Ransomware Group intelligence
Akira
ActiveTrack Akira with 1676 published victims and 2 known leak locations in a single intelligence view.
Overview
Akira is tracked by Breach House as a ransomware group with 1676 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 20m ago | akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion |
| Leak location 1 | Onion service | Down checked 21m ago | akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion |
Top Activity Sectors (18)
- Finance / Legal / Insurance 426
- Communication / Marketing 320
- Manufacturing / Engineering 170
- Services 128
- Construction / Real Estate 105
- Not identified 75
- Healthcare / Pharma 66
- IT 64
- Energy 39
- Hospitality / Food & Beverage / Tourism 32
- Transportation / Travel / Logistics 32
- Agriculture / Food 31
- Retail / E-commerce 27
- Telecommunications 27
- Education 25
- Public Sector 16
- NGOs / Associations 5
- null 1
Typical Attacks (29)
▼How Akira typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Akira, Akira, Akira _v2.
-
What they do: Akira uses valid account information to remotely access victim networks, such as VPN credentials.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Akira uses compromised VPN accounts for initial access to victim networks.
What that means: Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
-
T1047 Windows Management Instrumentation Execution
What they do: Akira will leverage COM objects accessed through WMI during execution to evade detection.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: Akira has used PowerShell scripts for credential harvesting and privilege escalation.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Akira executes from the Windows command line and can take various arguments for execution.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Akira executes native Windows functions such as GetFileAttributesW and `GetSystemInfo`.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Akira _v2 can create a child process for encryption.
What that means: Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence.
-
T1027.001 Binary Padding Stealth
What they do: Akira has used binary padding to obfuscate payloads.
What that means: Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Akira has used legitimate names and locations for files to evade defenses.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1480 Execution Guardrails Stealth
What they do: Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Akira has disabled or modified security tools for defense evasion.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1558 Steal or Forge Kerberos Tickets Credential Access
What they do: Akira have used scripts to dump Kerberos authentication credentials.
What that means: Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket.
-
T1018 Remote System Discovery Discovery
What they do: Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: Akira uses the GetSystemInfo Windows function to determine the number of processors on a victim machine.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Akira can identify remote file shares for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1482 Domain Trust Discovery Discovery
What they do: Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments.
What that means: Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
-
T1654 Log Enumeration Discovery
What they do: Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems.
What that means: Adversaries may enumerate system and service logs to find useful data.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Akira has used RDP for lateral movement.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1213.002 Sharepoint Collection
What they do: Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.
What that means: Adversaries may leverage the SharePoint repository as a source to mine valuable information.
-
T1560.001 Archive via Utility Collection
What they do: Akira uses utilities such as WinRAR to archive data prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1219 Remote Access Tools Command and Control
What they do: Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: Akira will exfiltrate victim data using applications such as Rclone.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Akira encrypts files in victim environments as part of ransomware operations.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Akira _v2 can stop running virtual machines.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Akira will delete system volume shadow copies via PowerShell commands.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1531 Account Access Removal Impact
What they do: Akira deletes administrator accounts in victim networks prior to encryption.
What that means: Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
-
T1657 Financial Theft Impact
What they do: Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (41)
▼Software Akira has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (15)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1qr0pqfghr9cksfc5arr2rak3lt2y50v03pc76nh |
bitcoin | $997,461 | 2 |
bc1qfdzu6uv2nek524pe7lz4w0mxtt9898vfaegdaj |
bitcoin | $482,181 | 1 |
bc1q0dx45y82r5rt36sm38jv0k4dexwc4nj9z4ryw7 |
bitcoin | $446,073 | 2 |
bc1q9wnp6k7xxdqkdv4fa5ceyhv08espuskhu8ghq2 |
bitcoin | $351,883 | 1 |
bc1qknumj4326runqxfr58kg0s7v7gu9y5v5t9uv6h |
bitcoin | $298,537 | 2 |
bc1qr0txunr259we37wer7w6et33qyq0n6hv83pw24 |
bitcoin | $252,389 | 1 |
bc1q0lwpz2yufw3x9as6f679lwk8jx43g44683x5mc |
bitcoin | $229,395 | 4 |
bc1qhzd63mz9mfucak7yzfn65p6rcsgztnsqr3dak8 |
bitcoin | $150,205 | 1 |
bc1qqrsd02sqthm8gej8lfesgpx82saw7q2g5pjtah |
bitcoin | $149,891 | 1 |
bc1q4my6vqq8cg689drf9jccqudjclv67sz4cudkyd |
bitcoin | $139,534 | 1 |
bc1qpwwtck0zhzrj56fxeayz6wz5546nlp607qzpvh |
bitcoin | $109,655 | 2 |
bc1qghj85gz0dkr9jeucana3z4xu50ujtllj50rvj0 |
bitcoin | $106,115 | 2 |
+3 more wallets not shown (the 12 largest by amount received are listed).
