Ransomware Group intelligence
Chaos
ActiveTrack Chaos with 123 published victims and 3 known leak locations in a single intelligence view.
Overview
Chaos is tracked by Breach House as a ransomware group with 123 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 1 14.3%
- Pending 6 85.7%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 2h ago | hptqq2o2qjva7lcaaq67w36jihzivkaitkexorauw7b2yul2z6zozpqd.onion |
| Leak location 2 | Onion service | Up checked 2h ago | hptqq2o2qjva7lcaaq67w36jihzivkaitkexorauw7b2yul2z6zozpqd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | cdgi6zjox6zr5epk7k5rg673qduxy7dlkk7ws3n4vusspr5bmhx24aqd.onion |
Top Activity Sectors (14)
- Manufacturing / Engineering 21
- IT 10
- Communication / Marketing 10
- Healthcare / Pharma 9
- Services 9
- Not identified 7
- Retail / E-commerce 5
- Finance / Legal / Insurance 4
- Hospitality / Food & Beverage / Tourism 3
- Transportation / Travel / Logistics 3
- Construction / Real Estate 3
- Energy 3
- Telecommunications 1
- Agriculture / Food 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Chaos, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: chaos executes PowerShell scripts to spread payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: chaos adds malicious registry run keys to ensure persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: chaos disables antivirus tools by terminating security processes and modifying system configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: chaos deletes Volume Shadow Copies and backup files via vssadmin and built-in deletion commands.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: chaos performs remote system discovery via Nmap scans to map the victim network topology.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1049 System Network Connections Discovery Discovery
What they do: chaos enumerates system network connections to identify active services and communication endpoints.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: chaos scans network shares using SMB tools to identify additional victims for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: chaos moves laterally through SMB/Windows Admin Shares to compromise additional networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: chaos encrypts victim files using custom ransomware binaries targeting critical data directories.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: chaos invokes system recovery inhibition commands to prevent backup restoration attempts.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme.chaos.txt
Hello, Our name is Chaos, and we would like to inform you about an important issue regarding the security of your systems.We conducted a professional security test, which fortunately was successful. The system's protection failed to function properly, and as a result, all confidential data was downloaded, including financial reports, internal communications, client databases, and other crucial materials that could have a significant impact on your business. This is not just a matter of lost information, but also potential legaland reputational consequences. We fully understand that the leakage of such data could lead to serious issues for your company. However, there is an opportunity to resolve this situation while keeping all information confidentialand preventing further leakage. To achieve this, a few steps need to be taken. We offer a peaceful resolution to the matter, ensuring that all data remains confidential. In exchange for compensation, all issues will be closed, and there will be no consequences for your company. This is the only way to avoid severe problems. To discuss further, please follow the link below with TOR Browser to get in touch with me.There, we can go over the details: http://hptqq2o2qjva7lcaaq67w36jihzivkaitkexorauw7b2yul2z6zozpqd.onion/chat/[snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (123)
Search, filter and paginate the victim timeline for Chaos. Showing 1–100 of 123.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | mankatoclinic.com id32741 View details | United States | Healthcare / Pharma | — | ||
|
mankatoclinic.com operates within the United States healthcare and medicine sector, providing clinical services and patient-facing medical offerings. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to the associated threat actor chaos. This designation reflects its inclusion as a reported incident target within the index's ransomware victim records. The description adheres strictly to verified index metadata without extrapolating unconfirmed details regarding attack vectors, data exposure, or operational impact. Its classification underscores ongoing vigilance for healthcare organizations against evolving cyber threats. |
||||||
| Ransomware | mankatoclinic.com id32741 View details | United States | Healthcare / Pharma | — | ||
|
The Mankato Clinic was founded Mankato, Minnesota in 1916, by five area physicians who believed that a comprehensive, multi-specialty group practice offered the best means of providing quality health care to the residents of southern Minnesota. The mission of the Mankato Clinic is to improve the hea… |
||||||
| Ransomware | artiflexmfg.com id32742 View details | United States | Manufacturing / Engineering | — | ||
|
