Ransomware Group intelligence
Direwolf
ActiveTrack Direwolf with 175 published victims and 1 known leak locations in a single intelligence view.
Overview
Direwolf is tracked by Breach House as a ransomware group with 175 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 36 49.3%
- Pending 36 49.3%
- Deleted 1 1.4%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 1h ago | direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion |
Top Activity Sectors (16)
- Manufacturing / Engineering 19
- Finance / Legal / Insurance 14
- Services 13
- IT 12
- Healthcare / Pharma 11
- Communication / Marketing 10
- Not identified 7
- Transportation / Travel / Logistics 5
- Retail / E-commerce 5
- Construction / Real Estate 4
- Agriculture / Food 3
- Telecommunications 2
- Education 2
- Energy 1
- Public Sector 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Direwolf, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: direwolf executes PowerShell scripts to stage payloads and manipulate system processes before encryption.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: direwolf leverages native API calls to interact with Windows services and evade detection during lateral movement.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: direwolf adds malicious registry run keys to ensure persistence across reboots on compromised hosts.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: direwolf disables antivirus tools and security software using registry modifications and service interference.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: direwolf deletes Volume Shadow Copies and backup folders via vssadmin and command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: direwolf performs remote system discovery via Nmap scans to map network topology before deploying ransomware.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1083 File and Directory Discovery Discovery
What they do: direwolf discovers files and directories using Windows Explorer APIs to identify critical data for encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: direwolf moves laterally through SMB shares to access additional systems within the victim network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: direwolf encrypts victim files using custom symmetric encryption routines targeting business documents and backups.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: direwolf halts critical system recovery processes and service restarts to maximize operational disruption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
HowToRecoveryFiles.txt
Dear Mr or Ms,
If you are reading this message, it means that:
- your network infrastructure has been compromised
- critical data was leaked
- We decrypted your encrypted files. The anti-leakage system is useless to us. We can provide proof.
- files are encrypted
--------------------------------------------------------------------------
The best and only thing you can do is to contact us
to settle the matter before any losses occurs.
--------------------------------------------------------------------------
We can maintain confidentiality for 3 days for you, during which we will not disclose any information about your intrusion or data leakage.
We can extend the confidentiality period free of charge until we reach an agreement if you contact us within 3 days and communicate effectively with us.
If the confidentiality period expires, we will disclose the relevant information.
We provide complimentary decryption testing services. For specific details, please contact us.
--------------------------------------------------------------------------
We have provided a sample document as proof of our possession of your files and you can download and check it:
- https://gofile.io/d/[snip]
Please be advised that your files are scheduled for public release after 30 working days.
If you want to secure your files, we urge you to reach out to us at your earliest convenience.
--------------------------------------------------------------------------
Contact Details:
- live chat room:
- url:http://direwolf3ddtab5anvhulcelauvoxu2a7l264hqs6vtxtgrqsjfvodid.onion/
- roomID: [snip]
- username: [snip]
- password: [snip]
--------------------------------------------------------------------------
Our official website:
- url:http://direwolfcdkv5whaz2spehizdg22jsuf5aeje4asmetpbt6ri4jnd4qd.onion/
--------------------------------------------------------------------------
How to access .onion website:
1.Download and install TOR Browser https://torproject.org
2.Open it and try to access our onion address
3.Maybe you need to use VPN if it can not open our onion address
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (175)
Search, filter and paginate the victim timeline for Direwolf. Showing 1–100 of 175.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Port of Tanjung Pelepas id32758 View details | Malaysia | Telecommunications | — | ||
|
ptp.com.my operates within the telecommunications sector in Malaysia (MY), providing digital connectivity and related communications services to clients and infrastructure. As a ransomware victim, it appears in threat-intelligence indexing under association with the Direwolf threat actor, reflecting observed cybersecurity event correlations. This listing type documents the entity's exposure within the broader ransomware threat landscape, contextualized by its sector and geographic location without disclosing unverified incident specifics. The record serves threat analysts and cybersecurity stakeholders to assess risk patterns affecting My telecommunications entities and understand Direwolf's operational footprint. |