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
akira_readme_3.txt
Hi friends, Whatever who you are and what your title is, if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. ATTENTION! Strictly prohibited: - Deleting files with .arika extension; - Replacing or renaming .arika and .akira files; - Using third party software to recover your systems. If you violate these rules, we cannot guarantee a successful recovery. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining you financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of the deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidentally corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and use in order to get into, identify backup solutions and download your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at once. Then all of this will be published in our blog - akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad[.]onion. 5. We're more than negotiable and will definitely find a way to settle this quickly and reach an agreement which will satisfy both of us. 6. Negotiations with Akira can only be conducted in a chat room, which you can access using the login details provided below or in the notes (a readme.txt file) in your systems. You should ignore any attempts (such as emails/social media messages, phone calls, etc.) to redirect you to another chat or email address (proton.me is often used by unauthorized individuals) on our behalf. 7. Be careful while working with recovery agencies as they often try to use your cyber incident to stuff their pockets. There are many risks for you to lose money and get nothing in return. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - torproject[.]org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion/d/[snip] . 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
akira_readme_2.txt
Hi friends, Whatever who you are and what your title is, if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. ATTENTION! Strictly prohibited: - Deleting files with .arika extension; - Replacing or renaming .arika and .akira files; - Using third party software to recover your systems. If you violate these rules, we cannot guarantee a successful recovery. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining you financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of the deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidentally corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and use in order to get into, identify backup solutions and download your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at once. Then all of this will be published in our blog - akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad[.]onion. 5. We're more than negotiable and will definitely find a way to settle this quickly and reach an agreement which will satisfy both of us. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - torproject[.]org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion/d/[snip] . 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
akira_readme.txt
Hi friends, Whatever who you are and what your title is if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining your financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of a deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidently corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of a great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and used in order to get into, identify backup solutions and upload your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at ones. Then all of this will be published in our blog - https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion. 5. We're more than negotiable and will definitely find the way to settle this quickly and reach an agreement which will satisfy both of us. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - https://www.torproject.org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion. 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1676)
Search, filter and paginate the victim timeline for Akira. Showing 1501–1600 of 1676.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Hamilton-Madison House id10470 View details | United States | Healthcare / Pharma | — | |
|
The Hamilton-Madison House is a historic 118-year old settlement house/multi service agency addressing the education, health and social needs of immigrant and ethnic minority communities. As you understand there are so many personal files. We will upload about10Gb of their files and you can find so much interesting in there (passports, birth certificates, IDs etc). |
|||||
| Ransomware | Hydratek id10469 View details | Canada | Communication / Marketing | — | |
|
HydraTek provides specialty consulting engineering services for problems involving water hammer in pipe systems. We will make their data available for you soon. Finance, HR, projects, contract and other files will be represented in archives. |
|||||
| Ransomware | DENHAM the Jeanmaker id10450 View details | Netherlands | Finance / Legal / Insurance | — | |
|
The company manufactures and sells men and womens, outerwear, tops, bottoms and accessories. In the 100Gb data archive we are going to upload you will find HR files with personal documents, client information, some confidential files, finance and accounting information. |
|||||
| Ransomware | Becker Logistics id10438 View details | United States | Transportation / Travel / Logistics | — | |
|
Becker Logistics, headquartered in Glendale Heights, Illinois, and established in 1997, is a transportation management company. Wewill upload about 43gb of files with numerous documents containing personal information, HR, customer info, nda documents, contracts, accounting and financials files. |
|||||
| Ransomware | Bestway Sales id10437 View details | United States | Retail / E-commerce | — | |
|
Bestway Sales a leading manufacturer and marketer of agriculturalsprayers, recently announced the introduction of a line of UTV Skid Mounted Sprayers that are designed for rugged use by farmers,ranchers and commercial spraying operations. Operational data, customer information and other files will be available soon. |
|||||
| Ransomware | TGS Transportation id10436 View details | United States | Transportation / Travel / Logistics | — | |
|
TGS Transportation is an international and domestic intermodal drayage provider. We will upload their files soon. There are financial, HR, customers data with contacts and other operational data. |
|||||
| Ransomware | Premium Guard id10435 View details | United States | Communication / Marketing | — | |
