🔐
Ransomware Intelligence
Real-time tracking of ransomware victims, threat groups, and attack trends worldwide. Monitor active ransomware gangs, their targets by sector and country, and stay ahead of double-extortion campaigns with live data from 30+ group leak sites.
Active Ransomware Victims (30d)+71 today
920
▲ 247 in last 7 days
Known Ransomware Groups
106
35 active · 33 dark
Top Active Groups (7d)
thegentlemenqilinclop
Recent Ransomware Victims3,363 total
🔍
25 / 3,363| Date | Victim | Sector | Country | Group | Link |
|---|---|---|---|---|---|
| 2026-08-12 | Riker Danzig Scherer Hyland & Perretti | Professional Services | — | SilentRansomGroup | ↗ |
| 2026-08-12 | Hightech Signs | Manufacturing | United States | kairos | ↗ |
| 2026-08-12 | Riker Danzig LLP | Professional Services | United States | SilentRansomGroup | ↗ |
| 2026-08-12 | gamaus.com | Technology | United States | incransom | ↗ |
| 2026-08-12 | Westbrook Greenhouse Systems www.westbrooksystems.com serviced by an IT company Computer C... | Agriculture and Food Production | United States | blacknevas | ↗ |
| 2026-08-12 | Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co... | Healthcare | United States | blacknevas | ↗ |
| 2026-08-12 | Jack Rutherford Customs Brokers Ltd / The Rutherford Group www.therg.ca serviced by an IT ... | Professional Services | Canada | blacknevas | ↗ |
| 2026-08-12 | United Association Local Union 345 | Other | United States | qilin | ↗ |
| 2026-08-12 | BEDC.COM.AU | Energy & Utilities | Australia | incransom | ↗ |
| 2026-08-12 | diabetesandmetabolism.com | Healthcare | United States | incransom | ↗ |
| 2026-08-12 | AOL.COM | Technology | United States | clop | ↗ |
| 2026-08-12 | GATE7LLC.COMGBBEV.COM | Not Found | United Kingdom | clop | ↗ |
| 2026-08-12 | ENTERATEK.MXESBERBEVERAGE.COM | Agriculture and Food Production | Mexico | clop | ↗ |
| 2026-08-12 | NUVITIA.COM | Technology | France | clop | ↗ |
| 2026-08-12 | IPMSOLUTIONS.SK | Professional Services | Slovakia | clop | ↗ |
| 2026-08-12 | ECCELLENT.COM | Other | Italy | clop | ↗ |
| 2026-08-12 | STNET.IT | Technology | Italy | clop | ↗ |
| 2026-08-12 | QCPL.IN | Manufacturing | India | clop | ↗ |
| 2026-08-12 | FLUIDLOGIC.COM | Technology | United States | clop | ↗ |
| 2026-08-12 | MIDLANDIND.COM.AU | Manufacturing | Australia | clop | ↗ |
| 2026-08-12 | ITKHOLDING.HU | Technology | Hungary | clop | ↗ |
| 2026-08-12 | G3AEROSPACE.COM | Government & Defense | United States | clop | ↗ |
| 2026-08-12 | ARCHERGREY.COM | Other | United States | clop | ↗ |
| 2026-08-12 | OMNITANKER.COM | Transportation | United States | clop | ↗ |
| 2026-08-12 | LIFESTRAW.COM | Retail & E-Commerce | United States | clop | ↗ |
Page 1 / 135
📈 Ransomware Trend — Last 30 Days920 victims
Daily victims
Ransomware Groups Overview106 total
35 active · 33 dark
| Gang Name | Total | 30d | 7d | Status | Country | Sectors | Last Seen |
|---|---|---|---|---|---|---|---|
thegentlemen | 432 | +136 | +36 | ● Active | — | — | 2026-08-10 |
qilin | 472 | +127 | +38 | ● Active | — | — | 2026-08-12 |
clop Observed for the first time in Febuary 2019, variant from CryptoMix Family, itself a varia… | 89 | +87 | +46 | ● Active | — | — | 2026-08-12 |
incransom | 148 | +41 | +7 | ● Active | — | — | 2026-08-12 |
Global Secret Group | 36 | +36 | +3 | ● Active | — | — | 2026-08-10 |
dragonforce Research on the operators of the DragonForce ransomware was conducted, and it was identifi… | 191 | +35 | +3 | ● Active | — | — | 2026-08-11 |
CRPxO | 37 | +31 | — | ● Dark | — | — | 2026-08-02 |
safepay SafePay ransomware started in October 2024 as a new ransomware service, using some of the … | 94 | +29 | — | ● Dark | — | — | 2026-08-03 |
krybit | 99 | +28 | +11 | ● Active | — | — | 2026-08-12 |
akira | 136 | +21 | +5 | ● Active | — | — | 2026-08-10 |
play Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through do… | 61 | +21 | +6 | ● Active | — | — | 2026-08-09 |
Deadlock | 86 | +20 | +1 | ● Active | — | — | 2026-08-10 |
nova Rebrand of RALord | 83 | +20 | — | ● Dark | — | — | 2026-07-25 |
Section9 | 20 | +20 | — | ● Dark | — | — | 2026-07-30 |
Orova | 17 | +17 | +11 | ● Active | — | — | 2026-08-11 |
ExfilSquad | 15 | +15 | — | ● Dark | — | — | 2026-07-26 |
genesis Financial interests only.
