Ransomware Group intelligence
Tengu
InactiveTrack Tengu with 50 published victims and 1 known leak locations in a single intelligence view.
Overview
Tengu is tracked by Breach House as a ransomware group with 50 published victims.
India is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 3h ago | longcc4fqrfcqt5lzceutylaxir6h66fp6df3oin6mvwvz6pfdbxc6qd.onion |
Top Activity Sectors (15)
- IT 8
- Communication / Marketing 6
- Manufacturing / Engineering 5
- Not identified 4
- Public Sector 4
- Hospitality / Food & Beverage / Tourism 3
- Construction / Real Estate 3
- Education 3
- Agriculture / Food 3
- Energy 3
- Services 2
- NGOs / Associations 2
- Retail / E-commerce 2
- Healthcare / Pharma 1
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Tengu, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: tengu executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: tengu modifies Registry Run Keys to maintain persistence by reloading malicious payloads on system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: tengu disables antivirus tools by terminating security processes and modifying system configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: tengu deletes Volume Shadow Copies and backup directories via command-line tools to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1110 Brute Force Credential Access
What they do: tengu brute-forces local and domain accounts using credential lists to gain elevated access to protected resources.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1049 System Network Connections Discovery Discovery
What they do: tengu queries system network connections to identify high-value servers and data repositories for targeted encryption.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1057 Process Discovery Discovery
What they do: tengu uses process discovery to identify critical system processes for targeting or disabling during lateral movement.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: tengu leverages SMB/Windows Admin Shares to spread ransomware across networked machines within victim environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: tengu encrypts victim files using custom ransomware binaries targeting critical data across compromised systems.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: tengu calls system recovery inhibitors like shutdown scripts to prevent automated restoration attempts post-encryption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
[rand2].README.txt
████████╗███████╗███╗░░██╗░██████╗░██╗░░░██╗ ╚══██╔══╝██╔════╝████╗░██║██╔════╝░██║░░░██║ ░░░██║░░░█████╗░░██╔██╗██║██║░░██╗░██║░░░██║ ░░░██║░░░██╔══╝░░██║╚████║██║░░╚██╗██║░░░██║ ░░░██║░░░███████╗██║░╚███║╚██████╔╝╚██████╔╝ ░░░╚═╝░░░╚══════╝╚═╝░░╚══╝░╚═════╝░░╚═════╝░ TENGU Locker Blog: http://longcc4fqrfcqt5lzceutylaxir6h66fp6df3oin6mvwvz6pfdbxc6qd.onion/ http://longejh5gj5igfinj36rmqt2ydx2vun6zmditi3ij6hebawnn4xucqad.onion/ http://longf6faa6tiudn5n6ar77z5balign2cxo2tjfsxuf6wnlzjamqew2yd.onion/ http://longhbqhzlv3p7tvx3iwhfizkmtkm2nhnlbw5d4qr65wjz5e6aa23mid.onion/ http://longjr5sl6a57ajn52nysmvgobmb7lktjthssmt2jeyjagk3rw36djyd.onion/ We have breached your network and copied your data. We have copied all your confidential data and uploaded it to a private storage device. You run a high-value company, and your data is critical. We have encrypted your files. As you read this message, your network, or at least a device within your network, will have been encrypted by the world's most powerful ransomware. Your files have been encrypted using a new military-grade encryption algorithm, and you cannot decrypt them. But don't worry, we can decrypt your files. There is only one way to recover your computers and servers and maintain your privacy: contact us via live chat and pay for the unlocker software and private decryption keys. The unlocker will fully restore your network in less than 5 hours. What are the guarantees? ----------------- We can publish all your important data and send emails to your competitors. We have a dedicated Open Network Intelligence (OSINT) team and a media team specializing in data leaks across Telegram, Facebook, Twitter, and major news sites. You could face significant problems with serious consequences, including: - Loss of valuable intellectual property - Increased incident response costs - Misuse of information - Loss of customer trust - Damage to your brand and reputation - Legal and regulatory issues After you pay the costs of the data breach and decryption, we guarantee that we will not attack you again and will permanently delete your data from our servers. ------------------ We will only communicate with authorized individuals. This could be your CEO, senior management, or others. If you are not one of these people, do not contact us! Inform your superiors and remain calm! If we do not receive a response from you within 48 hours, we will begin publishing your data on our official blog. Your next steps: 1) Download the Tor Browser: https://www.torproject.org/download/ 2) Visit the chat: http://longcc4fqrfcqt5lzceutylaxir6h66fp6df3oin6mvwvz6pfdbxc6qd.onion/chat/[snip]/ 3) Use this ID to log in: [snip] 4) Supp: A458DAEFD26B207A65C2D0164B354DA25F7A77D7E52D1B16E577F3A143D8EC7C272B58F72FDD Do not attempt to decrypt the files yourself - you may cause permanent data loss!
