🔐
Ransomware Intelligence
Real-time tracking of ransomware victims, threat groups, and attack trends worldwide. Monitor active ransomware gangs, their targets by sector and country, and stay ahead of double-extortion campaigns with live data from 30+ group leak sites.
Active Ransomware Victims (30d)+9 today
747
▲ 170 in last 7 days
Known Ransomware Groups
125
45 active · 30 dark
Top Active Groups (7d)
qilinthegentlemenakira
Recent Ransomware Victims4,604 total
🔍
25 / 4,604| Date | Victim | Sector | Country | Group | Link |
|---|---|---|---|---|---|
| 2026-09-26 | cipher.systems | Technology | United States | m3rx | ↗ |
| 2026-09-26 | International Chemical Co. | Manufacturing | — | Barracuda | ↗ |
| 2026-09-26 | M****n | Not Found | United States | payoutsking | ↗ |
| 2026-09-26 | Applied Composites | Manufacturing | United States | Storm | ↗ |
| 2026-09-26 | Magna Legal Services | Professional Services | United States | Storm | ↗ |
| 2026-09-26 | Ligue se Grupo | Other | Portugal | thegentlemen | ↗ |
| 2026-09-26 | Charles Keith | Retail & E-Commerce | Singapore | thegentlemen | ↗ |
| 2026-09-26 | ENKEI******* | Manufacturing | — | thegentlemen | ↗ |
| 2026-09-26 | FTAPI Software | Technology | United States | thegentlemen | ↗ |
| 2026-09-26 | Crossett | Other | United States | termite | ↗ |
| 2026-09-25 | N... | Not Found | — | SilentRansomGroup | ↗ |
| 2026-09-25 | S... | Not Found | — | SilentRansomGroup | ↗ |
| 2026-09-25 | GE Vernova Inc. | Energy & Utilities | United States | metaencryptor | ↗ |
| 2026-09-25 | PKF Hadiwinata | Professional Services | Indonesia | metaencryptor | ↗ |
| 2026-09-25 | Platinum Healthcare Staffing | Healthcare | United States | metaencryptor | ↗ |
| 2026-09-25 | Electrolux & Ontrac | Manufacturing | — | emperador | ↗ |
| 2026-09-25 | Securitas Group | Professional Services | Sweden | everest | ↗ |
| 2026-09-25 | Morula IVF | Healthcare | South Africa | everest | ↗ |
| 2026-09-25 | Tobin & Company | Financial Services | United States | Wallstreet | ↗ |
| 2026-09-25 | Ar Valve Resources | Energy & Utilities | United Kingdom | Wallstreet | ↗ |
| 2026-09-25 | GTFM | Not Found | United States | Wallstreet | ↗ |
| 2026-09-25 | Beatus Cartons | Manufacturing | United Kingdom | Wallstreet | ↗ |
| 2026-09-25 | Reliance Audit | Professional Services | — | everest | ↗ |
| 2026-09-25 | UNIRITA | Technology | Japan | everest | ↗ |
| 2026-09-25 | CENELEC | Professional Services | Belgium | everest | ↗ |
Page 1 / 185
📈 Ransomware Trend — Last 30 Days747 victims
Daily victims
Ransomware Groups Overview125 total
45 active · 30 dark
| Gang Name | Total | 30d | 7d | Status | Country | Sectors | Last Seen |
|---|---|---|---|---|---|---|---|
qilin | 641 | +85 | +17 | ● Active | — | — | 2026-09-25 |
thegentlemen | 562 | +78 | +5 | ● Active | — | — | 2026-09-26 |
akira | 194 | +40 | +9 | ● Active | — | — | 2026-09-24 |
krybit | 151 | +34 | +4 | ● Active | — | — | 2026-09-24 |
incransom | 196 | +31 | +8 | ● Active | — | — | 2026-09-25 |
clop Observed for the first time in Febuary 2019, variant from CryptoMix Family, itself a varia… | 116 | +25 | +23 | ● Active | — | — | 2026-09-23 |