|
Premium Guard Inc. (PGI) specializes in designing, manufacturing,and distributing products for automotive, diesel, powersport, and specialty filter markets. 40GB of files with clients and customers data, financial files, projects, orders, contracts will be available for downloading soon. |
|||||
| Ransomware | Blackburn College id10395 View details | United States | Education | — | |
|
Blackburn College is a private college in Carlinville, Illinois. Blackburn is a federally recognized work college with a student-managed work program, enabling students to gain leadership experience as they manage other students. We are going to upload 30GB ofthe college files. There are many operational files inside, HR files with personal docs of students and employees. |
|||||
| Ransomware | Vincentz Network id10394 View details | Germany | Telecommunications | — | |
|
Vincentz Network is in partnership with different industries in the national and international markets. These include geriatric care, the paint industry, the automotive industry, furniture production, painting technology, technical dealers and ambitious woodworkers. We have 70GB of data that will be uploaded here to share with you. You will find there numerous detailed financial and operational documents. We will also upload a few databases with HR and accounting files. |
|||||
| Ransomware | Viridi id10378 View details | United States | Healthcare / Pharma | — | |
|
Viridi Parente designs and builds fail-safe battery systems for industrial, medical, commercial, municipal, and residential building applications. 70 GB of data contain lots of files with accounting, payment, projects information. There are also many nondisclosure documents, NDA and personal documents of employees. Uploading is coming. |
|||||
| Ransomware | Ito Pallpack Gruppen id10377 View details | Norway | Communication / Marketing | — | |
|
Ito Pallpack Gruppen is a business that has delivered industrial solutions for six decades. With our own production department, they have unique opportunities for testing and pre-installation of the deliveries. 30 GB of files will be uploaded soon. Finance, project, contracts and personal information - all this can be foundinside the archive we are going to share with you. |
|||||
| Ransomware | Van Buren Public Schools id10372 View details | United States | Education | — | |
|
The Van Buren Public Schools is a school district headquartered in Belleville, Michigan. A lot of files with information about students and their parents, HR information, accounting and other files. |
|||||
| Ransomware | Heller Industries id10371 View details | United States | Finance / Legal / Insurance | — | |
|
Heller Industries, Inc. provides reflow technology solutions. TheCompany offers curing systems, semi conductors, and reflow equipment for electronic manufacturers and assemblers. Almost 300gb ofdata will be available soon. There are numerous NDAs with names of widely known corporations, personal documents, finance files and so on. |
|||||
| Ransomware | International Electronic Machines Corp id10295 View details | Communication / Marketing | — | ||
|
On this blessed day we are sharing with you that another company is going to celebrate the New Year with their data on our blog. International Electronic Machines develops, produces and markets innovative imaging, optical and other sensor-based systems for safety and security applications for intelligent transportation system applications. 16Gb of data will be uploaded early next year. Many HR files with personal information, IP, project files and so on. |
|||||
| Ransomware | Nissan Australia id10264 View details | Australia | Communication / Marketing | — | |
|
We've obtained 100 GB of Nissan Australia. They seem not to be very interested in the data, so we will upload it for you within afew days. You will find docs with personal information of their employees in the archives and much other interested stuff like NDAs, projects, information about clients and partners etc. By the way, there is a notice on their website regarding investigation about possible personal information leakage, so we will confirm that with the data uploading. |
|||||
| Ransomware | Nexiga id10044 View details | Communication / Marketing | — | ||
|
Nexiga offers a full service geomarketing to optimize marketing and sales with market and geodata, analyzes and geoinformation systems. 30Gb of their files will be uploaded soon. You can find lots of projects documentation, finance and accounting are presentedwidely. A bit of personal docs with addresses, phones etc. |
|||||
| Ransomware | Hyman Hayes Associates id10028 View details | Healthcare / Pharma | — | ||
|
Hyman Hayes Associates is a full service architecture firm specializing in healthcare, laboratory, and general building design. These guys do not need their data so the files of this company willbe available for downloading soon. There are many files with project information, a bit financials and contracts, other operational docs. |
|||||
| Ransomware | SmartWave Technologies id9978 View details | IT | — | ||
|
SmartWave Technologies is a vertically integrated team of engineers, scientists and technicians that provide design-through-manufacturing capability. These guys don't care about their 65 GB of data containing confidential personal information, lots of HR docs,even medical information. Clients, projects and accounting filesare represented as well. We'll provide access to the files soon. |
|||||
| Ransomware | Mitrani Caballero Ojam & Ruiz Moreno - Abogados id9977 View details | Argentina | Finance / Legal / Insurance | — | |
|
Mitrani Caballero Ojam & Ruiz Moreno Abogados is a legal firm that assists the most important companies in Argentina in their critical or most important legal needs. Seems like these lawyers willneed some legal assistance. Expect their data here in a few days. |
|||||
| Ransomware | The Teaching Company, LLC id9976 View details | Finance / Legal / Insurance | — | ||
|
The Teaching Company, doing business as The Great Courses, provides courses on digital versatile disc, audio compact disc, and other formats. 60Gb of data will be uploaded. Clients information, lots of accounting and finance data, courses info and even a holiday video! We will update soon. |
|||||
| Ransomware | MSD Information technology id9961 View details | IT | — | ||
|
MSD is a proven Managed I.T. Solutions provider & Specialized Software Provider. 47 of data will be available here soon. Some of personal information, finance, clients docs are inside. |
|||||