TENGU.README.txt
TENGU Locker ████████╗███████╗███╗░░██╗░██████╗░██╗░░░██╗ ╚══██╔══╝██╔════╝████╗░██║██╔════╝░██║░░░██║ ░░░██║░░░█████╗░░██╔██╗██║██║░░██╗░██║░░░██║ ░░░██║░░░██╔══╝░░██║╚████║██║░░╚██╗██║░░░██║ ░░░██║░░░███████╗██║░╚███║╚██████╔╝╚██████╔╝ ░░░╚═╝░░░╚══════╝╚═╝░░╚══╝░╚═════╝░░╚═════╝░ Blog:http://longcc4fqrfcqt5lzceutylaxir6h66fp6df3oin6mvwvz6pfdbxc6qd.onion/ We've hacked your network and copied your data. We've hacked your entire network and searched all your data. We've copied all your confidential data and uploaded it to a private storage device. You run a high-value business, and your data is critical. We've encrypted your files. As you're reading this message, your files and data have been encrypted by the world's most powerful ransomware. Your files have been encrypted with a new military-grade encryption algorithm, and you can't decrypt them. But don't worry, we can decrypt your files. There's only one way to recover your computers and servers and maintain your privacy: contact us via live chat and pay for the TENGU DECRYPTOR device and private decryption keys. The TENGU DECRYPTOR will restore your entire network in less than 5 hours. What are the guarantees? ------------------ We can make all your important data public and send emails to your competitors. We have a dedicated Open Network Intelligence (OSINT) team and a media team specializing in data leaks across Telegram, Facebook, Twitter, and major news sites. You can easily reach us. You could face major problems with serious consequences, including the loss of valuable intellectual property and other sensitive information, increased incident response costs, misuse of information, loss of customer trust, damage to your brand and reputation, and legal and regulatory issues. After paying the costs of a data breach and decryption, we guarantee that your data will never be leaked, and we remain completely silent to protect our reputation. Be careful! ------------------ We will only speak with authorized individuals. This could be your CEO, senior management, or others. If you're not one of these people, don't contact us! Your decisions and actions could seriously damage your company! Inform your superiors and stay calm! If you don't hear from us within 48 hours, we'll start posting your status on our official blog, and everyone will start noticing! Your Next Steps └─ Contact us via live chat to start the process and request a decryption test. 1) Download Tor Browser: https://www.torproject.org/download/ 2) Chat:http://longcc4fqrfcqt5lzceutylaxir6h66fp6df3oin6mvwvz6pfdbxc6qd.onion/ID 3) Use this code— id —to log in to the chat
[rand].README.txt
[ TENGU ]
---------
Ticket ID: [snip]
Blog: http://fuvodyoktsjdwu3mrbbrmdsmtblkxau6l7r5dygfwgzhf36mabjtcjad.onion/
To Management,
If you are reading this, your company is at a critical juncture. The decisions you make in the next hours will determine its future. We are here to present the only viable path forward.
Your Current Reality
├─ Your network infrastructure has been comprehensively compromised.
├─ All accessible backups—virtual and physical—have been securely wiped.
└─ A significant volume of your most sensitive corporate data has been exfiltrated prior to encryption.
The Path to Resolution
├─ We aim for a swift, discreet, and financially reasonable settlement.
├─ We will analyze your financial health to determine a fair demand.
└─ If you have cyber insurance, inform us for guidance on the process.
