Ransomware Group intelligence
Akira
ActiveTrack Akira with 1676 published victims and 2 known leak locations in a single intelligence view.
Overview
Akira is tracked by Breach House as a ransomware group with 1676 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 20m ago | akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion |
| Leak location 1 | Onion service | Down checked 21m ago | akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion |
Top Activity Sectors (18)
- Finance / Legal / Insurance 426
- Communication / Marketing 320
- Manufacturing / Engineering 170
- Services 128
- Construction / Real Estate 105
- Not identified 75
- Healthcare / Pharma 66
- IT 64
- Energy 39
- Hospitality / Food & Beverage / Tourism 32
- Transportation / Travel / Logistics 32
- Agriculture / Food 31
- Retail / E-commerce 27
- Telecommunications 27
- Education 25
- Public Sector 16
- NGOs / Associations 5
- null 1
Typical Attacks (29)
▼How Akira typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Akira, Akira, Akira _v2.
-
What they do: Akira uses valid account information to remotely access victim networks, such as VPN credentials.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Akira uses compromised VPN accounts for initial access to victim networks.
What that means: Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
-
T1047 Windows Management Instrumentation Execution
What they do: Akira will leverage COM objects accessed through WMI during execution to evade detection.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: Akira has used PowerShell scripts for credential harvesting and privilege escalation.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Akira executes from the Windows command line and can take various arguments for execution.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Akira executes native Windows functions such as GetFileAttributesW and `GetSystemInfo`.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Akira _v2 can create a child process for encryption.
What that means: Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence.
-
T1027.001 Binary Padding Stealth
What they do: Akira has used binary padding to obfuscate payloads.
What that means: Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Akira has used legitimate names and locations for files to evade defenses.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1480 Execution Guardrails Stealth
What they do: Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Akira has disabled or modified security tools for defense evasion.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1558 Steal or Forge Kerberos Tickets Credential Access
What they do: Akira have used scripts to dump Kerberos authentication credentials.
What that means: Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket.
-
T1018 Remote System Discovery Discovery
What they do: Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: Akira uses the GetSystemInfo Windows function to determine the number of processors on a victim machine.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Akira can identify remote file shares for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1482 Domain Trust Discovery Discovery
What they do: Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments.
What that means: Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
-
T1654 Log Enumeration Discovery
What they do: Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems.
What that means: Adversaries may enumerate system and service logs to find useful data.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Akira has used RDP for lateral movement.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1213.002 Sharepoint Collection
What they do: Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.
What that means: Adversaries may leverage the SharePoint repository as a source to mine valuable information.
-
T1560.001 Archive via Utility Collection
What they do: Akira uses utilities such as WinRAR to archive data prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1219 Remote Access Tools Command and Control
What they do: Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: Akira will exfiltrate victim data using applications such as Rclone.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Akira encrypts files in victim environments as part of ransomware operations.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Akira _v2 can stop running virtual machines.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Akira will delete system volume shadow copies via PowerShell commands.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1531 Account Access Removal Impact
What they do: Akira deletes administrator accounts in victim networks prior to encryption.
What that means: Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
-
T1657 Financial Theft Impact
What they do: Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (41)
▼Software Akira has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (15)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1qr0pqfghr9cksfc5arr2rak3lt2y50v03pc76nh |
bitcoin | $997,461 | 2 |
bc1qfdzu6uv2nek524pe7lz4w0mxtt9898vfaegdaj |
bitcoin | $482,181 | 1 |
bc1q0dx45y82r5rt36sm38jv0k4dexwc4nj9z4ryw7 |
bitcoin | $446,073 | 2 |
bc1q9wnp6k7xxdqkdv4fa5ceyhv08espuskhu8ghq2 |
bitcoin | $351,883 | 1 |
bc1qknumj4326runqxfr58kg0s7v7gu9y5v5t9uv6h |
bitcoin | $298,537 | 2 |
bc1qr0txunr259we37wer7w6et33qyq0n6hv83pw24 |
bitcoin | $252,389 | 1 |
bc1q0lwpz2yufw3x9as6f679lwk8jx43g44683x5mc |
bitcoin | $229,395 | 4 |
bc1qhzd63mz9mfucak7yzfn65p6rcsgztnsqr3dak8 |
bitcoin | $150,205 | 1 |
bc1qqrsd02sqthm8gej8lfesgpx82saw7q2g5pjtah |
bitcoin | $149,891 | 1 |
bc1q4my6vqq8cg689drf9jccqudjclv67sz4cudkyd |
bitcoin | $139,534 | 1 |
bc1qpwwtck0zhzrj56fxeayz6wz5546nlp607qzpvh |
bitcoin | $109,655 | 2 |
bc1qghj85gz0dkr9jeucana3z4xu50ujtllj50rvj0 |
bitcoin | $106,115 | 2 |
+3 more wallets not shown (the 12 largest by amount received are listed).
