Ransomware Group intelligence
Ragnarlocker
InactiveTrack Ragnarlocker with 128 published victims and 4 known leak locations in a single intelligence view.
Overview
Ragnarlocker is tracked by Breach House as a ransomware group with 128 published victims.
France is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Onion service | Up checked 1h ago | ragnarnwvli32xnmwudsvhbl7klzmofxeylyhcqfc5ifx5mbybq3ekqd.onion |
| Leak location 2 | Onion service | Up checked 1h ago | rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion |
| Leak location 3 | Onion service | Down checked 1h ago | p6o7m73ujalhgkiv.onion |
| Leak location 1 | Onion service | Down checked 1h ago | rgleak7op734elep.onion |
Top Activity Sectors (16)
- Not identified 48
- Services 35
- Communication / Marketing 8
- Manufacturing / Engineering 7
- Finance / Legal / Insurance 6
- IT 6
- Construction / Real Estate 3
- Telecommunications 3
- Retail / E-commerce 2
- Energy 2
- Transportation / Travel / Logistics 2
- Agriculture / Food 2
- Education 1
- Healthcare / Pharma 1
- Public Sector 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (13)
▼How Ragnarlocker typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Ragnar Locker.
-
T1059.003 Windows Command Shell Execution
What they do: Ragnar Locker has used cmd.exe and batch scripts to execute commands.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1569.002 Service Execution Execution
What they do: Ragnar Locker has used sc.exe to execute a service that it creates.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Ragnar Locker has used sc.exe to create a new service for the VirtualBox driver.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1218.007 Msiexec Stealth
What they do: Ragnar Locker has been delivered as an unsigned MSI package that was executed with msiexec.exe.
What that means: Adversaries may abuse msiexec.exe to proxy execution of malicious payloads.
-
T1218.010 Regsvr32 Stealth
What they do: Ragnar Locker has used regsvr32.exe to execute components of VirtualBox.
What that means: Adversaries may abuse Regsvr32.exe to proxy execution of malicious code.
-
T1218.011 Rundll32 Stealth
What they do: Ragnar Locker has used rundll32.exe to execute components of VirtualBox.
What that means: Adversaries may abuse rundll32.exe to proxy execution of malicious code.
-
T1564.006 Run Virtual Instance Stealth
What they do: Ragnar Locker has used VirtualBox and a stripped Windows XP virtual machine to run itself.
What that means: Adversaries may carry out malicious operations using a virtual instance to avoid detection.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Ragnar Locker has attempted to terminate/stop processes and services associated with endpoint security products.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1120 Peripheral Device Discovery Discovery
What they do: Ragnar Locker may attempt to connect to removable drives and mapped network drives.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1614 System Location Discovery Discovery
What they do: Before executing malicious code, Ragnar Locker checks the Windows API GetLocaleInfoW and doesn't encrypt files if it finds a former Soviet country.
What that means: Adversaries may gather information in an attempt to calculate the geographical location of a victim host.
-
T1486 Data Encrypted for Impact Impact
What they do: Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Ragnar Locker has attempted to stop services associated with business applications and databases to release the lock on files used by these applications so they may be encrypted.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Ragnar Locker can delete volume shadow copies using vssadmin delete shadows /all /quiet.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (11)
▼Software Ragnarlocker has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery & enumeration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (4)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
13nmJ3SsNB5pSyQrmX3e6zveY9kHGw8Vs3 |
bitcoin | $4,517,994 | 2 |
19kcqKevFZhiX7NFLa5wAw4JBjWLcpwp3e |
bitcoin | $3,980,534 | 2 |
1CG8RAqNaJCrmEdVLK7mm2mTuuK28dkzCU |
bitcoin | $1,481,197 | 4 |
151Ls8urp6e2D1oXjEQAkvqogSn3TS8pp6 |
bitcoin | $899,289 | 1 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
ragnarlocker1.txt
***************************************************************************************************************
HELLO [snip] !
If you reading this message, it means your network was PENETRATED and all of your files and data has been ENCRYPTED
-------------------------------------------------
| |
| by R A G N A R L O C K E R ! |
| |
-------------------------------------------------
***************************************************************************************************************
[ YOU HAVE TO CONTACT US via LIVE CHAT IMMEDIATELY TO RESOLVE THIS CASE AND MAKE A DEAL ]
(contact information you will find at the bottom of this notes)
**** WARNING ****
DO NOT Modify, rename, copy or move any files or you can DAMAGE them and decryption will be impossible.
DO NOT Use any third-party or public Decryption software, it also may DAMAGE files.
DO NOT Shutdown or Reset your system, it can DAMAGE files
---------------------------------------------------------------------
----[WHAT'S HAPPENED]
Your security perimeter was BREACHED and all files on your critically important servers and hosts were completely ENCRYPTED.