Benefits of Cooperation
├─ Your systems can be fully operational in approximately 24 hours after payment.
├─ Our decryptor is tested and guaranteed. Request a free decryption test for verification.
└─ Paying us is cheaper than prolonged downtime and reputational damage.
What You Must Not Do
├─ Do not modify, rename, or attempt to repair encrypted files.
├─ Do not shut down affected systems or run aggressive antivirus scans.
├─ Do not engage data recovery firms or third-party negotiators.
└─ Do not delay. Time is your most valuable and depleting resource.
The Stakes
├─ We possess: Corporate databases, financial records, legal documents, internal communications, and all backup sets.
└─ Violating our terms will result in permanent destruction of decryption keys and public release of your data.
Your Next Steps
└─ Contact us via live chat to begin the process and request a decryption test.
The clock is ticking. Your next move defines your outcome.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (50)
Search, filter and paginate the victim timeline for Tengu. Showing 1–50 of 50.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Sileno Companies Inc id27173 View details | Switzerland | Hospitality / Food & Beverage / Tourism | ||
|
Sileno Companies Inc. A US company primarily operating in the hospitality and real estate sectors, its activities include: Hotel operation Property management Management of hotels' restaurants and bars Hospitality project development 22.9TB was encrypted in 14 hours on 3/5/2026 More than 67.07 GB was extracted |
|||||
| Ransomware | Communitymosaic.co.uk id27080 View details | United Kingdom | Other | ||
|
Community Mosaic Cic is an active company incorporated on 21 June 2018 with the registered office located in Peterborough, Cambridgeshire. Community Mosaic Cic was registered 7 years ago |
|||||
| Ransomware | Eos Technology srl id27079 View details | Italy | IT | ||
|
Eos Technology srl is a company with 15 years of experience in the ICT sector, initially starting as an assembly and repair laboratory for PCs and peripherals. Over time, it has developed expertise that has allowed it to become a partner of various international brands. The company offers a range of services including IT assistance, multimedia services, help desk support, corporate security systems, and the design of virtual switchboards and video surveillance systems. Eos Technology srl aims to provide consulting services to clients navigating the dynamic audiovisual ICT landscape. |
|||||
| Ransomware | DAINTY CLOUD INC id26934 View details | United States | IT | ||
|
DaintyCloud offers a variety of affordable virtual private server (VPS) solutions including Windows, Linux, and GPU servers across more than 34 data centers worldwide. Their services cater to clients who require high performance for applications such as gaming, video processing, and cloud computing. With competitive pricing and features like one-click deployment and easy management, DaintyCloud is geared towards both individual users and businesses seeking reliable cloud services. Additionally, they provide proxy services, ensuring clients have access to high-speed, dedicated IP options |
|||||
| Ransomware | Al Arif Contracting Co. (L.L.C) id26856 View details | United Arab Emirates | Construction / Real Estate | ||
|
AAG Construction strives to grow our organization through investigating advancing technology, industry changes and the varying needs of our clientele as our industry evolves. We will continuously diversify our skill set to distinguish us from our competition and foster loyal customers as we build infrastructure projects that improve the quality of life in UAE and the Region. (OR) The Company continues to move forward in become the leading Engineering and Construction firm in UAE and eventually the region, by consistently delivering projects that meet international standards.. AAG Construction strives to grow our organization through investigating advancing technology, industry changes and the varying needs of our clientele as our industry evolves. We will continuously diversify our skill set to distinguish us from our competition and foster loyal customers as we build infrastructure projects that improve the quality of life in UAE and the Region. (OR) The Company continues to move |
|||||
| Ransomware | martec.it id26855 View details | Italy | IT | ||
|