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
akira_readme_3.txt
Hi friends, Whatever who you are and what your title is, if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. ATTENTION! Strictly prohibited: - Deleting files with .arika extension; - Replacing or renaming .arika and .akira files; - Using third party software to recover your systems. If you violate these rules, we cannot guarantee a successful recovery. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining you financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of the deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidentally corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and use in order to get into, identify backup solutions and download your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at once. Then all of this will be published in our blog - akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad[.]onion. 5. We're more than negotiable and will definitely find a way to settle this quickly and reach an agreement which will satisfy both of us. 6. Negotiations with Akira can only be conducted in a chat room, which you can access using the login details provided below or in the notes (a readme.txt file) in your systems. You should ignore any attempts (such as emails/social media messages, phone calls, etc.) to redirect you to another chat or email address (proton.me is often used by unauthorized individuals) on our behalf. 7. Be careful while working with recovery agencies as they often try to use your cyber incident to stuff their pockets. There are many risks for you to lose money and get nothing in return. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - torproject[.]org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion/d/[snip] . 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
akira_readme_2.txt
Hi friends, Whatever who you are and what your title is, if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. ATTENTION! Strictly prohibited: - Deleting files with .arika extension; - Replacing or renaming .arika and .akira files; - Using third party software to recover your systems. If you violate these rules, we cannot guarantee a successful recovery. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining you financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of the deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidentally corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and use in order to get into, identify backup solutions and download your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at once. Then all of this will be published in our blog - akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad[.]onion. 5. We're more than negotiable and will definitely find a way to settle this quickly and reach an agreement which will satisfy both of us. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - torproject[.]org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion/d/[snip] . 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
akira_readme.txt
Hi friends, Whatever who you are and what your title is if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining your financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of a deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidently corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of a great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and used in order to get into, identify backup solutions and upload your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at ones. Then all of this will be published in our blog - https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion. 5. We're more than negotiable and will definitely find the way to settle this quickly and reach an agreement which will satisfy both of us. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - https://www.torproject.org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion. 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1676)
Search, filter and paginate the victim timeline for Akira. Showing 1101–1200 of 1676.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | mipa.com.br id17200 View details | Brazil | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | usm-americas.com id17199 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | feheq.com id17198 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | stewartautosales.com id17197 View details | United States | Retail / E-commerce | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | milleraa.com id17196 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | jsfrental.com id17195 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | summitmovinghouston.com id17194 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | dwgp.com id17193 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | easycom.com id17192 View details | Colombia | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | alfa.com.co id17191 View details | Colombia | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | westernwoodsinc.com id17190 View details | United States | Services | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | viscira.com id17189 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | elitt-sas.fr id17188 View details | France | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | cfctech.com id17187 View details | United States | IT | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | armellini.com id17186 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | mbacomputer.com id17185 View details | United States | IT | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | directex.net id17184 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | 360energy.com.ar id17183 View details | Argentina | Energy | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | saludsa.com.ec id17182 View details | Ecuador | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | intercomp.com.mt id17181 View details | Malta | Other | — | |
|
Extract from Taking stock of 2024 Part 2 |
|||||
| Ransomware | Taking stock of 2024| Part 2 id17169 View details | Communication / Marketing | — | ||
|
Our team was able to breach the IT defenses of a huge number of c ompanies over the past year. Among them are: | intercomp.com.mt | saludsa.com.ec | 360energy.com.ar | directex .net | mbacomputer.com | armellini.com | cfctech.com | elitt-sas. fr | viscira.com | westernwoodsinc.com | alfa.com.co | easycom.co m | dwgp.com | summitmovinghouston.com | jsfrental.com | milleraa .com | stewartautosales.com | feheq.com | usm-americas.com | mipa l.com.br | acesaz.com | premierop.com | alphascriptrx.com | emin. cl | engineeredequip.com | mielectric.com.br | We always act hone stly and try not to disclose the fact of data leakage until the v ery last moment. Therefore, it is in your best interest not to be on this list and contact us immediately. |
|||||
| Ransomware | vanguardpaints.com id17068 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | Taking stock of 2024 | Part 1 id17069 View details | Construction / Real Estate | — | ||
|
Our team was able to breach the IT defenses of a huge number of companies over the past year. Among them are: worldfabricinc.com, JFGV.ca, atlanticelectrics.com, cannara.ca, njcar.org, yhti.com, dkgrar.com, calfaucets.com, atr.com, simcointeriors.com, madisonforms.com, scrantonrealtors.org, isisecurity.com, sgbllp.com, ad.snadc.com, clarkpower.com, allbrightcotton.com, idrefjall.com, swissit.cz, irisib.com, foxconstructiongroup.co.uk, elf.uk.com, farmatodo.com, omniflow.com, rqsi.com, teligentems.com, centerracoop.com, andrewlauren.com, garcesfruit.com, ibp.com, empereon-constar.com, rightofwayequipment.net, adhydraclean.com, vanguardpaints.com. We always act honestly and try not to disclose the fact of data leakage until the very last moment. Therefore, it is in your best interest not to be on this list and contact us immediately. |
|||||
| Ransomware | adhydraclean.com id17067 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | rightofwayequipment.net id17066 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | empereon-constar.com id17065 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | ibp.com id17064 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | garcesfruit.com id17063 View details | Chile | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | andrewlauren.com id17062 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | centerracoop.com id17061 View details | Serbia | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | teligentems.com id17060 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | rqsi.com id17059 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | omniflow.com id17058 View details | Portugal | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | farmatodo.com id17057 View details | Venezuela, Bolivarian Republic of | Agriculture / Food | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | elf.uk.com id17056 View details | United Kingdom | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | foxconstructiongroup.co.uk id17055 View details | United Kingdom | Construction / Real Estate | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | irisib.com id17054 View details | United Kingdom | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | swissit.cz id17053 View details | Czechia | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | idrefjall.com id17052 View details | Sweden | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | allbrightcotton.com id17051 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | clarkpower.com id17050 View details | United States | Energy | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | ad.snadc.com id17049 View details | Andorra | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | sgbllp.com id17048 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | isisecurity.com id17047 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | scrantonrealtors.org id17046 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | madisonforms.com id17045 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | simcointeriors.com id17044 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | atr.com id17043 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | calfaucets.com id17042 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | dkgrar.com id17041 View details | Denmark | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | yhti.com id17040 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | njcar.org id17039 View details | United States | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | cannara.ca id17038 View details | Canada | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | atlanticelectrics.com id17037 View details | United Kingdom | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | JFGV.ca id17036 View details | Canada | Other | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | worldfabricinc.com id17035 View details | United States | Services | — | |
|
Extract from Taking stock of 2024 Part 1 |
|||||
| Ransomware | Perfect Plastic id17019 View details | Manufacturing / Engineering | — | ||
|
A world leader in payment card production. Innovative solutions i n contactless, EMV, chip cards, and personalization. We are ready to upload a lot of private corporate documents such as: confidential agreements and contracts, driver licenses, finan cial data (audits, payment details, reports), contact numbers and e-mail addresses of employees and customers, etc. |
|||||
| Ransomware | Benuta id17018 View details | Germany | Finance / Legal / Insurance | — | |
|
In just twelve years, Benuta has become one of the fastest growin g companies in the European online carpet retail sector. We are ready to upload a lot of private corporate documents such as: NDAs, contact numbers and e-mail addresses of employees and c ustomers, financial data (audits, payment details, reports), conf idential agreements and contracts, inside correspondence, HR docu ments, etc. |
|||||
| Ransomware | Menway id17015 View details | France | Finance / Legal / Insurance | — | |
|
Menway offers a wide range of skills to provide a tailor-made res ponse to all HR issues, serving businesses and employees. We are ready to upload more than 20 GB of private corporate docum ents such as: NDAs, HR documents, contact numbers and e-mail addr esses of employees and customers, financial data (audits, payment details, reports), etc. |
|||||
| Ransomware | Mark ResolveInc id16955 View details | United States | Services | — | |
|
This organization primarily operates in the Business Co nsulting, nec business / industry within the Engineerin g, Accounting, Research, and Management Services sector . You will find more than 13 GB of private corporate docu ments such as: driver licenses, internal financial docu ments, inside corporate correspondence, customer contac t emails and phones, etc We have made the process of downloading company data as simple as possible for our users. All you need is any torrent client (like Vuze, Utorrent, qBittorrent or Tra nsmission to use magnet links). You will find the torre nt file above. 1. Open uTorrent, or any another torrent client. 2. Add torrent file or paste the magnet URL to upload t he data safely. 3. Archives have no password. MAGNET URL: magnet:?xt=urn:btih:2BAAC706035AA9FA370691A 9C31B0977C541AC59&dn=mresolve.local&tr=udp://tracker.op enbittorrent.com:80/announce&tr=udp://tracker.opentrack r.org:1337/announce&tr=wss://wstracker.online |
|||||
| Ransomware | QCN CO., LTD id16954 View details | Taiwan, Province of China | Services | — | |
|
The company provides numerous consulting services and develops sy stems and applications. Based on the accumulated technology and e xperience, QCN has been opening new business lines since 2010 und er two mottos: mobile solutions and overseas cooperation projects . We are ready to upload more than 12 GB of private corporate docum ents such as: contact numbers and e-mail addresses of employees a nd customers, financial data (audits, payment details, reports), confidential agreements and contracts, etc. |
|||||
| Ransomware | Mercy Supply Collaborative id16948 View details | United States | Healthcare / Pharma | — | |
|
Mercy is a diversified, privately held healthcare services organi zation, focused on positioning itself to meet the challenges of a n increasingly complex healthcare environment. We are ready to upload a lot of private corporate documents such as: financial data (audits, payment details, reports), contact nu mbers and e-mail addresses of employees and customers, etc. |
|||||