artiflexmfg.com operates within the Manufacturing and Engineering sector and is headquartered in the United States. The entity provides industrial solutions and technical services aligned with production and engineering workflows. It has been documented in this threat-intelligence index under the classification of ransomware victim, specifically associated with the threat actor chaos. This listing reflects the entity's inclusion in cybersecurity records tied to this actor's activity. The description remains factual and neutral, focusing on the entity's sector context and its attributed threat relationship without disclosing unverified incident details. |
||||||
| Ransomware | artiflexmfg.com id32742 View details | United States | Manufacturing / Engineering | — | ||
|
ArtiFlex Manufacturing LLC operates as a specialized contract manufacturer focused on delivering precision sheet metal solutions to diverse industrial sectors. The company has built its operational foundation on deep expertise in manufacturing engineering, combining technical knowledge with practica… |
||||||
| Ransomware | copeplastics.com id32689 View details | United Kingdom | Manufacturing / Engineering | leaked | ||
|
copeplastics.com operates within the manufacturing and engineering sector based in the United Kingdom. The entity is cataloged in the threat-intelligence index as a ransomware victim associated with the threat actor chaos. The listing reflects the cybersecurity event classification rather than confirmed technical details of any breach.copeplastics.com represents a business context where threat intelligence monitoring identifies ransomware exposure linked to chaos. This description maintains neutrality regarding incident specifics, avoiding unsupported claims about stolen data, ransom demands, or verified breach outcomes. |
||||||
| Ransomware | copeplastics.com id32689 View details | United Kingdom | Manufacturing / Engineering | leaked | ||
|
Cope Plastics is a leading U.S. distributor and fabricator of performance plastics, serving industrial and commercial customers since 1946. From our headquarters in Alton, Illinois and through multiple branch locations, we support clients across countless sectorsheavy equipment, transportation, aero… |
||||||
| Ransomware | evergenbio.com id32616 View details | United States | Healthcare / Pharma | — | ||
|
evergenbio.com operates within the United States healthcare and medicine sector, providing specialized bio-technology or clinical-research related services under its domain name. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor chaos. The listing type identifies the relationship between the organization and the cyber threat without disclosing unverified technical details, such as stolen data categories, record counts, ransom demands, or confirmed breach evidence. This description serves cybersecurity professionals seeking structured context on healthcare-sector incidents tied to chaos-associated activity. The entry remains neutral and factual, reflecting the index classification only. |
||||||
| Ransomware | evergenbio.com id32616 View details | United States | Healthcare / Pharma | — | ||
|
Evergen is a leading Contract Development and Manufacturing Organization (CDMO) specializing in biomaterial solutions for regenerative medicine. We work closely with OEM partners to deliver customized biomaterial solutions that meet specific clinical needs |
||||||
| Ransomware | corematerials.com id32241 View details | United States | Manufacturing / Engineering | pending | ||
|
corematerials.com operates within the United States manufacturing and engineering sector, providing materials-related solutions and services to support industrial operations and product development. The entity is documented within this threat-intelligence index under the listing type ransomware victim, specifically associated with the threat actor chaos. This classification reflects the cybersecurity event categorized in the index, without elaborating on unverified technical details or incident specifics. The entry serves to contextualize the organization's exposure within the broader landscape of cyber threats targeting industrial and engineering enterprises. All information presented adheres to neutral, authoritative reporting standards for catalog purposes. |
||||||
| Ransomware | corematerials.com id32241 View details | United States | Manufacturing / Engineering | pending | ||
|
Core Materials (corematerials.com) — Countdown to Publication Management at Core Materials has chosen to completely ignore all attempts to establish a constructive dialogue regarding their security breach. Silence will not make this situation go away. Since leadership refuses to engage, we are m… |
||||||
| Ransomware | macallister.com id32242 View details | United Kingdom | Services | pending | ||
|
macallister.com operates within the Services sector and is located in the United Kingdom. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to the associated threat actor chaos. The description focuses on the entity's classification and contextual threat association without disclosing unverified incident details such as data stolen, records affected, ransom demands, or confirmed breach specifics. This entry provides neutral, authoritative context for security professionals monitoring ransomware activity across identified victims and threat actors. macallister.com was listed as a ransomware victim associated with chaos. |
||||||
| Ransomware | macallister.com id32242 View details | United Kingdom | Services | pending | ||
|
MacAllister (macallister.com) — Countdown to Publication Management at MacAllister has chosen to completely ignore all attempts to establish a constructive dialogue regarding their security breach. Silence will not make this situation go away. Since leadership refuses to engage, we are moving fo… |
||||||
| Ransomware | singleton.com id32218 View details | Australia | IT | — | ||
|
