Ransomware Stats
{
“Cyberattacks”: {
“Last Update RSS”: “2026-03-04T03:06:05.050711+00:00”,
“Last Update json”: “2026-03-04T03:06:07.896656+00:00”,
“Number”: 3259
},
“Groups”: {
“Last Update”: “2026-03-04T03:47:58.386406+00:00”,
“Numbers”: 324
},
“Last Updates”: {
“BTC Transactions”: “2025-01-20T11:18:01.771520+00:00”,
“Infostealers”: “2026-03-04T04:02:52.937107+00:00”,
“TTPs”: “2025-08-27T10:40:22.900732+00:00”,
“Vulnerabilities”: “2025-11-01T12:00:56.611765+00:00”
},
“Victims”: {
“Last Update CSV”: “2026-03-04T03:06:06.288687+00:00”,
“Last Update RSS”: “2026-03-04T03:06:05.596700+00:00”,
“Last Update json”: “2026-03-04T04:03:14.031706+00:00”,
“Numbers”: 26245
}
}
[
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 21:50:29.286985”,
“claim_url”: “http:\/\/safepaypfxntwixwjrlcscft433ggemlhgkkdupi2ynhtcmvdgubmoyd.onion\/blog\/post\/ripobeccom\/”,
“country”: “CA”,
“description”: “Is a Canadian family-owned agricultural supply company headquartered in Saint-Apollinaire, Quebec, specialising in the production and distribution of premium wood \u2026”,
“discovered”: “2026-03-03 21:51:00.798687”,
“domain”: “ripobec.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “safepay”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 21:50:09”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/cmlwb2JlYy5jb21Ac2FmZXBheQ==”,
“victim”: “ripobec.com”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 21:46:32.764496”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=8e75d0e6-a719-3586-9d9a-3cca12d67929”,
“country”: “FR”,
“description”: “N\/A”,
“discovered”: “2026-03-03 21:46:51.811515”,
“domain”: “www.aluthea.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/792ca9843029cd001dcfc3003591c47c.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QWx1dGhlYSBHcm91cEBxaWxpbg==”,
“victim”: “Aluthea Group”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 21:45:48.808536”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=ae51059f-c48a-33c5-b924-122325f184ce”,
“country”: “”,
“description”: “N\/A”,
“discovered”: “2026-03-03 21:46:10.445341”,
“domain”: “www.luro.fr”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/cd81040133037a3d7a9697ade9fa5342.png”,
“url”: “https:\/\/www.ransomware.live\/id\/THVyb0BxaWxpbg==”,
“victim”: “Luro”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 21:45:02.314869”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=23245cfa-8e68-3a51-a96b-dc10d5227afb”,
“country”: “”,
“description”: “N\/A”,
“discovered”: “2026-03-03 21:45:26.193630”,
“domain”: “www.viviany.fr”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/717d9cf56b1dfdd9d29bfa5679422c08.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Vml2aWFueUBxaWxpbg==”,
“victim”: “Viviany”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 21:25:08.936829”,
“claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=c463def4-0ffb-4045-baad-cb1f75c26876”,
“country”: “”,
“description”: “Minogue Associates, Inc. specializes in comprehensive construction valuation reports and estimates for both commercial and residential properties, as well as consulting services for construction litigation. Established in 1973, the company has extensive experience in damage assessment and estimating services for a wide range of structures, including high-rise buildings, hotels, and schools. Their clients include property owners and insurance companies seeking expert appraisal and dispute resolution services. With a reputation for professionalism and integrity, Minogue Associates handles high-profile assignments involving significant financial exposures.”,
“discovered”: “2026-03-03 22:36:36.627979”,
“domain”: “minogueassociates.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “dragonforce”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 22:35:41”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/7fe99146285e70774f200dbd2f0e7a8b.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TWlub2d1ZSBBc3NvY2lhdGVzQGRyYWdvbmZvcmNl”,
“victim”: “Minogue Associates”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-03-03 21:24:09.467197”,
“claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=06160a3d-a88b-4896-a565-32391867f203”,
“country”: “US”,
“description”: “Lawrence Journal-World is a news organization based in Lawrence, Kansas, providing coverage on diverse topics including news, sports, opinion, and community events. The publication offers a platform for local announcements, classified ads, and job listings, catering primarily to residents and the surrounding community. It also features educational insights and updates relevant to local schools and government activities. Target clients include local residents, businesses, and those interested in Lawrence’s happenings.”,
“discovered”: “2026-03-03 22:37:31.766123”,
“domain”: “ljworld.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “dragonforce”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 22:36:39”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/30cb7277995ca4419ea5ae3125bdd210.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TGF3cmVuY2UgSm91cm5hbCAtIFdvcmxkQGRyYWdvbmZvcmNl”,
“victim”: “Lawrence Journal – World”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 20:16:27.804859”,
“claim_url”: “http:\/\/safepaypfxntwixwjrlcscft433ggemlhgkkdupi2ynhtcmvdgubmoyd.onion\/blog\/post\/franz-sales-hausde\/”,
“country”: “DE”,
“description”: “Located at Steeler Stra\u00dfe 261, 45138 Essen, is a support organization dedicated to empowering people with disabilities to live self-determined \u2026”,
“discovered”: “2026-03-03 20:16:47.603542”,
“domain”: “Franz-Sales-Haus.de”,
“duplicates”: [],
“extrainfos”: [],
“group”: “safepay”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/8615ffe1e0df91a100b3e99282e2441e.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RnJhbnotU2FsZXMtSGF1cy5kZUBzYWZlcGF5”,
“victim”: “Franz-Sales-Haus.de”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-03-03 20:13:20.960171”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=3e72369f-72e9-36ad-b202-df75f2b46b47”,
“country”: “CH”,
“description”: “N\/A”,
“discovered”: “2026-03-03 20:13:37.563064”,
“domain”: “www.gericke-spedition.de”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/849db27263b8588f710126642ed581b8.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R2VyaWNrZUBxaWxpbg==”,
“victim”: “Gericke”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-03-03 20:12:41.172442”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=82e1194d-ab32-3572-8df8-1665e6df1efc”,
“country”: “US”,
“description”: “N\/A”,
“discovered”: “2026-03-03 20:12:58.508597”,
“domain”: “www.conklinoffice.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/7b957f6612c3ac9b4e1410b6dcc39a09.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q29ua2xpbiBPZmZpY2UgRnVybml0dXJlQHFpbGlu”,
“victim”: “Conklin Office Furniture”
},
{
“activity”: “Technology”,
“attackdate”: “2026-03-03 20:11:58.770067”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=8fee8d56-9031-397e-8e7f-b8828005511a”,
“country”: “”,
“description”: “N\/A”,
“discovered”: “2026-03-03 20:12:19.126609”,
“domain”: “www.jbccomputers.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/970514ec983ae81d242b466c90431c08.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SkJDIENvbXB1dGVyc0BxaWxpbg==”,
“victim”: “JBC Computers”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 20:10:36.163890”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=lSZLemmlFZ4CRX”,
“country”: “CA”,
“description”: “Canada”,
“discovered”: “2026-03-03 20:11:13.735284”,
“domain”: “www.equestrian.ca”,
“duplicates”: [],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/388dd7d52180cc2e2bd3676ced78077f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RXF1aW5lIENhbmFkYUBwbGF5”,
“victim”: “Equine Canada”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-03-03 20:09:51.423294”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=bxG4jSz0TzfgUv”,
“country”: “US”,
“description”: “United States”,
“discovered”: “2026-03-03 20:10:34.616554”,
“domain”: “www.gapvax.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f27101e90b3cf92f067f458b1c6a802a.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R2FwVmF4QHBsYXk=”,
“victim”: “GapVax”
},
{
“activity”: “Energy”,
“attackdate”: “2026-03-03 16:38:04.821278”,
“claim_url”: “https:\/\/handala-hack.to\/aramco-hacked\/”,
“country”: “SA”,
“description”: “For years, Aramco\u2019s oil money was turned into bullets and bombs that were dropped on Palestinian children, or it funded the construction of the Epstein cult\u2019s pedophile island, or paid for Trump\u2019s missiles to strike a girls\u2019 school in Iran. But that is no longer the case. Now the entire infrastructure of Aramco has been\u2026”,
“discovered”: “2026-03-03 16:38:16.441768”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “handala”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f0748c9a2d101729b8515b8a5dd314a4.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QXJhbWNvQGhhbmRhbGE=”,
“victim”: “Aramco”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 14:05:18.880684”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=9b7f17b3-14fe-34c5-8188-96202981ccfa”,
“country”: “”,
“description”: “N\/A”,
“discovered”: “2026-03-03 14:05:41.960665”,
“domain”: “www.hotel-les-oliviers.eu”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/a9c6d4a4ae2f57aa069f559555527695.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TGVzIE9saXZpZXJzQHFpbGlu”,
“victim”: “Les Oliviers”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-03-03 10:10:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a727988f1d14b743b8c8e5”,
“country”: “US”,