| Ransomware | Grand Fire Protection id16941 View details | United States | Communication / Marketing | — | |
|
Grand Fire provides first-class fire protection and underground u tility services in Nashville and Middle Tennessee. We are ready to upload a lot of private corporate documents such as: license agreements, financial data (audits, payment details, reports), contact numbers and e-mail addresses of employees and c ustomers, SSNs, family member information, incident with compensa tion reports, etc. |
|||||
| Ransomware | Mark Resolve Inc id16937 View details | United States | Services | — | |
|
This organization primarily operates in the Business Consulting, nec business / industry within the Engineering, Accounting, Resea rch, and Management Services sector. We are ready to upload more than 13 GB of private corporate docum ents such as: driver licenses, internal financial documents, insi de corporate correspondence, customer contact emails and phones, etc |
|||||
| Ransomware | WorldNet Telecommunications LLC id16779 View details | Puerto Rico | Telecommunications | — | |
|
WorldNet stands out for offering services to companies with a ful l range of technology solutions, including digital security, IT c onsulting, voice, data, cloud services, broadband Internet, satel lite telephony and business continuity. We are ready to upload more than 8 GB of private corporate docume nts such as: license agreements, NDAs, internal financial data (a udits, payment details, reports), insurance documents, customer c ontact emails and phones, etc. |
|||||
| Ransomware | Enghouse (ex. Navita) id16778 View details | Canada | Communication / Marketing | — | |
|
Enghouse is a publicly traded Canadian company that provides ente rprise software solutions focused on remote work, visual computin g, and communications for next-generation software-defined networ ks. We are ready to upload some private corporate documents such as: internal financial data (audits, payment details, reports), emplo yee tax payer numbers, employee contact emails, etc. |
|||||
| Ransomware | Architects West id16764 View details | United States | Finance / Legal / Insurance | — | |
|
Architects West is a leading architecture firm based in Coeur dAl ene and Spokane, offering architectural, landscape architectural, and interior design services since 1973. We are ready to upload more than 120 GB of private corporate docu ments such as: HR documents, contact numbers and e-mail addresses of employees and customers, confidential agreements and contract s, financial data (audits, payment details, reports), etc. |
|||||
| Ransomware | Hayloft Property Management id16760 View details | United States | Communication / Marketing | — | |
|
Hayloft Property Management Co. offers spacious, modern living, w here quality and comfort come first. Their apartments for rent ar e located in five states, with nine different communities: South Dakota, Iowa, Minnesota, Nebraska, and Kansas. We are ready to upload about 9 GB of private corporate documents such as: license agreements, contact numbers and e-mail addresses of employees and customers, SSNs, internal financial documents, incident reports, etc. |
|||||
| Ransomware | Divimast id16702 View details | Italy | Services | — | |
|
Divimast is a business consulting company that brings together co nsultants who have been in the market for more than 20 years, hig hly specialized and ready to offer customized solutions for each client. We are ready to upload about 8 GB of private corporate documents such as: confidential agreements, internal financial documents, e mployee passports (identity cards), HR documents, contact numbers and e-mail addresses of employees and customers, etc. |
|||||
| Ransomware | VODOTEHNIKA D.D. id16701 View details | Croatia | Communication / Marketing | — | |
|
Vodotehnika provides quality design, production and retail of hom e equipment and decor as well as support services. We are ready to upload some private corporate documents such as: internal financial documents, contact numbers and e-mail addresse s of employees and customers, passports (identity cards), etc. |
|||||
| Ransomware | Chain And Rope SuppliersLTD id16700 View details | Ireland | Communication / Marketing | — | |
|
Started over 40 years ago, Chain And Rope Suppliers has grown from a specialist supplier of lifting equipment to Ireland's leading lifting controls and safety specia list. You will find some private corporate documents includin g: internal financial documents, contact numbers and e- mail addresses of employees and customers etc. We have made the process of downloading company data as simple as possible for our users. All you need is any torrent client (like Vuze, Utorrent, qBittorrent or Tra nsmission to use magnet links). You will find the torre nt file above. 1. Open uTorrent, or any another torrent client. 2. Add torrent file or paste the magnet URL to upload t he data safely. 3. Archives have no password. MAGNET URL: magnet:?xt=urn:btih:DD954FADF10F9C810E0F9B6 E3BCB0832E8B244E1&dn=chainandrope.ie&tr=udp://tracker.o penbittorrent.com:80/announce&tr=udp://tracker.opentrac kr.org:1337/announce&tr=wss://wstracker.online |
