Ransomware Stats
{
“groups”: 370,
“victims”: 30120
}
[
{
“activity”: “Retail & E-Commerce”,
“attackdate”: “2026-07-27T11:58:04.234886+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=af6a747d-1fc7-42e2-a953-0c198cf49576”,
“country”: “US”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-27T11:58:25.874094+00:00”,
“domain”: “www.wilberts.com”,
“group”: “qilin”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/7c5d96a6ea10b84c963ee6e6a46d206f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/V2lsYmVydCdzQHFpbGlu”,
“victim”: “Wilbert’s”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-27T11:10:00+00:00”,
“claim_url”: “”,
“country”: “US”,
“data_size”: null,
“description”: “Over XX of data was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline. | Updated: 27 July 2026 | Warning: FINAL WARNING PAY OR LEAK”,
“discovered”: “2026-07-27T12:59:16.314722+00:00”,
“domain”: “ringcentral.com”,
“group”: “shinyhunters”,
“infostealer”: {
“employees”: 120,
“employees_url”: 59,
“infostealer_stats”: {
“Acreed”: 171,
“Atomic”: 42,
“Aura Stealer”: 1,
“Azorult”: 595,
“CRYPTBOT”: 45,
“DarkCrystal”: 16,
“Ficker”: 6,
“Generic Stealer”: 4849,
“KPOT”: 2,
“Lumma”: 4203,
“Mystic”: 26,
“Predator”: 5,
“Raccoon”: 1375,
“RedLine”: 5021,
“StealC”: 869,
“Taurus”: 10,
“UNKNOWN”: 206,
“Vidar”: 672
},
“last_employee_compromised”: “2026-07-07T00:00:00+00:00”,
“last_user_compromised”: “2026-07-25T18:18:47.388000+00:00”,
“thirdparties”: 173,
“update”: “2026-07-27T12:59:57.132436”,
“users”: 21969,
“users_url”: 100
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/UmluZ0NlbnRyYWwsIEluYy5Ac2hpbnlodW50ZXJz”,
“victim”: “RingCentral, Inc.”
},
{
“activity”: “Professional Services”,
“attackdate”: “2026-07-27T11:10:00+00:00”,
“claim_url”: “”,
“country”: “US”,
“data_size”: null,
“description”: “Yes it was us. Now come talk to us. We have been trying to reach you. If you do not come talk to us within the given deadline, we fully and completely intend to release all the data and files. This is a final warning to reach out by 31 July 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline. | Updated: 27 July 2026 | Warning: FINAL WARNING PAY OR LEAK”,
“discovered”: “2026-07-27T12:58:56.004876+00:00”,
“domain”: “ey.com”,
“group”: “shinyhunters”,
“infostealer”: {
“employees”: 838,
“employees_url”: 47,
“infostealer_stats”: {
“Acreed”: 63,
“Atomic”: 14,
“Aura Stealer”: 1,
“Azorult”: 53,
“CRYPTBOT”: 10,
“Generic Stealer”: 819,
“KPOT”: 2,
“Lumma”: 581,
“Mystic”: 2,
“Predator”: 1,
“Raccoon”: 244,
“RedLine”: 632,
“StealC”: 131,
“Taurus”: 1,
“UNKNOWN”: 31,
“Vidar”: 121
},
“last_employee_compromised”: “2026-07-25T18:53:10.975000+00:00”,
“last_user_compromised”: “2026-07-25T00:00:00+00:00”,
“thirdparties”: 1017,
“update”: “2026-07-27T13:00:15.032060”,
“users”: 2053,
“users_url”: 100
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/RXJuc3QgJiBZb3VuZ0BzaGlueWh1bnRlcnM=”,
“victim”: “Ernst & Young”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-27T04:57:32.519957+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=iptv-platform”,
“country”: “US”,
“data_size”: “3.2 GB”,
“description”: “Sector: Technology \/ Video Streaming | Data leaked: 3.2 GB”,
“discovered”: “2026-07-27T04:57:50.593106+00:00”,
“domain”: “IPTVPlatform.com”,
“group”: “CRPxO”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/bff21c7d5a56e5aba89ae55a983b031d.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SVBUViBQbGF0Zm9ybUBDUlB4Tw==”,
“victim”: “IPTV Platform”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-27T04:56:55.947105+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=marketech”,
“country”: “US”,
“data_size”: “6.7 GB”,
“description”: “Sector: Marketing \/ SEO | Data leaked: 6.7 GB”,
“discovered”: “2026-07-27T04:57:14.381582+00:00”,
“domain”: “marketech.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T05:03:01.909869”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/81319f03549e18b997b9ac8ac198f970.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TWFya2V0ZWNoQENSUHhP”,
“victim”: “Marketech”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-27T04:56:17.437127+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=american-hospice-home-health”,
“country”: “US”,
“data_size”: “11.3 GB”,
“description”: “Sector: Healthcare \/ Hospice | Data leaked: 11.3 GB”,
“discovered”: “2026-07-27T04:56:37.802815+00:00”,
“domain”: “americanhomehealthservices.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T05:02:27.295348”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/61e662432f9daf6996d4a6f54e9c460b.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QW1lcmljYW4gSG9zcGljZSAmIEhvbWUgSGVhbHRoIFNlcnZpY2VzIChBaGhoIENhcmUpQENSUHhP”,
“victim”: “American Hospice & Home Health Services (Ahhh Care)”
},
{
“activity”: “Financial Services”,
“attackdate”: “2026-07-27T04:55:39.590481+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=bright-star-partners-insurance”,
“country”: “US”,
“data_size”: “41.8 GB”,
“description”: “Sector: Insurance \/ Financial Services | Data leaked: 41.8 GB”,
“discovered”: “2026-07-27T04:55:59.358180+00:00”,
“domain”: “brightstarinsurancepartners.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T05:03:37.237654”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/a9e761bd50deee57f7d793e66bd253a4.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QnJpZ2h0IFN0YXIgUGFydG5lcnMgSW5zdXJhbmNlQENSUHhP”,
“victim”: “Bright Star Partners Insurance”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-27T04:55:01.158473+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=ecare-platform”,
“country”: “US”,
“data_size”: “14.2 GB”,
“description”: “Sector: Healthcare \/ Technology | Data leaked: 14.2 GB”,
“discovered”: “2026-07-27T04:55:21.501975+00:00”,
“domain”: “ecareplatform.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T05:04:03.916734”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/4379f32633683fe5baeb504963256190.png”,
“url”: “https:\/\/www.ransomware.live\/id\/ZUNhcmUgUGxhdGZvcm1AQ1JQeE8=”,
“victim”: “eCare Platform”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-27T04:54:23.003793+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=dignity-phoenix”,
“country”: “US”,
“data_size”: “5.4 GB”,
“description”: “Sector: Non-Profit \/ Social Services | Data leaked: 5.4 GB”,
“discovered”: “2026-07-27T04:54:42.961577+00:00”,
“domain”: “dignityphoenix.org”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T05:04:20.905725”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/9b018c8f37dc3749106f895794eed12f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RGlnbml0eSBQaG9lbml4QENSUHhP”,
“victim”: “Dignity Phoenix”
},
{
“activity”: “Professional Services”,
“attackdate”: “2026-07-27T04:53:44.965477+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=schorr-law”,
“country”: “US”,
“data_size”: “27.6 GB”,
“description”: “Sector: Legal \/ Real Estate | Data leaked: 27.6 GB”,
“discovered”: “2026-07-27T04:54:04.939955+00:00”,
“domain”: “schorr-law.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T05:04:36.608317”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/4c9ceb7b6768c420467b1f63ca949aae.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U2Nob3JyIExhd0BDUlB4Tw==”,
“victim”: “Schorr Law”
},
{
“activity”: “Professional Services”,
“attackdate”: “2026-07-27T04:53:06.815665+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=simpkins-law-firm”,
“country”: “US”,
“data_size”: “31.2 GB”,
“description”: “Sector: Legal \/ Family Law | Data leaked: 31.2 GB”,
“discovered”: “2026-07-27T04:53:26.796048+00:00”,
“domain”: “simkins.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T05:04:53.427854”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/cdec3da30a830115d16051b1a6c09b58.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U2ltcGtpbnMgTGF3IEZpcm1AQ1JQeE8=”,
“victim”: “Simpkins Law Firm”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-27T04:52:28.568061+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=leah-walker-orthodontics”,
“country”: “US”,
“data_size”: “8.3 GB”,
“description”: “Sector: Healthcare \/ Orthodontics | Data leaked: 8.3 GB”,
“discovered”: “2026-07-27T04:52:48.688038+00:00”,
“domain”: “socalbraces.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T05:05:10.133121”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/96e70f638fbacf6557f551d33842f979.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TGVhaCBXYWxrZXIgT3J0aG9kb250aWNzQENSUHhP”,
“victim”: “Leah Walker Orthodontics”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-27T04:51:47.931636+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=elko-dental-specialists”,
“country”: “US”,
“data_size”: “7.8 GB”,
“description”: “Sector: Healthcare \/ Dental | Data leaked: 7.8 GB”,
“discovered”: “2026-07-27T04:52:10.339525+00:00”,
“domain”: “elkosmiles.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T05:05:24.718453”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/19b54be3f60b44a8987c010ef8f754d1.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RWxrbyBEZW50YWwgU3BlY2lhbGlzdHNAQ1JQeE8=”,
“victim”: “Elko Dental Specialists”
},
{
“activity”: “Hospitality”,
“attackdate”: “2026-07-27T04:22:45.848320+00:00”,
“claim_url”: “http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=8289671c-c761-48b7-833b-f75f83d4b7b8”,
“country”: “TH”,
“data_size”: null,
“description”: “Katathani Phuket Beach Resort is a luxury beachfront resort located on Kata Noi Beach in Phuket, Thailand, offering a range of accommodations from suites to family-friendly rooms. The resort features world-class amenities including multiple dining options, a spa, fitness facilities, and a kids club, catering to couples, families, and solo travelers alike. Guests can enjoy stunning ocean views, direct beach access, and a variety of recreational activities, ensuring a memorable stay in a tranquil setting. With its commitment to providing exceptional service and a serene atmosphere, Katathani is an ideal destination for those seeking relaxation and luxury in paradise.”,