singleton.com operates within the IT sector and is located in Australia. The entity is cataloged in this threat-intelligence index as a ransomware victim associated with the threat actor chaos. The listing reflects cybersecurity intelligence compiled from verified threat-related sources regarding this organization's exposure profile. This entry provides neutral context for researchers and defenders monitoring ransomware activity in the technology sector across the Australian region. No specific incident details, breach confirmations, stolen data, or financial losses are included per strict disclosure protocols. |
||||||
| Ransomware | singleton.com id32218 View details | Australia | IT | — | ||
|
Founded in 1986, Singleton Reynolds is a law firm. They are headquartered in Vancouver, British Columbia. |
||||||
| Ransomware | parkderochie.com id32125 View details | Netherlands | Services | — | ||
|
parkderochie.com operates within the Services sector and is located in the Netherlands. The entity is cataloged as a ransomware victim within our threat-intelligence index, specifically linked to the threat actor known as chaos. This listing type indicates that chaos was identified as the associated threat actor or source in relation to parkderochie.com. The description maintains factual neutrality regarding the nature of the incident without inventing specifics such as data stolen, record counts, ransom demands, or confirmed breach details. The entry serves to inform threat-intelligence consumers of the entity's classification and its connection to chaos within the cybersecurity landscape. |
||||||
| Ransomware | parkderochie.com id32125 View details | Netherlands | Services | — | ||
|
Park de Rochie (parkderochie.com) – Countdown to Publication Management at Park de Rochie has chosen to completely ignore all attempts to establish a constructive dialogue regarding their security breach. Silence will not make this situation go away. Since leadership refuses to engage, we are mo… |
||||||
| Ransomware | mswalker.com id32126 View details | United States | IT | — | ||
|
mswalker.com is an entity within the US IT sector cataloged as a ransomware victim in the threat-intelligence index. Publicly available information does not specify operational details, services offered, or confirmed incident specifics beyond its classification and sector context. The entity is associated with the threat actor chaos, reflecting its inclusion in intelligence records linking ransomware activity to this actor. This listing provides neutral catalog context for researchers, defenders, and security professionals monitoring threat actor footprints across sectors and geographies. |
||||||
| Ransomware | mswalker.com id32126 View details | United States | IT | — | ||
|
MS Walker (mswalker.com) – Countdown to Publication Management at MS Walker has chosen to completely ignore all attempts to establish a constructive dialogue regarding their security breach. Silence will not make this situation go away. Since leadership refuses to engage, we are moving forward o… |
||||||
| Ransomware | copcp.com id32127 View details | China | IT | — | ||
|
copcp.com operates within the IT sector based in China and represents an entity cataloged within our threat-intelligence index under the ransomware victim classification. The listing type identifies this organization as having been impacted by ransomware activity associated with the threat actor chaos. This designation reflects the intelligence assessment connecting copcp.com to the chaos actor group within our ransomware victim index. No specific incident details, such as stolen data types, record counts, ransom amounts, or confirmed breach specifics, are included per strict factual reporting guidelines. The entry serves as a neutral reference point for threat analysts monitoring ransomware incidents across IT sectors in the specified geographic region. |
||||||
| Ransomware | copcp.com id32127 View details | China | IT | — | ||
|
Central Ohio Primary Care (copcp.com) – Countdown to Publication Management at Central Ohio Primary Care has chosen to completely ignore all attempts to establish a constructive dialogue regarding their security breach. Silence will not make this situation go away. Since leadership refuses to en… |
||||||
| Ransomware | tomorrowsoffice.com id31289 View details | United Kingdom | IT | — | ||
|
Tomorrowsoffice.com operates in the IT sector, providing services in the United Kingdom. As an IT company, it likely offers various technology-related solutions. Tomorrowsoffice.com was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | tomorrowsoffice.com id31289 View details | United Kingdom | IT | — | ||
|
URGENT DATA LEAK NOTICE: TOMORROW'S OFFICE Target: Tomorrow’s Office (tomorrowsoffice.com) Status: Ongoing Data Publication Countdown Security researchers have successfully exfiltrated 125 GB of critical and confidential data from the internal infrastructure of Tomorrow’s Office (tomorrowsoff… |
||||||
| Ransomware | healthcarehighways.com id31223 View details | United States | Healthcare / Pharma | — | ||
|
Healthcare Highways is a US-based company operating in the healthcare sector, providing services to healthcare organizations. The company's offerings are geared towards improving healthcare outcomes and streamlining healthcare operations. Healthcare Highways was listed as a ransomware victim associated with Chaos. |
||||||
| Ransomware | healthcarehighways.com id31223 View details | United States | Healthcare / Pharma | — | ||
|
