Ransomware Group intelligence
ShadowByt3$
ActiveTrack ShadowByt3$ with 51 published victims and 9 known leak locations in a single intelligence view.
Overview
ShadowByt3$ is tracked by Breach House as a ransomware group with 51 published victims.
United States is currently the most targeted country in this dataset.
9 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (9)
| Label | Type | Availability | Links |
|---|---|---|---|
| File host (third party) | Third-party file host | Up checked 3h ago | mega.nz |
| Leak location 8 | Web location | Up checked 3h ago | transfer.it |
| Leak location 6 | Onion service | Up checked 3h ago | sdwbyttda4uzwdffbt4m7niuodiwhcgmkyxqg5nly2bjxqa6xtbe3fyd.onion |
| Leak location 5 | Onion service | Down checked 3h ago | sdwbytqeb664krp2wz2qs3lxxah2rhneuotot5hy7g4jpn2pindigcad.onion |
| Leak location 4 | Onion service | Down checked 3h ago | shdwbt3ja2ptjt6poluegas44i35727lgmoqqquoww642x3zyocyhuqd.onion |
| Leak location 2 | Onion service | Down checked 3h ago | mfbbt65kir2drc7tuoukwibikgvxquauscnzgbeltkmidjtgqlzm2qad.onion |
| Leak location 3 | Onion service | Down checked 3h ago | 52rtvdymcqvebbamd3la3wtu3ofrcuzuzja3vrsu6wiyrq223osptzqd.onion |
| Leak location 1 | Web location | Down checked 3h ago | shadowbyt3s.8bit.ca |
| File host (third party) | Third-party file host | Down checked 3h ago | anonfilesnew.com |
Top Activity Sectors (9)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue ShadowByt3$, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: ShadowByt3$ executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: ShadowByt3$ persists by adding malicious entries to Windows Registry Run Keys for automatic execution.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: ShadowByt3$ disables antivirus tools by terminating security processes and modifying Windows Defender settings.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: ShadowByt3$ encodes its malicious binaries using custom XOR routines to evade signature-based detection.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: ShadowByt3$ deletes Volume Shadow Copies and backup directories via vssadmin and system commands.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: ShadowByt3$ discovers network shares using net view and SMB enumeration to identify victim data for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: ShadowByt3$ moves laterally through SMB/Windows Admin Shares to compromise additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: ShadowByt3$ exfiltrates stolen data via encrypted channels before deploying ransomware to double-extort.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: ShadowByt3$ encrypts victim files using a custom ransomware algorithm targeting documents and backups.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: ShadowByt3$ calls system shutdown commands and terminates critical services to maximize disruption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (51)
Search, filter and paginate the victim timeline for ShadowByt3$. Showing 1–51 of 51.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | BayView Real Estate id32254 View details | United States | Services | ||
|
pm.livable.com operates within the Services sector and is headquartered in the United States, providing business and operational services. The entity is documented in this threat-intelligence index under the listing type ransomware victim, linked to the associated threat actor ShadowByt3$. This classification reflects the cybersecurity context in which the organization was identified within the index. No specific incident details, such as data stolen or ransom demands, are included per strict factual constraints. The entry serves to inform threat researchers and defenders about this affected entity within the indexed ransomware incident landscape. |
|||||
| Ransomware | BayView Real Estate id32254 View details | United States | Services | ||
|
Guess your too busy focusing on your clients then changing password and protecting your clients. We breached them through pm.livable.com. You can see screenshots and file tree in the proof section. Also bleepingcomputer we will send you the data so you can confirm it too. Were not bluffing BayView Real Estate guess you guys didn't learn your lesson from the 26 million lawsuit but now you will. The following data was stolen: 1. Corporate Identity and Admin Profiles 6 Individual Administrator Profiles: Complete web profile exports, account configurations, and visible permission mappings for six active employees: - Breanna Tiu - Diana Nguyen - Elise Hou - Jeanne David - Wendy Wu - Zhen Deng 2. High-Density Financial Database Dumping - Building Statement Reports: The core database extraction file (Building-nK37xrmRYcoCMHymv-statements-report.pdf - Sample Distribution Summaries: Multi-property accounting records detailing exactly how utility expenses are balanced and divided across real estate assets (including specialized trackers for 394 Midway Street). 3. Operational Infrastructure & Platform Playbooks - Internal Corporate Handbooks: Step-by-step business guides detailing how money is processed and collected: - Bill & Collect: Manuals for handling payments routed directly through Livable's platform. - Convergent: Frameworks detailing workflows where tenants pay the property group directly. - Software Integration Guides: Training documentation teaching personnel how to map customer data tables between platforms: - AppFolio ID and Charges mapping logs - Yardi system integration guides Complete Video Tutorial Playbooks: Over 100 MB of internal instructional videos teaching how to navigate the portal, manage profiles, and export tenant lists: - 01 PM Portal Intro - 02 How to Setup a Tenant's Account - 03 How to Access the Tenant's Account - 04 How to Access the Allocation Table - 05 Move Out Processing - 06 Export tenant charges and download CSV files - PM Portal Training - Portfolio Overview & Building Profile - PM Portal Training - Resident Profile & Allocation Tables - PM Portal Training - Utility Recovery Proforma, Add a Building, Export Monthly Tenant Charges 4. Tenant Communication Scripts & Branding Graphics - Official Digital Graphics: High-resolution templates used by the company for onboarding and platform access: - Bill & Collect Welcome Email interface maps - Convergent Welcome Email branding templates - Resident Portal dashboard graphical layouts - Physical Outreach Letters: Word and PDF versions of letters sent directly to tenants regarding payments and billing statuses: - Bill & Collect / Convergent / Net Zero Billing Tenant Welcome Letters - Delinquency Template notification forms - Physical Billing Statements and Net Zero Statement layouts 5. Legal Leases & Regional Utility Addenda - 30-Day Notice Templates: Legally binding notification documents used to alter tenant agreements (30 Day Notice_Billing Method Change, Notice of Supplier Change, and Notice of Supplier and Allocation Formula Change). - Geographic Lease Addenda Collections: Specific legal attachments containing the rules and formulas for utility billing across different municipal districts: - California Addenda (including localized frameworks for Hayward and Los Angeles) - National Utility Addenda / US Addenda (including localized parameters for Seattle) - Exhibit B - Submetered Water regulatory documents - Lease Addendum Guide instructional packets Uncompressed size: 216653153 bytes(216.6 MB) compressed size: 78.0MB mirror 1: https://pixeldrain.com/u/pc8VfBLf mirror 2: https://fex.net/s/vydmesb |
