Ransomware Group intelligence
Redalert
InactiveTrack Redalert with 6 published victims and 2 known leak locations in a single intelligence view.
Overview
Redalert is tracked by Breach House as a ransomware group with 6 published victims.
France is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | blog2hkbm6gogpv2b3uytzi3bj5d5zmc4asbybumjkhuqhas355janyd.onion |
| Leak location 2 | Onion service | Unknown | je2yizds7r4uidk6uixfxwjj5w7or2agit4aj66l4lrhdbrvr3lsymid.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (6)
Search, filter and paginate the victim timeline for Redalert.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | www.bbadmin.com id4224 View details | Other | — | ||
|
www.bbadmin.com is the website of Bay Bridge Administrators, an Austin, Texas-based third-party administrator for fully insured employee benefit plans. Its services include employee benefits administration, policyholder support, retirement plan solutions, and a secure benefits portal for claims and account access. The company presents itself as a nationally recognized provider serving benefit-plan clients. It was listed as a ransomware victim associated with redalert. |
|||||
| Ransomware | groupg4.com id4128 View details | Services | — | ||
|
groupg4.com is the digital presence of G4 Group, a multidisciplinary architecture and engineering studio headquartered in Barcelona, Spain, with offices in Madrid, Turin, Paris, and Dubai. The firm specializes in architecture, building engineering services, and project consultancy, offering site management, permit handling, quality control, audits, and financial oversight for diverse clients. With over 20 years of experience, G4 Group serves local businesses and international corporations by adapting its design and engineering expertise to each unique project. The company was listed as a ransomware victim associated with the threat actor redalert, marking its inclusion in threat-intelligence records as an affected entity in the Services sector. |
|||||
| Ransomware | coarc.org id3880 View details | Other | — | ||
|
Coarc is a nonprofit organization based in Columbia County, New York, that provides comprehensive services to children and adults with disabilities through more than 20 locations across the region. The organization offers day habilitation, employment support, community living programs, and specialized care to expand abilities for over 500 individuals annually. Its mission focuses on empowering individuals one person at a time, with additional services including contract manufacturing and gift shop operations. Coarc was listed as a ransomware victim associated with the threat actor redalert, though no specific data breach details have been publicly confirmed by the organization itself. |
|||||
| Ransomware | keystonelegal.co.uk id3835 View details | United Kingdom | Finance / Legal / Insurance | — | |
|
Keystone Legal is a leading UK provider of After The Event (ATE) and Legal Expenses Insurance (LEI) for solicitors, established in 1988 and headquartered in Aldershot, Hampshire, GB. The company offers strategic, operationally and commercially focused ATE insurance solutions tailored to the litigation landscape in the UK. It works with law firms of all sizes across the country, delivering innovative and effective insurance products underwritten by Keystone Legal Benefits Ltd. Keystone Legal was listed as a ransomware victim associated with the threat actor redalert. |
|||||
| Ransomware | vahanen.com id3796 View details | Other | — | ||
|
Vahanen Group was a Finnish multidisciplinary consulting company focused on the construction and real estate sector, with services spanning architecture, building services engineering, structural engineering, refurbishment, property management, and building physics. It was headquartered in Finland, and public company materials describe it as a technical consultant serving the property and construction branch. The vahanen.com domain was later decommissioned after AFRY replaced the website. vahanen.com was listed as a ransomware victim associated with redalert. |
|||||
| Ransomware | syredis.fr id3784 View details | France | Other | — | |
|
Syredis is a French IT and cloud services company that provides infrastructure, hosting, monitoring, and collaborative cloud tools. Its services include infrastructure as a service for servers, networks, and storage, as well as platforms for public-sector communication and IT supervision. The company presents itself around secure, cost-effective systems for applications, data, and operational management. syredis.fr was listed as a ransomware victim associated with redalert. |
|||||