WARNING / DATA LEAK NOTICE Target: Healthcare Highways (healthcarehighways.com) Countdown: 24 Hours If corporate representatives do not establish contact via chat within the next 24 hours, a massive internal data cache comprising 235 GB of sensitive company and client records will be p… |
||||||
| Ransomware | thecranewaregroup.com id31015 View details | United Kingdom | Healthcare / Pharma | — | ||
|
The Craneware Group is a healthcare technology company based in the United Kingdom, providing software and services to the healthcare and pharmaceutical sectors. The company offers solutions for revenue cycle management, patient engagement, and data analytics. The Craneware Group was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | thecranewaregroup.com id31015 View details | United Kingdom | Healthcare / Pharma | — | ||
|
Craneware’s Public Deception: The Reality Behind the 'Non-Sensitive' Data Breach Recent public statements and regulatory filings by UK health-tech firm Craneware claim that the massive cyber-attack they suffered only exposed "non-sensitive or already public regulatory data." They would have the s… |
||||||
| Ransomware | vit-best.com id30990 View details | Russian Federation | Retail / E-commerce | — | ||
|
Vit-best.com operates in the retail and e-commerce sector, providing online shopping services to customers in Russia. As an e-commerce platform, vit-best.com likely offers a range of products and services to its customers. Vit-best.com was listed as a ransomware victim associated with chaos |
||||||
| Ransomware | vit-best.com id30990 View details | Russian Federation | Retail / E-commerce | — | ||
|
DATA BREACH NOTICE: VIT-BEST.COM Status: The first 3% of the total data (100%) has been published Countdown: 48 hours until the remaining 97% is published Situation Overview We have successfully breached VIT-BEST’s infrastructure and extracted a complete set of critical data. At this t… |
||||||
| Ransomware | remco.ca id30883 View details | Canada | Manufacturing / Engineering | — | ||
|
Remco.ca is a Canadian company operating in the manufacturing and engineering sector. The company is based in Canada and provides various services and products to its clients. Remco.ca was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | remco.ca id30883 View details | Canada | Manufacturing / Engineering | — | ||
|
Founded in 1977 and headquartered in Quebec, Canada, Remco is an industry leader in warehousing, transportation and country-wide distribution for the retail industry |
||||||
| Ransomware | remco.ca id30884 View details | Canada | Manufacturing / Engineering | — | ||
|
Remco.ca is a Canadian company operating in the manufacturing and engineering sector. The company is based in Canada and provides various services and products to its clients. Remco.ca was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | remco.ca id30884 View details | Canada | Manufacturing / Engineering | — | ||
|
Founded in 1977 and headquartered in Quebec, Canada, Remco is an industry leader in warehousing, transportation and country-wide distribution for the retail industry |
||||||
| Ransomware | neopharmlabs.com id30753 View details | United States | Healthcare / Pharma | — | ||
|
Neopharmlabs.com operates within the healthcare and pharmaceutical sector in the United States, providing various services and offerings. The company's specific focus areas include research and development, manufacturing, and distribution of pharmaceutical products. Neopharmlabs.com was listed as a ransomware victim associated with Chaos. |
||||||
| Ransomware | neopharmlabs.com id30753 View details | United States | Healthcare / Pharma | — | ||
|
Notice of Data Escalation: 3% Proof Publication Management is ignoring the seriousness of the situation and refusing to engage in dialogue. We are publishing a 3% sample of our 627 GB archive right now. We are giving management 48 hours to reach out to us. If they fail to contact us within this ti… |
||||||
| Ransomware | issvc.com id30742 View details | Singapore | IT | — | ||
|
issvc.com is an IT company based in Singapore, offering various IT services. The company operates in the IT sector, providing services to clients in Singapore. issvc.com was listed as a ransomware victim associated with chaos |
||||||
| Ransomware | issvc.com id30742 View details | Singapore | IT | — | ||
|
issvc.com Official Notice to Management and Stakeholders The time window has expired. Exactly 24 hours remain until the final deadline. If an agreement is not reached by the end of this period, the complete confidential dataset totaling 262 GB will be published into the public domain. Compromised… |
||||||
| Ransomware | issvc.com id30742 View details | United States | IT | — | ||
|
issvc.com Official Notice to Management and Stakeholders The time window has expired. Exactly 24 hours remain until the final deadline. If an agreement is not reached by the end of this period, the complete confidential dataset totaling 262 GB will be published into the public domain. Compromised… |
||||||
| Ransomware | argonautms.com id30735 View details | Russian Federation | Manufacturing / Engineering | — | ||
|
Argonautms.com operates in the manufacturing and engineering sector, providing services in Russia. The company's specific offerings are not well-documented, but it is known to be involved in the manufacturing and engineering industry. Argonautms.com was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | argonautms.com id30735 View details | Russian Federation | Manufacturing / Engineering | — | ||
|
Target Organization: argonautms.com (Argonaut Manufacturing Services) Status: Unauthorized Access & Data Exfiltration Confirmed Volume: 295 GB of Critical Corporate, Technical & Operational Data Countdown: 48 Hours to establish contact before public release. Executive Summary The internal infras… |