“description”: “At Chris Hudson Law Group, we value the attorney-client relationship and understand that being an injured party in an accident is a stressful and overwhelming experience \u2014 things are even worse if there is a permanent disability or if a death occurs. We’re here to help you recover and move past this difficult time.”,
“discovered”: “2026-03-03 19:39:56.216980”,
“domain”: “www.chrishudsonlaw.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/20a5cc81027004874ee9c67282c8f49b.png”,
“url”: “https:\/\/www.ransomware.live\/id\/d3d3LmNocmlzaHVkc29ubGF3LmNvbUBpbmNyYW5zb20=”,
“victim”: “www.chrishudsonlaw.com”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 10:10:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a761858f1d14b743bcc860”,
“country”: “US”,
“description”: “Hopkins Barvi\u00e9 & Hopkins, P.L.L.C. is your trusted Gulf Coast firm for personal injury, business litigation, and family law\u2014fiercely protecting your rights while guiding you with honesty, respect, and genuine care.”,
“discovered”: “2026-03-03 22:41:08.753022”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/9963c999be48808245a37e98a0c2e993.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SG9wa2lucyBMYXdAaW5jcmFuc29t”,
“victim”: “Hopkins Law”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-03-03 10:10:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a75fc98f1d14b743bc999c”,
“country”: “US”,
“description”: “The Law Offices of Eric Hershler, APC, in Los Angeles, focuses exclusively on personal injury cases.”,
“discovered”: “2026-03-03 22:41:22.892918”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/c441ff77d080022b17733d109200bfd7.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SGVyc2hlciBMYXdAaW5jcmFuc29t”,
“victim”: “Hersher Law”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-03-03 10:10:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a75d7a8f1d14b743bc56dc”,
“country”: “US”,
“description”: “The attorneys at Jonathan R. Brockman, P.C. are dedicated to helping victims who have been injured or killed due to the negligence of others. Between them, our attorneys have more than 70 years of experience pursuing personal injury claims on behalf of clients and representing clients in a court of law. They have successfully tried cases in federal court and argued cases in the Georgia Court of Appeals and the Georgia Supreme Court.”,
“discovered”: “2026-03-03 22:41:41.635960”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/86ad1b1c6bf98b808d34af75ef08379f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QnJvY2ttYW4gSW5qdXJ5IExhd3llckBpbmNyYW5zb20=”,
“victim”: “Brockman Injury Lawyer”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-03-03 10:10:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a76eeb8f1d14b743bdca2d”,
“country”: “US”,
“description”: “At the Law Offices of Brent W. Caldwell, we help people who have been injured in accidents get the legal support they need during a difficult time. While there are many personal injury firms in California and Nevada, we take pride in being more than just a law office with strong results. We are focused on building real relationships with our clients and treating every case with the attention it deserves.”,
“discovered”: “2026-03-04 00:41:28.801741”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/8b1d77b62ab27f6b16e6c897b6819d12.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TGF3IE9mZmljZXMgb2YgTWFyayBFLiBMZXdpcyAmIEFzc29jaWF0ZXNAaW5jcmFuc29t”,
“victim”: “Law Offices of Mark E. Lewis & Associates”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-03-03 10:10:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a7670b8f1d14b743bd2d3d”,
“country”: “US”,
“description”: “Alexander D. Napolin is a top-rated, 100% plaintiff-side California personal injury attorney, exclusively advocating for injured individuals \u2013 never defending insurance companies or corporations.”,
“discovered”: “2026-03-04 00:42:11.652280”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/74f567d6273a74df8bbc8afb0fa35019.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TmFwb2xpbiBMYXcgRmlybUBpbmNyYW5zb20=”,
“victim”: “Napolin Law Firm”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 09:46:49.185545”,
“claim_url”: “”,
“country”: “”,
“description”: “Demanor AS specializes in providing customized goods lifts and lifting machines tailored to the specific needs and conditions of their clients.”,
“discovered”: “2026-03-03 09:46:50.729208”,
“domain”: “demanor.no”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:46:29”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/RGVtYW5vckBBaUxvY2s=”,
“victim”: “Demanor”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 09:46:26.087969”,
“claim_url”: “”,
“country”: “US”,
“description”: “Aaronson Rappaport Feinstein and Deutsch, LLP is a New York-based law firm that specializes in providing legal services across various practice areas, including medical malpractice, construction litigation, and product liability.”,
“discovered”: “2026-03-03 09:46:27.072512”,
“domain”: “arfdlaw.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:46:06”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/QWFyb25zb24gUmFwcGFwb3J0IEZlaW5zdGVpbiAmIERldXRzY2hAQWlMb2Nr”,
“victim”: “Aaronson Rappaport Feinstein & Deutsch”
},
{
“activity”: “Technology”,
“attackdate”: “2026-03-03 09:43:38.327135”,
“claim_url”: “”,
“country”: “DE”,
“description”: “ELO Digital Office, founded in 1996 and headquartered in Stuggart, Germany, is a provider of enterprise content management systems and develops software solutions to digitize business processes.”,
“discovered”: “2026-03-03 09:43:39.435579”,
“domain”: “elo.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:43:19”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/RUxPIERpZ2l0YWwgT2ZmaWNlQEFpTG9jaw==”,
“victim”: “ELO Digital Office”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 05:08:18.237331”,
“claim_url”: “http:\/\/om6q4a6cyipxvt7ioudxt24cw4oqu4yodmqzl25mqd2hgllymrgu4aqd.onion\/r\/7c0dk4mZyLqlb6RQEmh978aiMnuuS23Hzdc+mmkCRDsqX2ScCI5AFpiSZNeBlfW81kfuw9MZbuawwhnpQfAzZyOVc4Ulg2”,
“country”: “US”,
“description”: “Injury accident law firm data breach: driver IDs and other personal data.”,
“discovered”: “2026-03-03 05:09:15.030353”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “anubis”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/52b564cfff57105f95bf2b8cc1392d29.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QW5kYWwgTGF3IEdyb3VwQGFudWJpcw==”,
“victim”: “Andal Law Group”
},
{
“activity”: “Technology”,
“attackdate”: “2026-03-03 04:46:02.463512”,
“claim_url”: “”,
“country”: “US”,
“description”: “Several hundreds of millions of records containing PII, transaction\/order data, other internal corporate data, and a lot more (you don’t want us to say publicly) have been compromised. This is a final warning to reach out by 05 Mar 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline. | Updated: 03 Mar 2026 | Warning: FINAL WARNING”,
“discovered”: “2026-03-03 04:46:05.244779”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “shinyhunters”,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/V29mbG93LCBJbmMuQHNoaW55aHVudGVycw==”,
“victim”: “Woflow, Inc.”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-03-03 01:05:25.789000”,
“claim_url”: “http:\/\/termiteuslbumdge2zmfmfcsrvmvsfe4gvyudc5j6cdnisnhtftvokid.onion\/post\/69a6314dfeb604ea6ee5ab74”,
“country”: “US”,
“description”: “Bartram Trail Surveying, Inc. is a Florida licensed land surveying company that specializes in providing accurate and precise land surveying services across the state. Utilizing state-of-the-art technology, including drone surveying, LiDAR, and GIS, they cater to builders, engineers, and clients involved in land development projects. \n”,
“discovered”: “2026-03-03 02:21:03.650917”,
“domain”: “www.bartramtrail.net”,
“duplicates”: [],
“extrainfos”: [],
“group”: “termite”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/bc903a56fd9d89b91c02c71c96467218.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QmFydHJhbSBUcmFpbCBTdXJ2ZXlpbmdAdGVybWl0ZQ==”,
“victim”: “Bartram Trail Surveying”
},
{
“activity”: “Transportation\/Logistics”,
“attackdate”: “2026-03-03 00:50:30.661002”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=24c84000-9d85-33e1-bf61-b47cb14f0e26”,
“country”: “US”,
“description”: “N\/A”,
“discovered”: “2026-03-03 00:50:52.367822”,
“domain”: “www.bayshoreford.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/7d60a119c54f9f7a24602c9c7da326f3.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QmF5c2hvcmUgRm9yZCBUcnVjayBTYWxlc0BxaWxpbg==”,
“victim”: “Bayshore Ford Truck Sales”
},
{
“activity”: “Energy”,
“attackdate”: “2026-03-03 00:08:07.000000”,
“claim_url”: “https:\/\/handala-hack.to\/sharjah-national-oil-corporation-hacked\/”,
“country”: “AE”,
“description”: “Today, one of the UAE\u2019s largest oil and gas giants, Sharjah National Oil Corporation, has fallen to a decisive blow from us, Handala Hack. Your critical infrastructure, the very heart of the region\u2019s energy production and distribution, was dismantled in moments. Now, 1.3 terabytes of your most confidential financial data, oil contracts, project details, and\u2026”,
“discovered”: “2026-03-03 03:03:45.137746”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “handala”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/07d14616ce5f6ad68caf94ac04951028.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U2hhcmphaCBOYXRpb25hbCBPaWwgQ29ycG9yYXRpb25AaGFuZGFsYQ==”,
“victim”: “Sharjah National Oil Corporation”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-03 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “Katz, Kantor, Stonestreet & Buckner serves all of West Virginia with compassionate and zealous legal representation built on decades of experience. Established in 1931, our firm has been representing clients from Bluefield, Princeton, Beckley, Welch, Lewisburg, Charleston, Morgantown, and all areas in between in West Virginia for over 88 years.”,