|||||
| Ransomware | Beyond79 id16652 View details | United States | Finance / Legal / Insurance | — | |
|
Welcome Beyond79 is a community of committed jewelry professional s dedicated to the cultivation of passionate customers by deliver ing the ultimate online jewelry experience. We are ready to upload a lot of private documents such as: SSNs, contact numbers and e-mail addresses of employees and customers, internal financial documents, confidential correspondence, intern al financial documents, etc. |
|||||
| Ransomware | Moinho Globo Alimentos id16643 View details | Brazil | Public Sector | — | |
|
Moinho Globo Alimentos is currently the fourth largest milling in dustry in the state, with an installed milling capacity of 12,500 tons/month. We are ready to upload more than 58 GB of private corporate docum ents such as: contact numbers and e-mail addresses of employees a nd customers, personal CNP/CPF/NIF, internal financial documents , etc. |
|||||
| Ransomware | PJ's Rebar id16642 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
Rebar supply & preassembly company that is focused on pre-assembl ed, fabricated, and stock rebar in all grades and sizes. We are ready to upload more than 40 GB of private corporate docum ents including: contact numbers and e-mail addresses of employees and customers, internal financial documents, etc. |
|||||
| Ransomware | Union Studio id16641 View details | United States | Communication / Marketing | — | |
|
Union Studio is a growing Providence, RI-based office of 12 desig ners, architects and planners focused on the design of exceptiona l New Urbanist communities. We are ready to upload more than 38 GB of private corporate docum ents such us: driver licenses, employee licenses, HR documents, C OVID-19 screening information, contact numbers and e-mail address es of employees, passports, etc. |
|||||
| Ransomware | Peikko id16580 View details | Finland | Energy | — | |
|
Peikko Group Corporation is a global supplier of slim floor struc tures, wind energy applications, and connection technology for pr ecast and cast-in-situ construction. We are ready to upload about 30 GB of private corporate documents such as: internal financial documents and disclosure agreements, taxpayer INs, contact numbers and e-mail addresses of employees, HR documents etc. |
|||||
| Ransomware | Ichikawa North America Corporation id16577 View details | Japan | Finance / Legal / Insurance | — | |
|
Ichikawa Co., Ltd. manufactures and sells paper making and indust rial felts in Japan and internationally. We are ready to upload some private corporate documents including : internal financial documents, confidential agreements, customer contact phone numbers and e-mails, SSNs. employee contacts, driv er licenses etc. |
|||||
| Ransomware | Thomas J. Henry Law id16574 View details | United States | Finance / Legal / Insurance | — | |
|
Thomas J. Henry Law is one of the largest personal injury law fir ms in Texas, handling all types of personal injury claims and rep resenting clients in mass torts, product liability, child injurie s, and whistleblower defense cases. We have obtained over 4 Tb of private corporate documents includi ng: NDAs, SSNs, passports, driver licenses, confidential medical information, medicare documents, contact numbers and e-mail addre sses of employees and customers, personnel incident reports etc. We can put this information freely available at any time. |
|||||
| Ransomware | Capesesp id16573 View details | Brazil | Healthcare / Pharma | — | |
|
CAPESESP - National Health Foundation Employee Pension and Assist ance Fund - is a closed supplementary pension entity sponsored by the National Health Foundation – FUNASA. We are ready to upload more than 90 GB of private corporate docum ents including: HR documents, contact numbers and e-mail addresse s of employees and customers, INSSs, personal identity cards, con fidential corporate documents, employee medical documents, birth certificates etc. |
|||||
| Ransomware | Metalmatrix Clamps id16572 View details | Brazil | Manufacturing / Engineering | — | |
|
Metalmatrix is a reference in the state-of-the-art manufacturin g of safe clamps for all segments. They have representatives thro ughout Brazil and export worldwide. We are ready to upload more than 10 GB of private corporate docum ents including: internal financial information, CNPJ numbers, con tact numbers and e-mail addresses of employees and customers etc. |
|||||
| Ransomware | Northern Lights Electric id16551 View details | United States | Communication / Marketing | — | |
|