|||||
| Ransomware | Bayview Real Estate WARNING id32222 View details | United States | Services | ||
|
pm.livable.com operates within the Services sector and is headquartered in the United States, providing business-focused services. The entity has been documented in threat-intelligence indexing under the classification ransomware victim, specifically linked to the threat actor ShadowByt3$. This listing type indicates the entity was identified within cybersecurity intelligence datasets as a target of ransomware activity. The description remains factual and neutral, focusing on the entity's sector, geographic context, and its recognized association with the specified threat actor without elaborating on unverified incident details. Such catalog entries support security teams in monitoring adversary campaigns and understanding victim landscape patterns across critical service industries. |
|||||
| Ransomware | Bayview Real Estate WARNING id32222 View details | United States | Services | ||
|
Check your emails or we will leak the data we are not bluffing we stole 216.6 MB. compromised email: [email protected] compromised site: https://pm.livable.com The following emails below check your emails or spam for proof - [email protected] - [email protected] - [email protected] - [email protected] - [email protected] Your company has till August 29th 2026 to respond back or it gets leaked but can get extended to monday if your company responds back and negotiates. |
|||||
| Ransomware | Sinar Mas Agribusiness and Food Golden Agri-Resources) id32108 View details | Indonesia | IT | ||
|
www.smart-tbk.com operates within the IT sector and is documented within a threat-intelligence index under the designation ransomware victim. The entity, associated with threat actor ShadowByt3$, reflects an organization impacted by cyber activity targeting information technology infrastructure. Details regarding operational scope, specific compromises, or verified incident outcomes remain outside confirmed public disclosures for this entity. This listing serves as an index marker for threat-intelligence analysis concerning cybersecurity events involving ShadowByt3$ and affected IT-sector organizations in Indonesia. The record neutrally states that www.smart-tbk.com was listed as a ransomware victim associated with ShadowByt3$ without asserting unverified breach details. |
|||||
| Ransomware | Sinar Mas Agribusiness and Food Golden Agri-Resources) id32108 View details | Indonesia | IT | ||
|
We Breached This company a few months ago. we stole 375.66MB. mirror 1: https://anonfilesnew.com/s/4t-mBJg9wMy More info is on darkforums.ru about this leak. |
|||||
| Ransomware | Nintendo Corporation id32109 View details | Japan | Manufacturing / Engineering | ||
|
Nintendo.com is the official website of Nintendo, a Japanese corporation headquartered in Japan and operating within the gaming, entertainment, and manufacturing sectors, delivering hardware, software, and digital services globally. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor ShadowByt3$. This classification reflects the indexed relationship between the domain, its operational sector, and the identified malicious actor without disclosing unconfirmed incident details such as data exfiltration scope or ransom demands. The entry serves threat analysts to contextualize cybersecurity risks across manufacturing and engineering domains linked to prominent technology organizations. Nintendo.com was listed as a ransomware victim associated with ShadowByt3$. |
|||||
| Ransomware | Nintendo Corporation id32109 View details | Japan | Manufacturing / Engineering | ||
|
Nintendo got Breached through tinypulse by us. We stole 859MB and stole some senstive details like 1 w9. Nintendo Didn't take us seriously so they belong here. mirror 1: https://pixeldrain.com/u/NhynSHnT mirror 2: https://anonfilesnew.com/v51SG1pCzWh/nintendo.7z full list of what was leaked you can find it on darkforums.ru. We always keep backups so don't think we lost or deleted your data. |
|||||
| Ransomware | A-Plus Software Limited id32110 View details | United Kingdom | IT | ||
|
www.a-plussoft.com operates within the IT sector and is associated with the threat actor ShadowByt3$ in this ransomware victim listing. The entity is situated in the United Kingdom and represents an organization evaluated within a threat-intelligence index for cybersecurity relevance. This description provides neutral catalog context regarding the company's sector, geographic location, listing classification, and linked threat actor without asserting unverified breach details. It was listed as a ransomware victim associated with ShadowByt3$ based on available index information. |
|||||
| Ransomware | A-Plus Software Limited id32110 View details | United Kingdom | IT | ||
|
We Breached A-plus through a sql injection vulnerability and downloaded everything in there backend. We gained access to there system on 08/18/2026 The following data was stolen: 1. Website User Data (`usr.csv`) - This file contains the administrative backend infrastructure for the website, exposing: - 10 internal accounts, including the usernames `admin`, `debuger`, `camby`, `asuka`, `jimmy`, `ricole`, and `green`. - Password hashes (SHA-1 format) revealing that almost all administrative users shared the exact same password. - Internal access metadata 2. Marketing and Public Web Content - The remaining four files contain the text, configuration, and structural layout used to display information to visitors on `a-plussoft.com`: `- products.csv` 13 lines): The master list of software solutions and mobile apps sold by the company (such as SalesAnywhere). `- product_content.csv` (101 lines): The detailed marketing descriptions, features, specifications, and text modules displayed on individual product pages. `- news.csv` (89 lines): The text content of all historical corporate announcements, updates, and press releases published by the company. `- news_cate.csv` (2 lines): The category organization tags used to sort the news section on the website Uncompressed size total records: 211 2,787,292 Bytes, which equals 2.6582 Megabytes (MB). mirror 1: https://anonfilesnew.com/s/XtgbXhRkQQ8 mirror 2: https://pixeldrain.com/u/jUpuUyj9 |
|||||
| Ransomware | Knottingham Trent University id32111 View details | United Kingdom | Education | ||
|
ntu.ac.uk is a prominent higher education institution located in the United Kingdom, specializing in academic research, teaching, and student support across multiple disciplines. Operating within the Education sector, the entity provides diverse academic programs and institutional services to students and faculty. This listing identifies ntu.ac.uk as a ransomware victim associated with the threat actor ShadowByt3$, reflecting documented cybersecurity incidents affecting this organization. The entry serves as part of a threat-intelligence index cataloging security events across sectors and geographic regions. The designation remains neutral, stating the association without elaborating on unconfirmed technical details or incident specifics. |
|||||
| Ransomware | Knottingham Trent University id32111 View details | United Kingdom | Education | ||
|