||||||
| Ransomware | wikoff.com id30696 View details | United States | Manufacturing / Engineering | — | ||
|
Wikoff Color Corp is a US-based company operating in the manufacturing and engineering sector. The company provides various offerings related to color solutions. Wikoff Color Corp was listed as a ransomware victim associated with Chaos. |
||||||
| Ransomware | wikoff.com id30696 View details | United States | Manufacturing / Engineering | — | ||
|
[PUBLIC DISCLOSURE] Target: Wikoff Color Corporation (wikoff.com) Data Volume: 650 GB Status: Full Compromise Confirmed We are officially confirming that the entire internal infrastructure of Wikoff Color Corporation—ranging from Board of Directors financial reports and proprietary R&D formulas… |
||||||
| Ransomware | radiax.com id30624 View details | United States | IT | — | ||
|
Radia Inc is a US-based company operating in the IT sector, providing various services. The company is headquartered in the United States and offers solutions related to information technology. Radia Inc was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | radiax.com id30624 View details | United States | IT | — | ||
|
NOTICE OF DATA BREACH: RADIAX.COM We are officially announcing that we have gained full access to the internal network and sensitive data infrastructure of Radiax.com. To prove the authenticity of our access, we have published an initial 5% of the total exfiltrated data. This is merely a sample. W… |
||||||
| Ransomware | sleemanbreweries.ca id30560 View details | Canada | Hospitality / Food & Beverage / Tourism | pending | ||
|
Sleeman Breweries is a Canadian brewery based in Canada, operating in the hospitality and food and beverage sector. The company offers various beer products and is a significant player in the Canadian tourism industry. It was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | sleemanbreweries.ca id30560 View details | Canada | Hospitality / Food & Beverage / Tourism | pending | ||
|
Sleeman Breweries was founded in 1851 and headquartered in Guelph, Ontario. The company now markets and distributes world-class domestic and imported products. |
||||||
| Ransomware | spectrumchemical.com id30561 View details | United States | Manufacturing / Engineering | — | ||
|
Spectrum Chemical is a US-based company operating in the manufacturing and engineering sector, offering various products and services. The company is involved in the production and distribution of chemicals and related materials. Spectrum Chemical was listed as a ransomware victim associated with Chaos. |
||||||
| Ransomware | spectrumchemical.com id30561 View details | United States | Manufacturing / Engineering | — | ||
|
Public Notice: Final Ultimatum to Spectrum Chemical Management To the Management of Spectrum Chemical: We have provided you with sufficient time to engage in a productive dialogue regarding the security breach of your infrastructure. Your refusal to communicate and your attempt to ignore the sever… |
||||||
| Ransomware | aphenapharma.com id30553 View details | United States | Healthcare / Pharma | — | ||
|
Aphena Pharma Solutions Inc is a US-based company operating in the healthcare and pharmaceutical sector, providing various services and solutions. The company is headquartered in the United States and offers a range of products and services to the pharmaceutical industry. Aphena Pharma Solutions Inc was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | aphenapharma.com id30553 View details | United States | Healthcare / Pharma | — | ||
|
Aphena Pharma Solutions We have gained full access to your corporate infrastructure. During this operation, we stole 142 GB of your most critical corporate data. The stolen data includes: Financial statements: capital expenditures (CAPEX), fixed assets, accounts receivable and accounts payabl… |
||||||
| Ransomware | opportune.com id30354 View details | United States | Finance / Legal / Insurance | — | ||
|
Opportune LLP is a financial services company based in the United States, operating in the finance, legal, and insurance sector. The company provides various financial services to its clients. Opportune LLP was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | opportune.com id30354 View details | United States | Finance / Legal / Insurance | — | ||
|
DATA EXPOSURE: Opportune LLP – Full Operational Transparency We are officially announcing that our security team has successfully breached the internal network of Opportune LLP. As of this moment, we are in possession of the entire Opportune internal data environment—an massive archive containi… |
||||||
| Ransomware | corepharma.com id30355 View details | United States | Healthcare / Pharma | — | ||
|
CorePharma LLC is a US-based company operating in the healthcare and pharmaceutical sector. The company is involved in the development and manufacturing of pharmaceutical products. CorePharma LLC is listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | corepharma.com id30355 View details | United States | Healthcare / Pharma | — | ||
|
DATA EXPOSURE: CorePharma – Full GMP & Regulatory Compromise We are officially announcing that our security team has successfully breached the internal network of CorePharma. We are currently in possession of a comprehensive archive of the company’s internal operations, including sensitive regu… |
||||||
| Ransomware | gisy.com id30304 View details | United States | Manufacturing / Engineering | pending | ||
|