MARTEC MARINE is part of an Italian privately owned Group active in the Defense and Integrated Safety solutions for Navy, Cruise ships and Mega Yachts since 1994.From the early beginning of its activities Martec has deeply invested in the design and development of safety systems, being awarded, at present, as one of the most skilled companies in an international context, in this field.More than 12 Navy ships and more than 80 Cruise liners and Mega Yachts have Martec Damage Control Systems installed.Product range vary from hardware (Damage Control Systems, Electronic Incident Board, Fire Detection System, Emergency Shutdown System, Automatic Fire Sensing and Suppression System) to software packages (Damage Control, Decision Support, On Board Stability, Personnel Tracking, Security and Technical Patrol Management, Injured Treatment).Innovation, Integration and Flexibility are the key words for MARTEC: development of new solutions based on customer requirements, integration with third par |
|||||
| Ransomware | www.shora.ma id26688 View details | Morocco | Services | ||
|
Shora Advisory is a network of accounting, consulting, and auditing firms located in major cities across Morocco, dedicated to providing high value-added services. They offer a range of services including financial management consulting, accounting expertise, legal and tax expertise, and training. The company focuses on proximity to clients, respecting their specific needs and constraints related to their industry. Shora Advisory aims to combine their expertise with that of their clients to foster mutual success |
|||||
| Ransomware | femar.it id26638 View details | Italy | Healthcare / Pharma | ||
|
Femar Group is a multifaceted company based in Catania, specializing in various sectors including special services, logistics, energy, and pharmaceuticals. The group encompasses several subsidiaries such as Femar Servizi Speciali, Femar Logistica, and Silverpharma, among others. Their diverse offerings cater to a wide range of clients looking for comprehensive solutions in their respective industries. With a strong presence in the industrial zone, Femar Group aims to deliver quality services and products to meet the needs of its clientele |
|||||
| Ransomware | 真言宗智山派 成就院 id26637 View details | Japan | NGOs / Associations | ||
|
Jōju-in is a traditional Japanese Buddhist temple belonging to the Shingon-shū Chisan-ha (真言宗智山派) sect, one of the main branches of Shingon Buddhism in Japan. The temple is located in Tochigi Prefecture (栃木県), specifically in the Northern Tochigi (栃木北部) region |
|||||
| Ransomware | Junta Local de Conciliación y Arbitraje id26396 View details | Mexico | Public Sector | ||
|
Affiliated with the Government of Mexico City, it provides information and services related to the Local Commission for Labor Conciliation and Arbitration (Junta Local de Conciliación y Arbitraje) in Mexico City (Ciudad de México). |
|||||
| Ransomware | PT. Mitra Antar Tangguh id26395 View details | Indonesia | Other | ||
|
PT. Mitra Utama Sinergi Tangguh is a company officially registered in Indonesia in the form of a limited liability company PT – Perseroan Terbatas |
|||||
| Ransomware | megasilver.com.tw id26217 View details | Taiwan, Province of China | IT | ||
|
Megasilver Information System Co., Ltd. (Chinese: 兆銀資訊系統股份有限公司) is a Taiwanese company engaged in information technology services and software system development, especially in digital service solutions and intelligent operating systems. |
|||||
| Ransomware | all Data id26012 View details | Education | |||
|
Tahkout Group skyegtours.com KSP TLM INDONESIA COMPAGNIE FONCIÈRE PARISIENNE lenotech.com.ph Jakarta Nanyang School namico.go.ke |
|||||
| Ransomware | We will be back soon id26004 View details | Communication / Marketing | |||
|
We are currently preparing all the files of the companies we hacked and will publish them for you. We will disappear for a while to fix some internal issues and will return with a new TENGU RaaS version that everyone can join |
|||||
| Ransomware | b2motorsport.co.il id25915 View details | Israel | Manufacturing / Engineering | ||
|
B2 Motorsport (known as B2M for short) is an Israeli company/workshop for improving and modifying cars and motorcycles, offering high-performance services and spare parts for models such as BMW and MINI, as well as motorcycle parts. |
|||||
| Ransomware | Tahkout Group id25897 View details | Algeria | Manufacturing / Engineering | ||
|
Tahkout Group is a large Algerian group of companies (sometimes described as a business alliance) founded and run by Mahieddine Tahkout, a well-known Algerian businessman in the automotive, transport, real estate and industrial sectors. |
|||||
| Ransomware | KSP TLM INDONESIA id25855 View details | Indonesia | Retail / E-commerce | ||
|