“discovered”: “2026-07-27T05:22:38.980659+00:00”,
“domain”: “www.katathani.com”,
“group”: “dragonforce”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/0d87bde997a710df7c5b8fe23e425eb7.png”,
“url”: “https:\/\/www.ransomware.live\/id\/S2F0YXRoYW5pIFBodWtldCBCZWFjaCBSZXNvcnRAZHJhZ29uZm9yY2U=”,
“victim”: “Katathani Phuket Beach Resort”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-27T04:20:38.058657+00:00”,
“claim_url”: “”,
“country”: “CL”,
“data_size”: null,
“description”: “Hardware Asesor\u00edas Software Ltda (HAS Ltda) is a technology provider based in Bucaramanga, Colombia, specializing in the distribution of hardware and software licenses . The company acts as an official partner for brands such as Apple, Adobe, and HP, serving business customers, government agencies, and engineering firms.”,
“discovered”: “2026-07-27T04:20:39.367661+00:00”,
“domain”: “www.hasltda.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/SGFyZHdhcmUgQXNlc29yaWFzIFNvZnR3YXJlIEx0ZGFARGVhZGxvY2s=”,
“victim”: “Hardware Asesorias Software Ltda”
},
{
“activity”: “Retail & E-Commerce”,
“attackdate”: “2026-07-27T04:20:17.286426+00:00”,
“claim_url”: “”,
“country”: “GB”,
“data_size”: null,
“description”: “Tesco Engineer Co., Ltd. is a Thai construction and manufacturing company based in Bangkok, operating in civil engineering and industrial pipe manufacturing since 1976.”,
“discovered”: “2026-07-27T04:20:18.909070+00:00”,
“domain”: “tesco-engineers.com”,
“group”: “Deadlock”,
“infostealer”: {
“employees”: 2,
“employees_url”: 1,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 2,
“update”: “2026-07-27T04:20:17”,
“users”: 2,
“users_url”: 4
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/VGVzY28gRW5naW5lZXJARGVhZGxvY2s=”,
“victim”: “Tesco Engineer”
},
{
“activity”: “Other”,
“attackdate”: “2026-07-27T03:20:32.645003+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/33\/”,
“country”: “US”,
“data_size”: null,
“description”: “Country: US |\nWebsite: lcadv.org |\nRevenue: $13.3 Million |\nIndustry: Non-Profit & Charitable Organizations |\nEmployees: 201-500 |\nProperties: 241 GB (287,451 Files, 31,100 Folders)”,
“discovered”: “2026-07-27T03:20:56.244316+00:00”,
“domain”: “lcadv.org”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T03:20:32”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/e733e1ef8e70132771e089ad3e13176d.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TG91aXNpYW5hIENvYWxpdGlvbiBBZ2FpbnN0IHwgRG9tZXN0aWMgVmlvbGVuY2VAR2xvYmFsIFNlY3JldCBHcm91cA==”,
“victim”: “Louisiana Coalition Against | Domestic Violence”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-27T01:56:34.395006+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=prosmile-family-dental”,
“country”: “US”,
“data_size”: “9.6 GB”,
“description”: “Sector: Healthcare \/ Dental | Data leaked: 9.6 GB”,
“discovered”: “2026-07-27T01:56:55.725540+00:00”,
“domain”: “familydentistmodesto.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T04:39:14.321767”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/af45cf5c6e04f5cecc06323719c248ce.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UHJvU21pbGUgRmFtaWx5IERlbnRhbCBDYXJlQENSUHhP”,
“victim”: “ProSmile Family Dental Care”
},
{
“activity”: “Transportation”,
“attackdate”: “2026-07-27T01:55:55.571970+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=qube-aviation-catering”,
“country”: “US”,
“data_size”: “22.5 GB”,
“description”: “Sector: Aviation \/ Catering | Data leaked: 22.5 GB”,
“discovered”: “2026-07-27T01:56:16.299819+00:00”,
“domain”: “qubeaviationcatering.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T04:39:32.325333”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/e6c38090a17849ea1f8410762be0de99.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UXViZSBBdmlhdGlvbiBDYXRlcmluZ0BDUlB4Tw==”,
“victim”: “Qube Aviation Catering”
},
{
“activity”: “Professional Services”,
“attackdate”: “2026-07-27T01:55:15.809060+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=performance-data-solutions”,
“country”: “US”,
“data_size”: “12.8 GB”,
“description”: “Sector: Motorsport \/ Data Acquisition | Data leaked: 12.8 GB”,
“discovered”: “2026-07-27T01:55:37.516445+00:00”,
“domain”: “performancedatasolutions.net”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T04:40:07.025648”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/7fe1476b2793312664a67b725966c461.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UGVyZm9ybWFuY2UgRGF0YSBTb2x1dGlvbnNAQ1JQeE8=”,
“victim”: “Performance Data Solutions”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-27T01:54:36.183876+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=host-and-protect”,
“country”: “IE”,
“data_size”: “156.2 GB”,
“description”: “Sector: Web Hosting \/ Security | Data leaked: 156.2 GB”,
“discovered”: “2026-07-27T01:54:57.651461+00:00”,
“domain”: “hostandprotect.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T04:44:25.983536”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/e89182c30f8392976e11da9cec65b8e2.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SG9zdCAmIFByb3RlY3QgKFJlZEJsaW5rKUBDUlB4Tw==”,
“victim”: “Host & Protect (RedBlink)”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-27T01:53:56.422672+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=rnnr-cloud”,
“country”: “US”,
“data_size”: “68.9 GB”,
“description”: “Sector: Technology \/ Cloud Services | Data leaked: 68.9 GB”,
“discovered”: “2026-07-27T01:54:18.053785+00:00”,
“domain”: “rnnr.cloud”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T04:43:25.164393”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/b7b0bedb6ba02c85c8b2a685d799e918.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Um5uUiBDbG91ZEBDUlB4Tw==”,
“victim”: “RnnR Cloud”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-27T01:53:12.589989+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=codeconductor-ai”,
“country”: “US”,
“data_size”: “52.4 GB”,
“description”: “Sector: Technology \/ AI \/ SaaS | Data leaked: 52.4 GB”,
“discovered”: “2026-07-27T01:53:38.213503+00:00”,
“domain”: “CodeConductor.ai”,
“group”: “CRPxO”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/49060296d5388ee114a046c308321147.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q29kZUNvbmR1Y3Rvci5haUBDUlB4Tw==”,
“victim”: “CodeConductor.ai”
},
{
“activity”: “Financial Services”,
“attackdate”: “2026-07-27T01:52:33.683341+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=prei-capital”,
“country”: “US”,
“data_size”: “18.7 GB”,
“description”: “Sector: Financial \/ Capital | Data leaked: 18.7 GB”,
“discovered”: “2026-07-27T01:52:53.494639+00:00”,
“domain”: “preicapital.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T04:42:54.690047”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/22818bff7d1ecd67c1800618090c784f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UHJlaSBDYXBpdGFsQENSUHhP”,
“victim”: “Prei Capital”
},
{
“activity”: “Professional Services”,
“attackdate”: “2026-07-27T01:51:53.825252+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=flp-law-group”,
“country”: “US”,
“data_size”: “42.1 GB”,
“description”: “Sector: Legal \/ Bankruptcy | Data leaked: 42.1 GB”,
“discovered”: “2026-07-27T01:52:15.445847+00:00”,
“domain”: “flpllp.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T04:42:39.888672”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/59428b853a5f04014c94e59c00e4d94c.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RkxQIExhdyBHcm91cCBMTFBAQ1JQeE8=”,
“victim”: “FLP Law Group LLP”
},
{
“activity”: “Financial Services”,
“attackdate”: “2026-07-27T01:51:15.168003+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=summit-hill-insurance”,
“country”: “US”,
“data_size”: “34.5 GB”,
“description”: “Sector: Insurance | Data leaked: 34.5 GB”,
“discovered”: “2026-07-27T01:51:35.654605+00:00”,
“domain”: “summithillinsurance.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 1,
“employees_url”: 1,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 1,
“update”: “2026-07-27T04:42:21.654125”,
“users”: 0,
“users_url”: 2
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/adc96db37f6c5485cdbb029ead151889.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U3VtbWl0IEhpbGwgSW5zdXJhbmNlQENSUHhP”,
“victim”: “Summit Hill Insurance”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-27T01:50:32.990029+00:00”,
“claim_url”: “http:\/\/tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion\/victim.php?slug=mro-aerospace”,
“country”: “US”,
“data_size”: “87.3 GB”,
“description”: “Sector: Aerospace \/ Defense | Data leaked: 87.3 GB”,
“discovered”: “2026-07-27T01:50:56.971799+00:00”,
“domain”: “mroaerospace.com”,
“group”: “CRPxO”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T04:41:34.310846”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/99f3ebb6d0dfb9c3b93af1ade65e0b1e.png”,
“url”: “https:\/\/www.ransomware.live\/id\/TVJPIEFlcm9zcGFjZUBDUlB4Tw==”,
“victim”: “MRO Aerospace”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-27T00:20:26.446273+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/32\/”,
“country”: “US”,
“data_size”: null,
“description”: “Country: Cambridge, Minnesota 55008, US |\nWebsite: parkmfg.com |\nRevenue: $17.9 Million |\nIndustry: Appliances, Electrical, and Electronics Manufacturing |\nEmployees: 50-100 |\nProperties: 195 GB (411,109 Files, 48,413 Folders)”,
“discovered”: “2026-07-27T00:20:52.552323+00:00”,
“domain”: “parkmfg.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T00:20:26”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/9526af0430bc21e3a547ed5239293984.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UGFyayBNYW51ZmFjdHVyaW5nIENvcnAuQEdsb2JhbCBTZWNyZXQgR3JvdXA=”,
“victim”: “Park Manufacturing Corp.”