Northern Lights Electric installs electric vehicle chargers, rece ssed lighting, and generators. We are ready to upload some of private corporate documents includ ing: driver licenses, employee personal licenses, contact numbers and e-mail addresses of employees and customers etc. |
|||||
| Ransomware | Chain And Rope Suppliers LTD id16550 View details | Ireland | Finance / Legal / Insurance | — | |
|
Started over 40 years ago, Chain And Rope Suppliers has grown fro m a specialist supplier of lifting equipment to Ireland's leading lifting controls and safety specialist. We are ready to upload some private corporate documents including : internal financial documents, contact numbers and e-mail addres ses of employees and customers etc. |
|||||
| Ransomware | Galfer id16548 View details | Spain | Telecommunications | — | |
|
GALFER is a leading manufacturer of friction materials and compon ents for braking systems for the automobile, motorcycling, and bi cycle sectors. We are ready to upload more than 65 GB of private corporate docum ents including: NDAs, contact numbers and e-mail addresses of emp loyees and customers, employees DNI numbers, HR confidential info rmation etc. |
|||||
| Ransomware | Permoda id16547 View details | Panama | Communication / Marketing | — | |
|
A leading company in the retail industry. Permoda is an expert in the production, manufacturing and distribution of textiles and s ells their products through the KOAJ brand. They are present in C olombia, Costa Rica, Ecuador and Panama. We are ready to upload more than 220 GB of private corporate docu ments including: contact numbers and e-mail addresses of employee s and customers, internal financial documents, confidential agree ments and contracts, certification documents etc |
|||||
| Ransomware | Press Color id16542 View details | United States | Communication / Marketing | — | |
|
Press Color, Inc. (PCI) is a privately held Wisconsin based print ing ink manufacturer of flexographic and offset inks. Incorporat ed over sixty years ago, PCI offers total solutions for the print ing and converting industry. We are ready to upload a lot of private corporate documents inclu ding: NDAs, driver licenses, HR documents, contact numbers and e- mail addresses of employees and customers, internal financial doc uments, SSNs etc. |
|||||
| Ransomware | Surface Combustion id16540 View details | United States | Communication / Marketing | — | |
|
Surface Combustion, Inc. is a highly respected producer of therma l processing equipment, headquartered in Maumee, Ohio. We are ready to upload more than 20 GB of private corporate docum ents including: contact numbers and e-mail addresses of employees and customers, SSNs, driver licenses, HR documents, confidential agreements etc. |
|||||
| Ransomware | Slawson Companies id16539 View details | United States | Finance / Legal / Insurance | — | |
|
Slawson Companies is a community builder that has diversified int o commercial and residential real estate development, restaurants , and hotels. We are ready to upload more than 20 GB of private corporate docum ents including: driver licenses, NDAs, credit cards info, interna l financial documents, vaccination certificates, contact numbers and e-mail addresses of employees and customers etc. |
|||||
| Ransomware | Drivestream id16526 View details | United States | Services | — | |
|
Drivestream is a management and IT consulting firm specializing i n migrating the enterprise business processes of large and medium sized businesses to the Cloud. We are ready to upload more than 80 GB of private corporate docum ents including: SSNs, family contacts, contact numbers and e-mail addresses of employees and customers, driver licenses, passports etc. |
|||||
| Ransomware | Drywall Partitions id16525 View details | Construction / Real Estate | — | ||
|
Drywall Partitions, Inc. is a commercial drywall construction fir m building new and remodel projects with special emphasis on tena nt finish build-outs. We are ready to upload a lot of private corporate documents inclu ding: internal financial documents, inside corporate corresponden ce, SSNs, contact numbers and e-mail addresses of employees etc. |
|||||
| Ransomware | AAA Environmental id16524 View details | United States | Finance / Legal / Insurance | — | |
|
AAA Environmental provides environmental training, industrial hyg iene, safety, online classes, and consultation services. We are ready to upload a lot of private corporate documents inclu ding: internal financial documents, employee medical documents, c ontact numbers and e-mail addresses of employees and customers, f amily contacts, medicare information, driver licenses, credit car d information, SSNs etc. |
|||||
| Ransomware | Maverick Constructors id16508 View details | United States | Finance / Legal / Insurance | — | |
|