<br/> We do not provide or work with affiliate programs, no c… | 49 | +13 | +4 | ● Active | — | — | 2026-08-11 |
chaos | 34 | +12 | — | ● Dark | — | — | 2026-08-05 |
direwolf | 15 | +11 | +11 | ● Active | — | — | 2026-08-11 |
Storm ransomware | 11 | +11 | +11 | ● Active | — | — | 2026-08-10 |
anubis | 39 | +10 | +1 | ● Active | — | — | 2026-08-10 |
coinbasecartel | 68 | +9 | — | ● Dark | — | — | 2026-08-01 |
cmdorganization | 41 | +8 | — | ● Dark | — | — | 2026-07-31 |
spacebears | 21 | +8 | +3 | ● Active | — | — | 2026-08-12 |
arcusmedia | 8 | +8 | — | ● Dark | — | — | 2026-07-26 |
shinyhunters | 59 | +7 | +1 | ● Active | — | — | 2026-08-09 |
m3rx | 36 | +7 | — | ● Dark | — | — | 2026-07-26 |
aurora | 27 | +7 | +1 | ● Active | — | — | 2026-08-11 |
blacknevas | 12 | +7 | +4 | ● Active | — | — | 2026-08-12 |
Dark Project | 7 | +7 | — | ● Dark | — | — | 2026-08-05 |
majinahanashi | 7 | +7 | +7 | ● Active | — | — | 2026-08-12 |
SilentRansomGroup | 27 | +6 | +5 | ● Active | — | — | 2026-08-12 |
kairos | 18 | +6 | +1 | ● Active | — | — | 2026-08-12 |
Booba Project | 8 | +6 | — | ● Dark | — | — | 2026-07-31 |
Panzer | 6 | +6 | +4 | ● Active | — | — | 2026-08-11 |
payload | 51 | +5 | +3 | ● Active | — | — | 2026-08-11 |
gunra | 31 | +5 | — | ● Dark | — | — | 2026-08-05 |
interlock | 18 | +5 | +1 | ● Active | — | — | 2026-08-11 |
bravox | 17 | +5 | +4 | ● Active | — | — | 2026-08-10 |
unsafe | 7 | +5 | +3 | ● Active | — | — | 2026-08-10 |
Helix | 5 | +5 | +5 | ● Active | — | — | 2026-08-07 |
AiLock AiLock is a Ransomware-as-a-Service (RaaS) group first identified in March 2025. It employ… | 23 | +4 | — | ● Dark | — | — | 2026-07-15 |
Gammax | 4 | +4 | +1 | ● Active | — | — | 2026-08-06 |
Barracuda | 4 | +4 | +4 | ● Active | — | — | 2026-08-06 |
killsec | 8 | +3 | — | ● Dark | — | — | 2026-07-23 |
securotrop | 8 | +3 | — | ● Dark | — | — | 2026-07-30 |
blackout Ransomware | 3 | +3 | — | ● Dark | — | — | 2026-07-19 |
nightspire | 43 | +2 | — | ● Dark | — | — | 2026-07-27 |
worldleaks | 34 | +2 | — | ● Dark | — | — | 2026-07-21 |
threeam | 24 | +2 | +1 | ● Active | — | — | 2026-08-06 |
lynx | 18 | +2 | +2 | ● Active | — | — | 2026-08-06 |
payoutsking Payouts King Group. We are not RaaS. No affiliates are accepted. We use Tox messaging prot… | 13 | +2 | — | ● Dark | — | — | 2026-08-05 |
termite | 9 | +2 | — | ● Dark | — | — | 2026-07-28 |
morpheus | 8 | +2 | — | ● Dark | — | — | 2026-07-30 |
Wallstreet | 6 | +2 | +2 | ● Active | — | — | 2026-08-10 |
moneymessage | 5 | +2 | — | ● Dark | — | — | 2026-07-25 |
apt73 A new ransomware group is said to have emerged in mid-April 2024, under the name "APT73." … | 77 | +1 | — | ● Dark | — | — | 2026-07-24 |
lockbit5 | 65 | +1 | — | ● Dark | — | — | 2026-08-05 |
everest | 28 | +1 | — | ● Dark | — | — | 2026-08-05 |
BrainCipher | 25 | +1 | — | ● Dark | — | — | 2026-07-22 |
titan | 15 | +1 | — | ● Dark | — | — | 2026-07-21 |
blackwater | 8 | +1 | — | ● Dark | — | — | 2026-07-25 |
ransomhouse | 6 | +1 | — | ● Dark | — | — | 2026-07-15 |
Doommageddon | 5 | +1 | — | ● Dark | — | — | 2026-07-19 |