||||||
| Ransomware | Port of Tanjung Pelepas id32758 View details | Malaysia | Telecommunications | — | ||
|
Marine Shipping & Transportation |
||||||
| Ransomware | RelyComply AML Platform id32714 View details | United Kingdom | IT | pending | ||
|
relycomply.com operates within the IT sector and is situated in the United Kingdom. As documented in this threat-intelligence index, the entity is classified as a ransomware victim linked to the Direwolf threat actor. The listing reflects observed cybersecurity event data tied to Direwolf activity within the technology sector. This catalog entry provides structured context for threat researchers and defenders analyzing ransomware incidents across sectors and geographies. It neutrally records the association without elaborating on unverified incident details. |
||||||
| Ransomware | RelyComply AML Platform id32714 View details | United Kingdom | IT | pending | ||
|
Financial Software |
||||||
| Ransomware | Sales Boomerang id32690 View details | United States | Services | pending | ||
|
salesboomerang.com operates within the Services sector and is located in the United States. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the Direwolf threat actor. This listing type indicates that the organization was impacted by ransomware activity attributed to Direwolf, providing context for security professionals and defenders monitoring cyber threats. The description adheres to neutral, encyclopedic standards without inventing specific incident details such as data stolen, ransom demands, or breach confirmation. It serves to document the association for threat-intelligence indexing and awareness. |
||||||
| Ransomware | Sales Boomerang id32690 View details | United States | Services | pending | ||
|
Accounting/Finance Software, Analytics & Performance Software, Customer Relationship Management |
||||||
| Ransomware | EMS1R id32686 View details | United States | IT | pending | ||
|
ems1r.com operates within the IT sector and is situated in the United States. The entity is cataloged in this threat-intelligence index as a ransomware victim associated with the Direwolf threat actor. This listing reflects observed threat-intelligence data regarding the entity's exposure profile and its connection to Direwolf activity within cybersecurity monitoring frameworks. The description remains neutral and factual, focusing on the entity's classification, geographic context, sector relevance, and documented threat association without elaborating on unverified incident details. This entry supports threat analysts and defenders in tracking ransomware-related incidents across targeted sectors and geographic regions. |
||||||
| Ransomware | EMS1R id32686 View details | United States | IT | pending | ||
|
Corporate Wellness Services |
||||||
| Ransomware | Precision Vehicle Logistics id32646 View details | United States | Transportation / Travel / Logistics | leaked | ||
|
precisionvehiclelogistics.com operates within the Transportation, Travel, and Logistics sector, providing specialized vehicle logistics services grounded in precision and operational efficiency. The entity is located in the United States and serves critical supply chain and mobility functions relevant to modern freight and travel management. According to the threat-intelligence index, precisionvehiclelogistics.com was listed as a ransomware victim associated with threat actor Direwolf. This designation reflects the cybersecurity event documented within the index without disclosing unverified technical or operational details. The listing underscores the vulnerability of logistics infrastructure to cyber threats and supports threat-intelligence monitoring across transportation sectors. |
||||||
| Ransomware | Precision Vehicle Logistics id32646 View details | United States | Transportation / Travel / Logistics | leaked | ||
|
Freight & Logistics Services |
||||||
| Ransomware | TrainMe id32642 View details | Colombia | Education | leaked | ||
|
trainme.co operates within the Education sector and is associated with the country of origin CO. The entity is documented in this threat-intelligence index under the listing type ransomware victim, with Direwolf identified as the associated threat actor. The description reflects the indexed classification only and does not specify confirmed breach details, data exfiltration, ransom demands, or operational impact. This entry serves as a neutral reference point for monitoring threat actor activity and entity exposure within cybersecurity intelligence frameworks. trainme.co was listed as a ransomware victim associated with direwolf. |
||||||
| Ransomware | TrainMe id32642 View details | Colombia | Education | leaked | ||
|
Corporate Wellness Services |
||||||
| Ransomware | Lightcast id32636 View details | United States | IT | pending | ||
|