| Ransomware | Goiasa id9960 View details | Communication / Marketing | — | ||
|
Goiasa produces and supplies renewable energy at the lowest cost,with excellence in service and in harmony with the community andthe environment. A lot of information about their projects, sales, HR - 47GB. A few SQLs with more than 26 million lines inside. |
|||||
| Ransomware | Studio MF id9957 View details | Services | — | ||
|
Studio MF provides solutions for continued dedication to the start-up and innovative PMI, supporting the growth and development ofits own business project. We'll share 10Gb of their data soon asthese MFs don't care of it. You can find many files with clientsinformation and other business data. |
|||||
| Ransomware | Tasteful Selections id9890 View details | Agriculture / Food | — | ||
|
Tasteful Selections is a joint venture of RPE, CSS Farms and Plover River Farms Alliance, Inc. They are a vertically integrated grower, shipper, marketer of premium specialty potatoes. 410 Gb of their data will be available here soon. Lots of personal information (SSN and passports. Mostly employees), confidential agreements, clients information and so on. |
|||||
| Ransomware | Compass Group Italia id9875 View details | Italy | Healthcare / Pharma | — | |
|
Compass Group is a company based in Italia. Compass Group offers a wide range of services for companies, schools, hospitals, social and health facilities, business premises, sports and leisure. Data of this Italian giant will be published. There are so many files in the 107Gb of data we've taken from them. Finance, HR, legal, personal and so on. |
|||||
| Ransomware | Aqualectra Holdings id9874 View details | Energy | — | ||
|
Aqualectra is Curacao’s government owned utilities company that produces and distributes water and electricity to over 80.000 households and companies. Data fo this company will be available for downloading soon. Operational, business files, lots of payment files etc. |
|||||
| Ransomware | Midea Carrier id9842 View details | Chile | Communication / Marketing | — | |
|
Midea Carrier is the result of the union of two global market giants: Midea, a leader in the production of household appliances, and Carrier, a leader in air conditioning and founded by the inventor of air conditioning – Willis Carrier. In 2011, the two companies formed a joint venture to produce and distribute products in Brazil, Argentina and Chile, thus becoming the largest manufacturer of air conditioning equipment in Latin America. 40Gb of data will be released soon. You can find there international contract, agreements, legal documents, HR files etc. |
|||||
| Ransomware | Getrix id9839 View details | Italy | Construction / Real Estate | — | |
|
Getrix is the most used real estate management software in Italy.Client information, contracts, real estate and building information. Everything is about 10Gb. The archive will be available soon. |
|||||
| Ransomware | Bern Hotels & Resorts id9834 View details | Panama | Hospitality / Food & Beverage / Tourism | — | |
|
Bern Hotels & Resorts is one of Panama's biggest hotel groups. A dozen GB of operational files with detailed personal information will be released soon. Let us know in comment section if you are interested in passport and payment information. |
|||||
| Ransomware | Iptor id9816 View details | Communication / Marketing | — | ||
|
Iptor provides fully integrated enterprise solutions, with highlyadaptable and robust software backed by world-class support fromdistribution and supply chain experts. 20Gb of data will be uploaded. You can find there many confidential agreements, contracts and other operational files. |
|||||
| Ransomware | Bauwerk Boen Group id9805 View details | Communication / Marketing | — | ||
|
Bauwerk Boen Group is, according to the assessment of the BauwerkBoen management, Europe's leading developer, manufacturer and supplier of parquet flooring in the premium segment as well as the second-largest market participant in wood flooring. 40Gb of theirdata will be available here soon for downloading. Lots of contracts, agreement (including confidential ones), employee files and so on. |
|||||
| Ransomware | Lydall, Inc. id9785 View details | Communication / Marketing | — | ||
|
Lydall is a New York Stock Exchange listed company, headquarteredin Manchester, Connecticut with global manufacturing operations producing specialty engineered products for the thermal/acoustical and filtration/separation markets. We are going to upload a good amount of their projects files with drawing and everything. There are many HR files with detailed information, finance, accounting in there. |
|||||
| Ransomware | Alpura id9783 View details | Mexico | Communication / Marketing | — | |
|
Alpura, the leading milk producer in Mexico, taking care of everydetail and with the most advanced technology, offers you the best dairy products. You can get to know this company! We'll upload almost 20Gb of their data. There are up-to-date files for the last 3 years in the archive. |
|||||
| Ransomware | Servicio Móvil id9780 View details | Communication / Marketing | — | ||
|
At Servicio Móvil is a Spanish national leader in integral logistics services, information management and business processes. 114Gb of their data will be available here. Contracts, project, agreements, clients information and much of financial data is represented in the files. |
|||||
| Ransomware | Teleflora id9779 View details | Canada | Finance / Legal / Insurance | — | |
|
Teleflora is an online flower company headquartered in Los Angeles, California, Teleflora has over 10,000 member florists throughout the U.S. and Canada, with an additional 20,000 affiliated florists outside North America. We'll share a couple of dozens Gbs ofthis company files. Operational, financial docs, some HR files etc. |
|||||
| Ransomware | Legacy Mail Management id9721 View details | Services | — | ||
|
The company categorized under Mailing and Shipping Services. It was established in 2016 and incorporated in IA. The data we got from them will be uploaded here within this week. There are more than 40000 files will be available for downloading and studying. Please wait for updates. |
|||||
| Ransomware | Alspec id9673 View details | Energy | — | ||
|
Alspec offers is a versatile Servery window that is easy to fabricate and install. Almost 20Gb of Alspec's data will be uploaded here as there is no interest in it from them. |
|||||
| Ransomware | Custom Engineering &Fabrication, Inc. id9672 View details | Manufacturing / Engineering | — | ||
|