},
{
“activity”: “Hospitality”,
“attackdate”: “2026-07-27T00:01:00+00:00”,
“claim_url”: “http:\/\/incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion\/blog\/disclosures\/6a6277ab5ae71db30c86ca0a”,
“country”: “US”,
“data_size”: null,
“description”: “The HOP, an American regional public transit system operated by the Hill Country Transit District (HCTD). Founded in the 1960s in the state of Texas (USA) as a voluntary transportation service, the organization has grown over the decades into a major public public-transport network.”,
“discovered”: “2026-07-27T00:25:17.945973+00:00”,
“domain”: “takethehop.com”,
“group”: “incransom”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T00:24:49”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f506e152bc6da3e38a3411eb267bea3f.png”,
“url”: “https:\/\/www.ransomware.live\/id\/dGFrZXRoZWhvcC5jb21AaW5jcmFuc29t”,
“victim”: “takethehop.com”
},
{
“activity”: “Professional Services”,
“attackdate”: “2026-07-27T00:00:00+00:00”,
“claim_url”: “http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=6435c147-970c-4b24-9f6b-3e04ac9dddad”,
“country”: “FR”,
“data_size”: null,
“description”: “N\/A”,
“discovered”: “2026-07-27T11:59:02.253716+00:00”,
“domain”: “savills.fr”,
“group”: “qilin”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-27T12:58:01.654008”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/8a7c60212252aeee922f32445faab86d.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U2F2aWxscyBGcmFuY2VAcWlsaW4=”,
“victim”: “Savills France”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-26T23:50:38.308645+00:00”,
“claim_url”: “”,
“country”: “US”,
“data_size”: null,
“description”: “Revenue: $24B\n\nDATA SUMMARY:\n2.6M~ records containing: customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.”,
“discovered”: “2026-07-26T23:50:39.165392+00:00”,
“domain”: “wesco.com”,
“group”: “ExfilSquad”,
“infostealer”: {
“employees”: 5,
“employees_url”: 1,
“infostealer_stats”: {
“Acreed”: 1,
“Azorult”: 46,
“CRYPTBOT”: 1,
“Generic Stealer”: 87,
“Lumma”: 51,
“Predator”: 1,
“Raccoon”: 63,
“RedLine”: 136,
“StealC”: 13,
“UNKNOWN”: 5,
“Vidar”: 21
},
“last_employee_compromised”: “2025-09-26T01:37:00+00:00”,
“last_user_compromised”: “2026-07-13T17:53:18.170000+00:00”,
“thirdparties”: 13,
“update”: “2026-07-27T04:41:16.120102”,
“users”: 462,
“users_url”: 16
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/V2VzY28gSW50ZXJuYXRpb25hbEBFeGZpbFNxdWFk”,
“victim”: “Wesco International”
},
{
“activity”: “Manufacturing”,
“attackdate”: “2026-07-26T22:50:56.604143+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/31\/”,
“country”: “IN”,
“data_size”: null,
“description”: “Country: India |\nWebsite: hindujatech.com |\nRevenue: $381 Million |\nIndustry: Engineering Services, Architecture, Engineering & Design, Product Engineering Solutions |\nEmployees: 2000-5000 |\nProperties: 515 GB (212,785 Files, 83,982 Folders)”,
“discovered”: “2026-07-26T22:51:57.881062+00:00”,
“domain”: “hindujatech.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 73,
“update”: “2026-07-26T22:50:56”,
“users”: 187,
“users_url”: 38
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/0869ccdff47d123d8cea4166454c9297.png”,
“url”: “https:\/\/www.ransomware.live\/id\/SGluZHVqYSBUZWNoIHwgQk1XIEdyb3VwICYgxaBrb2RhIEF1dG9AR2xvYmFsIFNlY3JldCBHcm91cA==”,
“victim”: “Hinduja Tech | BMW Group & \u0160koda Auto”
},
{
“activity”: “Retail & E-Commerce”,
“attackdate”: “2026-07-26T19:50:55.267968+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/30\/”,
“country”: “US”,
“data_size”: null,
“description”: “Country: Crystal Lake, US |\nWebsite: protuffdecals.com |\nRevenue: $9.6 million |\nIndustry: Business Services General, Business Services |\nEmployees: 10-20 |\nProperties: 412 GB (589,623 Files, 40,081 Folders)”,
“discovered”: “2026-07-26T19:51:22.588009+00:00”,
“domain”: “protuffdecals.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T19:50:55”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f0ef85e5db720dfa34277f73f324c3d0.png”,
“url”: “https:\/\/www.ransomware.live\/id\/UHJvLVR1ZmYgfCBEZWNhbHNAR2xvYmFsIFNlY3JldCBHcm91cA==”,
“victim”: “Pro-Tuff | Decals”
},
{
“activity”: “Transportation”,
“attackdate”: “2026-07-26T19:50:21.273898+00:00”,
“claim_url”: “”,
“country”: “US”,
“data_size”: null,
“description”: “High Class Limousine & Car Service Corp. is a licensed private passenger transportation service in New York City, founded in 1995, specializing in non-emergency medical transportation . The company provides rides to medical appointments, dialysis sessions, and rehabilitation facilities, and has locations in Manhattan and the Bronx.”,
“discovered”: “2026-07-26T19:50:23.006749+00:00”,
“domain”: “www.highclasscarlimo.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/SGlnaCBDbGFzcyBDYXIgTGltb0BEZWFkbG9jaw==”,
“victim”: “High Class Car Limo”
},
{
“activity”: “Hospitality”,
“attackdate”: “2026-07-26T19:23:38.531529+00:00”,
“claim_url”: “http:\/\/anubisyfkh5rixydjpoo3jqucauajz2juybrbtuglcppjj2y3eg3y6ad.onion\/r\/pd6fbi+hxlHWHT9iyJvkoMfFPlamNFsA7TdiiwblLx1OL3o6UBAFJAoglUrOMSY3s2hiFkcQYnjcbuo6SgpBHFBN2l1aU96”,
“country”: “US”,
“data_size”: null,
“description”: “Patient and employee data breach at elderly care service.”,
“discovered”: “2026-07-26T19:24:27.412318+00:00”,
“domain”: “eaglecrestlife.org”,
“group”: “anubis”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T19:27:13.700434”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/f0807f4e7a9f26925209d7933498bac3.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RWFnbGUgQ3Jlc3QgQ29tbXVuaXRpZXNAYW51Ymlz”,
“victim”: “Eagle Crest Communities”
},
{
“activity”: “Professional Services”,
“attackdate”: “2026-07-26T19:21:50.310293+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/29\/”,
“country”: “CA”,
“data_size”: null,
“description”: “Country: Canada |\nWebsite: spergel.ca |\nRevenue: $28.2 Million |\nIndustry: Business Services,Project Management |\nEmployees: 51-200 |\nProperties: 5.4 TB (7,830,792 Files, 902,844 Folders)”,
“discovered”: “2026-07-26T19:22:14.826310+00:00”,
“domain”: “spergel.ca”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T19:21:50”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/198a30f26a2ef177e42cc7c7f81d4499.png”,
“url”: “https:\/\/www.ransomware.live\/id\/U3BlcmdlbEBHbG9iYWwgU2VjcmV0IEdyb3Vw”,
“victim”: “Spergel”
},
{
“activity”: “Energy & Utilities”,
“attackdate”: “2026-07-26T19:21:18.991314+00:00”,
“claim_url”: “”,
“country”: “AU”,
“data_size”: null,
“description”: “West African Resources Limited (ASX: WAF) isan Australia-based, mid-tier gold mining and exploration companywith its primary operations located in Burkina Faso, West Africa . Founded in 2006, the company is headquartered in Subiaco, Western Australia, and focuses on the acquisition, development, and mineral processing of high-grade gold assets.”,
“discovered”: “2026-07-26T19:21:20.232704+00:00”,
“domain”: “www.westafricanresources.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/V2VzdCBBZnJpY2FuIFJlc291cmNlcyBsdGRARGVhZGxvY2s=”,
“victim”: “West African Resources ltd”
},
{
“activity”: “Energy & Utilities”,
“attackdate”: “2026-07-26T19:20:58.520856+00:00”,
“claim_url”: “”,
“country”: “AZ”,
“data_size”: null,
“description”: “Caspian One is an international provider of IT services and specialist talent for industries such as FinTech investment banking and broadcasting. Based in England the company offers professional recruitment and managed technology solutions and operates in Europe and North America.”,
“discovered”: “2026-07-26T19:20:59.978436+00:00”,
“domain”: “www.caspianone.com”,
“group”: “Deadlock”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/Q2FzcGlhbiBPbmVARGVhZGxvY2s=”,
“victim”: “Caspian One”
},
{
“activity”: “Not Found”,
“attackdate”: “2026-07-26T18:47:24.892603+00:00”,
“claim_url”: “\/post\/a0d8e6d2971e253e”,
“country”: “BR”,
“data_size”: null,
“description”: “MINING”,
“discovered”: “2026-07-26T18:47:26.697113+00:00”,
“domain”: “”,
“group”: “Section9”,
“infostealer”: “”,
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/KioqKioqKiouY29tLmJyQFNlY3Rpb245”,
“victim”: “********.com.br”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-26T18:14:37.599023+00:00”,
“claim_url”: “”,
“country”: “FI”,
“data_size”: null,
“description”: “Backbone network traffic analysis and SS7 protocol vulnerability assessment across 3 continents.”,
“discovered”: “2026-07-26T18:14:42.968027+00:00”,
“domain”: “prismtelecom.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T18:17:05.093597”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/UHJpc20gVGVsZWNvbUBHbG9iYWwgU2VjcmV0IEdyb3Vw”,
“victim”: “Prism Telecom”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-26T18:14:17.688821+00:00”,
“claim_url”: “”,
“country”: “IN”,
“data_size”: null,
“description”: “Zero-trust architecture review and cryptographic key management assessment.”,
“discovered”: “2026-07-26T18:14:19.490300+00:00”,
“domain”: “cipherdyn.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T18:17:47.864394”,
“users”: 1,
“users_url”: 1
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/Q2lwaGVyIER5bmFtaWNzQEdsb2JhbCBTZWNyZXQgR3JvdXA=”,
“victim”: “Cipher Dynamics”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-26T18:13:58.065346+00:00”,
“claim_url”: “”,
“country”: “AE”,
“data_size”: null,
“description”: “Satellite communication relay analysis with deep-packet inspection across 14 ground stations.”,
“discovered”: “2026-07-26T18:13:59.637532+00:00”,
“domain”: “stratosns.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T18:15:40.679793”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/U3RyYXRvcyBOZXR3b3JrQEdsb2JhbCBTZWNyZXQgR3JvdXA=”,
“victim”: “Stratos Network”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-26T18:13:38.027656+00:00”,
“claim_url”: “”,
“country”: “DE”,
“data_size”: null,
“description”: “Full-scope penetration testing of financial transaction processing pipeline and API gateway.”,
“discovered”: “2026-07-26T18:13:39.287272+00:00”,
“domain”: “omnilink.software”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T18:15:06.137708”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/T21uaUxpbmsgQUdAR2xvYmFsIFNlY3JldCBHcm91cA==”,
“victim”: “OmniLink AG”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-26T18:13:18.453454+00:00”,
“claim_url”: “”,
“country”: “US”,
“data_size”: null,
“description”: “Ongoing analysis of cloud-native architecture and microservice communication protocols.”,
“discovered”: “2026-07-26T18:13:19.932019+00:00”,
“domain”: “vertexsystems.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 4,
“update”: “2026-07-26T18:14:42.312948”,
“users”: 1,
“users_url”: 1
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/VmVydGV4IFN5c3RlbXNAR2xvYmFsIFNlY3JldCBHcm91cA==”,
“victim”: “Vertex Systems”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-26T18:12:58.084995+00:00”,
“claim_url”: “”,
“country”: “KR”,
“data_size”: null,
“description”: “Internal infrastructure audit revealed multiple critical entry points across distributed network segments.”,
“discovered”: “2026-07-26T18:12:59.532965+00:00”,
“domain”: “nexon.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 297,
“employees_url”: 35,
“infostealer_stats”: {
“Acreed”: 89,
“Atomic”: 16,
“Azorult”: 1788,
“CRYPTBOT”: 172,
“DarkCrystal”: 19,
“Ficker”: 128,
“Generic Stealer”: 9549,
“KPOT”: 14,
“Lumma”: 7605,
“Mystic”: 60,
“Predator”: 41,
“Raccoon”: 4272,
“RedLine”: 20800,
“StealC”: 2724,
“Taurus”: 52,
“UNKNOWN”: 768,
“Vidar”: 1903
},
“last_employee_compromised”: “2026-07-25T00:00:00+00:00”,
“last_user_compromised”: “2026-07-25T18:30:42.452000+00:00”,
“thirdparties”: 22,
“update”: “2026-07-26T18:14:17.990947”,
“users”: 126181,
“users_url”: 100
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/TmV4b24gQ29ycC5AR2xvYmFsIFNlY3JldCBHcm91cA==”,
“victim”: “Nexon Corp.”