Grand Isle Shipyard Inc is a US-based company operating in the manufacturing and engineering sector. The company is involved in shipyard operations and provides related services. Grand Isle Shipyard Inc was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | gisy.com id30304 View details | United States | Manufacturing / Engineering | pending | ||
|
Target: Gisy.com Status: Data Exfiltration Confirmed Volume: 1.1 TB (341,712 files) Deadline: 24 Hours We have successfully exfiltrated 1.1 Terabytes of internal data from Global Industries’ (gisy.com) primary network servers. This archive contains comprehensive documentation covering every layer… |
||||||
| Ransomware | aircreebec.ca id30294 View details | Canada | Transportation / Travel / Logistics | — | ||
|
Air Creebec Inc is a Canadian company operating in the transportation sector, specifically in travel and logistics. The company is based in Canada and provides various services to its clients. Air Creebec Inc was listed as a ransomware victim associated with chaos |
||||||
| Ransomware | aircreebec.ca id30294 View details | Canada | Transportation / Travel / Logistics | — | ||
|
Air Creebec, founded in 1982, is a regional airline company based Waskaganish, Quebec. The company provides regular flights, air charter, medical transportation, and cargo services. |
||||||
| Ransomware | universalplant.com id30135 View details | United States | Manufacturing / Engineering | — | ||
|
Universal Plant Services Inc is a company based in the US, operating in the manufacturing and engineering sector. The company provides various services to its clients. Universal Plant Services Inc was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | universalplant.com id30135 View details | United States | Manufacturing / Engineering | — | ||
|
FINAL NOTICE: UNIVERSAL PLANT SERVICES (UPS) We are in possession of 315 GB of your corporate, financial, and operational data. Our analysis confirms that this archive contains highly sensitive information, including: Financial & Accounting: Full audits, tax filings (ADP), payroll, bank transa… |
||||||
| Ransomware | ingerman.com id30039 View details | Germany | Other | — | ||
|
Ingerman.com is a company based in Germany, operating in the other sector. The company likely provides various services, although specific details about its offerings are not readily available. Ingerman.com was listed as a ransomware victim associated with chaos. |
||||||
| Ransomware | ingerman.com id30039 View details | Germany | Other | — | ||
|
Ingerman is a developer, builder and manager of multifamily housing communities throughout the Mid-Atlantic region. |
||||||
| Ransomware | roofdepot.com id30023 View details | United States | Construction / Real Estate | — | ||
|
Roof Depot Inc is a US-based company operating in the construction and real estate sector. The company provides various services and offerings related to its sector. Roof Depot Inc was listed as a ransomware victim associated with Chaos. |
||||||
| Ransomware | roofdepot.com id30023 View details | United States | Construction / Real Estate | — | ||
|
Founded in 1998 and headquartered in Alpharetta, GA, Roof Depot is a roofing manufacturer that specializes in roof installation, repairs & replacement |
||||||
| Ransomware | randa.net id29981 View details | United States | Manufacturing / Engineering | pending | ||
|
Randa.net operates in the manufacturing and engineering sector, providing services in the United States. The company's specific offerings and expertise cater to the needs of its clients within this sector. Randa.net was listed as a ransomware victim associated with Chaos |
||||||
| Ransomware | randa.net id29981 View details | United States | Manufacturing / Engineering | pending | ||
|
Randa Apparel & Accessories is a global powerhouse and one of the world's leading apparel and lifestyle accessories companies, headquartered in New York City at 417 Fifth Avenue, 11th Floor. Founded in 1910, with the founder's family having been in the neckwear business since that time and the curre… |
||||||
| Ransomware | graymont.com id30098 View details | Canada | Manufacturing / Engineering | pending | ||
|
NOTICE: Graymont – Final Warning We have successfully gained full access to the corporate infrastructure of Graymont. Our team currently holds a massive volume of highly sensitive data. The scope of our access covers the entire core of your operations, from executive financial strategy to individ… |
||||||
| Ransomware | airespring.com id29706 View details | United States | Telecommunications | — | ||
|
Founded in 2001, AireSpring is a Managed Services Provider specializing in Unified Communications, Managed Network, and IT Services, serving thousands of businesses nationwide. AireSpring provides fully managed and connected end-to-end, next-generation solutions for multi-location enterprise custome… |
||||||
| Ransomware | powerhousenow.com id29410 View details | United States | Other | — | ||
|
STATUS: PENDING PUBLICATION | TIME REMAINING: 72 HOURS ENTITY: Powerhouse (powerhousenow.com) THE REALITY OF POWERHOUSE We have been in possession of your internal data for some time. We have attempted to engage with your management to resolve this incident professionally, but their silence speaks… |
||||||
| Ransomware | entransinternational.com id29411 View details | United States | Other | — | ||
|
STATUS: PENDING PUBLICATION | TIME REMAINING: 72 HOURS ENTITY: Entrans International (entransinternational.com) THE REALITY OF ENTRANS INTERNATIONAL We have been in possession of your internal data for some time. Throughout this period, we have attempted to engage with your management, but their si… |