Custom Engineering & Fabrication is a leading provider of manufacturing solutions to a wide variety of industries, including asphalt, scrap recycling, steel, glass, foam, exterior doors, wood, mineral wool, and paper. These tricky guys lost about 700Gb of their data and don't want it back. Many business docs with personal information there are in the archives. We will share the files here with you soon. |
|||||
| Ransomware | IQ Supply Solutions id9671 View details | Services | — | ||
|
IQ Supply Solutions was founded in November 2017. As a women owned company we have expanded our business by being dedicated to giving our customers the very best service with a focus on detail, dependability and uniqueness. A few Gb of data including personal information will be uploaded soon. The women decided to show their real dedication to their clients. |
|||||
| Ransomware | Metro MPLS id9609 View details | Panama | IT | — | |
|
Metro MPLS is a company created to provide data transport services in the Republic of Panama based on a metropolitan fiber optic network using SDH (Synchronous Digital Hierarchy) and Metro Ethernet technology, enabling them to deliver multiple services to customers. Lots of financial, personal and project info will be available soon. |
|||||
| Ransomware | ATC SA id9605 View details | Communication / Marketing | — | ||
|
ATC is an international software company. For more than 25 years,the company provides innovative solutions for the Central Government, Media, Banking, Distribution, Manufacturing and Services. Their corporate data will be available soon. |
|||||
| Ransomware | SALUS Controls id9469 View details | Manufacturing / Engineering | — | ||
|
SALUS Controls is a company that operates in the Industrial Automation industry. 40 GB of data will be available here soon. Personal documents, operational information, contracts, agreements... There is much to look at. |
|||||
| Ransomware | Battle Motors (CraneCarrier, CCC) id9468 View details | Finance / Legal / Insurance | — | ||
|
Battle Motors is a leader in the vocational truck industry, providing custom, severe-service chassis under Battle Motors Engineered Chassis brands. Their data of 50Gb size will be available for downloading here soon. Operational, business agreements, contracts, accounting data etc are in the archive waiting for uploading. |
|||||
| Ransomware | City Furniture Hire id9466 View details | Public Sector | — | ||
|
City Furniture Hire Limited provides quality rental furniture to meet your individual needs whether it be for events, exhibitions,conferences or your office. Everyone interested in data of the company will have the access soon. Wait for an update. |
|||||
| Ransomware | Autocommerce id9465 View details | Slovenia | Retail / E-commerce | — | |
|
The company Autocommerce, d.o.o. is a company that represents theMercedes-Benz brand on the Slovenian car market. We will organize an exhibition hall with the data we exfiltrated from them for everyone interested soon (about 10Gb DB). Welcome everyone! |
|||||
| Ransomware | Simons Petroleum/Maxum Petroleum/Pilot Thomas Logistics id9462 View details | Energy | — | ||
|
We've obtained about 70Gb data of a group of companies in logistics/energy providing fields named Simons Petroleum, Maxum Petroleum and Pilot Thomas Logistics. Lots of operating files, confidential docs, personal information of employees, NDAs and so on. I'll make an update soon. |
|||||
| Ransomware | Michael Garron Hospital id9444 View details | Canada | Healthcare / Pharma | — | |
|
Nestled in the heart of East Toronto, Michael Garron Hospital (MGH), a division of Toronto East Health Network, is a vibrant community teaching hospital serving one of Canada’s most diverse communities. We have taken 882k files or 775 GB from their network. You will find lots of confidential information very soon. Stay tuned. |
|||||
| Ransomware | BioPower SustainableEnergy Corporation id9426 View details | Energy | — | ||
|
BioPower Sustainable Energy Corporation is a Canadian manufacturer of commercial and residential grade wood pellets. You will be able to download their data here soon. Lots of operation documents, internal correspondence, employee information, vendors and companies data. Everything is about 20GB. |
|||||
| Ransomware | BITZER id9425 View details | Communication / Marketing | — | ||
|
BITZER manufactures reciprocating compressors, screw compressors,scroll compressors, condensing units, heat exchangers and pressure vessels. We are going to upload 40GB of data. Contacts, agreements and other interested docs of a big manufacturer are coming soon. |
|||||
| Ransomware | Patriotisk Selskab id9301 View details | Denmark | Finance / Legal / Insurance | — | |
|
Patriotisk Selskab provides nationwide advice to professional agricultural companies within, among other things, finance, audit, law, livestock, environment and plant breeding. We will upload thedata we have from them soon. You will find European personal documents, confidential agreements and other papers inside. |
|||||
| Ransomware | Freeman Johnson id9269 View details | United Kingdom | Finance / Legal / Insurance | — | |
|
Freeman Johnson Solicitors are based in County Durham and North Yorkshire. They have been providing legal services to the community for more than 150 years. More than 200Gb of the community data will be available for downloading. Working on it. |
|||||
| Ransomware | Stanford University id9241 View details | Education | — | ||
|
Stanford University is one of the world's leading research universities. Stanford is known for its entrepreneurial character, drawn from the legacy of its founders, Jane and Leland Stanford, and its relationship to Silicon Valley. Soon the university will be also known for 430Gb of internal data leaked online. Private information, confidential documents etc. Who is interested - contact us in messages section. |
|||||
| Ransomware | CMC Group id9207 View details | Construction / Real Estate | — | ||
|
CMC Group is a fully integrated real estate development company focused on luxury residential, commercial and retail properties. 270Gb of data will be available. Very detailed clients informationincluding a DB (addresses, phone numbers, passports/ssns scans etc), confidential documents, contracts projects... And enormous number of accounting files are going to be uploaded. |
|||||
| Ransomware | Royal College of Physicians and Surgeonsof Glasgow id9149 View details | United Kingdom | Education | — | |
|
The Royal College of Physicians and Surgeons of Glasgow, is an institute of physicians and surgeons in Glasgow, Scotland. No one from this college is interested to save personal data of students and employees. Sad but true. You will have the opportunity to download the files (800Gb) soon. |