},
{
“activity”: “Financial Services”,
“attackdate”: “2026-07-26T18:04:01.849643+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/1\/”,
“country”: “US”,
“data_size”: null,
“description”: “Country: Pennsylvania, United States |\nWebsite: farmersofmarble.com |\nRevenue: $5.2 Million |\nIndustry: Insurance |\nEmployees: 11-50 |\nProperties: 5.72 GB (18,699 Files, 2,631 Folders)”,
“discovered”: “2026-07-26T18:04:19.853636+00:00”,
“domain”: “farmersofmarble.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T18:04:01”,
“users”: 1,
“users_url”: 2
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/09737c09f8dc7654e0f88b1cc3b11541.png”,
“url”: “https:\/\/www.ransomware.live\/id\/RmFybWVycyBNdXR1YWwgRmlyZSBJbnN1cmFuY2VAR2xvYmFsIFNlY3JldCBHcm91cA==”,
“victim”: “Farmers Mutual Fire Insurance”
},
{
“activity”: “Professional Services”,
“attackdate”: “2026-07-26T18:03:08.452560+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/2\/”,
“country”: “US”,
“data_size”: null,
“description”: “Country: Columbus, Indiana, United States |\nWebsite: agslawyers.com |\nRevenue: $5 Million |\nIndustry: Law Firms & Legal Services |\nEmployees: 11-50 Employees |\nProperties: 328 GB (708,816 Files, 47,925 Folders)”,
“discovered”: “2026-07-26T18:03:43.015861+00:00”,
“domain”: “agslawyers.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T18:03:08”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/eaab404fb7d15bb832892360a2dbe6c5.png”,
“url”: “https:\/\/www.ransomware.live\/id\/V2VzdCBTaXh0aCBMYXdAR2xvYmFsIFNlY3JldCBHcm91cA==”,
“victim”: “West Sixth Law”
},
{
“activity”: “Professional Services”,
“attackdate”: “2026-07-26T18:02:02.950695+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/5\/”,
“country”: “US”,
“data_size”: null,
“description”: “Country: Kentucky, United States |\nWebsite: bakerbusinessandtax.com |\nRevenue: $1 Million |\nIndustry: Accounting for Legal Practices |\nEmployees: 1-10 Employees |\nProperties: 213Gb (817,209 Files, 48,866 Folders)”,
“discovered”: “2026-07-26T18:02:48.522022+00:00”,
“domain”: “bakerbusinessandtax.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T18:02:02”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/68d2d4032fc473bd0974247dd9d23941.png”,
“url”: “https:\/\/www.ransomware.live\/id\/QmFrZXIgQnVzaW5lc3MgJiBUYXggU29sdXRpb25zQEdsb2JhbCBTZWNyZXQgR3JvdXA=”,
“victim”: “Baker Business & Tax Solutions”
},
{
“activity”: “Retail & E-Commerce”,
“attackdate”: “2026-07-26T18:01:24.147087+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/6\/”,
“country”: “US”,
“data_size”: null,
“description”: “Country: Ohio, United States |\nWebsite: carpetsdirectfindlay.com |\nRevenue: $5 Million |\nIndustry: Retail,Furniture |\nEmployees: 11-50 |\nProperties: 31.1 GB (1,442 Files, 788 Folders)”,
“discovered”: “2026-07-26T18:01:43.584826+00:00”,
“domain”: “carpetsdirectfindlay.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T18:01:24”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “https:\/\/images.ransomware.live\/victims\/ad5c80534611d6fa51ef0aa0b1429c1d.png”,
“url”: “https:\/\/www.ransomware.live\/id\/Q2FycGV0cyBEaXJlY3RAR2xvYmFsIFNlY3JldCBHcm91cA==”,
“victim”: “Carpets Direct”
},
{
“activity”: “Technology”,
“attackdate”: “2026-07-26T18:00:44.532771+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/7\/”,
“country”: “US”,
“data_size”: null,
“description”: “Country: Kentucky, United States |\nWebsite: ohrestorationservices.com |\nRevenue: $6 Million |\nIndustry: Construction |\nEmployees: 30 Employees |\nProperties: 301 GB (33,041 Files, 4,133 Folders)”,
“discovered”: “2026-07-26T18:01:04.672821+00:00”,
“domain”: “ohrestorationservices.com”,
“group”: “Global Secret Group”,
“infostealer”: {
“employees”: 0,
“employees_url”: 0,
“infostealer_stats”: [],
“last_employee_compromised”: null,
“last_user_compromised”: null,
“thirdparties”: 0,
“update”: “2026-07-26T18:00:44”,
“users”: 0,
“users_url”: 0
},
“press”: null,
“ransom”: null,
“screenshot”: “”,
“url”: “https:\/\/www.ransomware.live\/id\/QW55V2VhdGhlckBHbG9iYWwgU2VjcmV0IEdyb3Vw”,
“victim”: “AnyWeather”
},
{
“activity”: “Healthcare”,
“attackdate”: “2026-07-26T18:00:04.036099+00:00”,
“claim_url”: “http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/9\/”,
“country”: “US”,
“data_size”: null,
“description”: “Country: Kentucky, United States |\nWebsite: middendorfanimalhospital.com |\nRevenue: <$5 Million |\nIndustry: Healthcare Services,Veterinary Services |\nEmployees: 11-50 |\nProperties: 28.1 GB (34,237 Files, 8,806 Folders)",
"discovered": "2026-07-26T18:00:24.794396+00:00",
"domain": "middendorfanimalhospital.com",
"group": "Global Secret Group",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T18:00:03",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/68f2c5935f99123296046abcd814127b.png",
"url": "https:\/\/www.ransomware.live\/id\/TWlkZGVuZG9yZiBBbmltYWwgSG9zcGl0YWwgJiBMYXNlciBDZW50cmVAR2xvYmFsIFNlY3JldCBHcm91cA==",
"victim": "Middendorf Animal Hospital & Laser Centre"
},
{
"activity": "Manufacturing",
"attackdate": "2026-07-26T17:59:16.645890+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/10\/",
"country": "US",
"data_size": null,
"description": "Country: Oklahoma, United States |\nWebsite: chappellsupply.com |\nRevenue: $9.2 Million |\nIndustry: Consumer Services,Retail,Manufacturing,Repair Services |\nEmployees: 11-50 |\nProperties: 160 GB (268,758 Files, 30,522 Folders)",
"discovered": "2026-07-26T17:59:45.066794+00:00",
"domain": "chappellsupply.com",
"group": "Global Secret Group",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T17:59:16",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/f43d4382cda7b85351ad974b843d2d60.png",
"url": "https:\/\/www.ransomware.live\/id\/Q2hhcHBlbGwgU3VwcGx5ICYgRXF1aXBtZW50QEdsb2JhbCBTZWNyZXQgR3JvdXA=",
"victim": "Chappell Supply & Equipment"
},
{
"activity": "Hospitality",
"attackdate": "2026-07-26T17:58:36.427819+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/11\/",
"country": "AR",
"data_size": null,
"description": "Country: Argentina |\nWebsite: lasevillanita.com |\nRevenue: $15 million |\nIndustry: Freight & Logistics Services,Transportation |\nEmployees: 11-50 |\nProperties: 200 GB (385,318 Files, 13,074 Folders)",
"discovered": "2026-07-26T17:58:56.724222+00:00",
"domain": "lasevillanita.com",
"group": "Global Secret Group",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 4,
"update": "2026-07-26T17:58:36",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/6b7cb8b2aba8fef592767ac2fe55b8c7.png",
"url": "https:\/\/www.ransomware.live\/id\/TGEgU2V2aWxsYW5pdGFAR2xvYmFsIFNlY3JldCBHcm91cA==",
"victim": "La Sevillanita"
},
{
"activity": "Financial Services",
"attackdate": "2026-07-26T17:57:58.625103+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/12\/",
"country": "CY",
"data_size": null,
"description": "Country: Cyprus |\nWebsite: onepluscapital.net |\nRevenue: $7 Million |\nIndustry: Finance |\nEmployees: 11-50 |\nProperties: 117 GB (285,919 Files, 32,404 Folders)",
"discovered": "2026-07-26T17:58:17.588544+00:00",
"domain": "onepluscapital.net",
"group": "Global Secret Group",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T17:57:58",
"users": 1,
"users_url": 1
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/fd0e5f5973886a0179b0c8daa99d547f.png",
"url": "https:\/\/www.ransomware.live\/id\/T25lIFBsdXMgQ2FwaXRhbEBHbG9iYWwgU2VjcmV0IEdyb3Vw",
"victim": "One Plus Capital"
},
{
"activity": "Technology",
"attackdate": "2026-07-26T17:57:04.832326+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/15\/",
"country": "ES",
"data_size": null,
"description": "Country: Spain |\nWebsite: acens.com |\nRevenue: $46.3 Million |\nIndustry: Hosting |\nEmployees: 201-500",
"discovered": "2026-07-26T17:57:39.723583+00:00",
"domain": "acens.com",
"group": "Global Secret Group",
"infostealer": {
"employees": 8,
"employees_url": 5,
"infostealer_stats": {
"Acreed": 13,
"Azorult": 36,
"CRYPTBOT": 3,
"Generic Stealer": 94,
"Lumma": 101,
"Raccoon": 79,
"RedLine": 132,
"StealC": 19,
"UNKNOWN": 1,
"Vidar": 17
},
"last_employee_compromised": "2024-06-06T13:06:38+00:00",
"last_user_compromised": "2026-07-22T07:05:27.782000+00:00",
"thirdparties": 23,
"update": "2026-07-26T17:57:04",
"users": 523,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/2b7abc5089e6e1651d088f22812aaa63.png",
"url": "https:\/\/www.ransomware.live\/id\/QWNlbnMgfCBDbG91ZCAmIEJhY2t1cEBHbG9iYWwgU2VjcmV0IEdyb3Vw",
"victim": "Acens | Cloud & Backup"
},
{
"activity": "Energy & Utilities",
"attackdate": "2026-07-26T17:56:28.064688+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/20\/",
"country": "CA",
"data_size": null,
"description": "Country: Canada |\nWebsite: westnovasuperline.ca |\nRevenue: $18.9 Million |\nIndustry: Convenience Stores, Gas Stations & Liquor Stores |\nEmployees: 51-200 |\nProperties: 45.8 GB (114,200 Files, 2,672 Folders)",