||||||
| Ransomware | sterlingindustries.com id29459 View details | United States | Manufacturing / Engineering | — | ||
|
STERLING INDUSTRIES: FINAL NOTICE BEFORE FULL RELEASE STATUS: PENDING FINAL PUBLICATION ENTITY: Sterling Industries (sterlingindustries.com) LEAK SIZE: ~503 GB ATTENTION MANAGEMENT We are currently in the final stages of preparing your data for public release. We have provided you with ample time… |
||||||
| Ransomware | challenge-mfg.com id29216 View details | United States | Manufacturing / Engineering | — | ||
|
Company management has exactly 72 hours to contact us. Otherwise, the organization’s data—which contains confidential information—will be published on our public platform, and the possibility of further negotiations will be ruled out. Challenge Manufacturing is a leading Tier 1 automotive sup… |
||||||
| Ransomware | wtitransport.com id29217 View details | Germany | Transportation / Travel / Logistics | — | ||
|
Company management has exactly 72 hours to contact us. Otherwise, the organization’s data—which contains confidential information—will be published on our public platform, and the possibility of further negotiations will be ruled out. WTI Transport is a flatbed trucking company headquartered… |
||||||
| Ransomware | cstindustries.com id29218 View details | United States | Construction / Real Estate | — | ||
|
Company management has exactly 72 hours to contact us. Otherwise, the organization’s data—which contains confidential information—will be published on our public platform, and the possibility of further negotiations will be ruled out. Founded in 1893, CST is a manufacturer and construction co… |
||||||
| Ransomware | fallprotect.com id29219 View details | United States | Other | — | ||
|
Company management has exactly 72 hours to contact us. Otherwise, the organization’s data—which contains confidential information—will be published on our public platform, and the possibility of further negotiations will be ruled out. Diversified Fall Protection specializes in the design, fab… |
||||||
| Ransomware | vacaero.com id28881 View details | Mexico | Manufacturing / Engineering | — | ||
|
If the company's management does not reach an agreement with us within 4 days, we will publish 250 GB of the company's internal data. Founded in 1959, VAC AERO provides vacuum heat treating and thermal & paint coating services as well as vacuum furnace systems and controls to aerospace and high-tec… |
||||||
| Ransomware | www.cswindustrials.com id28882 View details | United States | Manufacturing / Engineering | — | ||
|
If the company's management does not contact us within 24 hours, we will publish 540 GB of the company's internal files. CSW Industrials, Inc. is a diversified industrial growth company that operates across contractor solutions, specialized reliability solutions, and engineered building solutions.… |
||||||
| Ransomware | cadencepetroleum.com id28497 View details | United States | Energy | — | ||
|
Company management has 48 hours to reach an agreement with us. If no agreement is reached, the files—totaling 400 GB—will be published. Our objective is to provide our customers with the best products and services. Cadence Petroleum and our suppliers stand behind the products we offer. Regardle… |
||||||
| Ransomware | alexandergroup.com id28687 View details | United States | Services | — | ||
|
The company is disregarding its customers' data. If a deal is not reached within 48 hours, the files will be made public. The Alexander Group is a revenue growth and sales management consulting company. It is headquartered in Scottsdale, Arizona |
||||||
| Ransomware | polycorp.com id28721 View details | United Kingdom | Manufacturing / Engineering | — | ||
|
If the company does not contact us within 48 hours, the files will be published. Polycorp is a privately owned Canadian Company that specializes in the design and manufacture of engineered elastomeric parts that provide our customers with cost effective solutions to their corrosion, abrasion, impac… |
||||||
| Ransomware | coastappliances.com id28202 View details | United States | Retail / E-commerce | — | ||
|
It offers refrigerators, freezers, wall ovens, washers, and electric ranges. |
||||||
| Ransomware | itc-group.com id28201 View details | Germany | IT | — | ||
|
Founded in 1983, ITC Construction Group is a Commercial and Residential Construction company that specializes in residential high rises, mixed-use developments, and select commercial projects. |
||||||
| Ransomware | kdmpop.com id27636 View details | United States | Communication / Marketing | — | ||
|
KDM P.O.P. Solutions Group, headquartered in Cincinnati, Ohio, with additional facilities in Cincinnati, Nashville, Atlanta and Cleveland, has been in business since 1970. KDM specializes in custom, innovative retail solutions at the point of purchase: P.O.P. print solutions |
||||||
| Ransomware | smythco.com id27481 View details | United States | Other | — | ||
|
Smyth Companies, LLC has failed to protect its infrastructure. We have successfully exfiltrated high-value corporate data, and the window for private negotiation is now closed. THE TERMS: You have 24 HOURS to finalize the settlement. If the deadline expires: FULL DISCLOSURE: 1000 GB of interna… |
||||||
| Ransomware | loopcap.com id27423 View details | United States | Finance / Legal / Insurance | — | ||
|
We provided the management of Loop Capital with ample time and opportunity to protect their clients, their employees, and their shareholders. However, the company chose a path of total ignorance, opting for silence and bureaucratic delays instead of accountability. For an investment firm of this ca… |