“discovered”: “2026-03-03 19:42:56.530679”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “kairos”,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/S2F0eiBLYW50b3IgU3RvbmVzdHJlZXQgJiBCdWNrbmVyQGthaXJvcw==”,
“victim”: “Katz Kantor Stonestreet & Buckner”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-02 23:16:03.871677”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=afa2a0ea-20ba-3ddf-8c5c-2aeea9e5dc43”,
“country”: “”,
“description”: “N\/A”,
“discovered”: “2026-03-02 23:16:18.855256”,
“domain”: “www.lundeen-consulting.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/d30420e6d3d8f80c4949f983d21d08f2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/THVuZGVlbiBDb25zdWx0aW5nQHFpbGlu”,
“victim”: “Lundeen Consulting”
},
{
“activity”: “Hospitality and Tourism”,
“attackdate”: “2026-03-02 23:15:24.189093”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=83ccb8e6-884e-3a9d-be81-276e075d37e8”,
“country”: “BS”,
“description”: “N\/A”,
“discovered”: “2026-03-02 23:15:41.664557”,
“domain”: “www.fusionsuperplex.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/d6d870885b128c13dc831e514669562e.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RnVzaW9uIFN1cGVycGxleEBxaWxpbg==”,
“victim”: “Fusion Superplex”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-02 21:51:33.602505”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=23324ed5-1d05-3a3c-8817-5545ae670939”,
“country”: “”,
“description”: “N\/A”,
“discovered”: “2026-03-02 21:52:00.104431”,
“domain”: “www.phoenixsystems.tv”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/b558ff03bed4069ef06450ab33c4ce34.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UGhvZW5peCBTeXN0ZW1zQHFpbGlu”,
“victim”: “Phoenix Systems”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-03-02 21:49:53.622278”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=KyZN7Uu2uEj1FZ”,
“country”: “DE”,
“description”: “Germany”,
“discovered”: “2026-03-02 21:50:30.539092”,
“domain”: “www.cabka.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/1b1edfe991703756ccd4bfb8c29dcaeb.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q2Fia2FAcGxheQ==”,
“victim”: “Cabka”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-02 21:49:15.748801”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=iBFJv1izaj7Avy”,
“country”: “US”,
“description”: “United States”,
“discovered”: “2026-03-02 21:49:52.156780”,
“domain”: “www.ohklegal.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/4e25a9e4b18d7cdd50bb322b732e7189.png”,
“url”: “https:\/\/www.ransomware.live\/id\/VGhlIEt1a2VyIEdyb3VwQHBsYXk=”,
“victim”: “The Kuker Group”
},
{
“activity”: “Construction”,
“attackdate”: “2026-03-02 21:48:38.357997”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=GWHc5jXRjaQ2Xo”,
“country”: “US”,
“description”: “United States”,
“discovered”: “2026-03-02 21:49:14.041090”,
“domain”: “www.lraconstructors.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/55e16d79f9c91eae1feb3cbb5706bfab.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TFJBIENvbnN0cnVjdG9yc0BwbGF5”,
“victim”: “LRA Constructors”
},
{
“activity”: “Hospitality and Tourism”,
“attackdate”: “2026-03-02 21:48:00.464460”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=2b6sdrwgOklQkn”,
“country”: “US”,
“description”: “United States”,
“discovered”: “2026-03-02 21:48:36.903781”,
“domain”: “www.cobblestonecreekcc.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/6c67edcbc0f98e1ed9816de2afbc6594.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q29iYmxlc3RvbmUgQ3JlZWsgQ291bnRyeSBDbHViQHBsYXk=”,
“victim”: “Cobblestone Creek Country Club”
},
{
“activity”: “Business Services”,
“attackdate”: “2026-03-02 21:47:23.426444”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=uiH8YUlv4Cfu06”,
“country”: “US”,
“description”: “United States”,
“discovered”: “2026-03-02 21:47:59.037565”,
“domain”: “www.projectconsulting.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/d4853741eccd010a51f57f071d2472bd.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UHJvamVjdCBDb25zdWx0aW5nIFNlcnZpY2VzQHBsYXk=”,
“victim”: “Project Consulting Services”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-03-02 21:46:45.905254”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=DQtZWs5LgurnKL”,
“country”: “US”,
“description”: “United States”,
“discovered”: “2026-03-02 21:47:21.987749”,
“domain”: “www.goprofessionalcases.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/aba38a6a636772beb534b27291ee61f2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R28gUHJvZmVzc2lvbmFsIENhc2VzQHBsYXk=”,
“victim”: “Go Professional Cases”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-02 21:46:05.983399”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=jm47mNKnWblGg”,
“country”: “”,
“description”: “United States”,
“discovered”: “2026-03-02 21:46:44.350172”,
“domain”: “www.wcctechgroup.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/b4ef1eb700b4c739c63bd9c8a5bb27c2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/V0NDIFRlY2hub2xvZ2llcyBHcm91cEBwbGF5”,
“victim”: “WCC Technologies Group”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-02 21:45:20.863664”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=7TBimCgidUuAww”,
“country”: “”,
“description”: “United States”,
“discovered”: “2026-03-02 21:46:01.550786”,
“domain”: “www.flgch.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/8928f2cd5456fbf0b82cc53cc45093f2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RmF2YXJvIExhdmV6em8gR2lsbCBDYXJldHRpQHBsYXk=”,
“victim”: “Favaro Lavezzo Gill Caretti”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-02 19:36:11.325550”,
“claim_url”: “http:\/\/bravoxxwcfz5qk43ychgveprpd5mw5hvxfs4a2uz2okx7mumiht4fzyd.onion\/blog\/9926540e-a358-42a4-9526-87f6e075ee34”,
“country”: “CH”,
“description”: “It develops and implements digital software for finance, document, and HR management.”,
“discovered”: “2026-03-02 19:36:34.949249”,
“domain”: “soreco.ch”,
“duplicates”: [],
“extrainfos”: {
“data_size”: “118.2GB”
},
“group”: “bravox”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-02 19:35:52”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/69817b37994b93e2da5fa42ebff96e0b.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U29yZWNvQGJyYXZveA==”,
“victim”: “Soreco”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-03-02 19:11:05.007830”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=8a78806b-e5c1-3850-b873-bf82962ea20f”,
“country”: “TR”,
“description”: “N\/A”,
“discovered”: “2026-03-02 19:11:26.994357”,
“domain”: “www.akkok.com.tr”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/06be2195a473bf6942dde553a8a6d42f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QWtrw7ZrIEhvbGRpbmdAcWlsaW4=”,
“victim”: “Akk\u00f6k Holding”
},
{
“activity”: “Transportation\/Logistics”,
“attackdate”: “2026-03-02 18:41:47.032381”,
“claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=6771fef6-0664-49f3-b855-164749d0b14a”,
“country”: “GB”,
“description”: “Import Services Ltd (importservices.co.uk) is a Southampton-based UK logistics company specializing in retail supply chain services, contract warehousing, freight forwarding, order fulfillment, and port-centric distribution for imports and domestic operations.\nbreched with love 3”,
“discovered”: “2026-03-03 19:37:31.515201”,
“domain”: “importservices.co.uk”,
“duplicates”: [],
“extrainfos”: [],
“group”: “dragonforce”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 19:36:41”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/9acf2d386a953783f413bbd00781d0c1.png”,
“url”: “https:\/\/www.ransomware.live\/id\/dWtpbXBvcnRzZXJ2aWNlcy5jb21AZHJhZ29uZm9yY2U=”,
“victim”: “ukimportservices.com”
},
{
“activity”: “Transportation\/Logistics”,
“attackdate”: “2026-03-02 18:41:47.032381”,
“claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=6771fef6-0664-49f3-b855-164749d0b14a”,
“country”: “GB”,
“description”: “Import Services Ltd (importservices.co.uk) is a Southampton-based UK logistics company specializing in retail supply chain services, contract warehousing, freight forwarding, order fulfillment, and port-centric distribution for imports and domestic operations.\nbreched with love 3”,
“discovered”: “2026-03-04 00:04:56.471796”,
“domain”: “importservices.co.uk”,
“duplicates”: [],
“extrainfos”: [],
“group”: “dragonforce”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 19:36:41”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/9acf2d386a953783f413bbd00781d0c1.png”,
“url”: “https:\/\/www.ransomware.live\/id\/aW1wb3J0c2VydmljZXMuY28udWtAZHJhZ29uZm9yY2U=”,
“victim”: “importservices.co.uk”
},
{
“activity”: “Energy”,
“attackdate”: “2026-03-02 13:29:53.115777”,
“claim_url”: “https:\/\/handala-hack.to\/israel-opportunity-energy-hacked\/”,
“country”: “IL”,
“description”: “One of the most prominent oil and gas exploration companies has been hacked. This is the beginning of a rage that had been suppressed for years out of humanity, ethics, and religious restraint. However, the leaders of the Epstein faction , Trump and Netanyahu , ignited years of anger and fury. Know that from now\u2026”,
“discovered”: “2026-03-02 13:30:26.216110”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “handala”,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/SXNyYWVsIE9wcG9ydHVuaXR5IEVuZXJneUBoYW5kYWxh”,
“victim”: “Israel Opportunity Energy”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-02 10:10:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a5a97b8f1d14b74397b6b7”,
“country”: “US”,