KSP TLM Indonesia is a large cooperative savings and loan association in Indonesia that focuses on empowering the community economy - especially small and medium-sized female entrepreneurs. |
|||||
| Ransomware | FRUIT-BONTÉ Agroalimentaire id25854 View details | France | Agriculture / Food | ||
|
FRUIT-BONTÉ Agroalimentaire is a Tunisian food company operating in the agricultural sector and the production of fruit-based food products. |
|||||
| Ransomware | lenotech.com.ph id25850 View details | Philippines | IT | ||
|
Lenotech Corporation specializes in a diverse range of technology products, including peripherals, laptops, and storage solutions from well-known brands such as A4tech, Lenovo, and Seagate. Their offerings include advanced gaming mice, high-performance laptops, and reliable dash cameras, catering to both individual consumers and businesses. The company aims to serve tech-savvy clients looking for quality and innovative technology solutions. With a commitment to customer satisfaction, Lenotech also provides marketing and dealer application services |
|||||
| Ransomware | COMPAGNIE FONCIÈRE PARISIENNE id25849 View details | France | Construction / Real Estate | ||
|
COMPAGNIE FONCIÈRE PARISIENNE (abbreviated as CFP) is a French company that operates in real estate, specifically in the leasing and management of real estate (renting and managing buildings and land). |
|||||
| Ransomware | skyegtours.com id25848 View details | United Kingdom | Transportation / Travel / Logistics | ||
|
Sky Egypt specializes in tourism services, offering a range of travel packages and flight tickets. The company aims to provide quality travel experiences to clients looking to explore various destinations. They cater to travelers seeking both budget-friendly and premium options. Sky Egypt emphasizes customer satisfaction and convenience in planning travel itineraries |
|||||
| Ransomware | Disuelas JC SAS id25817 View details | Colombia | Communication / Marketing | ||
|
La empresa Disuelas Jc Sas tiene como domicilio principal de su actividad la dirección, CALLE 26 SUR 29 49 en la ciudad de BOGOTA, BOGOTA. El teléfono de Disuelas Jc Sas es el 6016296011. Esta empresa fué constituida como SOCIEDAD POR ACCIONES SIMPLIFICADA y se dedica a Fabricacion de partes del calzado |
|||||
| Ransomware | premmotors.com id25816 View details | India | Communication / Marketing | ||
|
Prem Motors is a leading automobile dealership for Maruti Suzuki, established in 1990 and headquartered in Gwalior, India. The company operates 58 showrooms, 43 workshops, and various outlets across multiple states, providing a comprehensive range of services including sales, service, accessories, finance, and insurance. With a strong focus on customer satisfaction and a commitment to quality, Prem Motors has earned numerous awards for its performance and service excellence. The company aims to deliver a unique buying experience and maintain a professional reputation among manufacturers, financiers, and customers alike. |
|||||
| Ransomware | namico.go.ke id25815 View details | Kenya | Public Sector | ||
|
The National Mining Corporation (NAMICO) is a Kenyan state corporation that serves as the government's investment arm in the mining and minerals sector. Established under the Kenya Mining Act 2016, its primary objective is the exploration, development, management, and investment of the country's mineral resources on behalf of the state. |
|||||
| Ransomware | Jakarta Nanyang School id25814 View details | Indonesia | Education | ||
|
Jakarta Nanyang School (JNY) is a co-educational institution catering to students aged 3 to 18, offering a global and progressive educational approach. Established in 2012 in Bumi Serpong Damai, JNY focuses on the holistic development of students, enhancing their academic, moral, physical, social, and emotional growth. The school provides a nurturing environment and a variety of programs including Kindergarten, Primary, Secondary, and Junior College. JNY aims to serve families seeking a comprehensive and innovative educational experience for their children |
|||||
| Ransomware | STRONG WINGS LLP id25694 View details | India | Manufacturing / Engineering | ||
|
STRONG WINGS LLP is an Indian Limited Liability Partnership operating in the automotive, vehicle maintenance, and related trading sectors, and is officially registered in Pune, Maharashtra, India. |
|||||
| Ransomware | www.coconutboard.gov.in id25622 View details | India | Communication / Marketing | ||
|