Storm ransomware | 61 | +25 | +5 | ● Active | — | — | 2026-09-26 |
lockbit5 | 101 | +24 | +4 | ● Active | — | — | 2026-09-25 |
direwolf | 62 | +20 | — | ● Dark | — | — | 2026-09-11 |
safepay SafePay ransomware started in October 2024 as a new ransomware service, using some of the … | 116 | +19 | — | ● Dark | — | — | 2026-09-15 |
emperador | 28 | +19 | +5 | ● Active | — | — | 2026-09-25 |
AuditTeam | 33 | +18 | +2 | ● Active | — | — | 2026-09-22 |
metaencryptor | 24 | +18 | +9 | ● Active | — | — | 2026-09-25 |
SilentRansomGroup | 58 | +17 | +8 | ● Active | — | — | 2026-09-25 |
Wallstreet | 23 | +17 | +7 | ● Active | — | — | 2026-09-25 |
Panzer | 32 | +16 | — | ● Dark | — | — | 2026-09-18 |
Vexy Ransomware | 16 | +16 | +1 | ● Active | — | — | 2026-09-25 |
N0n | 14 | +14 | +3 | ● Active | — | — | 2026-09-25 |
play Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through do… | 79 | +13 | +2 | ● Active | — | — | 2026-09-21 |
shinyhunters | 82 | +12 | +3 | ● Active | — | — | 2026-09-24 |
everest | 45 | +12 | +6 | ● Active | — | — | 2026-09-25 |
BrainCipher | 37 | +12 | +1 | ● Active | — | — | 2026-09-23 |
rhysida Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group util… | 21 | +11 | +2 | ● Active | — | — | 2026-09-24 |
chaos | 47 | +9 | — | ● Dark | — | — | 2026-09-17 |
medusalocker Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilitie… | 45 | +9 | +3 | ● Active | — | — | 2026-09-23 |
dragonforce Research on the operators of the DragonForce ransomware was conducted, and it was identifi… | 207 | +8 | +3 | ● Active | — | — | 2026-09-24 |
Booba Project | 19 | +7 | +5 | ● Active | — | — | 2026-09-23 |
anubis | 49 | +6 | +2 | ● Active | — | — | 2026-09-22 |
Global Secret Group | 47 | +6 | +2 | ● Active | — | — | 2026-09-21 |
pear ABOUT US:
<br/>
<br/>"Pure Extraction And Ransom (PEAR) Team is the community of highly re… | 38 | +6 | +3 | ● Active | — | — | 2026-09-24 |
Orova | 28 | +6 | +2 | ● Active | — | — | 2026-09-20 |
Eclipse | 10 | +6 | — | ● Dark | — | — | 2026-09-14 |
ShadowByt3$ | 8 | +6 | — | ● Dark | — | — | 2026-09-16 |
spacebears | 29 | +5 | +1 | ● Active | — | — | 2026-09-23 |
arcusmedia | 15 | +5 | +1 | ● Active | — | — | 2026-09-23 |
unsafe | 12 | +5 | +1 | ● Active | — | — | 2026-09-21 |
EndZone | 5 | +5 | +3 | ● Active | — | — | 2026-09-24 |
aurora | 36 | +4 | — | ● Dark | — | — | 2026-09-07 |
Dark Project | 17 | +4 | — | ● Dark | — | — | 2026-09-09 |
termite | 13 | +4 | +4 | ● Active | — | — | 2026-09-26 |
Barracuda | 12 | +4 | +3 | ● Active | — | — | 2026-09-26 |
Doommageddon | 9 | +4 | +1 | ● Active | — | — | 2026-09-21 |
Spirals | 4 | +4 | +2 | ● Active | — | — | 2026-09-24 |
nightspire | 47 | +3 | +2 | ● Active | — | — | 2026-09-21 |
kairos | 22 | +3 | +1 | ● Active | — | — | 2026-09-22 |
majinahanashi | 14 | +3 | — | ● Dark | — | — | 2026-09-01 |
DYSPHOR1A | 10 | +3 | — | ● Dark | — | — | 2026-09-06 |
iah6477 | 8 | +3 | — | ● Dark | — | — | 2026-09-15 |
insomnia | 6 | +3 | — | ● Dark | — | — | 2026-09-15 |
global Not a RaaS yet. | 3 | +3 | — | ● Dark | — | — | 2026-09-12 |
Falcon | 3 | +3 | — | ● Dark | — | — | 2026-08-31 |
genesis Financial interests only.