“description”: “Martin Cukjati & Tom, LLP is a full service law firm with over 75 years of combined legal experience representing people and businesses in high-stakes litigation. The cornerstone of our success is limiting our case load and dedicating ourselves to serving a select few clients, making sure your case receives the attention it deserves. This allows us to focus on our clients, and work towards achieving the best possible outcome.”,
“discovered”: “2026-03-02 16:31:37.864096”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/08a93140db6c769211395c8ee61ca675.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TWFydGluLCBDdWtqYXRpICYgVG9tLCBMTFBAaW5jcmFuc29t”,
“victim”: “Martin, Cukjati & Tom, LLP”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-02 10:10:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a5a97b8f1d14b74397b6b7”,
“country”: “US”,
“description”: “Martin Cukjati & Tom, LLP is a full service law firm with over 75 years of combined legal experience representing people and businesses in high-stakes litigation. The cornerstone of our success is limiting our case load and dedicating ourselves to serving a select few clients, making sure your case receives the attention it deserves. This allows us to focus on our clients, and work towards achieving the best possible outcome.”,
“discovered”: “2026-03-02 19:42:53.663672”,
“domain”: “mcfirm.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-02 19:42:15”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/08a93140db6c769211395c8ee61ca675.png”,
“url”: “https:\/\/www.ransomware.live\/id\/bWNmaXJtLmNvbUBpbmNyYW5zb20=”,
“victim”: “mcfirm.com”
},
{
“activity”: “Public Sector”,
“attackdate”: “2026-03-02 09:42:18.474947”,
“claim_url”: “”,
“country”: “”,
“description”: “Southold Town Senior ServicesSouthold Police Department The Town of Southold, New York provides various government services including forms and permits, online payments, and notifications for residents. Southold Police Department is a company that operates in the Local industry.”,
“discovered”: “2026-03-02 09:42:20.900011”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “rhysida”,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/U291dGhvbGQgVG93biBTZW5pb3IgU2VydmljZXNTb3V0aG9sZCBQb2xpY2UgRGVwYXJ0bWVudEByaHlzaWRh”,
“victim”: “Southold Town Senior ServicesSouthold Police Department”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-02 09:38:48.522741”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=8d20164c-4e95-38e1-8e98-535b966532e3”,
“country”: “MX”,
“description”: “N\/A”,
“discovered”: “2026-03-02 09:39:07.795704”,
“domain”: “www.grupodarc.com.ar”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/79bda0cee821c0c2570834b4b65bc886.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R3J1cG8gRCdhcmNAcWlsaW4=”,
“victim”: “Grupo D’arc”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-03-02 00:30:29.789025”,
“claim_url”: “http:\/\/om6q4a6cyipxvt7ioudxt24cw4oqu4yodmqzl25mqd2hgllymrgu4aqd.onion\/r\/pwlvqUcuRMAEU2HicaNUZc0Co3A6cHpiqPWwXTJb27l1E3SD02gPtghtzbv6edeILgAGsnOb2aTuQ0XOGUdfbGdxc2xFNzRL”,
“country”: “NL”,
“description”: “Data breach at leading global paints and coatings company.”,
“discovered”: “2026-03-02 00:31:12.636143”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “anubis”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/da22802f24a49752a1a9f70ca8ec099a.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QWt6b05vYmVsQGFudWJpcw==”,
“victim”: “AkzoNobel”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-02 00:00:00.000000”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=5f442bca-e033-3788-8ab5-bbfd917adbae”,
“country”: “”,
“description”: “N\/A”,
“discovered”: “2026-03-02 21:52:44.619283”,
“domain”: “www.idhentertainment.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f8908280bb1219e7afa622c93010cb17.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SURIIEVudGVydGFpbm1lbnRAcWlsaW4=”,
“victim”: “IDH Entertainment”
},
{
“activity”: “Energy”,
“attackdate”: “2026-03-02 00:00:00.000000”,
“claim_url”: “”,
“country”: “”,
“description”: “Status: STATUS: NEGOTIATING | Sector: Energy | DATA SIZE: 238GB | Deadline: 22d 3h”,
“discovered”: “2026-03-04 01:30:44.442100”,
“domain”: “verlatenergy.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “vect”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-04 01:30:24”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/VmVybGF0IEVuZXJneUB2ZWN0”,
“victim”: “Verlat Energy”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-03-01 19:14:10.730869”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=b6bd0e56-ab88-34b1-94d8-8ca7e0e0eee6”,
“country”: “FR”,
“description”: “N\/A”,
“discovered”: “2026-03-01 19:14:25.469697”,
“domain”: “www.lisi-group.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/c76673124917409ed283f64d517e828f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TElTSSBHcm91cEBxaWxpbg==”,
“victim”: “LISI Group”
},
{
“activity”: “Technology”,
“attackdate”: “2026-03-01 19:13:31.770328”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=e87bc918-ebc9-31ef-aa58-2fcaa306a14a”,
“country”: “US”,
“description”: “N\/A”,
“discovered”: “2026-03-01 19:13:48.569660”,
“domain”: “www.engofinllc.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/0dc6105eb117018a8b328038312f6722.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RW50ZXJwcmlzZSBOZXR3b3JrIEdyb3VwIG9mIEluZGlhbmFAcWlsaW4=”,
“victim”: “Enterprise Network Group of Indiana”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-03-01 17:28:54.000000”,
“claim_url”: “http:\/\/tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion”,
“country”: “US”,
“description”: “ssrco.com zoominfo.com\/c\/special-shapes-refractory-company-inc\/1132759207 Special Shapes Refractory Company (SSRC) is a leader in providing high-quality precast shapes and monolithic materials primarily for the glass, steel, and other industrial manufacturers. They focus on minimizing downtime and enhancing equipment reliability through innovative solutions, efficient manufacturing processes, and a commitment to customer service. SSRC caters to a wide range of industrial clients, offering customized refractory solutions and quick lead times. With decades of experience, they emphasize the importance of using pure raw materials to ensure the best product quality and performance”,
“discovered”: “2026-03-01 19:21:46.887685”,
“domain”: “ssrco.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 19:21:03”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/8c47959c80ef37fb0095eb6ecb94c7a8.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U3BlY2lhbCBTaGFwZXMgUmVmcmFjdG9yeUB0aGVnZW50bGVtZW4=”,
“victim”: “Special Shapes Refractory”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-03-01 17:27:50.000000”,
“claim_url”: “http:\/\/tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion”,
“country”: “CA”,
“description”: “labtician.com zoominfo.com\/c\/labtician-ophthalmics-inc\/139985585 Labtician Ophthalmics specializes in manufacturing and selling advanced surgical and therapeutic ophthalmology products. The company aims to enhance patients’ visual health by providing effective tools and solutions for various eye conditions. Their offerings cater primarily to eye care professionals and include extensive product catalogs and partnership opportunities. Labtician is committed to supporting both healthcare practitioners and their patients in managing, treating, and easing eye issues”,
“discovered”: “2026-03-01 19:22:54.695286”,
“domain”: “labtician.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 19:21:49”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/8c47959c80ef37fb0095eb6ecb94c7a8.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TGFidGljaWFuIE9waHRoYWxtaWNzQHRoZWdlbnRsZW1lbg==”,
“victim”: “Labtician Ophthalmics”
},
{
“activity”: “Agriculture and Food Production”,
“attackdate”: “2026-03-01 17:26:03.000000”,
“claim_url”: “http:\/\/tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion”,
“country”: “IN”,
“description”: “allindiaminerals.com zoominfo.com\/c\/all-india-minerals\/470618608 All India Minerals is India’s largest manufacturer of Washed Sand and Graded Silica Sand, established in 1969. The company employs advanced technologies and strict quality controls to produce high-quality silica sand for various industrial applications, including foundry core, molding, and glass industries. They operate a state-of-the-art mining and washing facility near Ankleshwar, ensuring excellent product quality through dedicated testing and processing. Committed to ecological improvement, All India Minerals focuses on maintaining a pollution-free environment while delivering superior products to meet customer needs”,
“discovered”: “2026-03-01 19:23:51.651012”,
“domain”: “allindiaminerals.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 19:22:57”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/8c47959c80ef37fb0095eb6ecb94c7a8.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QWxsIEluZGlhIE1pbmVyYWxzQHRoZWdlbnRsZW1lbg==”,
“victim”: “All India Minerals”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-01 17:24:25.000000”,
“claim_url”: “http:\/\/tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion”,
“country”: “ES”,
“description”: “ricopia.com zoominfo.com\/c\/ricopia\/405953806 Ricopia helps businesses upgrade their technology and work smarter. With over 100 tech experts, they’ve been helping companies of all sizes get better at digital tools for more than 30 years. They do this by checking how a company works, finding ways to improve technology, and helping teams learn new skills. Big names like ING Direct and BNP Paribas trust Ricopia to make their businesses run more smoothly and efficiently”,
“discovered”: “2026-03-01 19:25:11.444231”,
“domain”: “ricopia.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 19:23:54”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/8c47959c80ef37fb0095eb6ecb94c7a8.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Umljb3BpYUB0aGVnZW50bGVtZW4=”,