The Coconut Development Board (CDB) focuses on the promotion and development of coconut cultivation and processing in India. It offers a range of products including virgin coconut oil, desiccated coconut, and coconut milk, catering to both domestic and international markets. The board supports farmers and producer companies through various schemes and technology missions aimed at enhancing productivity and sustainability. Its intended clients include coconut farmers, producers, and consumers interested in coconut-based products. |
|||||
| Ransomware | Deck India Engineering Pvt. Ltd id25593 View details | India | Manufacturing / Engineering | ||
|
Deck India Engineering Pvt. Ltd. specializes in various heat treatment services including Liquid Nitriding, Nitro Carburising, and Gas Nitriding, serving a diverse client base across Maharashtra and beyond. Established in Pune in 1998, the company is recognized as the first SSI unit in the area dedicated to these processes, with a strong focus on quality and customer satisfaction. The management team consists of professional engineers and metallurgists with extensive industry experience. Additionally, they manufacture and supply heat treatment equipment and furnaces to meet high standards in various industries. |
|||||
| Ransomware | GSM PORTAL TEKNOLOJİ HİZMETLERİ TİC. LTD. ŞTİ id25579 View details | Türkiye | IT | ||
|
This is a small to medium-sized Turkish company officially registered in Istanbul, operating in the GSM telecommunications technology and technical services sector. It has complete official documentation but is not very active digitally |
|||||
| Ransomware | Nafae Sanitaire S.a.r.l id25570 View details | Morocco | Other | ||
|
Nafae Sanitaire S.a.r.l A local company in Tangier – Castilla district, specializing in plumbing and sanitary ware (sanitaire, plomberie, chauffage) |
|||||
| Ransomware | anfibius.net id25567 View details | Spain | Services | ||
|
Anfibius is an Ecuadorian company specializing in providing software solutions and technology services for integrated business and project management. |
|||||
| Ransomware | https://comercialautomotriz.com id25558 View details | Ecuador | Manufacturing / Engineering | ||
|
Comercial Automotriz de los Altos S.A. de C.V. is a Mexican small/medium-sized company operating in the automotive and tire sector. It specializes in: The sale of tires and auto parts Mechanical services and maintenance Retail sales and spare parts for vehicles It operates in several states, including Jalisco, Michoacán, and Aguascalientes, within the Los Altos region of Mexico. |
|||||
| Ransomware | Grupo Roa id25550 View details | Colombia | Construction / Real Estate | ||
|
Grupo ROA is a Mexican group of companies operating in the construction and infrastructure sector, founded on March 30, 1995 with the aim of meeting the challenges of large construction projects in the southeastern region of Mexico. |
|||||
| Ransomware | Nordstrom Rack id25530 View details | United States | Retail / E-commerce | ||
|
Nordstrom Rack is a company that operates in the Apparel & Accessories Retail industry. It employs 1to4 people and has 500Kto1M of revenue. The company is headquartered in San Jose, California |
|||||
| Ransomware | Samson Equipment id25526 View details | United States | Education | ||
|
Samson Equipment specializes in designing and manufacturing custom weight rooms tailored for schools, colleges, and tactical training professionals. Their product lineup includes a range of durable strength training equipment like power racks, barbells, and accessories, all made to withstand high usage. The company offers personalized services including 3D render consultations to envision the final layout of weight rooms before purchase. With a commitment to exceptional quality, customer service, and a lifetime warranty, Samson Equipment aims to empower athletes and training facilities alike. |
|||||
| Ransomware | https://seha.org.sa id25498 View details | Saudi Arabia | NGOs / Associations | ||
|
https://seha.org.sa/ This is the official website of the Health Services Association in the Qassim region of Saudi Arabia. It is a non-profit/charitable organization that provides health and social services to those in need. |
|||||
| Ransomware | Quick Safety Electric id25487 View details | Australia | Energy | ||
|
Quick Safety Electric Ltd (קויק סייפטי אלקטריק בע״מ) is an Israeli company officially registered in Lahavim, Israel, operating in the field of electricity/electrical services. |
|||||
| Ransomware | www.charoenchai.com id25442 View details | Thailand | Energy | ||
|
CHAROENCHAI TRANSFORMER CO., LTD. is a manufacturer and supplier of electrical transformers based in Thailand. They manufacture and distribute various types of electrical power transformers both domestically and for export. |