|||||
| Ransomware | Southland IntegratedServices id9148 View details | Services | — | ||
|
Southland Integrated Services provides a variety of health and social services such as primary care, behavioral health, dental services, and more. All the 40Gb we have will be uploaded soon. Medical records, confidential docs, passports may be found in there. |
|||||
| Ransomware | Protector Fire Services id9147 View details | Australia | Communication / Marketing | — | |
|
PROTECTOR FIRE SERVICES PTY LTD is a Western Australian owned andmanaged company, with a team of trained specialist personnel fully committed to the fire and safety requirements of the commercial & industrial sectors. We saw no interest from them in the incident, so the data will be available for everyone. There are some databases as a bonus. |
|||||
| Ransomware | Visionary Integration Professionals id9142 View details | Services | — | ||
|
Visionary Integration Professionals (VIP) is a technology firm providing tech-enabled business solutions, IT managed services, andmanagement consulting. Inside the 80Gb archive we are going to upload you can find lots of passports, ssns, dls and other id and personal employee information. There are also tons of accounting documents, contracts and confidential files. |
|||||
| Ransomware | Inventum Øst id9141 View details | Norway | Other | — | |
|
Inventum Øst AS is a supplier that supplies "Everything for the office" to companies all over Eastern Norway. We will make available 20Gb of this company data soon. May be even some Norwegians could find something interested there about local companies. |
|||||
| Ransomware | QuadraNet Enterprises id9139 View details | Communication / Marketing | — | ||
|
QuadraNet, since 2001, has been a leader in hosting and data center solutions as a telecommunications provider in Los Angeles and the surrounding areas. They don't want their data back so 640Gb will be uploaded here soon. Passports, ssns and everything we loveis inside. |
|||||
| Ransomware | Healix id8991 View details | Healthcare / Pharma | — | ||
|
Healix provides physician office-based infusion services. We obtained 642Gb of this company data and there is a probability that the files will be available here for downloading next week. Complete personal information set with medical records of thousands patients could be found in the data. Medical staff personal info is presented as well, Wait for the update. |
|||||
| Ransomware | Terwilliger Land Survey Engineers id8968 View details | Services | — | ||
|
Terwilliger Land Survey Engineers offer drone, land survey, and engineering services across multiple business sectors. We will share their 25Gb data here as they don't care about it. You can findthere much of projects information, court documents and other files. |
|||||
| Ransomware | Gruskin Group id8956 View details | Construction / Real Estate | — | ||
|
Gruskin Group is an integrated design firm that builds unified brand experiences through architecture, brand development, visual communications, web/interactive, industrial design, interior design, strategic consulting, and sustainable design. They've lost 37 Gb of data and we wanted help them but they refused. As a result,their files (accounting, HR, projects and so on) will be uploaded here and available for downloading. |
|||||
| Ransomware | Vertical Development id8899 View details | IT | — | ||
|
Vertical Development has helped companies design parts catalogs for over 30 years, both in paper and digital formats. Numerous contracts and agreement, NDAs, confidential docs and employee information of the company will be available soon. |
|||||
| Ransomware | Civic San Diego id8876 View details | Communication / Marketing | — | ||
|
CCDC is the public, non-profit corporation created by the City ofSan Diego to staff and implement Downtown redevelopment projectsand programs. Almost 200Gb of files. Confidential documents, personal information etc. Uploading soon. |
|||||
| Ransomware | The Polish AmericanAssociation id8873 View details | Poland | NGOs / Associations | — | |
|
Have you ever been interested in the US-Poland friendship details? The Polish American Association is ready to share it's internallive secrets. 185GB SQL will be available for downloading soon. Who cares of immigrants, right? |
|||||
| Ransomware | CLX Logistics id8747 View details | Transportation / Travel / Logistics | — | ||
|
CLX Logistics, LLC is a global 3PL provider of transportation management systems, managed services, supply chain consulting and intermodal transportation services for a broad base of industry verticals. We almost finished their data transportation and will upload 26GB of their data soon. Tons of business information: clients, personal information, a few confidential docs. We will update. |
|||||
| Ransomware | Glovis America id8676 View details | Finance / Legal / Insurance | — | ||
|
The company offers technical jobs, human resources support roles,safety supervisors and managers, or strategic management and leadership positions. 10 GB of data will be available for downloading here soon. Some projects info, personal employee documents, financial and accounting papers. |
|||||
| Ransomware | Fuji Seal International (US branch) id8674 View details | Communication / Marketing | — | ||
|
Fuji Seal Group provides shrink sleeve labels, self-adhesive labels, spouted pouches and label-application systems. The US branch of the company has been recently breached and the management refuses to negotiate. So we are informing you about the upcoming uploading of 30GB size data here. There are numerous confidential docs, contracts, agreements etc. |
|||||
| Ransomware | American Steel & Aluminum id8619 View details | Manufacturing / Engineering | — | ||
|
American Steel & Aluminum Co., Inc. was founded in 1967 with 3 employees, a small fabrication shop, and some big dreams for the future. Today they have 70 employees and 70Gb of data that will be uploaded here. There is much project information and financial docs. Employee information is also will be available. |
|||||
| Ransomware | Accuride id8600 View details | India | Finance / Legal / Insurance | — | |
|