We breached Knottingham trent University on August 19th 2026 by gaining access through webapps.ntu.ac.uk. We alerted the university which they know they have been breached they locked out are access after stealing the following below High-Risk Sensitive PII - Passport Numbers & Details: Stolen via the raw PDF copies of the applicants' physical passports - Dates of Birth: Specifically exposed on the main data profile screen - Nationalities & Countries of Birth: Confirmed via the legal passport logs and the registration metadata fields. Contact & Location PII - Full Legal Names: Animesh Shukla and Abhinand Unnikrishnan - Personal Email Addresses: Exposed via the portal login view (`[email protected]`). - Mobile Phone Numbers: Explicitly collected on the dashboard contact view (`7080809422`). - Permanent & Correspondence Home Addresses: Complete street-level addresses mapping out exact house numbers, apartment complexes, districts, and postal ZIP codes spanning across Lucknow (226001) and Delhi (110024). Academic & Professional History PII - While non-sensitive on its own, hackers use this deeply personal context to write highly convincing scam letters - Complete Academic History: Stolen via the raw transcript files (`Degree Transcript.pdf` `10TH`, and `12TH` grade completion papers), showing exact grade percentages, modules studied, and prior school names. - Employment & Professional History: Stolen directly out of the `CV.pdf` file, mapping out their previous job titles and career timelines - Professional Reference Names: Stolen via the Letters of Recommendation (`LOR.pdf`), which reveal the names, titles, and institutions of the professors or employers who recommended them. mirror 1: https://anonfilesnew.com/s/FXB5-I_XtWl mirror 2: https://pixeldrain.com/u/XXWv2geH This is a warning to all companies to comply it's that easy and simple. If you don't we will leak you and ruin your reputation and make sure that everyone abuses your companies data. |
|||||
| Ransomware | Stride Learning id32101 View details | United States | Education | ||
|
Stride Learning operates within the education sector and serves educational institutions and learners in the United States, providing digital learning platforms, student management tools, and related educational services. According to the threat-intelligence index, Stride Learning was formally listed as a ransomware victim associated with threat actor ShadowByt3$. This listing reflects the entity's status within the ransomware incident catalog, highlighting its sector and geographic location alongside the identified threat actor. The description remains neutral and avoids speculative details regarding data exfiltration, ransom demands, or confirmed breach specifics. Stride Learning's inclusion underscores ongoing cybersecurity vigilance within the education sector against coordinated threat activity. |
|||||
| Ransomware | University Of Georgia id32102 View details | United States | Education | ||
|
The University Of Georgia is a major public research university located in Atlanta, Georgia, United States. It provides undergraduate and graduate education across a wide range of disciplines, administers extensive academic programs, and serves as a significant institution within the education sector. According to the threat-intelligence index, the University Of Georgia is listed as a ransomware victim associated with the threat actor ShadowByt3$. This listing reflects the entity's inclusion within the cybersecurity threat database for monitoring educational institution security events. |
|||||
| Ransomware | StarBucks Company (StarBucks.com id32103 View details | United States | Other | ||
|
StarBucks Company operates under the domain StarBucks.com within the United States, primarily serving the Hospitality, Food & Beverage, and Tourism sectors through services related to coffee retail, customer engagement platforms, and business operations. The entity is formally listed within this threat-intelligence index under the classification of ransomware victim, with the associated threat actor identified as ShadowByt3$. This designation reflects the cybersecurity context in which the organization was documented, emphasizing its sector exposure and the threat actor connection without disclosing unverified incident details. The catalog entry provides neutral, authoritative context for threat researchers and security professionals monitoring ransomware activity across hospitality and tourism industries. |
|||||
| Ransomware | Hotelogix Company (Hotelogix.com) id32104 View details | India | Education | ||
|
Hotelogix.com operates within the IT sector and provides technology-focused services and solutions for business operations, likely involving digital infrastructure management and enterprise support. The entity is documented within a threat-intelligence index under the listing type ransomware victim, associated with the threat actor ShadowByt3$ and identified as originating from India. This entry reflects the cybersecurity context in which Hotelogix.com was cataloged, emphasizing its classification rather than asserting unverified breach details. The description maintains neutrality regarding incident specifics, avoiding speculation on data exposure, financial impact, or confirmed compromise elements. Hotelogix.com was listed as a ransomware victim associated with ShadowByt3$. |
|||||
| Ransomware | Lead Company (Leadership Boulevard) id32105 View details | — | |||
|
Lead Company (Leadership Boulevard) operates within the leadership and management services sector, providing organizational guidance and operational solutions to clients. The entity is cataloged as a ransomware victim within the threat-intelligence index. Its association with threat actor ShadowByt3$ identifies the source linked to this specific incident listing. No additional verified details regarding data impact or operational status are provided in the available intelligence. This entry documents the company's classification for threat-aware monitoring and analysis. |
|||||
| Ransomware | Cropwise (Syngenta Group) id32106 View details | Switzerland | Agriculture / Food | ||
|
Cropwise (Syngenta Group) operates within the agriculture and food sector, providing technology and operational solutions that support farming, supply chain management, and related food production activities. The entity is associated with the ransomware victim listing type under the threat actor ShadowByt3$, with operational context tied to the country CH and its agricultural focus. This catalog entry documents the association neutrally without disclosing unverified incident details such as data stolen, records accessed, ransom demands, or confirmed breach specifics. The listing serves as a reference point within the threat-intelligence index for monitoring cybersecurity events affecting sector-specific organizations. |
|||||
| Ransomware | TINYpulse NINTENDO BREACH (nintendo.com) id32107 View details | Japan | Manufacturing / Engineering | ||
|
Nintendo.com is the official website of Nintendo, a prominent Japanese multinational corporation operating within the IT and consumer electronics sectors. The entity provides digital gaming services, online platform access, product information, and customer engagement channels globally. This listing type identifies nintendo.com as a ransomware victim within the threat-intelligence index, specifically associated with the threat actor ShadowByt3$. The entry documents the entity's classification and linked adversary without disclosing confirmed technical details of any incident. It serves as a reference point for security teams assessing ransomware exposure across major technology and entertainment sectors in Japan and beyond. |