|||||
| Ransomware | strategic-ts.com id25354 View details | United States | IT | ||
|
The website https://strategic-ts.com/ belongs to a small US-based IT and technology services company—and serves as the official website for a company called Strategic Technology, which operates in IT services and technical support. This information is based on company data available from professional databases. |
|||||
| Ransomware | baja.gob.mx id25336 View details | Mexico | Public Sector | ||
|
This is the official website of the Baja California State Government in Mexico — an important government site used to provide e-services, official information, procedures for citizens, news, and local government programs. |
|||||
| Ransomware | Unknown id24733 View details | Other | |||
|
Unknown is an organization in the Other sector, but the available records do not provide enough verified public detail to confirm its exact location, products, or services. In threat-intelligence indexing, such entries are used when a victim is named but the company itself remains insufficiently identified in open sources. Tengu is a ransomware operation that targets organizations across multiple sectors and regions using double-extortion tactics. Unknown was listed as a ransomware victim associated with tengu. |
|||||
| Ransomware | https://www.revnomix.com id24593 View details | India | Hospitality / Food & Beverage / Tourism | ||
|
Revnomix - India Provides data analytics and revenue management services for hotels. Founded as a hospitality technology specialist, the company is dedicated to improving hotel performance through data-driven analytics solutions. The company is committed to quality, innovation, and customer satisfaction. |
|||||
| Ransomware | **Rollingertec S.A. - Luxembourg** id24277 View details | IT | |||
|
**Rollingertec S.A. - Luxembourg** Offering integrated solutions in the field of building technology and timber construction, with a special focus on roofs, facades, and metal insulation. Founded as a specialist in the sustainable construction sector, the company is dedicated to combining time-honored craft traditions with modern technology through comprehensive turnkey projects. The company is committed to high standards of quality, environmental sustainability, and customer satisfaction. |
|||||
| Ransomware | Coral Clubes - Mexico id24157 View details | Mexico | Hospitality / Food & Beverage / Tourism | ||
|
Coral Clubes - Mexico The Fimex Group offers a collection of luxury leisure and sports clubs, with a special focus on golf clubs and integrated resorts. Founded as a specialist in the leisure and sports sector, the group is dedicated to providing exceptional experiences for its members through world-class facilities. The group is committed to the highest standards of quality, service, and customer satisfaction. |
|||||
| Ransomware | Le MULTI LABORATOIRE LC2A id23329 View details | Morocco | Communication / Marketing | ||
|
Le Multi Laboratoire LC2A offers a platform for businesses looking to test or analyze their products by configuring their ideal analytical project online |
|||||
| Ransomware | UniCursos, Brazil id23316 View details | Brazil | Public Sector | ||
|
UniCursos, Brazil - Offers preparation courses for public sector exams in São José dos Campos and surrounding areas in the state of São Paulo. |
|||||
| Ransomware | FOOD & MUSIC MANAGEMENT SL id23304 View details | Spain | Agriculture / Food | ||
|
Food & Music Management SL, based in Barcelona, Spain, is a leading company in the hospitality and entertainment sector. It specializes in developing and managing high-end restaurants and culinary concepts that combine gastronomy with music and atmosphere. |
|||||
| Ransomware | Al Rimal Group id23303 View details | United Arab Emirates | Agriculture / Food | ||
|
Al Ramal Group is a manufacturing company specializing in food products. Al Ramal Food Industries FZCO was established in 2007 and is currently headquartered in the Sharjah Airport International Free Zone, Sharjah, United Arab Emirates. |
|||||
| Ransomware | STAR LÉGUMES id23302 View details | Morocco | Communication / Marketing | ||
|
Star Legumes, Morocco - Provides wholesale services for fruits, vegetables, spices, and dried seeds in Casablanca and surrounding areas. |
|||||
| Ransomware | Qatargas and Tar Company, Iran id23301 View details | Iran, Islamic Republic of | Energy | ||
|
Qatargas and Tar Company, Iran - Provides industrial gas and tar products to the petrochemical sector in Iran and regional markets |
|||||