Triple X | 1 | +1 | — | ● Dark | — | — | 2026-08-05 |
cry0 | 1 | +1 | +1 | ● Active | — | — | 2026-08-06 |
Black X | 1 | +1 | — | ● Dark | — | — | 2026-07-16 |
emperador | 1 | +1 | +1 | ● Active | — | — | 2026-08-12 |
lamashtu | 34 | — | — | ● Dark | — | — | 2026-06-17 |
stormous | 33 | — | — | ● Dark | — | — | 2026-07-01 |
medusalocker Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilitie… | 26 | — | — | ● Dark | — | — | 2026-07-07 |
pear ABOUT US:
<br/>
<br/>"Pure Extraction And Ransom (PEAR) Team is the community of highly re… | 25 | — | — | ● Dark | — | — | 2026-07-03 |
fulcrumsec | 24 | — | — | ● Dark | — | — | 2026-06-10 |
AuditTeam | 12 | — | — | ● Dark | — | — | 2026-06-14 |
Icarus | 12 | — | — | ● Dark | — | — | 2026-06-23 |
shadowbyt3$ | 12 | — | — | ● Dark | — | — | 2026-06-16 |
LeakBazaar | 9 | — | — | ● Dark | — | — | 2026-05-10 |
handala | 8 | — | — | ● Dark | — | — | 2026-04-08 |
sinobi | 6 | — | — | ● Dark | — | — | 2026-05-08 |
netrunner | 6 | — | — | ● Dark | — | — | 2026-04-03 |
rhysida Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group util… | 5 | — | — | ● Dark | — | — | 2026-06-18 |
lapsus$ Lapsus$ is a cyber extortion group first observed in late 2021, known for high-profile bre… | 5 | — | — | ● Dark | — | — | 2026-06-23 |
ALP-001 | 5 | — | — | ● Dark | — | — | 2026-04-08 |
0day Syndicate | 5 | — | — | ● Dark | — | — | 2026-05-29 |
settra | 5 | — | — | ● Dark | — | — | 2026-06-30 |
PrinzEugen | 5 | — | — | ● Dark | — | — | 2026-06-26 |
secpo | 5 | — | — | ● Dark | — | — | 2026-04-29 |
cloak | 4 | — | — | ● Dark | — | — | 2026-06-18 |
ransomexx We recently discovered a new file-encrypting Trojan built as an ELF executable and intende… | 3 | — | — | ● Dark | — | — | 2026-06-20 |
mnt6 | 3 | — | — | ● Dark | — | — | 2026-05-02 |
TiMc | 3 | — | — | ● Dark | — | — | 2026-04-09 |
abyss | 3 | — | — | ● Dark | — | — | 2026-06-01 |
D1R | 3 | — | — | ● Dark | — | — | 2026-07-13 |
crypto24 aka Public Data Storage | 3 | — | — | ● Dark | — | — | 2026-04-17 |
beast | 2 | — | — | ● Dark | — | — | 2026-05-16 |
Blackfield | 2 | — | — | ● Dark | — | — | 2026-07-03 |
Redact | 2 | — | — | ● Dark | — | — | 2026-06-28 |
embargo | 2 | — | — | ● Dark | — | — | 2026-06-30 |
nitrogen | 2 | — | — | ● Dark | — | — | 2026-06-03 |
insomnia | 2 | — | — | ● Dark | — | — | 2026-06-25 |
exitium | 1 | — | — | ● Dark | — | — | 2026-04-14 |
ms13089 | 1 | — | — | ● Dark | — | — | 2026-05-05 |
vect | 1 | — | — | ● Dark | — | — | 2026-04-15 |
radar | 1 | — | — | ● Dark | — | — | 2026-04-29 |
tridentlocker | 1 | — | — | ● Dark | — | — | 2026-04-27 |
orca | 1 | — | — | ● Dark | — | — | 2026-04-27 |
⬡ Collector Health Grid32/32 online
🖥
Feodo
25m
📦
MalwareBazaar
25m
🔒
SSLBL
25m
🛡
ThreatFox
25m
🌐
URLhaus
25m
🛡
AbuseIPDB
2h
⬡
AL
3h
🕸
C2Intel
3h
⚡
CISA KEV
3h
💣
Exploit-DB
3h
📊
FIRST EPSS
2d
🌫
GreyNoise
3h
📰
Mandiant
25m
⬡
MI
2d
🗺
MITRE ATT&CK
3h
⬡
MS
3h
✨
AI Summaries
25m
📋
NVD CVE
3h
🎣
OpenPhish
3h
🔐
Ransomware.live
25m
⬡
RA
77d
📰
Sec.Blogs
25m
🔍
SigmaHQ
2d
👤
Hudson Rock
3h
🤖
Clustering
25m
⬡
TH
3h
⬡
TH
3h
🔗
Tor Exits
3h
🔬
VirusTotal
2h
⬡
YA
2m
⬡
YA
47m
⬡
YA
17m