"discovered": "2026-07-26T17:56:45.625392+00:00",
"domain": "westnovasuperline.ca",
"group": "Global Secret Group",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T17:56:28",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/171d92b3d8321c9d5e555b12f1ae41f5.png",
"url": "https:\/\/www.ransomware.live\/id\/V2VzdCBOb3ZhIEZ1ZWxzICYgU3VwZXJsaW5lIEZ1ZWxzQEdsb2JhbCBTZWNyZXQgR3JvdXA=",
"victim": "West Nova Fuels & Superline Fuels"
},
{
"activity": "Energy & Utilities",
"attackdate": "2026-07-26T17:55:43.296769+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/23\/",
"country": "BR",
"data_size": null,
"description": "Country: Brazil |\nWebsite: sinopenergia.com.br |\nRevenue: $12.2 Million |\nIndustry: Electricity, Oil & Gas |\nEmployees: 51-200 |\nProperties:300 GB (43,113 Files, 5,372 Folders)",
"discovered": "2026-07-26T17:56:09.150350+00:00",
"domain": "sinopenergia.com.br",
"group": "Global Secret Group",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T17:55:43",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/cb8896f6ad81e7f42d05c59fe94c756e.png",
"url": "https:\/\/www.ransomware.live\/id\/U2lub3AgRW5lcmdpYUBHbG9iYWwgU2VjcmV0IEdyb3Vw",
"victim": "Sinop Energia"
},
{
"activity": "Retail & E-Commerce",
"attackdate": "2026-07-26T17:54:57.762892+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/25\/",
"country": "IQ",
"data_size": null,
"description": "Country: Iraq |\nWebsite: alhayatco.com |\nRevenue: $100 Million |\nIndustry: Food & Beverage |\nEmployees: 501-1,000 |\nProperties: 138 GB (205,992 Files, 17,178 Folders)",
"discovered": "2026-07-26T17:55:24.287847+00:00",
"domain": "alhayatco.com",
"group": "Global Secret Group",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T17:54:57",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/0a9c863a29ab9d8a50a0553d126c7efd.png",
"url": "https:\/\/www.ransomware.live\/id\/QWwgSGF5YXQgfCBQZXBzaUBHbG9iYWwgU2VjcmV0IEdyb3Vw",
"victim": "Al Hayat | Pepsi"
},
{
"activity": "Retail & E-Commerce",
"attackdate": "2026-07-26T17:53:23.289767+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/27\/",
"country": "US",
"data_size": null,
"description": "Country: New Jersey 07663, US |\nWebsite: nourison.com |\nRevenue: $59.4 Million |\nIndustry: Wholesale, Furniture, Home Decor, Retail, Real Estate |\nEmployees: 100-300 |\nProperties: 799 GB (93,941 Files, 13,733 Folders)",
"discovered": "2026-07-26T17:53:51.571348+00:00",
"domain": "nourison.com",
"group": "Global Secret Group",
"infostealer": {
"employees": 1,
"employees_url": 1,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T17:53:23",
"users": 14,
"users_url": 9
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/4ef84e36cdde90984cef6f5a42b09d14.png",
"url": "https:\/\/www.ransomware.live\/id\/Tm91cmlzb24gfCBIb21lQEdsb2JhbCBTZWNyZXQgR3JvdXA=",
"victim": "Nourison | Home"
},
{
"activity": "Retail & E-Commerce",
"attackdate": "2026-07-26T17:52:42.307690+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/3\/",
"country": "US",
"data_size": null,
"description": "Country: Colorado, United States |\nWebsite: coldfrontdist.com |\nRevenue: $120.1 Million |\nIndustry: Transportation |\nEmployees: 201-500 Employees |\nProperties: 473 GB (890,775 Files, 51,621 Folders)",
"discovered": "2026-07-26T17:53:04.308004+00:00",
"domain": "coldfrontdist.com",
"group": "Global Secret Group",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 1,
"update": "2026-07-26T17:52:42",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/59f24d7df2007cc0e537fb17b26e049c.png",
"url": "https:\/\/www.ransomware.live\/id\/Q29sZCBGcm9udCBEaXN0cmlidXRpb25AR2xvYmFsIFNlY3JldCBHcm91cA==",
"victim": "Cold Front Distribution"
},
{
"activity": "Financial Services",
"attackdate": "2026-07-26T17:51:49.911345+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/4\/",
"country": "GB",
"data_size": null,
"description": "Country: United Kingdom |\nWebsite: portmanfinancegroup.co.uk |\nRevenue: \u00a3300 Million |\nIndustry: Finance |\nEmployees: 1000-5000 Employees |\nProperties: 209 GB (255,244 Files, 34,852 Folders)",
"discovered": "2026-07-26T17:52:23.257564+00:00",
"domain": "portmanfinancegroup.co.uk",
"group": "Global Secret Group",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 2,
"update": "2026-07-26T17:51:49",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/076ee61758e0a3de40a9f8ab2d9e607f.png",
"url": "https:\/\/www.ransomware.live\/id\/UG9ydG1hbiBGaW5hbmNlIEdyb3VwQEdsb2JhbCBTZWNyZXQgR3JvdXA=",
"victim": "Portman Finance Group"
},
{
"activity": "Technology",
"attackdate": "2026-07-26T17:50:26.317523+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/8\/",
"country": "CN",
"data_size": null,
"description": "Country: China |\nWebsite: uniview.com |\nRevenue: $610 Million |\nIndustry: Manufacturing, Electronics |\nEmployees: 1000-5000 Employees |\nProperties: 1.5 TB (2,172,194 Files, 114,352 Folders)",
"discovered": "2026-07-26T17:50:50.629685+00:00",
"domain": "uniview.com",
"group": "Global Secret Group",
"infostealer": {
"employees": 8,
"employees_url": 5,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 14,
"update": "2026-07-26T17:35:07",
"users": 6887,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/3f6dc705ade87e0b7f1b3c064324fc6e.png",
"url": "https:\/\/www.ransomware.live\/id\/VW5pdmlldyBUZWNobm9sb2dpZXNAR2xvYmFsIFNlY3JldCBHcm91cA==",
"victim": "Uniview Technologies"
},
{
"activity": "Energy & Utilities",
"attackdate": "2026-07-26T17:47:18.567570+00:00",
"claim_url": "http:\/\/o5lsqyar7ox25z734k6zaxt2vf7bsyi4q5rturi5iyxzqo3ica7bjsad.onion\/project\/14\/",
"country": "US",
"data_size": null,
"description": "Country: Texas, United States |\nWebsite: novumenergy.com |\nRevenue: $966 Million |\nIndustry: Convenience Stores, Gas Stations & Liquor Stores |\nEmployees: 51-200 |\nProperties: 842 GB (971,325 Files, 117,085 Folders)",
"discovered": "2026-07-26T17:47:45.318676+00:00",
"domain": "novumenergy.com",
"group": "Global Secret Group",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T17:47:18",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/c0eb40bedf0ca40f1f8655ac9faf7f72.png",
"url": "https:\/\/www.ransomware.live\/id\/Tm92dW0gRW5lcmd5QEdsb2JhbCBTZWNyZXQgR3JvdXA=",
"victim": "Novum Energy"
},
{
"activity": "Healthcare",
"attackdate": "2026-07-26T17:14:21.204913+00:00",
"claim_url": "http:\/\/z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion\/blog\/?post_uuid=23ed9672-4fc8-4c75-ba59-f6e5d34941e2",
"country": "US",
"data_size": null,
"description": "Deluxe Medical Supply is a distributor of healthcare supplies that focuses on delivering quality home healthcare products and services. They provide a wide range of medical equipment, including mobility aids, incontinence supplies, and compression therapy garments, aimed at restoring independence and confidence for their clients. Their knowledgeable staff is dedicated to offering fast and efficient service to both patients and medical professionals. The company intends to serve individuals needing home healthcare solutions while ensuring affordable options and high-quality products.",
"discovered": "2026-07-26T17:22:30.292234+00:00",
"domain": "deluxemedical.com",
"group": "dragonforce",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T17:22:00",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/daedfdc02171bf98f2c68412bc6299cd.png",
"url": "https:\/\/www.ransomware.live\/id\/RGVsdXhlIE1lZGljYWwgU3VwcGx5QGRyYWdvbmZvcmNl",
"victim": "Deluxe Medical Supply"
},
{
"activity": "Professional Services",
"attackdate": "2026-07-26T14:58:02.318080+00:00",
"claim_url": "http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=c80be6d9-9f48-4983-8d7d-a66e4387bdac",
"country": "MX",
"data_size": null,
"description": "N\/A",
"discovered": "2026-07-26T14:58:27.528259+00:00",
"domain": "www.contactogarantido.com",
"group": "qilin",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/8f269fa9a811c666a71b25a8aaf3ecf6.png",
"url": "https:\/\/www.ransomware.live\/id\/Q29udGFjdG8gR2FyYW50aWRvQHFpbGlu",
"victim": "Contacto Garantido"
},
{
"activity": "Education",
"attackdate": "2026-07-26T14:29:30.902340+00:00",
"claim_url": "http:\/\/ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion\/site\/blog?uuid=1f231bbf-689b-4a64-be81-ee0b50e736ba",
"country": "RO",
"data_size": null,
"description": "N\/A",
"discovered": "2026-07-26T14:29:53.747725+00:00",
"domain": "www.uvvg.ro",
"group": "qilin",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/a33b19d88bcaf434040d952aae2d3323.png",
"url": "https:\/\/www.ransomware.live\/id\/VW5pdmVyc2l0YXRlYSBkZSBWZXN0IOKAnlZhc2lsZSBHb2xkaciZ4oCdIGRpbiBBcmFkQHFpbGlu",
"victim": "Universitatea de Vest \u201eVasile Goldi\u0219\u201d din Arad"
},
{
"activity": "Manufacturing",
"attackdate": "2026-07-26T11:28:10.440235+00:00",