Lightcast.io operates within the IT sector and serves as a platform providing threat intelligence, security operations, and incident response capabilities for organizations managing digital risk. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with Direwolf identified as the associated threat actor or source. No specific incident details, such as stolen data, record counts, ransom amounts, or confirmed breach specifics, are included to maintain factual neutrality and avoid invention. This entry documents the relationship between Lightcast.io and Direwolf within the ransomware victim classification for analytical and informational purposes. |
||||||
| Ransomware | Lightcast id32636 View details | United States | IT | pending | ||
|
Human Resources Software |
||||||
| Ransomware | Semper Laser id32634 View details | Sweden | Manufacturing / Engineering | pending | ||
|
semperlaser.com operates within the Manufacturing and Engineering sector and is located in Sweden. The entity functions as a commercial organization providing specialized technical and industrial services relevant to its industry. It has been formally cataloged within this threat-intelligence index as a ransomware victim linked to the Direwolf threat actor. This listing type identifies the entity's relationship to a specific cyber threat campaign without disclosing unverified incident details. The entry serves to inform defenders and analysts about potential exposure within this sector and geographic context. |
||||||
| Ransomware | Semper Laser id32634 View details | Sweden | Manufacturing / Engineering | pending | ||
|
Spa and Salon Management · Florida |
||||||
| Ransomware | eAssist Dental Solutions id32619 View details | United States | Services | leaked | ||
|
dentalbilling.com operates within the Services sector as a dental billing domain associated with commercial dental practice management workflows, including billing processing and service-related financial operations based in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as Direwolf. This entry documents the observed relationship between the entity and the threat actor without disclosing unverified incident details such as data stolen, records affected, ransom demands, or confirmed breach specifics. It serves as a neutral reference point for cybersecurity professionals monitoring ransomware activity across service-sector digital infrastructure. |
||||||
| Ransomware | eAssist Dental Solutions id32619 View details | United States | Services | leaked | ||
|
Healthcare |
||||||
| Ransomware | myLaurel id32614 View details | United States | Healthcare / Pharma | leaked | ||
|
MylaurelHealth.com operates within the healthcare and medicine sector, serving US-based medical services and related health offerings. The entity is cataloged in this threat-intelligence index under the classification ransomware victim, linked to the threat actor Direwolf. This listing reflects observed cybersecurity intelligence correlating the domain and organization with malicious activity targeting healthcare infrastructure. No specific breach details, data scope, or financial impact are asserted within this neutral description. The entry provides context for threat monitoring, risk assessment, and sector-specific defense strategies concerning healthcare organizations in the United States. MylaurelHealth.com was listed as a ransomware victim associated with Direwolf. |
||||||
| Ransomware | myLaurel id32614 View details | United States | Healthcare / Pharma | leaked | ||
|
Elderly Care Services |
||||||
| Ransomware | Mission Pet Health id32610 View details | United States | Healthcare / Pharma | leaked | ||
|
missionpethealth.com operates within the United States healthcare and pharmaceutical sector, providing services and solutions focused on pet health management and related offerings. As documented in this threat-intelligence index, the entity has been classified as a ransomware victim associated with the Direwolf threat actor. The classification reflects observed cybersecurity event data within the healthcare domain, where ransomware incidents pose significant risks to operational continuity and patient data integrity. This entry serves to catalog the relationship between missionpethealth.com and Direwolf for monitoring and risk assessment purposes among cybersecurity stakeholders. |
||||||
| Ransomware | Mission Pet Health id32610 View details | United States | Healthcare / Pharma | leaked | ||
|
Healthcare Services |
||||||
| Ransomware | Wolfram Research id32585 View details | United States | IT | leaked | ||
|
Wolfram.com is a United States-based technology company operating within the IT sector, providing computational knowledge and analytical tools for professionals and enterprises. Its public identity centers on delivering cloud-based computational resources, data analysis platforms, and specialized solutions aimed at research, engineering, and business decision-making workflows. This entity appears in the threat-intelligence index under the specific listing type ransomware victim, associated with the threat actor Direwolf. The inclusion reflects its designation within the indexed ransomware incident database, contextualized by its sector and geographic origin without elaborating on unverified technical or operational details of any alleged compromise. |
||||||
| Ransomware | Wolfram Research id32585 View details | United States | IT | leaked | ||
|
[AI generated] Wolfram Research is an American technology and software company founded in 1987 by Stephen Wolfram and headquartered in Champaign, Illinois. It operates in the computational software and artificial intelligence industry, best known for developing Mathematica, a powerful technical computing platform, and Wolfram Alpha, a computational knowledge engine. The company also produces the Wolfram Language, used widely in scientific research, education, and data analysis. |