Also we has DOWNLOADED about 500GB of your's most SENSITIVE Data just in case if you will NOT PAY, than everything will be PUBLISHED in Media and/or SOLD to any third-party.
We have collected the most important info such as:
-Accounting files, Financial Reports, Banking and Billing statements, HR documents, Payrolls, AFIP/ASIF databases
-Logistics Files, SQL Databases, ID cards, DL's, Transport Documents, Certificates of Transport Ministry, Phonebooks
-Confidential Agreements, Corporate Contracts, WorkFiles, Clients Information, License Keys, Surveillance cameras video
-Also we have your Private emails in .msg and .pst files and a lot of other Sensitive info.
----[WHAT SHOULD YOU DO]
- You have to contact us as soon as possible(you can find contacts below), we are offering discounts for quick deals so price can be better if you will respect our time.
- You should purchase our decryption tool, so will be able to restore your files. Without our Decryption keys it's impossible.
- You should make a Deal with us, to avoid your Data leakage.
- You should stay away from any third-parties recovery soft, since it could damage files.
- You should avoid any scammers using our name in different communication ways. We communicate only via LIVE CHAT
----[YOUR OPTIONS]
#1 If NO contact or Deal made in 3(three) Days than all your Data will be Published and/or Sold to any third-parties, Decryption key will be deleted permanently and recovery will be impossible.
Also this would be disastrous consequences to your's business reputation.
#2 If we make a Deal:
We will provide you with the Decryption Key and Manual how-to-use.
We will remove all your files from our file-storage with proof of Deletion and delete posts regarding your company with Guarantee to avoid any Data Leaks to public or to any third-parties.
Also we will help you to improve the security measures and provide you with the technical report and list of security-recommendations.
----
[There are couple of screenshots just as a proofs of data possession, you can find more in our Leak Blog]
Screenshots:
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
---------------------------------------------------------------------
Leak Blog Access:
This temporary post stays hidden only during 4(four) days until we make a Deal. Later, if we don't make a Deal it would be supplemented and become permanent and accessible for everyone.
Leak Blog: http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?[snip]
Password: [snip]
(use Tor Browser to open the link)
======================================================================
[ HERE IS THE SIMPLE MANUAL HOW TO GET CONTACT WITH US VIA LIVE CHAT ]
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
a) Download and install TOR browser from this site : https://torproject.org
b) For contact us via LIVE CHAT open our website : http://ragnarjtm25k3w4cy6kvfttfhm24mpynikjt7yll5pvpfo4a7yuzweyd.onion/client/?[snip]
c) To visit TEMPORARY LEAK PAGE with your data on our News Blog, open this website: http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?[snip]
password: [snip]
d) If Tor is restricted in your area, use VPN
e) All your Data will be published in 4(four) Days if NO contact made
f) Your Decryption keys will be permanently destroyed in 4(four) Days if no contact made
When you open LIVE CHAT website follow rules :
Follow the instructions on the website.
At the top you will find CHAT tab.
Send message to us and wait for response (we are not online 24/7, So you have to wait for your turn).
*We advise you to find some information about us in google and also check the tab "About Us" in our Blog (http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?about-us)
***********************************************************************************
---A PRIVATE KEY---
[snip]
---Z PRIVATE KEY---
***********************************************************************************
!_^_README_NOTES_RAGNAR_^_!.txt
********************************************************************************************************************
HELLO [snip] !
If you reading this message, it means your network was PENETRATED and your most sensitive files were COMPROMISED
-------------------------------------------------
| |
| by R A G N A R L O C K E R ! |
| |
-------------------------------------------------
********************************************************************************************************************
[ YOU HAVE TO CONTACT US via LIVE CHAT IMMEDIATELY TO RESOLVE THIS CASE AND MAKE A DEAL ]
(contact information you will find at the bottom of this notes)
**** WARNING ****
DO NOT Hire any third-party negotiators (recovery/FBI/police and etc), otherwise we will close chat immediately and Publish your Data.
---------------------------------------------------------------------------------------------------------------------------------------
----[WHAT'S HAPPENED]
With this message we want to let you know that we has obtained access everywhere in your network and we was able to encrypt your files and servers.
However, we didn't do that only because of willing to avoid interruption in hospitals normal business processes and don't put health of the patients under risk.
But unfortunately, you has allowed data leak, about 1TB of personal data was compromised. So, your clients didn't get the required protection.
Tottally we has DOWNLOADED about 1TB of your CONFIDENTIAL and most SENSITIVE Data just in case if you will NOT PAY, if so, than everything will be PUBLISHED in Media and/or SOLD to any third-party.