“victim”: “Ricopia”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-01 17:23:16.000000”,
“claim_url”: “http:\/\/tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion”,
“country”: “”,
“description”: “afezo.nl zoominfo.com\/c\/aannemingsmij-afezo-bv\/372576926 Afezo B.V. is a family-owned company specializing in urban sewer work and infrastructure development in Amsterdam and the Zaanstreek. With decades of experience, they offer a comprehensive range of services including wastewater management, road construction, and the development of drinking water networks. Their commitment to sustainability and innovative practices drives their projects, which aim to enhance both the physical environment and the community. Afezo serves a diverse clientele, from small-scale to large-scale projects, contributing significantly to the infrastructure of Amsterdam”,
“discovered”: “2026-03-01 19:26:25.860205”,
“domain”: “afezo.nl”,
“duplicates”: [],
“extrainfos”: [],
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 19:25:14”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/8c47959c80ef37fb0095eb6ecb94c7a8.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QWZlem9AdGhlZ2VudGxlbWVu”,
“victim”: “Afezo”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-01 11:56:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a499e68f1d14b743834763”,
“country”: “DE”,
“description”: “LKE Group creates custom transport equipment for businesses across different industries. They design and build specialized gear that helps companies move materials, products, and goods more efficiently. From warehouse systems to industrial transport devices, LKE makes machines that solve real moving and handling challenges for factories, logistics centers, and manufacturing plants.\r Employees: 500\r Revenue: $30.4 Million\r Industry: Architecture, Engineering & Design \r Phone Number: +49 23650000000”,
“discovered”: “2026-03-01 20:10:02.302548”,
“domain”: “lke-group.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 20:09:29”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/2ce3c3150bb2c696f03e3bc67c81789a.png”,
“url”: “https:\/\/www.ransomware.live\/id\/bGtlLWdyb3VwLmNvbUBpbmNyYW5zb20=”,
“victim”: “lke-group.com”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-01 11:46:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a4977f8f1d14b743831307”,
“country”: “US”,
“description”: “Founded in 2001, Abrams Architectural Products, Inc. is a leading distributor, fabricator, and installer of architectural metals, particularly aluminum composite material cladding systems. They collaborate with architects and general contractors to ensure their visions are realized through quality products, expert solutions, and tailored services. Their product offerings include a variety of architectural metal systems for both exterior and interior cladding, catering to projects of various sizes and complexities. With a strong reputation for excellence, they serve a diverse range of clients across the United States, providing top-tier general contracting services in fields such as airports, museums, and medical centers.\r Employees: 50 \r Revenue: $5.3 Million\r Industry: Architecture, Engineering & Design \r Phone Number: (770)745-8728”,
“discovered”: “2026-03-01 20:10:39.093718”,
“domain”: “abramssales.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 20:10:07”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/90a38d2d54ee2b14d27ce831762c3558.png”,
“url”: “https:\/\/www.ransomware.live\/id\/YWJyYW1zc2FsZXMuY29tQGluY3JhbnNvbQ==”,
“victim”: “abramssales.com”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-03-01 11:32:13.639582”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=f0408acf-556d-3035-b710-cde98f74f66c”,
“country”: “US”,
“description”: “N\/A”,
“discovered”: “2026-03-01 11:32:30.804840”,
“domain”: “www.riachgese.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/1e6d2b8b18dedc35a41223b3eba865e0.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UmlhY2ggR2VzZSBKYWNvYnNAcWlsaW4=”,
“victim”: “Riach Gese Jacobs”
},
{
“activity”: “Transportation\/Logistics”,
“attackdate”: “2026-03-01 11:31:32.865105”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=d7f6a86e-fd42-3677-81d7-411edf567597”,
“country”: “CA”,
“description”: “N\/A”,
“discovered”: “2026-03-01 11:31:51.044703”,
“domain”: “www.traffictech.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/2376702053ac7c7c128814d44e4c152c.png”,
“url”: “https:\/\/www.ransomware.live\/id\/VHJhZmZpYyBUZWNoQHFpbGlu”,
“victim”: “Traffic Tech”
},
{
“activity”: “Hospitality and Tourism”,
“attackdate”: “2026-03-01 00:00:00.000000”,
“claim_url”: “”,
“country”: “GE”,
“description”: “- VIP Lists- Invoices, Passport…- Financial Documents”,
“discovered”: “2026-03-03 08:46:58.512393”,
“domain”: “iotahotels.com”,
“duplicates”: [],
“extrainfos”: {
“data_size”: “120GB”
},
“group”: “nightspire”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 08:46:38”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/SU9UQSBIT1RFTCBUQklMSVNJQG5pZ2h0c3BpcmU=”,
“victim”: “IOTA HOTEL TBILISI”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-02-28 11:11:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a4a7828f1d14b7438463a2”,
“country”: “IL”,
“description”: “1 terabyte of data, blueprints, contracts and much more, not recognized by the israeli ministry of defense as a terrorist organization.”,
“discovered”: “2026-03-01 21:42:38.377558”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/692b1cff8325bfba7fe5c32c18fe1891.png”,
“url”: “https:\/\/www.ransomware.live\/id\/aHR0cDovL3JhbWV0LXRyb20uY28uaWwvQGluY3JhbnNvbQ==”,
“victim”: “http:\/\/ramet-trom.co.il\/”
},
{
“activity”: “Energy”,
“attackdate”: “2026-02-26 14:27:00.000000”,
“claim_url”: “http:\/\/lockbitapt67g6rwzjbcxnww5efpg4qok6vpfeth7wx3okj52ks4wtad.onion\/post\/d8678a36d024ccd655115f0c5d4c72f5”,
“country”: “ZA”,
“description”: “The Diesel-Electric Group including Bosch Service Dealers, e-CAR Service Centers and Bosch SA togeth…”,
“discovered”: “2026-03-01 13:57:16.046396”,
“domain”: “diesel-electric.co.za”,
“duplicates”: [],
“extrainfos”: [],
“group”: “lockbit5”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 13:56:42”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/ea8624b7154fb41c80a9e4d4d2ed6650.png”,
“url”: “https:\/\/www.ransomware.live\/id\/ZGllc2VsLWVsZWN0cmljLmNvLnphQGxvY2tiaXQ1”,
“victim”: “diesel-electric.co.za”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-02-26 14:24:00.000000”,
“claim_url”: “http:\/\/lockbitapt67g6rwzjbcxnww5efpg4qok6vpfeth7wx3okj52ks4wtad.onion\/post\/dc7844f33fa9e774cf9390f49fc94066”,
“country”: “BR”,
“description”: “Brassuco Alimentos has been a key player in the food industry since 1985. They make tasty drinks and…”,
“discovered”: “2026-03-01 13:57:50.608142”,
“domain”: “brassuco.com.br”,
“duplicates”: [],
“extrainfos”: [],
“group”: “lockbit5”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 13:57:18”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/4f2b733eb146697afd72a1e25e6784c5.png”,
“url”: “https:\/\/www.ransomware.live\/id\/YnJhc3N1Y28uY29tLmJyQGxvY2tiaXQ1”,
“victim”: “brassuco.com.br”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-02-24 00:00:00.000000”,
“claim_url”: “http:\/\/i62huw7ve22rpyw6lnq3kmfump2dmsg4xpveec3ere73njwatrz74gad.onion\/Company\/Belmont\/”,
“country”: “US”,
“description”: “Belmont Plastic Surgery, led by award-winning surgeon Dr. Jules Feledy, offers comprehensive cosmetic and reconstructive procedures. The practice specializes in breast augmentation, body contouring, and facial rejuvenation, delivering natural-looking.”,
“discovered”: “2026-03-03 15:14:38.237980”,
“domain”: “www.belmontplasticsurgeryva.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “insomnia”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f8670ec11f1d5a434c12fa7a1047e12a.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QmVsbW9udCBQbGFzdGljIFN1cmdlcnlAaW5zb21uaWE=”,
“victim”: “Belmont Plastic Surgery”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-02-24 00:00:00.000000”,
“claim_url”: “http:\/\/tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion”,
“country”: “AT”,
“description”: “chs-villach.at zoominfo.com\/c\/chs-villach\/429687687 CHS Villach is an educational institution offering a variety of vocational training programs in fields such as business, health and social services, media design, and arts. The school focuses on developing students’ personal and social skills, encouraging them to take responsibility and engage actively in their communities. It provides opportunities for hands-on learning through projects, internships, and collaborations, fostering independence and creativity among students. CHS Villach aims to prepare young individuals for successful careers while promoting quality education and personal growth”,
“discovered”: “2026-03-03 15:50:18.234463”,
“domain”: “chs-villach.at”,
“duplicates”: [],
“extrainfos”: [],
“group”: “thegentlemen”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-02-27 11:54:34”,
“users”: 0,
“users_url”: 0
},
“press”: {
“link”: “https:\/\/www.ransomware.live\/id\/Y2hzLXZpbGxhY2guYXRAMjAyNi0wMi0yNA==”,
“source”: “https:\/\/www.kleinezeitung.at\/kaernten\/20630734\/hackerangriff-auf-kaerntner-schule-daten-wurden-verschluesselt”,
“summary”: “La CHS de Villach a \u00e9t\u00e9 victime d’une attaque de hackers, des donn\u00e9es ont \u00e9t\u00e9 chiffr\u00e9es par un groupe appel\u00e9 The Gentlemen, mais les responsables ont r\u00e9agi rapidement pour emp\u00eacher le vol de donn\u00e9es. L’attaque a \u00e9t\u00e9 contenue et les donn\u00e9es sont en cours de r\u00e9cup\u00e9ration. Les autorit\u00e9s enqu\u00eatent sur l’incident pour identifier les responsables.”