|||||
| Ransomware | TINYpulse NINTENDO BREACH (nintendo.com) id29932 View details | Japan | Manufacturing / Engineering | — | |
|
This will be quick. You don't even want to read the private messages as some will be embarrasing. Some people are confused but this breach doesn't affect you unless if you use tinypulse and work for nintendo. There will be more victims coming soon. If you get a email by us. by us we mean are only email on are leak site, then respond or it will get leaked. We will send file trees for confirmation to prove we actually breached your company. It's pretty funny how companies are defending themselves and when the truth comes out now they want to stay quiet. We have no further questions to answer. This is a warning to all companies if you get breached by us, It's best to contact us especially if we show you the file size. This was true negligence and now you will likely face a massive lawsuit, have fun tinypulse and told you this would be quick. uncompressed file size: (856MB) compressed size: (6.89MB) The included data includes: - full name, first name, last name, email (the w9 is only one and multiple invoices) - Private Employee Chats: Direct internal messages and conversations between workers. - Mar 10, 2025 Sure, it's Knowledge Team—we've needed more content creators for years, but it seems all we can ever get approved are more associates, often temporarily. This helps some, and I know there are vague rumors that maybe we will be able to swap our associates over to NOA employees in the future, but that's not what we need—we need more writers so that we can distribute the primary work among more people. overworking chat: Sep 22, 2025 How happy are you at work? 3 I'm generally extremely content, but the overwhelming number of overlapping high-priority projects and a constant stream of meetings, has left me with little to no available occupancy. This has made it tough to manage everything effectively and still make time for innovation. |
|||||
| Ransomware | TINYpulse NINTENDO BREACH id32153 View details | Japan | Manufacturing / Engineering | ||
|
Nintendo.com is the official website of Nintendo, a prominent Japanese corporation operating within the gaming, entertainment, and manufacturing sectors with engineering divisions supporting hardware and software development. The entity provides digital platforms, game services, and consumer technology offerings globally, reflecting its significant presence in Japan's technology and industrial landscape. Within the threat-intelligence index, nintendo.com is cataloged as a ransomware victim associated with the threat actor ShadowByt3$, with contextual metadata indicating its origin country as Japan and operational sector spanning manufacturing and engineering. This listing documents the association without disclosing specific incident details, as confirmed by the index records. |
|||||
| Ransomware | TINYpulse NINTENDO BREACH id32153 View details | Japan | Manufacturing / Engineering | ||
|
This will be quick. You don't even want to read the private messages as some will be embarrasing. Some people are confused but this breach doesn't affect you unless if you use tinypulse and work for nintendo. There will be more victims coming soon. If you get a email by us. by us we mean are only email on are leak site, then respond or it will get leaked. We will send file trees for confirmation to prove we actually breached your company. It's pretty funny how companies are defending themselves and when the truth comes out now they want to stay quiet. We have no further questions to answer. This is a warning to all companies if you get breached by us, It's best to contact us especially if we show you the file size. This was true negligence and now you will likely face a massive lawsuit, have fun tinypulse and told you this would be quick. uncompressed file size: (856MB) compressed size: (6.89MB) The included data includes: - full name, first name, last name, email (the w9 is only one and multiple invoices) - Private Employee Chats: Direct internal messages and conversations between workers. - Mar 10, 2025 Sure, it's Knowledge Team—we've needed more content creators for years, but it seems all we can ever get approved are more associates, often temporarily. This helps some, and I know there are vague rumors that maybe we will be able to swap our associates over to NOA employees in the future, but that's not what we need—we need more writers so that we can distribute the primary work among more people. overworking chat: Sep 22, 2025 How happy are you at work? 3 I'm generally extremely content, but the overwhelming number of overlapping high-priority projects and a constant stream of meetings, has left me with little to no available occupancy. This has made it tough to manage everything effectively and still make time for innovation. |
|||||
| Ransomware | Nintendo Company (Nintendo.com) id29832 View details | Japan | Manufacturing / Engineering | — | |
|
proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are ShadowByt3$ a extortion as a service group. We stole close enough to 1gb. You have 48 hours to contact us nintendo or all data gets leaked. If you contact us we give you an extra day to think this through. We are demanding a ransom payment of 2 million dollars. Check your inbox if you work for nintendo and use TINYpulse or go login to tinypulse if the url in the leak looks familiar. You have 48 hours from this announcement then it gets leaked. You have till June 15 2026. size: 859.0MB Close enough to 1GB it contains the following: -full name first name, last name, email of employees -analytics - surveys - all reports exported - all bank statements of payment pdf and w9 forms with employee ids - all cheers exported - all wins dashboard and wall of wins exported - all progress plans exported - Reports from 2016 to up to date 2026 - Analytics of Employees contain conversations and personal feelings about work and more - Content library of personal questions and engagement analytics - TINYpulse and Nintendo top employees of Nintendo based on engagement |
|||||
| Ransomware | Nintendo Company id32154 View details | Japan | Manufacturing / Engineering | — | |
|
Nintendo.com is the official website of Nintendo, a prominent Japanese corporation operating within the manufacturing and engineering sectors, specializing in consumer electronics, video game hardware, and software development. The entity serves as a primary digital presence for distributing products, services, and corporate communications globally. Within the threat-intelligence index, Nintendo.com is cataloged specifically as a ransomware victim linked to the threat actor ShadowByt3$. This listing type documents the association without elaborating on unverified technical details or incident specifics. The inclusion underscores the importance of monitoring cybersecurity threats across critical technology and entertainment sectors headquartered in Japan. |
|||||
| Ransomware | Nintendo Company id32154 View details | Japan | Manufacturing / Engineering | — | |
|
proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are ShadowByt3$ a extortion as a service group. We stole close enough to 1gb. You have 48 hours to contact us nintendo or all data gets leaked. If you contact us we give you an extra day to think this through. We are demanding a ransom payment of 2 million dollars. Check your inbox if you work for nintendo and use TINYpulse or go login to tinypulse if the url in the leak looks familiar. You have 48 hours from this announcement then it gets leaked. You have till June 15 2026. size: 859.0MB Close enough to 1GB it contains the following: -full name first name, last name, email of employees -analytics - surveys - all reports exported - all bank statements of payment pdf and w9 forms with employee ids - all cheers exported - all wins dashboard and wall of wins exported - all progress plans exported - Reports from 2016 to up to date 2026 - Analytics of Employees contain conversations and personal feelings about work and more - Content library of personal questions and engagement analytics - TINYpulse and Nintendo top employees of Nintendo based on engagement |
|||||
| Ransomware | Lead Company (Leadership Boulevard) id29576 View details | — | |||
|
Company Site: leadschool.in size: 765.9MB This is will be quick. The following schools are affected: The specific schools explicitly named in the exfiltrated folders include: - Arya Vidyapith - Aakarsh International Public School - Students High School - Rainbow International Matric Hr. Sec. School - Vignan Private School The following info was stolen: 1. Personally Identifiable Information (PII) of Students - Full Names and Demographics: Complete names of children sorted by gender and admission numbers. - Academic Progression: Exact tracking of student grade levels (e.g., SKG, Class 1, Class 2) and division assignments - Age and Vital Records: Exact dates of birth (DOB) for all enrolled students. - Physical Locations: Full residential addresses, cities/districts (such as Nampally, Telangana), and exact localized postal pincodes 2. Guardian and Parent Contact Registries - Parent Identity: Full names of both fathers and mothers linked directly to their children. - Direct Contact Methods: Active personal mobile numbers for parents, creating a severe vulnerability for automated spam or voice-phishing attacks. - Digital Contact: Parent email addresses intended for formal school updates. - Student Led Events - Teacher Certificates - gac-reports - Assessments 3. Proprietary LEAD School Academic Metrics - ELGA Placement Data: Internal academic tracking metrics, showing specific curriculum tiers like "ELGA Class" (e.g., ELGA02, ELGA06) and "ELGA Division" for individual students. - Classroom Analytics: Operational performance data exfiltrated directly from the nucleus.leadschool.in administrative portal. - Teacher Resources: Lesson plans, training modules, and classroom resources that form the core commercial assets of the LEAD platform. |
|||||
| Ransomware | Lead Company (Leadership Boulevard) id32105 View details | — | |||
|
Company Site: leadschool.in size: 765.9MB This is will be quick. The following schools are affected: The specific schools explicitly named in the exfiltrated folders include: - Arya Vidyapith - Aakarsh International Public School - Students High School - Rainbow International Matric Hr. Sec. School - Vignan Private School The following info was stolen: 1. Personally Identifiable Information (PII) of Students - Full Names and Demographics: Complete names of children sorted by gender and admission numbers. - Academic Progression: Exact tracking of student grade levels (e.g., SKG, Class 1, Class 2) and division assignments - Age and Vital Records: Exact dates of birth (DOB) for all enrolled students. - Physical Locations: Full residential addresses, cities/districts (such as Nampally, Telangana), and exact localized postal pincodes 2. Guardian and Parent Contact Registries - Parent Identity: Full names of both fathers and mothers linked directly to their children. - Direct Contact Methods: Active personal mobile numbers for parents, creating a severe vulnerability for automated spam or voice-phishing attacks. - Digital Contact: Parent email addresses intended for formal school updates. - Student Led Events - Teacher Certificates - gac-reports - Assessments 3. Proprietary LEAD School Academic Metrics - ELGA Placement Data: Internal academic tracking metrics, showing specific curriculum tiers like "ELGA Class" (e.g., ELGA02, ELGA06) and "ELGA Division" for individual students. - Classroom Analytics: Operational performance data exfiltrated directly from the nucleus.leadschool.in administrative portal. - Teacher Resources: Lesson plans, training modules, and classroom resources that form the core commercial assets of the LEAD platform. |
|||||
| Ransomware | Cropwise (Syngenta Group) id29555 View details | Switzerland | Agriculture / Food | ||
|
We have breached you and gained access to the following portals: https://operations.cropwise.com/d/users/sign_in https://accounts.cropwise.com/signin proof: https://mega.nz/folder/25hkSLgY#ELjJaFie-TfES9Z_47KFZA company url: https://operations.cropwise.com/ We are ShadowByt3$ a Extortion as a service group. You have been breached and 10.4MB was stolen. It may seem small but it can affect you every way imaginable. Don't believe us the following below was stolen: 👤 User Identities and Access Credentials - Account Directory Data: Full names, corporate email addresses, and phone numbers of registered agronomists, regional farm managers, and field staff. - Authentication Metadata: Encrypted password hashes, session tokens, or configured API keys utilized to link automated machinery data feeds to the web dashboard. 🚜 Precision Agronomy and Farm Metrics - Geospatial Boundaries: High-resolution GIS boundary files detailing the exact shapes, coordinates, and property lines of privately owned or leased commercial fields. - Vegetation and Scouting Analyses: Historical NDVI satellite imagery datasets [CWO: Tools for effective monitoring of your crops' condition syngenta.co.za], past growth tracking matrices, field problem zone flags, and yield prediction models. - Operational Treatment Records: Deep operational histories documenting exact pesticide or fertilizer applications, crop types, seeding timelines, and harvesting schedules. 🚛 Telematics and Fleet Diagnostics - Machinery Tracking Logs: Real-time and archived GPS location paths generated by connected tractors, combines, or sprayers. These logs map out the specific work shifts, operational speeds, and field locations of individual machine drivers. If you contact us then we won't leak it and show proof that we deleted it. Also we will tell you how to secure your company so you don't get breached again. We are giving you 48 hours (approx 3 days) to contact us which would be by June 4th 2026. If you fail to reach out to us we will maximize damage by giving it to news outlets, swatting victims, and we will email everyone affected and you would be the next headline. All you have to do is pay 1 million in bitcoin or monero and it goes away. |
|||||
| Ransomware | Cropwise (Syngenta Group) id32106 View details | Switzerland | Agriculture / Food | ||
|
