Other | — | ||
|
Data is not available now. |
|||||
| Ransomware | m***o*ul id29237 View details | Other | — | ||
|
Data is not available now. |
|||||
| Ransomware | Huse Incorporated id29245 View details | United States | Other | — | |
|
- MSSQL-DB- HR Documents- Contracts |
|||||
| Ransomware | TAKOSAN OTOMOBIL id29246 View details | Türkiye | Other | — | |
|
- Technical Documents- Financial Sheets- Contracts & Invoices- Business strategy files |
|||||
| Ransomware | A**** F***** Plas**** id28327 View details | Manufacturing / Engineering | — | ||
|
Data is not available now. |
|||||
| Ransomware | Filter to A**** F***** Plas**** id28360 View details | Manufacturing / Engineering | — | ||
|
Data is not available now. |
|||||
| Ransomware | The Country Club of Darien id28392 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
- Sales / agent / commercial operations- Industrial / manufacturing / tooling business data- Research & development / technical project data- Business admin / office operations- Software / digital assets / branding |
|||||
| Ransomware | Progressive Oral Surgery & Implantology id28413 View details | United States | Healthcare / Pharma | — | |
|
Data is not available now. |
|||||
| Ransomware | P**g**s***e O*al S**g**y & I**la**ol**y id28586 View details | Healthcare / Pharma | — | ||
|
Data is not available now. |
|||||
| Ransomware | J**es **l*o id28587 View details | Construction / Real Estate | — | ||
|
Data is not available now. |
|||||
| Ransomware | Swansea Ambulance Corps id28637 View details | United Kingdom | Healthcare / Pharma | — | |
|
Data is not available now. |
|||||
| Ransomware | The **u***y C*** o* **r**n id28638 View details | Agriculture / Food | — | ||
|
Data is not available now. |
|||||
| Ransomware | S***s*a A**ul***e C***s id28284 View details | Healthcare / Pharma | — | ||
|
Data is not available now. |
|||||
| Ransomware | D-Troy Logistics id28204 View details | Mexico | Transportation / Travel / Logistics | — | |
|
- Internal Documents- Employee Data |
|||||
| Ransomware | BK Tomorrow id28190 View details | United States | Services | — | |
|
Source Code of BK Tomorrow |
|||||
| Ransomware | Sahara Air Products id28076 View details | United States | Communication / Marketing | — | |
|
- Confidential Technical Drawings- Documents- Customer invoices- Shipment Histories |
|||||
| Ransomware | *W* **L LLC id28029 View details | Construction / Real Estate | — | ||
|
Data is not available now. |
|||||
| Ransomware | Cabinet d’Étude en Sécurité Pyrotechnique id27939 View details | France | Manufacturing / Engineering | — | |
|
Data is not available now. |
|||||