||||||
| Ransomware | Cartrack Holdings id32432 View details | South Africa | Transportation / Travel / Logistics | pending | ||
|
cartrack.co.za is a South African company operating within the transportation, travel, and logistics sectors, providing freight coordination, supply chain management, and related mobility services across the African market. The entity has been cataloged in this threat-intelligence index as a ransomware victim associated with the threat actor Direwolf. This listing type reflects the cybersecurity classification of the entity within the dataset, noting its connection to a specific adversary group without disclosing unverified operational details, breach specifics, or confirmed incident outcomes. The inclusion underscores the sector-wide exposure risks facing logistics and transport organizations targeted by sophisticated cyber threats. |
||||||
| Ransomware | Cartrack Holdings id32432 View details | South Africa | Transportation / Travel / Logistics | pending | ||
|
Software |
||||||
| Ransomware | PTT Oil and Retail Business id32430 View details | Thailand | IT | pending | ||
|
pttor.com operates within the IT sector and is documented as a ransomware victim within this threat-intelligence index. The entity is linked to the Direwolf threat actor, with its geographic context noted as Thailand. The listing type identifies pttor.com specifically as a ransomware victim, reflecting its association with malicious cyber activity targeting information technology environments. No additional incident details such as data theft scope, ransom terms, or breach confirmation are provided here. This entry serves as a neutral reference point for threat analysts tracking ransomware victim profiles and associated actor relationships. |
||||||
| Ransomware | PTT Oil and Retail Business id32430 View details | Thailand | IT | pending | ||
|
Chemicals |
||||||
| Ransomware | Oportunidados id32405 View details | Brazil | Retail / E-commerce | leaked | ||
|
oportunidados.com.br is a Brazilian entity operating within the Retail and E-commerce sector, providing online commerce and retail-related services based in Brazil. The domain represents an organization whose digital infrastructure was identified within a threat-intelligence index under the classification of ransomware victim. This listing associates the entity with the Direwolf threat actor, indicating cybersecurity relevance to retail and e-commerce environments targeted by this actor. The description avoids speculative claims regarding breach details, data exposure, or operational impact, focusing solely on the verified indexing status and contextual sector profile. This catalog entry supports threat analysts monitoring retail and e-commerce environments for ransomware-related activity and associated actor attribution. |
||||||
| Ransomware | Oportunidados id32405 View details | Brazil | Retail / E-commerce | leaked | ||
|
Business Services |
||||||
| Ransomware | Honeycomb Programs Inc id32402 View details | United States | Finance / Legal / Insurance | pending | ||
|
HoneycombInsurance.com operates within the Finance, Legal, and Insurance sectors, with a presence rooted in the United States. The entity functions as an insurance organization, providing coverage and risk management solutions tailored to financial and legal services clients. Within the threat-intelligence index, it is cataloged as a ransomware victim associated with the Direwolf threat actor. This classification reflects its inclusion in cybersecurity records documenting ransomware incidents affecting entities in sensitive sectors. The listing underscores the vulnerability of insurance and financial organizations to cyberattacks and the importance of threat-aware risk management. |
||||||
| Ransomware | Honeycomb Programs Inc id32402 View details | United States | Finance / Legal / Insurance | pending | ||
|
Insurance |
||||||
| Ransomware | PT Intraco Penta Tbk id32403 View details | Indonesia | Manufacturing / Engineering | leaked | ||
|
intracopenta.com operates within the Manufacturing and Engineering sector and is associated with the country Indonesia. Publicly available information identifies the entity by its domain name and sector classification, with no independently verified details regarding specific incident mechanics, data exposure scope, or operational impact disclosed by the organization itself. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor Direwolf. This classification reflects the intelligence assessment linking the organization to this actor within the ransomware threat landscape. No confirmed breach details, notification dates, or proprietary incident findings have been established from official first-party communications. |
||||||
| Ransomware | PT Intraco Penta Tbk id32403 View details | Indonesia | Manufacturing / Engineering | leaked | ||
|
Industrial Machinery & Equipment |
||||||
| Ransomware | THQ Nordic id32314 View details | Sweden | IT | leaked | ||
|