"claim_url": "http:\/\/4k6plf4h2cm2nco6ae3inrsxnmqgl6lllmwefydhnlcq4tuhwbj4qpad.onion#hydraulic-components.net",
"country": "DE",
"data_size": null,
"description": "+44 1142764430 , VHS Hydraulics is a prominent supplier of hydraulic components and power packs, featuring products from renowned brands like Rexroth, Walvoil, and Casappa. With over 25 years of experience, they specialize in engineering bespoke power packs for demanding applications. Based in Sheffield, they offer extensive stock and provide same-day and next-day delivery services across the UK. Their team is equipped to assist clients with both individual components and complete hydraulic system solutions tailored to specific requirements. Stolen: 215 GB 226,961 Files",
"discovered": "2026-07-26T11:28:39.760589+00:00",
"domain": "hydraulic-components.net",
"group": "m3rx",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T11:28:10",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/11c1af7f6d37617568978c70c84d4e17.png",
"url": "https:\/\/www.ransomware.live\/id\/aHlkcmF1bGljLWNvbXBvbmVudHMubmV0QG0zcng=",
"victim": "hydraulic-components.net"
},
{
"activity": "Professional Services",
"attackdate": "2026-07-26T11:27:22.278181+00:00",
"claim_url": "http:\/\/4k6plf4h2cm2nco6ae3inrsxnmqgl6lllmwefydhnlcq4tuhwbj4qpad.onion#createinfor.pt",
"country": "PT",
"data_size": null,
"description": "+351 262187684 , CreateInfor is a company that operates in the Repair Services industry. It employs 10to19 people and has 500Kto1M of revenue. The company is headquartered in Caldas da Rainha, Leiria, Portugal. Stolen: --",
"discovered": "2026-07-26T11:27:51.221318+00:00",
"domain": "createinfor.pt",
"group": "m3rx",
"infostealer": {
"employees": 2,
"employees_url": 10,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T11:27:22",
"users": 1,
"users_url": 4
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/5abccc54b4e7426c9ac4befabd66611d.png",
"url": "https:\/\/www.ransomware.live\/id\/Y3JlYXRlaW5mb3IucHRAbTNyeA==",
"victim": "createinfor.pt"
},
{
"activity": "Professional Services",
"attackdate": "2026-07-26T11:26:31.749822+00:00",
"claim_url": "http:\/\/4k6plf4h2cm2nco6ae3inrsxnmqgl6lllmwefydhnlcq4tuhwbj4qpad.onion#servicebypremier.com",
"country": "US",
"data_size": null,
"description": "+1(954) 646-0016 , This local HVAC and Refrigeration company, established in 2007, provides services across South Florida, from Florida City to Port St. Lucie. They specialize in commercial HVAC and refrigeration repairs, including maintenance for A\/C and refrigeration equipment. The company prides itself on delivering honest service at reasonable prices, ensuring complete customer satisfaction. Their commitment to integrity and efficiency makes them a trusted choice for businesses in the region. Stolen: --",
"discovered": "2026-07-26T11:27:00.921115+00:00",
"domain": "servicebypremier.com",
"group": "m3rx",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T11:26:31",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/c3254af95301fca4d3848fbb035343ab.png",
"url": "https:\/\/www.ransomware.live\/id\/c2VydmljZWJ5cHJlbWllci5jb21AbTNyeA==",
"victim": "servicebypremier.com"
},
{
"activity": "Technology",
"attackdate": "2026-07-26T10:26:23.803003+00:00",
"claim_url": "",
"country": "US",
"data_size": null,
"description": "Revenue: $12.7B\n\nDATA SUMMARY:\n570K~ records containing: customer PII and addresses.",
"discovered": "2026-07-26T10:26:24.968894+00:00",
"domain": "analog.com",
"group": "ExfilSquad",
"infostealer": {
"employees": 280,
"employees_url": 51,
"infostealer_stats": {
"Acreed": 7,
"Atomic": 1,
"Azorult": 74,
"CRYPTBOT": 11,
"DarkCrystal": 4,
"Generic Stealer": 485,
"KPOT": 1,
"Lumma": 438,
"Mystic": 2,
"Predator": 3,
"Raccoon": 208,
"RedLine": 686,
"StealC": 91,
"Taurus": 2,
"UNKNOWN": 29,
"Vidar": 68
},
"last_employee_compromised": "2026-07-11T16:21:31+00:00",
"last_user_compromised": "2026-07-25T18:19:26.745000+00:00",
"thirdparties": 92,
"update": "2026-07-26T10:55:10.482053",
"users": 2321,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/QW5hbG9nIERldmljZXNARXhmaWxTcXVhZA==",
"victim": "Analog Devices"
},
{
"activity": "Manufacturing",
"attackdate": "2026-07-26T10:26:04.810582+00:00",
"claim_url": "",
"country": "SE",
"data_size": null,
"description": "Revenue: SEK 8B\n\nDATA SUMMARY:\n842K~ records containing: significant PII, property ownership\/interests, warranty and repair cases, contractor information, marketing preferences, and customer service history.",
"discovered": "2026-07-26T10:26:05.509472+00:00",
"domain": "bonava.se",
"group": "ExfilSquad",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T10:55:48.909047",
"users": 21,
"users_url": 4
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/Qm9uYXZhQEV4ZmlsU3F1YWQ=",
"victim": "Bonava"
},
{
"activity": "Government & Defense",
"attackdate": "2026-07-26T10:25:45.931180+00:00",
"claim_url": "",
"country": "US",
"data_size": null,
"description": "DATA SUMMARY:\n3M~ records containing: significant PII, citizen service requests, addresses, municipal case history, and internal case management data.",
"discovered": "2026-07-26T10:25:46.597126+00:00",
"domain": "atlantaga.gov",
"group": "ExfilSquad",
"infostealer": {
"employees": 3,
"employees_url": 3,
"infostealer_stats": {
"Acreed": 1,
"Azorult": 2,
"Generic Stealer": 4,
"Lumma": 4,
"RedLine": 4
},
"last_employee_compromised": "2026-01-24T00:28:00+00:00",
"last_user_compromised": "2026-05-05T06:36:46+00:00",
"thirdparties": 28,
"update": "2026-07-26T10:25:45",
"users": 19,
"users_url": 16
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/Q2l0eSBvZiBBdGxhbnRhQEV4ZmlsU3F1YWQ=",
"victim": "City of Atlanta"
},
{
"activity": "Government & Defense",
"attackdate": "2026-07-26T10:25:25.813727+00:00",
"claim_url": "",
"country": "US",
"data_size": null,
"description": "DATA SUMMARY:\n6M~ records containing: significant PII, resident contact details, service requests, complaint descriptions, addresses, location data, case\/ticket metadata, department routing, service status, resolution information, and extensive CRM metadata.",
"discovered": "2026-07-26T10:25:26.605303+00:00",
"domain": "houstontx.gov",
"group": "ExfilSquad",
"infostealer": {
"employees": 18,
"employees_url": 10,
"infostealer_stats": {
"Acreed": 3,
"Azorult": 72,
"DarkCrystal": 1,
"Generic Stealer": 186,
"Lumma": 127,
"Raccoon": 57,
"RedLine": 162,
"StealC": 8,
"Taurus": 1,
"UNKNOWN": 12,
"Vidar": 15
},
"last_employee_compromised": "2026-06-08T11:58:10+00:00",
"last_user_compromised": "2026-07-17T00:00:00+00:00",
"thirdparties": 29,
"update": "2026-07-26T10:25:25",
"users": 721,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/Q2l0eSBvZiBIb3VzdG9uQEV4ZmlsU3F1YWQ=",
"victim": "City of Houston"
},
{
"activity": "Technology",
"attackdate": "2026-07-26T10:25:05.581456+00:00",
"claim_url": "",
"country": "US",
"data_size": null,
"description": "Revenue: $1B\n\nDATA SUMMARY:\n430K~ records containing: customer and partner contact information, significant PII, and enterprise account identifiers.",
"discovered": "2026-07-26T10:25:06.535633+00:00",
"domain": "viavisolutions.com",
"group": "ExfilSquad",
"infostealer": {
"employees": 30,
"employees_url": 10,
"infostealer_stats": {
"Acreed": 1,
"Azorult": 7,
"DarkCrystal": 1,
"Generic Stealer": 57,
"Lumma": 46,
"Raccoon": 24,
"RedLine": 76,
"StealC": 20,
"UNKNOWN": 6,
"Vidar": 5
},
"last_employee_compromised": "2026-04-27T17:19:24+00:00",
"last_user_compromised": "2026-07-18T00:00:00+00:00",
"thirdparties": 31,
"update": "2026-07-26T10:56:23.947219",
"users": 255,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/VmlhdmkgU29sdXRpb25zQEV4ZmlsU3F1YWQ=",
"victim": "Viavi Solutions"
},
{
"activity": "Education",
"attackdate": "2026-07-26T10:24:46.923388+00:00",
"claim_url": "",
"country": "GB",
"data_size": null,
"description": "DATA SUMMARY:\n440K~ records containing: applicant and student contact information, significant PII, and admissions data.",
"discovered": "2026-07-26T10:24:47.510324+00:00",
"domain": "ncl.ac.uk",
"group": "ExfilSquad",
"infostealer": {
"employees": 192,
"employees_url": 21,
"infostealer_stats": {
"Acreed": 10,
"Atomic": 1,
"Azorult": 78,
"CRYPTBOT": 5,
"Generic Stealer": 403,
"Lumma": 393,
"Mystic": 4,
"Predator": 2,
"Raccoon": 219,
"RedLine": 547,
"StealC": 95,
"Taurus": 1,
"UNKNOWN": 25,
"Vidar": 55
},
"last_employee_compromised": "2026-07-02T14:39:49+00:00",
"last_user_compromised": "2026-07-25T00:00:00+00:00",
"thirdparties": 78,
"update": "2026-07-26T10:24:46",
"users": 1799,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/TmV3Y2FzdGxlIFVuaXZlcnNpdHlARXhmaWxTcXVhZA==",
"victim": "Newcastle University"
},
{
"activity": "Education",
"attackdate": "2026-07-26T10:24:23.355370+00:00",
"claim_url": "",
"country": "US",