Accuride, founded in 1986 and headquartered in Evansville, Indiana, manufactures and supplies vehicle components. Almost terabyte of files will be available for you. Of course there will be many interesting ones. For instance, engineering drawings and photo for TESLA, Mirelli and other sound names. Besides that many confidential documents, personal information of employees with private photo and docs, medical information etc. And finally there is muchinfo about clients and their orders and projects with detailed description (drawings, 3D models). Should I note tons of financialand accounting information? Wait for the release. |
|||||
| Ransomware | Energy One id8512 View details | United Kingdom | Energy | — | |
|
Energy One Limited provides various software products and services to wholesale energy, environmental, and carbon trading markets in the Asia-Pacific, the United Kingdom, and Europe. The company will provide you all with its 77GB data where you will find information on their projects with big business names, financial documents, contracts, and HR information as well. |
|||||
| Ransomware | New York & Company id8405 View details | Communication / Marketing | — | ||
|
New York & Company is a leading specialty manufacturer and retailer of women's fashion apparel and accessories providing women with modern, wear to work solutions that are multi-functional at affordable prices. The company's website has a list of its best deals, with more to be added soon. But I wouldn't say it will be one of the best deals for them. They have broken off the dialog, and at this point we have no choice but to post their corporate fileshere for everyone to see. Stand by for the release. |
|||||
| Ransomware | Children's Home of Wyoming Conference id8404 View details | Healthcare / Pharma | — | ||
|
The Children's Home is a family-centered agency with 16 programs,nearly 300 employees and more than 8 locations. CHWC offer six areas of assistance:Behavioral & Emotional Health, Therapeutic Intervention & Clinical Treatment, Leadership & Development, Physical Health & Wellness, Community Outreach & Civic Engagement, Academic Success & Career Readiness.More than 70Gb personal and company documentation data. |
|||||
| Ransomware | Rivers Casino id8401 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
Rivers Casino is a casino and hotel, that in addition to gambling, offers promotions, dining and entertainment. This is our new client that seems to be offering soon its internal secrets. We willlet you know soon about the breach more detailed. There will be uploaded about 140Gb. |
|||||
| Ransomware | O'Brien Steel Service id8365 View details | Manufacturing / Engineering | — | ||
|
O’Brien Steel Service is stocked and equipped to service customers of all sizes, ranging from small job shops to the largest OEMs in the USA. More than 70 GB of data will be published soon, including:- Financial documents and reports for 22-23 years;- HR;- Projects;- Employment contracts and documents;- IT documents;- Administrative documents.And also: -Contacts.csv - 5069 lines Clietns data;-Customers.csv - 3596 lines of the Companies data; -Competitors.csv - 3470 lines Suppliers data.Wait for the release. |
|||||
| Ransomware | Renton School District id8362 View details | Education | — | ||
|
Renton School District is a public school district serving Renton, Washington. 200Gb of Renton schools will be shared here soon. Business docs, projects information and personal information (e.g.medical staff). Wait for the release. |
|||||
| Ransomware | Green Diamond Resource id8330 View details | Services | — | ||
|
Green Diamond is a fifth-generation, family-owned forest productscompany that owns and manages working forests in nine states throughout the western and southern U.S. Working the forest for so long seems to have taken away the management of this company of their ability to communicate with people. They didn't utter a word for about two weeks after the hack.We found some interesting data on their network and are posting over 30GB of their business information, including personal information, here. |
|||||
| Ransomware | Jasper High School id8319 View details | Education | — | ||
|
Another one school that doesn't care about its students documents. More than 60Gb of data will be released here soon. Many confidential documents of students and employees and even some confidential files. Wait for the release. |
|||||
| Ransomware | Intertek id8317 View details | Services | — | ||
|
Intertek is an international provider of quality and safety services to a wide range of global and local industries. In the pack of more than 300Gb of data you can find all set of information: personal documents, business partners info, confidential agreementsand reports. There is also information about their US affiliate Professional Service Industries. |
|||||
| Ransomware | Penny Publications id8316 View details | Public Sector | — | ||
|
Penny Publications is recognized as North America’s leading puzzle magazine company and is dedicated to providing family-friendly puzzle entertainment of unsurpassed quality. We will make Penny Publications a bit more recognizable for people and upload the data we've taken from this company. 100 Gb will be available for downloading soon. Employee information, confidential documents and financial files can be found in the data as always. |
|||||
| Ransomware | Voss Enterprises, Divvies id8315 View details | Communication / Marketing | — | ||
|
Voss Enterprises (real estate) and Divvies (retail) are two more companies with no hint of a desire to keep their company data safe. We'll post the files of both companies this week. |
|||||
| Ransomware | Cutler-Smith id8314 View details | Finance / Legal / Insurance | — | ||
|
Cutler-Smith, P.C. is a uniquely positioned to deliver big law firm results with the attention, service and efficiencies that onlya boutique law firm can provide. They've lost 50Gb of their clients' data that will be provided here in our blog within this week. |
|||||
| Ransomware | Edmonds School District id8284 View details | United States | Education | — | |
|
Edmonds School District's 35 schools cover approximately 36 square miles within the communities of Brier, Edmonds, Lynnwood, Mountlake Terrace, Woodway and portions of unincorporated Snohomish County. Edmonds School District's data covers approximately 10GB ( sql file) on our server and seems not to be very interested in saving it. So we are ready to share it with everyone interested. I think you can imagine what data will be released: personal students documents, employees info, financials, accounting and much other. We are working on the release. |
|||||
| Ransomware | RIMSS id8182 View details | Agriculture / Food | — | ||
|