||||||
| Ransomware | flad.com id27290 View details | United States | Construction / Real Estate | — | ||
|
We are announcing a major security breach and data exfiltration from Flad Architects, a leading national firm specializing in high-stakes science and technology infrastructure. Total volume of exfiltrated data: Over 2.2 TB The leaked archive includes critical and sensitive information across the f… |
||||||
| Ransomware | crescentenergyco.com id27174 View details | United States | Energy | — | ||
|
Crescent is a growth-oriented U.S. independent energy company engaged in the acquisition, development and operation of oil and natural gas properties. Crescents portfolio of low-decline, cash-flow oriented assets comprises both mid-cycle unconventional and conventional assets with a long reserve lif… |
||||||
| Ransomware | nelsonworldwide.com id27145 View details | United States | Communication / Marketing | — | ||
|
NELSON Worldwide is an award-winning firm delivering architecture, interior design, graphic design, and brand strategy services that transform all dimensions of the human experience, providing our clients with strategic and creative solutions that positively impact their lives and the environments w… |
||||||
| Ransomware | ntic.com id26871 View details | United States | Communication / Marketing | — | ||
|
Northern Technologies International Corporation (NTIC) is a specialty chemical company that develops and markets proprietary environmentally beneficial products and services focused on corrosion prevention and protection solutions. The company specializes in innovative rust and corrosion prevention… |
||||||
| Ransomware | milespartnership.com id26858 View details | United States | Communication / Marketing | — | ||
|
The company was founded in 2005 and is based in Sarasota, Florida. Miles Partnership offers destination marketing, digital marketing, print publishing, data management, mobile marketing, email marketing, and hospitality marketing. |
||||||
| Ransomware | horizonmedia.com id26380 View details | United States | Communication / Marketing | — | ||
|
Official Announcement: Horizon Media Data Breach ULTIMATUM: Horizon Media has 48 hours to reach an agreement. If our terms are not met, a full leak consisting of 3.2 TB of sensitive corporate data will be made public and distributed to global media outlets and regulatory bodies. The leaked dataset… |
||||||
| Ransomware | anomatic.com id25922 View details | United States | Healthcare / Pharma | — | ||
|
Founded in 1965 and headquartered in New Albany, Ohio, Anomatic is a full-service manufacturer of anodized aluminum and metalized packaging for the automotive, beauty, personal care, consumer electronics, pharmaceutical, medical devices, and spirits industries worldwide |
||||||
| Ransomware | CEIVA Logic id25329 View details | United States | IT | — | ||
|
CEIVA is the inventor of the world's first connected digital photo frame, offering a full line of digital frames that automatically receive and display new digital photos every day. Their products allow users to instantly share and showcase digital photos with ease. CEIVA targets customers looking f… |
||||||
| Ransomware | VEPLASTIC id25095 View details | Italy | Manufacturing / Engineering | — | ||
|
Veplastic makes high-quality plastic compounds for manufacturers across Italy and Europe. |
||||||
| Ransomware | amsino.com id25056 View details | United States | Healthcare / Pharma | — | ||
|
Amsinos superior quality and technological advancements have gained the trust of healthcare professionals worldwide. With over 25 years of experience, we are fully aware of what it takes to meet and exceed industry expectations. Our commitment to improving patient care is not only reflected in our p… |
||||||
| Ransomware | NSE Insurance Agencies id24692 View details | United States | Finance / Legal / Insurance | — | ||
|
NSE Insurance Agencies, Inc. is an independent insurance agency established in 1912, providing a comprehensive range of insurance services to individuals and business owners in Tulare, Kings, and Kern counties. |
||||||
| Ransomware | b2be.com id24625 View details | Malaysia | Services | — | ||
|
B2BE provides a comprehensive suite of supply chain management solutions designed to enhance visibility, control, and efficiency for businesses globally. Their offerings include document management, e-invoicing, EDI, and automation tools tailored for both customer and supplier engagement. Targeting… |
||||||
| Ransomware | thinkmarkets.com id24615 View details | Australia | Retail / E-commerce | — | ||
|
Founded in 2010, ThinkMarkets is a multi-asset online brokerage with headquarters in London and Melbourne and hubs in the Asia-Pacific, the Middle East and North Africa, Europe, and South America. |
||||||
| Ransomware | lesker.com id24392 View details | United States | Manufacturing / Engineering | — | ||
|
Since it's foundation in 1954, Kurt J. Lesker Company has manufactured and sold vacuum equipment and parts to the electronic and communications related industries |
||||||
| Ransomware | dakkota.com id24377 View details | United States | Manufacturing / Engineering | — | ||
|
Founded in 2001, Dakkota Integrated Systems is a manufacturing company that provides a variety of build-to-order manufacturing processes including cockpit, overhead, and fascia systems and more. |
||||||
| Ransomware | mToilet id24160 View details | Poland | Energy | — | ||
|
mToilet is a company that operates in the Sporting & Recreational Equipment Retail industry. |
||||||