MAVERICK CONSTRUCTORS, LLC is a construction company based out of Lutz, Florida, United States. We are ready to upload more than 35 GB of private corporate docum ents including: financial data (audits, payment details, reports) , contact numbers and e-mail addresses of employees and customers etc. |
|||||
| Ransomware | A Bar A Ranch id16507 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
Along the banks of the North Platte River, in the heart of southe rn Wyoming’s Medicine Bow Mountains, lies the A Bar A Ranch. Esta blished in 1922, it is one of the oldest guest ranches in the cou ntry. It is also one of the largest, with nearly 100,000 acres fo r guests and staff to explore. We are ready to upload a lo of private corporate documents includ ing: financial data (audits, payment details, reports), contact n umbers and e-mail addresses of customers and employees, insurance documents, lease agreements etc. |
|||||
| Ransomware | Los Andes id16505 View details | Argentina | Finance / Legal / Insurance | — | |
|
Diario Los Andes is a morning newspaper published in the city of Mendoza, Argentina, owned by Grupo Clarín and the heirs of the Ca lle Family. We are ready to upload a lot of private corporate documents inclu ding: financial data (audits, payment details, reports), contact numbers and e-mail addresses of employees etc. |
|||||
| Ransomware | Bluegrass Ingredients id16504 View details | United States | Finance / Legal / Insurance | — | |
|
Bluegrass helps leading brands and flavor houses concept, test an d produce the custom flavors and formulations they need to stay a head. We are ready to upload more than 45 GB of private corporate docum ents including: NDAs, SSNs, financial data (audits, payment detai ls, reports), contact numbers and e-mail addresses of employees e tc. |
|||||
| Ransomware | Action Imports id16503 View details | Canada | Communication / Marketing | — | |
|
A national wholesale distributor that provides thousands of produ cts to retail locations across the country. We are ready to upload more than 10 GB of private corporate docum ents including: contact numbers and e-mail addresses of employees and customers, financial data (audits, payment details, reports) etc. |
|||||
| Ransomware | Gunnar Prefab id16502 View details | Sweden | Communication / Marketing | — | |
|
Gunnar Prefab develop, manufacture and deliver prefabri cated concrete products to the entire Nordic region. You will find some private corporate documents includin g: NDAs, contact numbers and e-mail addresses of employ ees and customers, HR documents etc. We have made the process of downloading company data as simple as possible for our users. All you need is any torrent client (like Vuze, Utorrent, qBittorrent or Tra nsmission to use magnet links). You will find the torre nt file above. 1. Open uTorrent, or any another torrent client. 2. Add torrent file or paste the magnet URL to upload t he data safely. 3. Archives password: gunnarprefab.se MAGNET URL: magnet:?xt=urn:btih:11CEFC2385FB8AE6EBE3621 4DEC744ABD020A845&dn=gunnarprefab.se&tr=udp://tracker.o penbittorrent.com:80/announce&tr=udp://tracker.opentrac kr.org:1337/announce&tr=wss://wstracker.online |
|||||
| Ransomware | VO Baker id16414 View details | United States | Finance / Legal / Insurance | — | |
|
V. O. BAKER COMPANY is a chemicals company based out of 8647 TWIN BROOK RD., MENTOR, Ohio, United States. We are ready to upload some private corporate documents including : SSN, contact numbers and e-mail addresses of employees and cust omers, employee injury reports, internal financial documents etc. |
|||||
| Ransomware | E-Tank id16407 View details | United States | Healthcare / Pharma | — | |
|
E-Tank is a rental solution for the frac tank, roll-off box, and industrial pump equipment. We are ready to upload more than 100 GB of private corporate docu ments including: SSNs, driver licenses, passports, contact number s and e-mail addresses of employees, family information, medical insurance documents etc. |
|||||
| Ransomware | Charlie’s Tax Service id16406 View details | United States | Communication / Marketing | — | |
|
Charlie's Tax Service is an accounting company that provides clie nts with tax preparation services. We are ready to upload more than 15 GB of private corporate docum ents including: SSNs, driver licenses, contact numbers and e-mail addresses of employees and customers etc. |
|||||
| Ransomware | Pinno Construction id16405 View details | United States | Construction / Real Estate | — | |
|
Pinno Construction offer all types of construction solutions from custom-designed new homes, remodels and additions to window, sid ing and roofing replacements and even commercial renovations. We are ready to upload more than 10 GB of private corporate docum ents including: driver licenses, internal financial documents, si gned lease agreements, SSNs, contact numbers and e-mail addresses of employees etc. |
|||||