WE HAS COLLECTED SUCH DATA AS:
- Medical record, medical history, Information regarding diagnoses and surgeries
- Clients personal info: Relatives/Address/DOB/email/phones and etc., Private letters and correspondence
- Departments: Oncology, Pediatrics, Surgery, Urology, Oculist, Cardiology, Gynecology and others
- Financial reports, Revenue, Budgets, Payrolls, Expenses, Bank statements
- Databases, Credentials, access to emails and accounts, Passwords, Workfiles
- And many other sensitive data...
----[WHAT SHOULD YOU DO]
- You have to contact us as soon as possible (you can find contacts below)
- You should make a Deal with us, to avoid LEAK of your Sensitive Data
- You should avoid any scammers using our name in different communication ways. We communicate only via LIVE CHAT
- You should avoid any third-party negotiators and recovery groups
----[YOUR OPTIONS]
1) IF NO CONTACT OR DEAL MADE IN 3 DAYS:
All your Data will be Published and/or Sold to any third-parties
Information regarding vulnerabilities of your network also can be published and/or sold
Such Leakage will have disastrous consequences to your business reputation.
2) If WE MAKE A DEAL:
We will remove all your files from our file-storage with proof of Deletion
We will permanently delete post with your company name
We guarantee to avoid sharing any details with third-parties
We will provide you with the penetration report and list of security-recommendations
[Here are couple of screenshots just as a proofs of Data possession, you can find more in our Leak Blog]
Screenshots:
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
-------------------------------------------------------------------------------------------------------------
LEAK BLOG ACCESS:
This temporary post stays hidden only during 3(three) days until we make a Deal.
If the Deal not made, Post would be supplemented and become permanent and accessible for everyone!
LEAK BLOG: http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?[snip]
Password: [snip]
(use Tor Browser to open the link)
======================================================================
[ HERE IS THE SIMPLE MANUAL HOW TO GET CONTACT WITH US VIA LIVE CHAT ]
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
1) Download and install TOR browser from this site : https://torproject.org
2) For contact us via LIVE CHAT open our website : http://ragnarmj3hlykxstyanwtgf33eyacccleg45ctygkuw7dkgysict6xyd.onion/client/?[snip]
3) To visit TEMPORARY LEAK PAGE with your data on our Leaks Blog
open this website: http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?[snip]
password: [snip]
4) If Tor is restricted in your area, use VPN
5) All your Data will be published in 3(three) Days if NO contact made
6) Information regarding vulnerabilities in your network will be Sold or Published
7) Your Data will be published if you will hire third-party negotiators to contact us
*We advise you to find some information about us in google
Also check the tab "About Us" in our Blog (http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?about-us)
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (128)
Search, filter and paginate the victim timeline for Ragnarlocker. Showing 1–100 of 128.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Scotbeef Ltd. - Leaks id9052 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Eicon Controle Inteligentes id9048 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | International Presence Ltd - Leaked id8989 View details | Communication / Marketing | |||
|
No additional victim description available. |
|||||
| Ransomware | Learning Partnership West - Leaked id8969 View details | United Kingdom | Education | ||
|
No additional victim description available. |
|||||
| Ransomware | Groupe Fructa Partner - Leaked id8947 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Network Pacific Real Estate - Leak id8910 View details | Construction / Real Estate | |||
|
No additional victim description available. |
|||||
| Ransomware | Astre - Leaked id8909 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Stratesys Full data leak id8770 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Announcement: COMECA Group going to be Leaked id8745 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Announcement: Skatax Accounting company going to be leaked id8742 View details | Finance / Legal / Insurance | |||
|
No additional victim description available. |
|||||
| Ransomware | Retail House - Full Leak id8735 View details | Retail / E-commerce | |||
|
No additional victim description available. |
|||||
| Ransomware | Announcement: Stratesys solutions going to be leaked id8722 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Announcement: Stratesys solutions going to b id8721 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Announcement: Groupe Fructa Partner will be leaked soon id8693 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | CITIZEN company LEAKED id8684 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Announcement: Retail House going to be LEAKED id8667 View details | Retail / E-commerce | |||
|
No additional victim description available. |
|||||
| Ransomware | Updates: Israel "MYMC" id8634 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Israel Medical Center - leaked id8518 View details | Healthcare / Pharma | |||
|
No additional victim description available. |
|||||
| Ransomware | DOIT - Canadian IT company allowed leak of its own clients. id8433 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Batesville didn't react on appeal and allows Full Leak id8085 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Batesville Tool & Die, Inc will be leaked in 3 Days id7990 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Belize Electricity Limited - Leaked id7198 View details | Belize | Energy | ||
|
No additional victim description available. |
|||||
| Ransomware | Portugal Scotturb Data Leaked id7120 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Australian Universal Crane Leak id6663 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Autlan Metallorum, Mexican Miner Leak id6467 View details | Manufacturing / Engineering | |||
|
No additional victim description available. |
|||||
| Ransomware | CANTALK, Canadian translation services - Leak id6254 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Public Appeal to the CANTALK management id5968 View details | Public Sector | |||
|
No additional victim description available. |
|||||
| Ransomware | Temporary Leak Page #0013995NTa id5967 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | New Leak in lawyers company AASP. id5571 View details | Finance / Legal / Insurance | |||
|
No additional victim description available. |
|||||
| Ransomware | New Leak in lawyers company. id5570 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AASP claim there was no data leakage! id5510 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Hundred thousands of personal data, leak preview id5151 View details | Communication / Marketing | |||