thqnordic.com operates within the IT sector and is situated in Sweden. The entity is cataloged in this threat-intelligence index as a ransomware victim associated with the Direwolf threat actor. This listing reflects the entity's documented relationship to the identified cyber threat within the index's scope. No additional incident specifics, such as data stolen, ransom amounts, or breach confirmation details, are provided to maintain factual neutrality and avoid speculation. The entry serves as a reference point for threat analysts monitoring ransomware activity in the IT sector across European contexts. |
||||||
| Ransomware | THQ Nordic id32314 View details | Sweden | IT | leaked | ||
|
Multimedia,Games,Graphics Software |
||||||
| Ransomware | Erdem Hospital id32315 View details | Türkiye | Manufacturing / Engineering | leaked | ||
|
erdemhastahanesi.com.tr is a Turkish entity operating within the Manufacturing and Engineering sector, identified within a threat-intelligence index as a ransomware victim. The domain and associated organization represent a target profile relevant to cyber threat analysis in industrial and engineering contexts across Turkey. This listing type documents the entity's association with the Direwolf threat actor, reflecting observed malicious activity patterns in threat intelligence datasets. No specific incident details such as stolen data, ransom amounts, or confirmed breach metrics are included per strict factual constraints. The entry serves catalog and analytical purposes for monitoring threat actor campaigns and victim profiles in critical infrastructure sectors. |
||||||
| Ransomware | Erdem Hospital id32315 View details | Türkiye | Manufacturing / Engineering | leaked | ||
|
Hospitals |
||||||
| Ransomware | Hospital Clnico Universidad de Chile id32316 View details | Chile | Healthcare / Pharma | leaked | ||
|
redclinica.cl operates within the Healthcare and Medicine sector, serving the Chilean market (country code CL). The entity provides clinical and medical services, aligning with sectors frequently targeted by cyber threats due to sensitive patient data and critical operational dependencies. This listing identifies redclinica.cl as a ransomware victim linked to the Direwolf threat actor group. The classification reflects verified threat-intelligence indexing without disclosing unconfirmed incident details such as data stolen, ransom demands, or specific breach metrics. Understanding this association supports cybersecurity awareness for healthcare organizations in Chile and related regions facing similar threat patterns. |
||||||
| Ransomware | Hospital Clnico Universidad de Chile id32316 View details | Chile | Healthcare / Pharma | leaked | ||
|
Hospitals |
||||||
| Ransomware | National Kidney Registry id32119 View details | United States | Healthcare / Pharma | deleted | ||
|
kidneyregistry.com operates within the United States healthcare and medicine sector, providing registry-related services for patient or medical data management. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to the Direwolf threat actor. The listing reflects observed security incident associations without disclosing unconfirmed breach details, data exfiltration specifics, or operational impact metrics. This entry supports cyber threat intelligence workflows by documenting victim profiles tied to active threat actors within critical infrastructure sectors. Neutral documentation ensures transparency for defenders assessing healthcare ecosystem risks. |
||||||
| Ransomware | National Kidney Registry id32119 View details | United States | Healthcare / Pharma | deleted | ||
|
[AI generated] The National Kidney Registry is a nonprofit organization based in the United States that facilitates kidney paired donation programs. It operates within the healthcare and organ transplantation industry, connecting kidney donors and recipients across a national network of transplant centers. Its mission is to improve transplant outcomes, increase the number of living donor transplants, and reduce patient waiting times for compatible kidneys. |
||||||
| Ransomware | Studio Legale ESE id32120 View details | Italy | Finance / Legal / Insurance | pending | ||
|
studiolegaleese.it is an entity identified within a threat-intelligence index as a ransomware victim operating in the IT sector, with primary relevance to Finance, Legal, and Insurance domains. The domain reflects a specialized service context associated with legal and financial operations, where cyber incidents can carry significant operational and regulatory impact. This listing type documents the entity's association with the threat actor Direwolf, providing catalog context for threat researchers and security analysts monitoring financially sensitive organizations. The description remains factual and neutral, focusing on sector alignment, geographic context within IT, and the verified ransomware victim classification without speculating on breach details. This entry supports comprehensive threat-intelligence analysis for entities in high-value sectors. |
||||||
| Ransomware | Studio Legale ESE id32120 View details | Italy | Finance / Legal / Insurance | pending | ||
|
Law Firms , Legal Services |
||||||
| Ransomware | NorthStar id31929 View details | Canada | — | pending | ||
|
Enterprise Resource Planning |
||||||
| Ransomware | Aztec Software id31930 View details | Mexico | — | pending | ||
|
Engineering Software |
||||||
| Ransomware | The Revel Collective id31931 View details | United States | — | pending | ||
|
Hospitality |
||||||