"data_size": null,
"description": "[AI generated] District of Columbia Public Schools (DCPS) is a public school district serving Washington, D.C., USA. It operates as the primary government-run K-12 educational system for the nation's capital, overseeing dozens of schools, thousands of students, and a large workforce of educators and administrators. DCPS falls under the education sector and is governed by the D.C. government, focusing on curriculum development, student achievement, and community engagement.",
"discovered": "2026-07-26T10:24:27.530153+00:00",
"domain": "dcps.dc.gov",
"group": "ExfilSquad",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T10:24:23",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/RGlzdHJpY3Qgb2YgQ29sdW1iaWEgUHVibGljIFNjaG9vbHNARXhmaWxTcXVhZA==",
"victim": "District of Columbia Public Schools"
},
{
"activity": "Financial Services",
"attackdate": "2026-07-26T10:24:03.679632+00:00",
"claim_url": "",
"country": "NG",
"data_size": null,
"description": "Revenue: \u20a62.3T\n\nDATA SUMMARY:\n90M~ records containing: extensive PII, banking relationships, account information, financial data, government identifiers, customer contact information, and banking support cases.",
"discovered": "2026-07-26T10:24:04.547097+00:00",
"domain": "zenithbank.com",
"group": "ExfilSquad",
"infostealer": {
"employees": 37,
"employees_url": 11,
"infostealer_stats": {
"Acreed": 14,
"Atomic": 8,
"Azorult": 61,
"CRYPTBOT": 2,
"DarkCrystal": 5,
"Ficker": 5,
"Generic Stealer": 1076,
"Lumma": 1408,
"Mystic": 17,
"Predator": 5,
"Raccoon": 515,
"RedLine": 1803,
"StealC": 234,
"Taurus": 1,
"UNKNOWN": 86,
"Vidar": 180
},
"last_employee_compromised": "2026-06-07T03:24:27+00:00",
"last_user_compromised": "2026-07-25T17:49:52.237000+00:00",
"thirdparties": 122,
"update": "2026-07-26T10:56:40.336946",
"users": 5897,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/WmVuaXRoIEJhbmsgUGxjQEV4ZmlsU3F1YWQ=",
"victim": "Zenith Bank Plc"
},
{
"activity": "Transportation",
"attackdate": "2026-07-26T10:23:44.978064+00:00",
"claim_url": "",
"country": "US",
"data_size": null,
"description": "Revenue: $1.5B\n\nDATA SUMMARY:\n2.4M~ records containing: significant PII, customer support cases, flight and travel information, complaint records, baggage details, and customer support email communications.",
"discovered": "2026-07-26T10:23:45.609462+00:00",
"domain": "flyfrontier.com",
"group": "ExfilSquad",
"infostealer": {
"employees": 5,
"employees_url": 3,
"infostealer_stats": {
"Acreed": 59,
"Atomic": 18,
"Azorult": 757,
"CRYPTBOT": 11,
"Generic Stealer": 2261,
"Lumma": 1774,
"Mystic": 2,
"Raccoon": 443,
"RedLine": 1983,
"StealC": 161,
"Taurus": 1,
"UNKNOWN": 99,
"Vidar": 259
},
"last_employee_compromised": "2025-07-05T06:19:00+00:00",
"last_user_compromised": "2026-07-25T18:20:19.308000+00:00",
"thirdparties": 13,
"update": "2026-07-26T10:56:51.263840",
"users": 10002,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/RnJvbnRpZXIgQWlybGluZXNARXhmaWxTcXVhZA==",
"victim": "Frontier Airlines"
},
{
"activity": "Retail & E-Commerce",
"attackdate": "2026-07-26T10:23:25.579967+00:00",
"claim_url": "",
"country": "US",
"data_size": null,
"description": "Revenue: $1.5B\n\nDATA SUMMARY:\n2M~ records containing: significant PII, customer support history, orders, shipping information, business account data, financial\/account information, internal notes, attachments, and AI support chat transcripts.",
"discovered": "2026-07-26T10:23:26.744697+00:00",
"domain": "taylormadegolf.com",
"group": "ExfilSquad",
"infostealer": {
"employees": 3,
"employees_url": 6,
"infostealer_stats": {
"Azorult": 25,
"DarkCrystal": 1,
"Generic Stealer": 100,
"Lumma": 73,
"Mystic": 2,
"Raccoon": 22,
"RedLine": 95,
"StealC": 22,
"UNKNOWN": 3,
"Vidar": 7
},
"last_employee_compromised": "2023-05-05T00:15:02+00:00",
"last_user_compromised": "2026-07-23T08:38:13.622000+00:00",
"thirdparties": 9,
"update": "2026-07-26T10:57:14.996165",
"users": 436,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/VGF5bG9yTWFkZSAmIFN1biBEYXkgUmVkIGdvbGZARXhmaWxTcXVhZA==",
"victim": "TaylorMade & Sun Day Red golf"
},
{
"activity": "Financial Services",
"attackdate": "2026-07-26T10:23:06.848734+00:00",
"claim_url": "",
"country": "US",
"data_size": null,
"description": "Revenue: $67B\n\nDATA SUMMARY:\n657K~ records containing: significant PII, recruitment and licensing information, onboarding data, and internal employee account information.",
"discovered": "2026-07-26T10:23:07.482882+00:00",
"domain": "allstate.com",
"group": "ExfilSquad",
"infostealer": {
"employees": 105,
"employees_url": 24,
"infostealer_stats": {
"Acreed": 94,
"Atomic": 36,
"Azorult": 1689,
"CRYPTBOT": 9,
"DarkCrystal": 3,
"Generic Stealer": 4323,
"Lumma": 2793,
"Mystic": 5,
"Raccoon": 858,
"RedLine": 3793,
"StealC": 197,
"Taurus": 13,
"UNKNOWN": 247,
"Vidar": 498
},
"last_employee_compromised": "2026-07-10T22:01:04.953000+00:00",
"last_user_compromised": "2026-07-25T18:20:40.568000+00:00",
"thirdparties": 278,
"update": "2026-07-26T10:57:45.135721",
"users": 17990,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/QWxsc3RhdGVARXhmaWxTcXVhZA==",
"victim": "Allstate"
},
{
"activity": "Technology",
"attackdate": "2026-07-26T10:22:48.109331+00:00",
"claim_url": "",
"country": "US",
"data_size": null,
"description": "Revenue: $318B\n\nDATA SUMMARY:\n8M~ records containing: significant PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions.",
"discovered": "2026-07-26T10:22:48.693353+00:00",
"domain": "microsoft.com",
"group": "ExfilSquad",
"infostealer": {
"employees": 15870,
"employees_url": 100,
"infostealer_stats": {
"Atomic": 15,
"Azorult": 1107,
"CRYPTBOT": 223,
"Ficker": 57,
"Generic Stealer": 1098,
"KPOT": 10,
"Lumma": 6070,
"Mystic": 185,
"Predator": 36,
"Raccoon": 8361,
"RedLine": 28336,
"StealC": 480,
"Taurus": 46,
"UNKNOWN": 1242,
"Vidar": 2734
},
"last_employee_compromised": "2026-07-25T17:50:09.207000+00:00",
"last_user_compromised": "2026-07-25T18:56:16.427000+00:00",
"thirdparties": 4491,
"update": "2026-07-26T10:58:19.706770",
"users": 570284,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/TWljcm9zb2Z0QEV4ZmlsU3F1YWQ=",
"victim": "Microsoft"
},
{
"activity": "Government & Defense",
"attackdate": "2026-07-26T10:22:29.309550+00:00",
"claim_url": "",
"country": "GB",
"data_size": null,
"description": "DATA SUMMARY:\n135k law enforcement contact records with first\/last name, email, police force area, etc.",
"discovered": "2026-07-26T10:22:29.999838+00:00",
"domain": "",
"group": "ExfilSquad",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/UG9saWNlIE5hdGlvbmFsIExlZ2FsIERhdGFiYXNlQEV4ZmlsU3F1YWQ=",
"victim": "Police National Legal Database"
},
{
"activity": "Government & Defense",
"attackdate": "2026-07-26T10:22:09.661008+00:00",
"claim_url": "",
"country": "GB",
"data_size": null,
"description": "DATA SUMMARY:\nHelp Portal (~600K records) \u2013 Parent and staff contact records containing full names, email addresses, phone numbers, and job titles. \n\nTuring Portal (~7K records) \u2013 Contact records containing full names, email addresses, phone numbers, and job titles.",
"discovered": "2026-07-26T10:22:11.079582+00:00",
"domain": "education.gov.uk",
"group": "ExfilSquad",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 18,
"update": "2026-07-26T10:22:09",
"users": 1165,
"users_url": 100
},
"press": null,
"ransom": null,
"screenshot": "",
"url": "https:\/\/www.ransomware.live\/id\/VUsgRGVwYXJ0bWVudCBmb3IgRWR1Y2F0aW9uQEV4ZmlsU3F1YWQ=",
"victim": "UK Department for Education"
},
{
"activity": "Professional Services",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/genesis6ixpb5mcy4kudybtw5op2wqlrkocfogbnenz3c647ibqixiad.onion\/e1ce50a6e22290f40df6\/",
"country": "CA",
"data_size": null,
"description": "A full service CPA firm",
"discovered": "2026-07-26T23:27:19.013249+00:00",
"domain": "bramptondirect.ca",
"group": "genesis",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T23:27:02",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/3f94886f3d6592e8a3771392e5d1e94f.png",
"url": "https:\/\/www.ransomware.live\/id\/V2lsbGlhbXMgQWNjb3VudGluZyBQcm9mZXNzaW9uYWxAZ2VuZXNpcw==",
"victim": "Williams Accounting Professional"
},
{
"activity": "Manufacturing",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/genesis6ixpb5mcy4kudybtw5op2wqlrkocfogbnenz3c647ibqixiad.onion\/c69e194c2dc7ab12ef4e\/",
"country": "US",
"data_size": null,
"description": "A company that operates in the Restaurants industry",
"discovered": "2026-07-26T23:26:41.885240+00:00",
"domain": "",
"group": "genesis",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/efe233d8378043d1fac6157bf663ea2e.png",
"url": "https:\/\/www.ransomware.live\/id\/SkpQIFNsaXAgRm9ybWluZyBJbmMuQGdlbmVzaXM=",
"victim": "JJP Slip Forming Inc."