RIMSS provides dealer support services to agricultural, truck, construction, and bus dealerships throughout the U.S. RIMSS is one of that companies who doesn't care when their corporate information is open to public. Why shouldn't we share it with people who are interested in such data? Wait for upload. |
|||||
| Ransomware | Camino Nuevo CharterAcademy id8173 View details | Education | — | ||
|
Camino Nuevo Charter Academy educates students in a college preparatory program. We will be uploading their 75GB data shortly. Youwill find some personal information there: ssns, passports, and other business documents. Please expect it soon. |
|||||
| Ransomware | The Clifton Public Schools id8171 View details | Education | — | ||
|
The Clifton Public Schools is a comprehensive community public school district that serves students in pre-kindergarten through twelfth grade. The leadership of this district has priced their school information too cheaply, which is the reason their internal information is here. As always, 60 GB of school documents with detailed personal information will be posted here. |
|||||
| Ransomware | Cequint id8155 View details | Telecommunications | — | ||
|
Cequint Inc. provides caller identification (ID) solutions for mobile devices. 880 GB of data is what we got from their network. Alarge number of different documents. The most interesting in this case are the source codes and information about the company's projects. In addition, as you realize, there are a lot of personaland financial documents. Please wait for the release. |
|||||
| Ransomware | Tally Energy Services id8154 View details | Energy | — | ||
|
Tally Energy Services is an integrated oilfield services company committed to helping our customers “make better wells.” We wantedto help these folks make their cyber defenses a little better, but we failed. Soon you're going to see 130GB of their data here. As always, there's a bunch of personal employee records with medical information and emergency contacts. Financial and incident reports are also prominently displayed. |
|||||
| Ransomware | Rite Technology id8116 View details | IT | — | ||
|
Rite Technology company offers products including copiers, printers, HP products and Sharp Aquos white boards. We will share a zipwith their data of about 15 GB containing good HR data with passport and ssns information of employees. There are also interesting accidents information and business documentation. |
|||||
| Ransomware | The Belt Railway Company of Chicago id8111 View details | Transportation / Travel / Logistics | — | ||
|
The Belt Railway Company of Chicago has a strong safety foundation and history, and employees continuously strive for zero incidents. But there was an incident that caused 85 GB of their data appearing on our server. BRC management decided to stay silent with us so we will upload all their documents soon. |
|||||
| Ransomware | Optimum Technology id8110 View details | IT | — | ||
|
Optimum Technology is dedicated to developing solutions that helpkeep law enforcement and communities safe. They haven't developed any solutions for cyber security yet so we will share 77Gb of their data soon. SQLs, personal docs, and other business information. |
|||||
| Ransomware | Boson id8109 View details | Education | — | ||
|
Boson offers IT learning software to individuals, businesses, academic institutions and government entities around the world. We gained access to their network found some files there. We will upload the soon. |
|||||
| Ransomware | TIMECO id8095 View details | Services | — | ||
|
Thousands of business owners use TIMECO to maximize their billable hours, eliminate time theft, decrease operating costs, and process payroll in minutes. As we've managed to penetrate to the network of this company, some of that businesses are at risk now. Currently, we working on gaining accesses to them. |
|||||
| Ransomware | Räddningstjänsten Västra Blekinge id8077 View details | Public Sector | — | ||
|
Räddningstjänsten Västra Blekinge is a sweden municipal association with three member municipalities: Karlshamn, Olofström and Sölvesborg. As these associations are not interested in saving theircitizens data, we will upload the everything we have on this company here soon. Please wait for an update. |
|||||
| Ransomware | Papel Prensa SA id8076 View details | Argentina | Communication / Marketing | — | |
|
Papel Prensa SA is an Argentina-based company engaged in the manufacture of newsprint paper. Confidential contracts, agreements, personal employee information and other business docs. About 120GB. Please wait for the release. |
|||||
| Ransomware | Koury Engineering id8050 View details | Manufacturing / Engineering | — | ||
|
Koury Engineering provides geotechnical engineering, material testing, and inspection services for residential and commercial construction projects throughout Southern California. More that 80GB of confidential contracts, agreements and NDAs, complete employeedata, projects information and much other documents will be uploaded later. All questions to messages section please. |
|||||
| Ransomware | Venture General Agency id8033 View details | Communication / Marketing | — | ||
|
Venture General Agency, LLC (VGA) is a family run Texas based Managing General Agency. These guys are not very talkative. All the data we have from this company will be released here next week. Personal docs and customer information, contracts and payments details - everything will be shared. If you are interested in something specific, let us know in messages section. |
|||||
| Ransomware | Datawatch Systems id8031 View details | Communication / Marketing | — | ||
|
Datawatch Systems experts work in partnership with you to design,install, and operate a security system to safeguard your facility. It's frustrating when one tries to save someone's property andbecome a victim for himself. We took from these experts 100 GB of data containing confidential agreements and contracts, personal documents, customers data and their projects details. Watch your data! Uploading is coming. |
|||||
| Ransomware | TGRWA id8019 View details | Communication / Marketing | — | ||
|
TGRWA is a structural engineering firm that specializes in new construction, renovation, and investigation services. All the information of employees, projects, financials, and business processesinformation will be released soon. |
|||||
| Ransomware | Guido id8018 View details | Finance / Legal / Insurance | — | ||
|
Guido Companies is a privately held Commercial Construction and Building Materials firm. We hold 115 GB of their corporate data including HR, accounting, financials and so on and so forth. Feel free to check soon! |
|||||