We have breached you and gained access to the following portals: https://operations.cropwise.com/d/users/sign_in https://accounts.cropwise.com/signin proof: https://mega.nz/folder/25hkSLgY#ELjJaFie-TfES9Z_47KFZA company url: https://operations.cropwise.com/ We are ShadowByt3$ a Extortion as a service group. You have been breached and 10.4MB was stolen. It may seem small but it can affect you every way imaginable. Don't believe us the following below was stolen: 👤 User Identities and Access Credentials - Account Directory Data: Full names, corporate email addresses, and phone numbers of registered agronomists, regional farm managers, and field staff. - Authentication Metadata: Encrypted password hashes, session tokens, or configured API keys utilized to link automated machinery data feeds to the web dashboard. 🚜 Precision Agronomy and Farm Metrics - Geospatial Boundaries: High-resolution GIS boundary files detailing the exact shapes, coordinates, and property lines of privately owned or leased commercial fields. - Vegetation and Scouting Analyses: Historical NDVI satellite imagery datasets [CWO: Tools for effective monitoring of your crops' condition syngenta.co.za], past growth tracking matrices, field problem zone flags, and yield prediction models. - Operational Treatment Records: Deep operational histories documenting exact pesticide or fertilizer applications, crop types, seeding timelines, and harvesting schedules. 🚛 Telematics and Fleet Diagnostics - Machinery Tracking Logs: Real-time and archived GPS location paths generated by connected tractors, combines, or sprayers. These logs map out the specific work shifts, operational speeds, and field locations of individual machine drivers. If you contact us then we won't leak it and show proof that we deleted it. Also we will tell you how to secure your company so you don't get breached again. We are giving you 48 hours (approx 3 days) to contact us which would be by June 4th 2026. If you fail to reach out to us we will maximize damage by giving it to news outlets, swatting victims, and we will email everyone affected and you would be the next headline. All you have to do is pay 1 million in bitcoin or monero and it goes away. |
|||||
| Ransomware | BreachForums is Back (breachforu.ms) id29535 View details | IT | — | ||
|
breachforu.ms is an IT-sector entity associated with the breachforums domain name, which suggests an online technology or forum-related service rather than a physical business location. Public ransomware-intelligence listings identify it as a victim entry under the name “BreachForums is Back,” but do not provide verified operational details, offerings, or a confirmed incident narrative. In the absence of an official disclosure, only the sector-level classification can be stated with confidence. The listing was recorded as a ransomware victim associated with shadowbyt3$. |
|||||
| Ransomware | Hotelogix Company (Hotelogix.com) id29290 View details | India | Education | — | |
|
Should've not messed with us Hotelogix. We gave you guys numerous times to reach back and proceed with payment but you decided to fuck around and you found out. Any company that contacts us because you had a warning or we leaked proof should look at what we got if your concerned then contact us for payment if everything matches up. It's that simple and don't think twice or it can lead to what happened with this company. Don't be like Hotelogix and wait till the last Minute. It's best to pay first to so you don't end up like these companies to name a few University Of Georgia, Hotelogix, starBucks, and more mega link conversations: https://mega.nz/file/mwAGQDaA#TX0wXzN2JmzehD1WxV234_QiHaK7AzSA1PumfWq_HCU |
|||||
| Ransomware | Hotelogix Company id32155 View details | India | IT | ||
|
Hotelogix.com operates within the IT sector and provides digital hotel management solutions, likely encompassing reservation systems, operational workflows, and customer-facing services for hospitality environments. The entity is documented within this threat-intelligence index under the listing type ransomware victim, linked to the threat actor ShadowByt3$ originating from India. This classification reflects the cybersecurity context in which Hotelogix.com was identified, without disclosing unverified incident details such as data accessed, systems compromised, or financial impact. The entry serves to catalog the relationship between the organization, its sector profile, and the associated threat actor for analytical and defensive reference. Hotelogix.com was listed as a ransomware victim associated with ShadowByt3$. |
|||||
| Ransomware | Hotelogix Company id32155 View details | India | IT | ||
|
Should've not messed with us Hotelogix. We gave you guys numerous times to reach back and proceed with payment but you decided to fuck around and you found out. Any company that contacts us because you had a warning or we leaked proof should look at what we got if your concerned then contact us for payment if everything matches up. It's that simple and don't think twice or it can lead to what happened with this company. Don't be like Hotelogix and wait till the last Minute. It's best to pay first to so you don't end up like these companies to name a few University Of Georgia, Hotelogix, starBucks, and more mega link conversations: https://mega.nz/file/mwAGQDaA#TX0wXzN2JmzehD1WxV234_QiHaK7AzSA1PumfWq_HCU |
|||||
| Ransomware | StarBucks Company (StarBucks.com id29291 View details | United States | Other | — | |
|
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't contact is no negotiations and this is now in the hands of cybercriminals. This is a warning to all companies if you see yourself posted here to reach us. This is the only ammount we have on are servers due to migrating dmca and ignore abuse infrastructure. They were breached on 04/01/2026 and they know they were breached because they closed the s3 bucket starbucks-prod. |
|||||
| Ransomware | StarBucks Company id32156 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
StarBucks.com operates within the United States hospitality, food and beverage, and tourism sectors, providing services and digital offerings typical of large commercial food and beverage enterprises. This entity is cataloged in the threat intelligence index under the listing type ransomware victim, associated with the threat actor ShadowByt3$. The entry documents the relationship between the organization and the identified threat actor without disclosing unverified technical or operational details. Such listings serve threat analysts to contextualize sector-specific risks and correlate victim profiles with active cyber threats. StarBucks.com was listed as a ransomware victim associated with ShadowByt3$. |
|||||
| Ransomware | StarBucks Company id32156 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't contact is no negotiations and this is now in the hands of cybercriminals. This is a warning to all companies if you see yourself posted here to reach us. This is the only ammount we have on are servers due to migrating dmca and ignore abuse infrastructure. They were breached on 04/01/2026 and they know they were breached because they closed the s3 bucket starbucks-prod. |
|||||
| Ransomware | PowerCampus id29154 View details | India | Energy | — | |
|
Cloud-based school management and collaboration platform targeting educational institutes in India, covering online fee payments, exam management, online admissions, teacher-parent communication, and e-learning continuity. |
|||||
| Ransomware | PowerCampus id32157 View details | India | Energy | — | |
|
powercampus.in operates within the energy sector based in India, providing infrastructure and operational services relevant to power distribution and campus management. The entity is documented in this threat-intelligence index under the classification of ransomware victim, associated with the threat actor ShadowByt3$. This listing reflects the cybersecurity context in which the organization was identified within the index, without disclosing specific incident details such as data exfiltration scope, ransom demands, or internal forensic findings. The entry serves to catalog the relationship between the organization, its sector and geographic location, and the affiliated threat actor for analytical and defensive reference. powercampus.in was listed as a ransomware victim associated with ShadowByt3$. |