<br/> We do not provide or work with affiliate programs, no c… | 52 | +2 | — | ● Dark | — | — | 2026-09-14 |
m3rx | 39 | +2 | +1 | ● Active | — | — | 2026-09-26 |
gunra | 34 | +2 | — | ● Dark | — | — | 2026-09-04 |
threeam | 27 | +2 | +1 | ● Active | — | — | 2026-09-21 |
titan | 25 | +2 | +2 | ● Active | — | — | 2026-09-22 |
interlock | 21 | +2 | — | ● Dark | — | — | 2026-09-07 |
bravox | 20 | +2 | +1 | ● Active | — | — | 2026-09-20 |
securotrop | 12 | +2 | — | ● Dark | — | — | 2026-09-18 |
kazu | 11 | +2 | — | ● Dark | — | — | 2026-09-07 |
moneymessage | 7 | +2 | +1 | ● Active | — | — | 2026-09-21 |
Black X | 3 | +2 | — | ● Dark | — | — | 2026-08-30 |
fulcrumsec | 25 | +1 | — | ● Dark | — | — | 2026-09-11 |
lynx | 19 | +1 | — | ● Dark | — | — | 2026-08-29 |
blacknevas | 14 | +1 | — | ● Dark | — | — | 2026-09-16 |
payoutsking Payouts King Group. We are not RaaS. No affiliates are accepted. We use Tox messaging prot… | 14 | +1 | +1 | ● Active | — | — | 2026-09-26 |
killsec | 10 | +1 | — | ● Dark | — | — | 2026-09-18 |
Gammax | 5 | +1 | — | ● Dark | — | — | 2026-09-18 |
crypto24 aka Public Data Storage | 4 | +1 | — | ● Dark | — | — | 2026-08-31 |
embargo | 3 | +1 | — | ● Dark | — | — | 2026-09-09 |
tridentlocker | 2 | +1 | — | ● Dark | — | — | 2026-09-04 |
cry0 | 2 | +1 | — | ● Dark | — | — | 2026-09-19 |
BlackLocks | 1 | +1 | — | ● Dark | — | — | 2026-09-05 |
secp0 | 1 | +1 | +1 | ● Active | — | — | 2026-09-22 |
ImNotAVillain | 1 | +1 | +1 | ● Active | — | — | 2026-09-24 |
Deadlock | 91 | — | — | ● Dark | — | — | 2026-08-24 |
coinbasecartel | 88 | — | — | ● Dark | — | — | 2026-08-23 |
nova Rebrand of RALord | 83 | — | — | ● Dark | — | — | 2026-07-25 |
apt73 A new ransomware group is said to have emerged in mid-April 2024, under the name "APT73." … | 77 | — | — | ● Dark | — | — | 2026-07-24 |
payload | 53 | — | — | ● Dark | — | — | 2026-08-20 |
cmdorganization | 41 | — | — | ● Dark | — | — | 2026-07-31 |
CRPxO | 37 | — | — | ● Dark | — | — | 2026-08-02 |
worldleaks | 34 | — | — | ● Dark | — | — | 2026-07-21 |
lamashtu | 34 | — | — | ● Dark | — | — | 2026-06-17 |
stormous | 33 | — | — | ● Dark | — | — | 2026-07-01 |
AiLock AiLock is a Ransomware-as-a-Service (RaaS) group first identified in March 2025. It employ… | 27 | — | — | ● Dark | — | — | 2026-08-26 |
Section9 | 20 | — | — | ● Dark | — | — | 2026-07-30 |
ExfilSquad | 15 | — | — | ● Dark | — | — | 2026-07-26 |
shadowbyt3$ | 12 | — | — | ● Dark | — | — | 2026-06-16 |
Icarus | 12 | — | — | ● Dark | — | — | 2026-06-23 |