},
“screenshot”: “https:\/\/images.ransomware.live\/victims\/8c47959c80ef37fb0095eb6ecb94c7a8.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q0hTIFZpbGxhY2hAdGhlZ2VudGxlbWVu”,
“victim”: “CHS Villach”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-02-23 17:35:00.000000”,
“claim_url”: “http:\/\/lockbitapt67g6rwzjbcxnww5efpg4qok6vpfeth7wx3okj52ks4wtad.onion\/post\/a81dd25be39543bd5bb2f275a8754e4f”,
“country”: “IN”,
“description”: “OMAX Autos Limited is a leading manufacturer of sheet metal components, specializing in commercial v…”,
“discovered”: “2026-03-01 13:58:24.510918”,
“domain”: “omaxauto.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “lockbit5”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 13:57:53”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/527e5ee5eea61eafc0c83898e293aeb2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/b21heGF1dG8uY29tQGxvY2tiaXQ1”,
“victim”: “omaxauto.com”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-02-23 17:29:00.000000”,
“claim_url”: “http:\/\/lockbitapt67g6rwzjbcxnww5efpg4qok6vpfeth7wx3okj52ks4wtad.onion\/post\/318e70b9aca9ff0d68d9053757cce4e4”,
“country”: “CN”,
“description”: “Yaomazi Food Co. LTD is located in Hongya, the hometown of Chinese green pepper. After more than 10…”,
“discovered”: “2026-03-01 13:58:58.885903”,
“domain”: “yaomazi.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “lockbit5”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 13:58:27”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/971df92530d70809886c105929393d4e.png”,
“url”: “https:\/\/www.ransomware.live\/id\/eWFvbWF6aS5jb21AbG9ja2JpdDU=”,
“victim”: “yaomazi.com”
},
{
“activity”: “Energy”,
“attackdate”: “2026-02-20 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “Data is not available now.”,
“discovered”: “2026-03-02 18:06:54.424925”,
“domain”: “www.bainonline.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “nightspire”,
“infostealer”: “”,
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/QmFpbiBPaWwgQ29tcGFueUBuaWdodHNwaXJl”,
“victim”: “Bain Oil Company”
},
{
“activity”: “Education”,
“attackdate”: “2026-02-19 00:00:00.000000”,
“claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=4941a871-b19a-4537-b056-e648e3706004”,
“country”: “BR”,
“description”: “Funda\u00e7\u00e3o Getulio Vargas (FGV) is a prestigious educational institution in Brazil, offering a wide range of programs including undergraduate, MBA, master’s, and doctoral courses. It serves students, professionals, and organizations, focusing on developing leadership and providing high-quality education. FGV also engages in research and provides technical assistance to both public and private sectors, contributing to national and international debates. Additionally, FGV promotes cultural initiatives and publishes academic works to enhance education and research in the country.”,
“discovered”: “2026-03-02 08:58:43.714879”,
“domain”: “fgv.br”,
“duplicates”: [],
“extrainfos”: [],
“group”: “dragonforce”,
“infostealer”: {
“employees”: 151,
“employees_url”: 52,
“infostealer_stats”: {
“Acreed”: 126,
“Atomic”: 17,
“Azorult”: 689,
“CRYPTBOT”: 102,
“DarkCrystal”: 115,
“Ficker”: 14,
“Generic Stealer”: 7387,
“KPOT”: 3,
“Lumma”: 12060,
“Mystic”: 84,
“Predator”: 44,
“Raccoon”: 6339,
“RedLine”: 18802,
“StealC”: 2110,
“Taurus”: 24,
“UNKNOWN”: 631,
“Vidar”: 1453
},
“thirdparties”: 183,
“thirdparties_domain”: 48,
“update”: “2026-03-02 17:27:13”,
“users”: 88336,
“users_url”: 100
},
“press”: {
“link”: “https:\/\/www.ransomware.live\/id\/Zmd2LmJyQDIwMjYtMDItMTk=”,
“source”: “https:\/\/www.tecmundo.com.br\/seguranca\/411228-fgv-sofre-vazamento-de-152-tb-em-suposto-ataque-cibernetico-do-grupo-dragonforce.htm”,
“summary”: “La Funda\u00e7\u00e3o Get\u00falio Vargas a \u00e9t\u00e9 victime d’une attaque de sequestro de donn\u00e9es par le groupe Dragonforce, avec 1,52 To de donn\u00e9es compromises, dont des informations personnelles sensibles. L’attaque a eu lieu apr\u00e8s un incident de cybers\u00e9curit\u00e9 similaire en f\u00e9vrier. Le groupe Dragonforce exige un ran\u00e7on en \u00e9change de la non-divulgation des donn\u00e9es.”
},
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f632916535fbe6e69ac39957db4d6898.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Zmd2LmJyQGRyYWdvbmZvcmNl”,
“victim”: “fgv.br”
},
{
“activity”: “Agriculture and Food Production”,
“attackdate”: “2026-02-18 00:00:00.000000”,
“claim_url”: “”,
“country”: “FR”,
“description”: “Data is not available now.”,
“discovered”: “2026-03-03 11:02:57.138049”,
“domain”: “www.ulm-coop.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “nightspire”,
“infostealer”: “”,
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/VW5pb24gTGFpdGllcmUgZGUgbGEgTWV1c2VAbmlnaHRzcGlyZQ==”,
“victim”: “Union Laitiere de la Meuse”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-02-18 00:00:00.000000”,
“claim_url”: “”,
“country”: “”,
“description”: “Data is not available now.”,
“discovered”: “2026-03-04 04:02:49.734097”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: {
“data_size”: “0GB”
},
“group”: “nightspire”,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/SyoqSSogSSoqKkkqQSAqQUBuaWdodHNwaXJl”,
“victim”: “K**I* I***I*A *A”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-02-18 00:00:00.000000”,
“claim_url”: “”,
“country”: “TR”,
“description”: “- Internal Documents- Financial Documents”,
“discovered”: “2026-03-04 04:03:13.346966”,
“domain”: “www.akol.av.tr”,
“duplicates”: [],
“extrainfos”: {
“data_size”: “0GB”
},
“group”: “nightspire”,
“infostealer”: “”,
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/QUtPTCBMQVdAbmlnaHRzcGlyZQ==”,
“victim”: “AKOL LAW”
},
{
“activity”: “Technology”,
“attackdate”: “2026-02-15 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “Data is not available now.”,
“discovered”: “2026-03-02 18:06:31.628063”,
“domain”: “simetri.us”,
“duplicates”: [],
“extrainfos”: [],
“group”: “nightspire”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-02 18:06:11”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/U0lNRVRSSSBJbmNAbmlnaHRzcGlyZQ==”,
“victim”: “SIMETRI Inc”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-02-02 23:33:21.736172”,
“claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=61e8d563-1b2b-423f-add3-1b967492af86”,
“country”: “US”,
“description”: “Founded in 2001 and headquartered in Clarksville, Virginia, Encompass Solutions is a preferred Epicor partner and Value-Added Re-seller (VAR), that delivers mission-critical ERP software solutions, custom development services, and process improvements for businesses in manufacturing industries. The company prides themselves on being expert business consultants, software implementation specialists, and managed services providers.”,
“discovered”: “2026-03-03 15:05:59.956037”,
“domain”: “www.encompass-inc.com”,
“duplicates”: [
{
“attackdate”: “2026-02-02 23:33:21.736172”,
“date”: “2026-03-03 15:06:00.063228”,
“group”: “devman”,
“link”: “https:\/\/www.ransomware.live\/id\/RU5DT01QQVNTLUlOQ0BkZXZtYW4=”
}
],
“extrainfos”: [],
“group”: “dragonforce”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/cc773cee1b8859db62bcc4635054adc2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RW5jb21wYXNzQGRyYWdvbmZvcmNl”,
“victim”: “Encompass”
},
{
“activity”: “Education”,
“attackdate”: “2026-01-30 00:00:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a4948d8f1d14b74382e4e8”,
“country”: “US”,
“description”: “Denmark High School is a company that employs 100to249 people and has 10Mto25M of revenue. The company is headquartered in Denmark, Wisconsin.\r Employees: 200 \r Revenue: $18.2 Million\r Industry: Education \r Phone Number: (920) 863-4200”,
“discovered”: “2026-03-01 20:11:14.154190”,
“domain”: “denmark.k12.wi.us”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-01 20:10:41”,
“users”: 0,
“users_url”: 0
},
“press”: {
“link”: “https:\/\/www.ransomware.live\/id\/ZGVubWFyay5rMTIud2kudXNAMjAyNi0wMS0zMA==”,
“source”: “https:\/\/dysruptionhub.com\/denmark-schools-outage-wisconsin\/”,
“summary”: “Le district scolaire de Denmark au Wisconsin a subi une interruption de son acc\u00e8s \u00e0 Internet pendant cinq jours en raison d’un incident cybern\u00e9tique. Les enseignants et les \u00e9tudiants ont d\u00fb recourir \u00e0 des m\u00e9thodes de travail bas\u00e9es sur le papier. L’incident a \u00e9t\u00e9 attribu\u00e9 \u00e0 une attaque cybern\u00e9tique, mais les d\u00e9tails sur les syst\u00e8mes affect\u00e9s et les donn\u00e9es compromises n’ont pas \u00e9t\u00e9 divulgu\u00e9s.”