|
AOAL - Azienda Ospedaliera di Alessandria |
|||||
| Ransomware | Wrapex Industrial - Leaked id4936 View details | Manufacturing / Engineering | |||
|
No additional victim description available. |
|||||
| Ransomware | Serena Hotels - Leaked id4930 View details | Hospitality / Food & Beverage / Tourism | |||
|
No additional victim description available. |
|||||
| Ransomware | ITONCLOUD - LEAKED id4839 View details | IT | |||
|
No additional victim description available. |
|||||
| Ransomware | Essent company - Leaked id4660 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | Leak Announcement - IT company ITonCLOUD id4643 View details | IT | |||
|
No additional victim description available. |
|||||
| Ransomware | Belgium company Zwijndrecht - Leaked id4612 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | DURAVIT A.G. - Announcement before publishing data id4399 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Dollmar SpA - Leaked id4362 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | DIPF-INTERN - Leaked id4361 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Fashion company ZIGI NY - Leaked id4335 View details | Services | |||
|
No additional victim description available. |
|||||
| Ransomware | DMCI Holding Leaked id4318 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | TANG CAPITAL LEAKED id4315 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Avalon luxury transport company - Leaked id4287 View details | Transportation / Travel / Logistics | |||
|
No additional victim description available. |
|||||
| Ransomware | AudioQuest Data Leaked id4276 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Malayan Flour Mills Bhd. Data Leak id4275 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Who is the real Bad Guys here? Or what recovery experts prefer to keep silent. id4208 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TAP Air Leak of more than 1.5 million of customers and many other. id4203 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TAP AIR PORTUGAL - 115k personal data leak id4123 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DDoS instead of the Discuss - Nice try TAP Air id4099 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TAP Air - First Facts id4074 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | USA Insurance company - Smith brothers File tree and some proofs id4060 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Huge drama for Tap Air Portugal id4059 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Announcement. Action Lab File-tree id3992 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DESFA - Pipeline company LEAK id3991 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Greece pipeline company breached - DESFA id3974 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | File-tree of Tang Capital id3962 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Puma Biotechnology - decided to allow Leaks id3895 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GENSCO Inc. - allows Leak id3824 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Epec.PL - Lied about the absence of Leak id3768 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New Leak: Prudential LTG. id3684 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New Leak: Northern Data Systems id3683 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sierra Packaging Leaked id3584 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Jonathan Adler Leaks id3571 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Germany Corporation "VMT-GmbH" Leaked id3512 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Simonson-Lumber decided to be Leaked id3414 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Simonson-Lumber Inc. First batch of Data. id3222 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | International Centre Leaked id3103 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Smith Transport Full Leak id2829 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GHI Hornos Industriales Fully Leaked id2775 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GHI Hornos Industriales first batch of Data (0,1%) id2743 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Airspan Networks got Leaked id2511 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | IT-companies Subex & Sectrio Leaked id2412 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Company Group LDLC id2180 View details | France | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Leak of IT company Saksoft id2159 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Full Data Leak Linical id2137 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Update: Linicals Data id2061 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Groupe LDLC is going to be Leaked id2057 View details | France | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Team Computers Ltd. - Leak id1980 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | LINICAL doesn't care about digital hygiene id1751 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Atlas Financial Holdings, Inc. - Leaked id1570 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FULL DATA LEAK of Primary Residential Mortgage, Inc. // id1378 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Primary Residential Mortgage inc. - Leaked id1357 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Who is the real Bad Guys here? Or what recovery experts prefer to keep silent. id1245 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Announcement: FTP id661 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GATEWAY Property Management id657 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Software company Xoriant id650 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New Leak GatewayPM id649 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | NEW Links for ADATA id639 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ADATA LEAKED id637 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ADATA id617 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Webhelp's company - XtraSource id580 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ludwig Pfeiffer Leaked id563 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Grupo SADA Leak id557 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New Data Leak post from Chemical company id556 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Kaye/Bassman International - New "Wall of Shamer" id552 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Cornerstone-BB Group Leaked id550 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Attention, Dassault Falcon Jet updated id548 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Advertising Material: Forest Construction Leaked id545 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||