blackwater | 11 | — | — | ● Dark | — | — | 2026-08-24 |
LeakBazaar | 9 | — | — | ● Dark | — | — | 2026-05-10 |
Helix | 8 | — | — | ● Dark | — | — | 2026-08-22 |
handala | 8 | — | — | ● Dark | — | — | 2026-04-08 |
morpheus | 8 | — | — | ● Dark | — | — | 2026-07-30 |
xpl0itrs | 7 | — | — | ● Dark | — | — | 2026-08-20 |
netrunner | 6 | — | — | ● Dark | — | — | 2026-04-03 |
ransomhouse | 6 | — | — | ● Dark | — | — | 2026-07-15 |
sinobi | 6 | — | — | ● Dark | — | — | 2026-05-08 |
0day Syndicate | 5 | — | — | ● Dark | — | — | 2026-05-29 |
lapsus$ Lapsus$ is a cyber extortion group first observed in late 2021, known for high-profile bre… | 5 | — | — | ● Dark | — | — | 2026-06-23 |
ALP-001 | 5 | — | — | ● Dark | — | — | 2026-04-08 |
PrinzEugen | 5 | — | — | ● Dark | — | — | 2026-06-26 |
settra | 5 | — | — | ● Dark | — | — | 2026-06-30 |
secpo | 5 | — | — | ● Dark | — | — | 2026-04-29 |
abyss | 4 | — | — | ● Dark | — | — | 2026-08-26 |
cloak | 4 | — | — | ● Dark | — | — | 2026-06-18 |
mnt6 | 3 | — | — | ● Dark | — | — | 2026-05-02 |
D1R | 3 | — | — | ● Dark | — | — | 2026-07-13 |
ransomexx We recently discovered a new file-encrypting Trojan built as an ELF executable and intende… | 3 | — | — | ● Dark | — | — | 2026-06-20 |
blackout Ransomware | 3 | — | — | ● Dark | — | — | 2026-07-19 |
TiMc | 3 | — | — | ● Dark | — | — | 2026-04-09 |
ms13089 | 2 | — | — | ● Dark | — | — | 2026-08-15 |
Redact | 2 | — | — | ● Dark | — | — | 2026-06-28 |
beast | 2 | — | — | ● Dark | — | — | 2026-05-16 |
nitrogen | 2 | — | — | ● Dark | — | — | 2026-06-03 |
Blackfield | 2 | — | — | ● Dark | — | — | 2026-07-03 |
radar | 1 | — | — | ● Dark | — | — | 2026-04-29 |
orca | 1 | — | — | ● Dark | — | — | 2026-04-27 |
ValenciaLeaks | 1 | — | — | ● Dark | — | — | 2024-09-18 |
dispossessor | 1 | — | — | ● Dark | — | — | 2024-04-19 |
L Group | 1 | — | — | ● Dark | — | — | 2026-08-23 |
exitium | 1 | — | — | ● Dark | — | — | 2026-04-14 |
vect | 1 | — | — | ● Dark | — | — | 2026-04-15 |
Triple X | 1 | — | — | ● Dark | — | — | 2026-08-05 |
⬡ Collector Health Grid32/32 online
🖥
Feodo
31m
📦
MalwareBazaar
31m
🔒
SSLBL
2h
🛡
ThreatFox
1m
🌐
URLhaus
31m
🛡
AbuseIPDB
1h
⬡
AL
2h
🕸
C2Intel
2h
⚡
CISA KEV
2h
💣
Exploit-DB
2h
📊
FIRST EPSS
1d
🌫
GreyNoise
14h
📰
Mandiant
31m
⬡
MI
1d
🗺
MITRE ATT&CK
14h
⬡
MS
2h
✨
AI Summaries
29m
📋
NVD CVE
2h
🎣
OpenPhish
2h
🔐
Ransomware.live
1m
⬡
RA
122d
📰
Sec.Blogs
1m
🔍
SigmaHQ
1d
👤
Hudson Rock
2h
🤖
Clustering
28m
⬡
TH
14h
⬡
TH
14h
🔗
Tor Exits
2h
🔬
VirusTotal
1h
⬡
YA
6h
⬡
YA
7h
⬡
YA
7h