},
“screenshot”: “https:\/\/images.ransomware.live\/victims\/e4750c51e2c676a0f315b7e00702fef9.png”,
“url”: “https:\/\/www.ransomware.live\/id\/ZGVubWFyay5rMTIud2kudXNAaW5jcmFuc29t”,
“victim”: “denmark.k12.wi.us”
},
{
“activity”: “Technology”,
“attackdate”: “2026-01-28 11:04:17.907434”,
“claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=ad791ae8-a535-4582-b77f-5911bb010de0”,
“country”: “GB”,
“description”: “TIW Group consists of two related contracting entities: Tidewater Interior Wall and Ceiling, Inc. and Mid-Atlantic Painting, Inc., offering Class-A drywall and painting services since 1998 and 2002 respectively. They cater to builders and general contractors, providing high-quality, efficient, and timely residential and commercial services. With a strong focus on customer service and a well-seasoned staff, TIW Group ensures excellence in every project with a combination of drywall and painting applications.”,
“discovered”: “2026-03-02 13:27:54.672601”,
“domain”: “www.tiw-group.com”,
“duplicates”: [
{
“attackdate”: “2026-01-28 11:04:17.907434”,
“date”: “2026-03-02 13:27:54.759928”,
“group”: “devman”,
“link”: “https:\/\/www.ransomware.live\/id\/dGl3LWdyb3VwLmNvbUBkZXZtYW4=”
}
],
“extrainfos”: [],
“group”: “dragonforce”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/e1edc2a204afa97e078e2ee847345c18.png”,
“url”: “https:\/\/www.ransomware.live\/id\/VElXIEdyb3VwQGRyYWdvbmZvcmNl”,
“victim”: “TIW Group”
},
{
“activity”: “Public Sector”,
“attackdate”: “2026-01-24 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “The Dallas Regional Chamber is a prominent business organization known for its role as the economic growth champion and business voice of the Dallas region.It focuses on priorities such as economic development, education, public policy, and quality of life.”,
“discovered”: “2026-03-03 09:46:02.557318”,
“domain”: “dallaschamber.org”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:45:41”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/RGFsbGFzIFJlZ2lvbmFsIENoYW1iZXJAQWlMb2Nr”,
“victim”: “Dallas Regional Chamber”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-01-16 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “ShopBot Tools is a leading manufacturer of high-quality CNC routers, designed for machining various materials including wood, plastic, and aluminum.”,
“discovered”: “2026-03-03 09:45:38.948224”,
“domain”: “shopbottools.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:45:18”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/U2hvcEJvdCBUb29sc0BBaUxvY2s=”,
“victim”: “ShopBot Tools”
},
{
“activity”: “Public Sector”,
“attackdate”: “2026-01-11 00:00:00.000000”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/view?uuid=30111f69-5882-3535-8484-77a751b3c1c5”,
“country”: “US”,
“description”: “N\/A”,
“discovered”: “2026-03-01 20:44:35.928713”,
“domain”: “www.sealbeachca.gov”,
“duplicates”: [
{
“attackdate”: “2026-01-11 00:00:00.000000”,
“date”: “2026-03-01 20:44:36.020466”,
“group”: “devman”,
“link”: “https:\/\/www.ransomware.live\/id\/c2VhbGJlYWNoY2EuZ292QGRldm1hbg==”
}
],
“extrainfos”: [],
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/28af7456b866540c22ca5b68659091bc.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q2l0eSBvZiBTZWFsIEJlYWNoIGFuZCBTZWFsIEJlYWNoIFBvbGljZSBEZXBhcnRtZW50QHFpbGlu”,
“victim”: “City of Seal Beach and Seal Beach Police Department”
},
{
“activity”: “Financial Services”,
“attackdate”: “2026-01-11 00:00:00.000000”,
“claim_url”: “”,
“country”: “”,
“description”: “Navicore Solutions strengthens the well-being of individuals and families through education, guidance, advocacy and support.”,
“discovered”: “2026-03-03 09:45:15.245190”,
“domain”: “navicoresolutions.org”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:44:53”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/TmF2aWNvcmUgU29sdXRpb25zQEFpTG9jaw==”,
“victim”: “Navicore Solutions”
},
{
“activity”: “Construction”,
“attackdate”: “2026-01-10 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “Emanuelson-Podas, Inc. is a mechanical, electrical, and plumbing engineering firm that specializes in creating innovative building system solutions.”,
“discovered”: “2026-03-03 09:44:03.148696”,
“domain”: “epinc.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:43:42”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/RW1hbnVlbHNvbi1Qb2Rhc0BBaUxvY2s=”,
“victim”: “Emanuelson-Podas”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-01-10 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “S&R Compression is an oil & energy company offering compression and vapor recovery services.”,
“discovered”: “2026-03-03 09:44:27.341232”,
“domain”: “sandrcompression.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:44:06”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/UyZSIENvbXByZXNzaW9uLCBMTENAQWlMb2Nr”,
“victim”: “S&R Compression, LLC”
},
{
“activity”: “Consumer Services”,
“attackdate”: “2026-01-09 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “PROS specializes in facilities management and maintenance services for specialty retail chains, boasting 20 years of experience.”,
“discovered”: “2026-03-03 09:44:50.705172”,
“domain”: “proservicecall.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:44:30”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/UHJvZmVzc2lvbmFsIFJldGFpbCBPdXRsZXQgU2VydmljZXNAQWlMb2Nr”,
“victim”: “Professional Retail Outlet Services”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-01-01 11:01:00.000000”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a5cfb18f1d14b7439bd883”,
“country”: “US”,
“description”: “All their developments, technologies, patents, data from other companies, please pay attention to the company that bought these technologies for 150 million, everything important was stolen – photo and video components\r \r \r Founded in 1969, Precision Coating provides high-tolerance coating and specialized metal-finishing services to the medtech industry for applications including vascular, endosurgical, and orthopedic instruments and devices. The GlideLine family of medical device coating finishes is the broadest offering of applied fluoropolymer (PTFE) coatings in the industry, customized to optimize the design, quality, and performance characteristics of high-quality medical products. InfiNiTiCoat is Precision Coating’s proprietary low-temp cure process, optimized for coating performance on nitinol devices; specifically optimized to preserve the desired characteristics of nitinol in wire, strip, and tube forms. PCCI has unique process control over challenging nitinol handling, coating, and curing. The MICRALOX\u00ae portfolio of chemistries offers superior patented aluminum oxide coatings with a microcrystalline barrier that revolutionizes aluminum anodizing with exceptional barrier properties and corrosion”,
“discovered”: “2026-03-02 18:36:34.120388”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “incransom”,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/9e9d4ab1b5f1f506316a9892435cf6e2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/aHR0cHM6Ly93d3cucHJlY2lzaW9uY29hdGluZy5jb20vQGluY3JhbnNvbQ==”,
“victim”: “https:\/\/www.precisioncoating.com\/”
},
{
“activity”: “Not Found”,
“attackdate”: “2025-12-19 12:37:06.652916”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/69a6f88b8f1d14b743b51a17”,
“country”: “US”,
“description”: “Maison Law provides skilled, experienced, and personalized legal guidance to the voiceless and the injured in the Central Valley.”,
“discovered”: “2026-03-03 15:11:27.038699”,
“domain”: “maisonlaw.com”,
“duplicates”: [
{
“attackdate”: “2025-12-19 12:37:06.652916”,
“date”: “2026-03-03 15:11:27.126524”,
“group”: “qilin”,
“link”: “https:\/\/www.ransomware.live\/id\/TWFpc29uIExhd0BxaWxpbg==”
}
],
“extrainfos”: [],