},
{
"activity": "Manufacturing",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/genesis6ixpb5mcy4kudybtw5op2wqlrkocfogbnenz3c647ibqixiad.onion\/960b5c42eb664129c99d\/",
"country": "US",
"data_size": null,
"description": "A reputable construction company based in Plainville, MA",
"discovered": "2026-07-26T23:26:05.785116+00:00",
"domain": "infinitypipeinc.com",
"group": "genesis",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T23:25:49",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/8c89325bed25dc7984e86dc7d080f337.png",
"url": "https:\/\/www.ransomware.live\/id\/QnVpbGRpbmcgRW52ZWxvcGUgU3lzdGVtc0BnZW5lc2lz",
"victim": "Building Envelope Systems"
},
{
"activity": "Retail & E-Commerce",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/genesis6ixpb5mcy4kudybtw5op2wqlrkocfogbnenz3c647ibqixiad.onion\/8bac6cf38a5a125166bd\/",
"country": "US",
"data_size": null,
"description": "A full-service real estate development company",
"discovered": "2026-07-26T23:25:30.132048+00:00",
"domain": "westlake-realty.com",
"group": "genesis",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T23:25:13",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/73acbff4034d53a13c6dfb3ef6aa55a5.png",
"url": "https:\/\/www.ransomware.live\/id\/V2VzdGxha2UgUmVhbHR5IEdyb3VwLCBJbmMuQGdlbmVzaXM=",
"victim": "Westlake Realty Group, Inc."
},
{
"activity": "Not Found",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/genesis6ixpb5mcy4kudybtw5op2wqlrkocfogbnenz3c647ibqixiad.onion\/326fec030728fd03a27f\/",
"country": "US",
"data_size": null,
"description": "A provider of IT services",
"discovered": "2026-07-26T23:24:35.722903+00:00",
"domain": "servonix.com",
"group": "genesis",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T23:24:19",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/bd826ba5745879c913ee3536311e1cd1.png",
"url": "https:\/\/www.ransomware.live\/id\/U2Vydm9uaXggVGVjaG5vbG9naWVzQGdlbmVzaXM=",
"victim": "Servonix Technologies"
},
{
"activity": "Energy & Utilities",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/genesis6ixpb5mcy4kudybtw5op2wqlrkocfogbnenz3c647ibqixiad.onion\/30e4ada54a4c7c042993\/",
"country": "US",
"data_size": null,
"description": "A family owned, local construction company.",
"discovered": "2026-07-26T23:23:58.660369+00:00",
"domain": "infinitypipeinc.com",
"group": "genesis",
"infostealer": {
"employees": 0,
"employees_url": 0,
"infostealer_stats": [],
"last_employee_compromised": null,
"last_user_compromised": null,
"thirdparties": 0,
"update": "2026-07-26T23:25:49",
"users": 0,
"users_url": 0
},
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/cd604534e9ecb245fbffab0ce7bdcaf9.png",
"url": "https:\/\/www.ransomware.live\/id\/SW5maW5pdHkgUGlwZWxpbmUsSW5jLkBnZW5lc2lz",
"victim": "Infinity Pipeline,Inc."
},
{
"activity": "Education",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/ed0baaeda35ff4f2",
"country": "PT",
"data_size": null,
"description": "UNIVERSITY",
"discovered": "2026-07-26T18:58:14.116989+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/ee753506accc5430be4d1203549a00ae.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKiouY29tLnB0QFNlY3Rpb245",
"victim": "*****.com.pt"
},
{
"activity": "Agriculture and Food Production",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/8a803504aab72fad",
"country": "UY",
"data_size": null,
"description": "FOOD & SERVICES",
"discovered": "2026-07-26T18:57:43.492283+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/af945b11a471876f43c20eed7e2df17e.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKioqKiouY29tLnV5QFNlY3Rpb245",
"victim": "********.com.uy"
},
{
"activity": "Retail & E-Commerce",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/aee038ac936b0bd3",
"country": "FR",
"data_size": null,
"description": "RETAIL",
"discovered": "2026-07-26T18:57:12.559177+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/4a5e06e6d31878e0da898a3ab831b582.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKi5mckBTZWN0aW9uOQ==",
"victim": "****.fr"
},
{
"activity": "Other",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/16bea0d49cf9e15c",
"country": "US",
"data_size": null,
"description": "NEWS",
"discovered": "2026-07-26T18:56:40.572237+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/b3ed52b91f9cc0ea8f219e8c21a9b66d.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKioqKiouY29tQFNlY3Rpb245",
"victim": "********.com"
},
{
"activity": "Healthcare",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/f6d5aae7716da9e1",
"country": "SE",
"data_size": null,
"description": "HEALTHCARE",
"discovered": "2026-07-26T18:56:10.020857+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/36c6f132c8757b114d8cfb5aa489a2a5.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKioqLmNvbS5zZUBTZWN0aW9uOQ==",
"victim": "******.com.se"
},
{
"activity": "Technology",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/9964536de9f48338",
"country": "US",
"data_size": null,
"description": "CYBERSECURITY",
"discovered": "2026-07-26T18:55:36.097723+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/0ad04bccb7eaf18b021ba0d92cd655a4.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKioqLmNvbUBTZWN0aW9uOQ==",
"victim": "******.com"
},
{
"activity": "Hospitality",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/4beecf86af9ead43",
"country": "MC",
"data_size": null,
"description": "TRAVEL & TOURISM",
"discovered": "2026-07-26T18:55:02.042890+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/52bc683664b9df321b67cd82b947a325.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKi5jb20ubWNAU2VjdGlvbjk=",
"victim": "****.com.mc"
},
{
"activity": "Agriculture and Food Production",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/09235e0d215914d3",
"country": "BR",
"data_size": null,
"description": "AGRICULTURE",
"discovered": "2026-07-26T18:54:30.309728+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/e58271f7e2e117f114a465b1400e4c8a.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKiouaW5kLmJyQFNlY3Rpb245",
"victim": "*****.ind.br"
},
{
"activity": "Technology",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/fc6f4c0c2350ca19",
"country": "",
"data_size": null,
"description": "CYBERSECURITY",
"discovered": "2026-07-26T18:53:59.808712+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/baaf56387e5ec9db3298328e15e65793.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKioqKioqKkBTZWN0aW9uOQ==",
"victim": "**********"
},
{
"activity": "Financial Services",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/064f028765a78e2d",
"country": "BR",
"data_size": null,
"description": "FINTECH",
"discovered": "2026-07-26T18:53:27.158367+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/281c8281af634cd1fed8c144d4fa3205.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKiouY29tLmJyQFNlY3Rpb245",
"victim": "*****.com.br"
},
{
"activity": "Technology",
"attackdate": "2026-07-26T00:00:00+00:00",
"claim_url": "http:\/\/v76bdil3v7hczufr7kwk75eq6oks27d3qwj6v5ajj6v6rubbvwhcq2qd.onion\/post\/5f127795e8742eca",
"country": "BR",
"data_size": null,
"description": "TELECOM",
"discovered": "2026-07-26T18:52:56.141837+00:00",
"domain": "",
"group": "Section9",
"infostealer": "",
"press": null,
"ransom": null,
"screenshot": "https:\/\/images.ransomware.live\/victims\/6b3a38bc9c02393fc18945c178083ab1.png",
"url": "https:\/\/www.ransomware.live\/id\/KioqKi5jb20uYnJAU2VjdGlvbjk=",
"victim": "****.com.br"
}
]