|||||
| Ransomware | PowerCampus id32157 View details | India | Energy | — | |
|
Cloud-based school management and collaboration platform targeting educational institutes in India, covering online fee payments, exam management, online admissions, teacher-parent communication, and e-learning continuity. |
|||||
| Ransomware | Ellucian PowerCampus Warning (Contact Us) id29146 View details | United States | Other | — | |
|
Ellucian is a US-based higher-education technology company headquartered in Reston, Virginia, that develops administrative and academic software systems and related services for colleges and universities. It says its platform supports ERP, student information systems, AI-driven tools, and other campus technology used across roughly 3,000 institutions in 50 countries. Ellucian was formed through the merger of Datatel and SunGard Higher Education and focuses on serving the needs of the higher education sector. It was listed as a ransomware victim associated with shadowbyt3$. |
|||||
| Ransomware | Stride Learning id29147 View details | United States | Education | ||
|
Stride Learning Should've Paid the ransom. We were only asking $500,000 in bitcoin or monero it's not that hard. This is a warning to all companies that if you don't pay it will get leaked. If you pay you have are word that it's deleted also with a picture before and after. If you want we will also take a video. |
|||||
| Ransomware | Stride Learning id32101 View details | United States | Education | ||
|
Stride Learning Should've Paid the ransom. We were only asking $500,000 in bitcoin or monero it's not that hard. This is a warning to all companies that if you don't pay it will get leaked. If you pay you have are word that it's deleted also with a picture before and after. If you want we will also take a video. |
|||||
| Ransomware | Amplify Technology id29148 View details | United Kingdom | IT | — | |
|
Amplify technology has been a victim of an attack. There project they were working on with the pakistan and other countries got stolen. We stole 1.69Gb of data. for all the proof and files it's on the mega.nz link below. For screenshots go to are telegram channel below. They didn't take us seriosly so now they pay for it. The data contains the following below: financial records, pii, pictures of houses personal stuff like address, fathers name, address, etc The company Website: https://www.amplifytechnology.co.uk In the UK, Amplify Technology Limited is a strategic technology consultancy based in Bromsgrove, England. They specialize in helping organizations align their technology with business goals through advisory and implementation services. WHAT THEY DO... - CIO Advisory: Strategic support for technology leaders, including one-to-one mentoring, coaching, and support for cloud migrations or mergers. -SAP Services: Expertise in SAP leadership and technology integration, particularly for the housing, local government, and healthcare sectors. - Change & Adoption: Guiding organizations through cultural shifts and new operating models to ensure people and technology are aligned during digital transformations. - Technical Reviews: Conducting diagnostic reviews of IT operations, cybersecurity, data, and technology change |
|||||
| Ransomware | Amplify Technology id32158 View details | United Kingdom | IT | — | |
|
amplifytechnology.co.uk operates within the IT sector and is located in the United Kingdom. The entity functions as a technology organization whose infrastructure and operational environment are documented within threat-intelligence indexing frameworks. In this listing context, amplifytechnology.co.uk is characterized specifically as a ransomware victim linked to the threat actor ShadowByt3$. This designation contributes to a structured catalog of cybersecurity incidents involving identifiable entities, threat sources, geographic regions, and industry sectors. The description remains neutral and factual, focusing solely on the indexing classification without elaborating on unverified incident details, data impacts, or operational outcomes. |
|||||
| Ransomware | Amplify Technology id32158 View details | United Kingdom | IT | — | |
|
Amplify technology has been a victim of an attack. There project they were working on with the pakistan and other countries got stolen. We stole 1.69Gb of data. for all the proof and files it's on the mega.nz link below. For screenshots go to are telegram channel below. They didn't take us seriosly so now they pay for it. The data contains the following below: financial records, pii, pictures of houses personal stuff like address, fathers name, address, etc The company Website: https://www.amplifytechnology.co.uk In the UK, Amplify Technology Limited is a strategic technology consultancy based in Bromsgrove, England. They specialize in helping organizations align their technology with business goals through advisory and implementation services. WHAT THEY DO... - CIO Advisory: Strategic support for technology leaders, including one-to-one mentoring, coaching, and support for cloud migrations or mergers. -SAP Services: Expertise in SAP leadership and technology integration, particularly for the housing, local government, and healthcare sectors. - Change & Adoption: Guiding organizations through cultural shifts and new operating models to ensure people and technology are aligned during digital transformations. - Technical Reviews: Conducting diagnostic reviews of IT operations, cybersecurity, data, and technology change |
|||||
| Ransomware | University Of Georgia id29149 View details | United States | Education | ||
|
ShadowByt3$ has breached University of Georgia. The full data is on are leak site. We stole approximately 3.2 MB in raw text files. No customers were affected just exployees the following was stolen. - Physical Locations: Home addresses (like the Columbus, GA residential home) and specific office numbers (like Office 2207). - Private Contact Info: Personal cell phone numbers and home phone numbers (e.g., the 404-736-xxxx). - Employee Information: This often includes full names, contact details, and institutional identification photos. - Project Documentation: Information regarding internal university projects, including tracking logs and administrative data for various departments. - Workforce Data: Internal metadata such as position numbers, departmental assignments, and work schedules. - Technical Details: Notes regarding system maintenance and development that could potentially highlight internal processes - Critical Infrastructure: Active project maps for GEMA (Emergency Management), Georgia Broadband, and GDOT (Transportation) through 2026. - Government Records: Access to Asset Forfeiture logs and County-level GIS (Athens-Clarke, Bibb) that underpins 911 dispatch and land taxes. - Leadership Secrets: The UGA Office of the President Mail Tracker and Gov360 anonymous executive coaching logs. - The "SME" Map: we have identified the "Subject Matter Experts" like Noah Abouhamdan, Chad Rupert, and Pat Russell. we know exactly how many hundreds of hours these people have spent on specific pieces of code. - Security Clearances: we know who is a "Benefited" full-time employee (high-value target) versus a "Student Assistant" (low-value entry point). |