“group”: “incransom”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2025-12-19 12:36:48”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/c37c0e57d1ba33ecaeb7479f96c8b60e.png”,
“url”: “https:\/\/www.ransomware.live\/id\/bWFpc29ubGF3LmNvbUBpbmNyYW5zb20=”,
“victim”: “maisonlaw.com”
},
{
“activity”: “Business Services”,
“attackdate”: “2025-12-11 00:00:00.000000”,
“claim_url”: “http:\/\/k7kg3jqxang3wh7hnmaiokchk7qoebupfgoik6rha6mjpzwupwtj25yd.onion\/topic.php?id=iQUQb0YLpHZ0Y”,
“country”: “US”,
“description”: “United States”,
“discovered”: “2026-03-02 21:50:47.932180”,
“domain”: “www.gordoncliffordmanagement.com”,
“duplicates”: [
{
“attackdate”: “2025-12-11 00:00:00.000000”,
“date”: “2026-03-02 21:50:48.004146”,
“group”: “pear”,
“link”: “https:\/\/www.ransomware.live\/id\/R29yZG9uIENsaWZmb3JkIFByb3BlcnRpZXMgSW5jLkBwZWFy”
}
],
“extrainfos”: [],
“group”: “play”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/b873dab74466e7d022ab5df09d29d25f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/R29yZG9uL0NsaWZmb3JkIFJlYWx0eUBwbGF5”,
“victim”: “Gordon\/Clifford Realty”
},
{
“activity”: “Business Services”,
“attackdate”: “2025-10-14 00:00:00.000000”,
“claim_url”: “”,
“country”: “JP”,
“description”: “Founded in 1983, Promotion Management Center, Inc. (PMC) provides fulfillment services.The company specializes in customer incentives, loyalty rewards, employee recognition awards, rebates and third party logistics (3PL) orders your programs generate.”,
“discovered”: “2026-03-03 09:43:16.121930”,
“domain”: “pmci.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:42:55”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/UHJvbW90aW9uIE1hbmFnZW1lbnQgQ2VudGVyQEFpTG9jaw==”,
“victim”: “Promotion Management Center”
},
{
“activity”: “Not Found”,
“attackdate”: “2025-10-11 00:00:00.000000”,
“claim_url”: “”,
“country”: “”,
“description”: “Sterling Industries is a North American-based contract manufacturer and assembler of medical devices and sub-components.”,
“discovered”: “2026-03-03 09:42:52.599213”,
“domain”: “sterlingindustries.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:42:30”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/U3RlcmxpbmcgSW5kdXN0cmllc0BBaUxvY2s=”,
“victim”: “Sterling Industries”
},
{
“activity”: “Agriculture and Food Production”,
“attackdate”: “2025-07-24 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “Raw Seafoods, Inc. is a family owned and operated company in Fall River, Massachusetts dedicated to providing our customers with exceptional products, and service.We specialize in fresh and frozen scallops, fish and value-added food solutions.”,
“discovered”: “2026-03-03 09:42:27.329693”,
“domain”: “rawseafoods.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:42:06”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/UmF3IFNlYWZvb2RzQEFpTG9jaw==”,
“victim”: “Raw Seafoods”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2025-07-21 00:00:00.000000”,
“claim_url”: “”,
“country”: “GB”,
“description”: “FUJIFILM Speciality Ink Systems Ltd is a company that operates in the Chemicals & Related Products industry.The company is headquartered in Saint Peters, Kent, United Kingdom.”,
“discovered”: “2026-03-03 09:42:01.779170”,
“domain”: “”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/RlVKSUZJTE0gU3BlY2lhbGl0eSBJbmsgU3lzdGVtc0BBaUxvY2s=”,
“victim”: “FUJIFILM Speciality Ink Systems”
},
{
“activity”: “Consumer Services”,
“attackdate”: “2025-07-06 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “Founded in 1942, Lewis Drug owns and operates a chain of drug and pharmacy stores.It provides prescription and non-prescription drugs.”,
“discovered”: “2026-03-03 09:41:57.950444”,
“domain”: “lewisdrug.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:41:37”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/TGV3aXMgRHJ1Z0BBaUxvY2s=”,
“victim”: “Lewis Drug”
},
{
“activity”: “Construction”,
“attackdate”: “2025-06-17 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “HomeSite Services Inc., a residential, commercial and retail services company, was founded in 2005 with three goals in mind:to perform superior work, offer quality products, and provide our clients with unbeatable service.”,
“discovered”: “2026-03-03 09:41:34.499130”,
“domain”: “homesiteservices.net”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:41:13”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/SG9tZVNpdGUgU2VydmljZXNAQWlMb2Nr”,
“victim”: “HomeSite Services”
},
{
“activity”: “Not Found”,
“attackdate”: “2025-04-17 00:00:00.000000”,
“claim_url”: “”,
“country”: “KR”,
“description”: “AJ Networks Co. Ltd is a company that operates in the Other Rental Stores (Furniture, A\/V, Construction & Industrial Equipment) industry.It employs 500to999 people and has 500Mto1G of revenue. The company is headquartered in Seoul, South Korea.”,
“discovered”: “2026-03-03 09:40:46.264529”,
“domain”: “ajnetworks.co.kr”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:40:24”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/QUogTmV0d29ya3NAQWlMb2Nr”,
“victim”: “AJ Networks”
},
{
“activity”: “Technology”,
“attackdate”: “2025-04-10 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “Integral Analytics specializes in data intelligence solutions for the energy sector, focusing on improving planning and forecasting for utilities, producers, manufacturers, and regulators.Their flagship products include LoadSEER, DSMore, and IDROP, which assist in energy efficiency, demand response, and distributed energy resource management.”,
“discovered”: “2026-03-03 09:40:21.405747”,
“domain”: “integralanalytics.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:39:59”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/SW50ZWdyYWwgQW5hbHl0aWNzQEFpTG9jaw==”,
“victim”: “Integral Analytics”
},
{
“activity”: “Technology”,
“attackdate”: “2024-03-27 14:57:43.127611”,
“claim_url”: “http:\/\/beast6azu4f7fxjakiayhnssybibsgjnmy77a6duufqw5afjzfjhzuqd.onion\/card\/camelot_electronics_technology_co___ltd_”,
“country”: “CN”,
“description”: “Camelot Hubei Technology Limited Company (also known as Hubei Camelot Electronics) is a subsidiary of Camelot Electronics Technology Co., Ltd. (Jinlu Electronics), specializing in the manufacturing of printed circuit boards (PCBs).”,
“discovered”: “2026-03-03 16:29:20.595477”,
“domain”: “-“,
“duplicates”: [
{
“attackdate”: “2024-03-27 14:57:43.127611”,
“date”: “2026-03-03 16:29:20.657021”,
“group”: “qilin”,
“link”: “https:\/\/www.ransomware.live\/id\/TC1QaW1lbnRhIChldGRlbGV0cm9uaWNzKUBxaWxpbg==”
}
],
“extrainfos”: {
“data_size”: “84GB”
},
“group”: “beast”,
“infostealer”: “”,
“press”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/3b2c43809caf589836e9024c56a8b126.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q2FtZWxvdCBFbGVjdHJvbmljcyBUZWNobm9sb2d5IENvLiwgTHRkLkBiZWFzdA==”,
“victim”: “Camelot Electronics Technology Co., Ltd.”
},
{
“activity”: “Consumer Services”,
“attackdate”: “2015-04-29 00:00:00.000000”,
“claim_url”: “”,
“country”: “US”,
“description”: “Revival Animal Health was founded in 1989 by Dr. Roy Nielsen, Jr., affectionately known as \”Doc Roy.\”Quickly the company expanded from pet vaccines to an extensive line of pet healthcare products.”,
“discovered”: “2026-03-03 09:41:10.676682”,
“domain”: “revivalanimal.com”,
“duplicates”: [],
“extrainfos”: [],
“group”: “AiLock”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: {
“Azorult”: 11,
“DarkCrystal”: 1,
“Generic Stealer”: 50,
“Lumma”: 53,
“Raccoon”: 11,
“RedLine”: 48,
“StealC”: 7,
“UNKNOWN”: 2,
“Vidar”: 5
},
“thirdparties”: 0,
“thirdparties_domain”: 0,
“update”: “2026-03-03 09:40:49”,
“users”: 226,
“users_url”: 21
},
“press”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/UmV2aXZhbCBBbmltYWwgSGVhbHRoQEFpTG9jaw==”,
“victim”: “Revival Animal Health”
}
]