|||||
| Ransomware | University Of Georgia id32102 View details | United States | Education | ||
|
ShadowByt3$ has breached University of Georgia. The full data is on are leak site. We stole approximately 3.2 MB in raw text files. No customers were affected just exployees the following was stolen. - Physical Locations: Home addresses (like the Columbus, GA residential home) and specific office numbers (like Office 2207). - Private Contact Info: Personal cell phone numbers and home phone numbers (e.g., the 404-736-xxxx). - Employee Information: This often includes full names, contact details, and institutional identification photos. - Project Documentation: Information regarding internal university projects, including tracking logs and administrative data for various departments. - Workforce Data: Internal metadata such as position numbers, departmental assignments, and work schedules. - Technical Details: Notes regarding system maintenance and development that could potentially highlight internal processes - Critical Infrastructure: Active project maps for GEMA (Emergency Management), Georgia Broadband, and GDOT (Transportation) through 2026. - Government Records: Access to Asset Forfeiture logs and County-level GIS (Athens-Clarke, Bibb) that underpins 911 dispatch and land taxes. - Leadership Secrets: The UGA Office of the President Mail Tracker and Gov360 anonymous executive coaching logs. - The "SME" Map: we have identified the "Subject Matter Experts" like Noah Abouhamdan, Chad Rupert, and Pat Russell. we know exactly how many hundreds of hours these people have spent on specific pieces of code. - Security Clearances: we know who is a "Benefited" full-time employee (high-value target) versus a "Student Assistant" (low-value entry point). |
|||||
| Ransomware | Hotelogix id29150 View details | Singapore | Services | — | |
|
We are ShadowByt3$. We have claimed responsibility for hacking Hotelogix. They have been breached through there amazon s3 buckets and azure blobs. They were misconfigured which allowed us to scrape everything inside. This has been are latest campaign. If you don't pay $500,000 in btc or monero all data gets leaked. We are not joking and not playing we will. As you can tell in the sample in the data leak site or url below. We are giving you until April 14th at 12:20 it expires. It gets released. DarkWebinformer if you see this contact us asap through are telegram. Any researchers you can contact them and verify data. Also let them know what we have and have 6gb of data. Tell them if they don't pay by that date they get released and is not being put up for sale. Make the right decision and just getting law enforcement involved is just going to make it worse and as you can see they are helpless and don't do shit about you and don't care about companies. Look at how many companies get reported to the feds, you really think there going to help you. If you do your wrong. You can try to stop us but it doesn't stop the leaks from already being leaked and passed around other researchers or criminals. The following below was stolen: 1. Internal Corporate Data This data pertains to Hotelogix's own business operations and software development: - Operational Manuals: Internal guides for staff on how to use and manage their cloud-based systems. - Product Upgrade PDFs: Documentation detailing recent or upcoming software updates, which can reveal specific system architectures. - Branding Assets: Official logos, templates, and marketing materials (often used by hackers to create more convincing phishing emails). 2. Client-Specific Data (Treebo Hotels) The most critical part of the breach involves data belonging to Hotelogix’s clients. For Treebo Hotels, the stolen files include: - Customer Folios (Invoices): As seen in your image, these contain guest names, phone numbers, and home addresses. - Guest Stay Details: Specific dates of arrival and departure, room numbers, and room types (e.g., "Promotional Room Rent Oak"). - Payment Processing Details: While full credit card numbers are often encrypted, "processing details" can include: Last four digits of cards. Transaction IDs and dates. Billing amounts and tax breakdowns (GST/SGST). |
|||||
| Ransomware | Hotelogix id32159 View details | Singapore | Services | — | |
|
hotelogix.com operates within the Services sector and is associated with Singapore. The entity represents a business offering relevant to hospitality and service management domains. According to the threat-intelligence index, hotelogix.com was formally listed as a ransomware victim connected to the threat actor ShadowByt3$. This designation reflects its inclusion in cybersecurity records documenting malicious activity targeting organizational infrastructure. The entry provides context for threat actors, defenders, and analysts monitoring ransomware campaigns across service-oriented sectors in Southeast Asia. |
|||||
| Ransomware | Hotelogix id32159 View details | Singapore | Services | — | |
|
We are ShadowByt3$. We have claimed responsibility for hacking Hotelogix. They have been breached through there amazon s3 buckets and azure blobs. They were misconfigured which allowed us to scrape everything inside. This has been are latest campaign. If you don't pay $500,000 in btc or monero all data gets leaked. We are not joking and not playing we will. As you can tell in the sample in the data leak site or url below. We are giving you until April 14th at 12:20 it expires. It gets released. DarkWebinformer if you see this contact us asap through are telegram. Any researchers you can contact them and verify data. Also let them know what we have and have 6gb of data. Tell them if they don't pay by that date they get released and is not being put up for sale. Make the right decision and just getting law enforcement involved is just going to make it worse and as you can see they are helpless and don't do shit about you and don't care about companies. Look at how many companies get reported to the feds, you really think there going to help you. If you do your wrong. You can try to stop us but it doesn't stop the leaks from already being leaked and passed around other researchers or criminals. The following below was stolen: 1. Internal Corporate Data This data pertains to Hotelogix's own business operations and software development: - Operational Manuals: Internal guides for staff on how to use and manage their cloud-based systems. - Product Upgrade PDFs: Documentation detailing recent or upcoming software updates, which can reveal specific system architectures. - Branding Assets: Official logos, templates, and marketing materials (often used by hackers to create more convincing phishing emails). 2. Client-Specific Data (Treebo Hotels) The most critical part of the breach involves data belonging to Hotelogix’s clients. For Treebo Hotels, the stolen files include: - Customer Folios (Invoices): As seen in your image, these contain guest names, phone numbers, and home addresses. - Guest Stay Details: Specific dates of arrival and departure, room numbers, and room types (e.g., "Promotional Room Rent Oak"). - Payment Processing Details: While full credit card numbers are often encrypted, "processing details" can include: Last four digits of cards. Transaction IDs and dates. Billing amounts and tax breakdowns (GST/SGST). |
|||||
| Ransomware | UMSA id26843 View details | Other | — | ||
|
File: UMSA_LEAK.7z |
|||||