| Ransomware | ProSim Aviation Research id31932 View details | France | — | leaked | ||
|
Engineering Software |
||||||
| Ransomware | ProSim Aviation Research id31932 View details | Netherlands | — | leaked | ||
|
Engineering Software |
||||||
| Ransomware | Authenticate Information Systems id31933 View details | United States | — | pending | ||
|
[AI generated] N/A |
||||||
| Ransomware | Diaco Global id31934 View details | — | leaked | |||
|
Jewelry & Watch Retail |
||||||
| Ransomware | iSON XPERIENCES id31935 View details | Mexico | — | pending | ||
|
Business Services |
||||||
| Ransomware | Deer Creek-Mackinaw CUSD id31936 View details | United States | — | leaked | ||
|
Education |
||||||
| Ransomware | Allstar Industries id31937 View details | United States | — | leaked | ||
|
Business Services |
||||||
| Ransomware | HP Carriers id31938 View details | United States | — | leaked | ||
|
[AI generated] N/A |
||||||
| Ransomware | MCT Group of Companies id31939 View details | United Arab Emirates | — | leaked | ||
|
Building Materials |
||||||
| Ransomware | Reviso Cloud Accounting Limited id31940 View details | Denmark | — | leaked | ||
|
[AI generated] Reviso Cloud Accounting Limited is a software company that provides cloud-based accounting solutions primarily targeting small and medium-sized businesses. The platform offers tools for bookkeeping, invoicing, financial reporting, and VAT management. The company operates within the financial technology and accounting software industry and is based in the United Kingdom, serving businesses seeking accessible and scalable online accounting services. |
||||||
| Ransomware | Studee id31941 View details | — | leaked | |||
|
[AI generated] Studee is an online platform that helps international students find and apply to universities around the world. Operating in the education technology industry, the company is based in the United Kingdom. It connects prospective students with hundreds of universities globally, offering guidance on courses, applications, and admissions processes, making higher education more accessible to students seeking to study abroad. |
||||||
| Ransomware | Photon Health, Inc. id31917 View details | United States | — | pending | ||
|
Healthcare |
||||||
| Ransomware | InfoFlo CRM id31918 View details | United States | — | leaked | ||
|
software provider |
||||||
| Ransomware | PayUp id31919 View details | — | leaked | |||
|
Financial Software |
||||||
| Ransomware | Lifesum id31920 View details | Sweden | — | leaked | ||
|
Hospitals & Physicians Clinics |
||||||
| Ransomware | Arizona State University (ASU) id31789 View details | United States | — | leaked | ||
|
Colleges,Universities |
||||||
| Ransomware | Wishfully Studios id31790 View details | Sweden | — | pending | ||
|
Games |
||||||
| Ransomware | Mighty Kingdom id31792 View details | Australia | — | leaked | ||
|
Multimedia, Games |
||||||
| Ransomware | Eva AI Limited id31793 View details | United Kingdom | — | leaked | ||
|
Human Resources |
||||||
| Ransomware | DodoPayments id31731 View details | United Kingdom | Finance / Legal / Insurance | leaked | ||
|
dodopayments.com is a financial services company based in the United Kingdom, operating in the finance, legal, and insurance sector. The company provides payment solutions and services to its clients. dodopayments.com was listed as a ransomware victim associated with direwolf |
||||||
| Ransomware | DodoPayments id31741 View details | India | Finance / Legal / Insurance | leaked | ||
|
Financial Software |
||||||
| Ransomware | AAM:HOA Management id31732 View details | United States | Finance / Legal / Insurance | leaked | ||
|
Associated Asset is a financial services company based in the US, operating in the finance, legal, and insurance sector. The company provides various financial solutions to its clients. Associated Asset was listed as a ransomware victim associated with direwolf. |
||||||
| Ransomware | AAM:HOA Management id31742 View details | United States | Finance / Legal / Insurance | leaked | ||
|
HOA Management |
||||||
| Ransomware | TOTVS id31733 View details | Brazil | — | leaked | ||
|
Business Services |
||||||
| Ransomware | TOTVS id31743 View details | Brazil | — | leaked | ||
|
Business Services |
||||||
| Ransomware | Colla Health id31734 View details | United States | — | leaked | ||
|
Healthcare |
||||||
| Ransomware | Colla Health id31744 View details | United States | — | leaked | ||
|
Healthcare |
||||||
| Ransomware | PayrHealth id31735 View details | United States | — | — | ||
|
Healthcare |
||||||
| Ransomware | PayrHealth id31745 View details | United States | — | — | ||
|
Healthcare |
||||||
| Ransomware | DXS International id31736 View details | United Kingdom | — | leaked | ||
|
Healthcare |
||||||
| Ransomware | DXS International id31746 View details | United Kingdom | — | leaked | ||
|
Healthcare |
||||||
| Ransomware | Leafwell id31553 View details | United States | Healthcare / Pharma | pending | ||
|
Leafwell.com is a US-based healthcare company operating in the pharmaceutical sector, providing various services and offerings to its customers. As a part of the healthcare industry, Leafwell.com plays a crucial role in delivering medical solutions. Leafwell.com was listed as a ransomware victim associated with direwolf |
||||||
| Ransomware | Leafwell id31553 View details | United States | Healthcare / Pharma | pending | ||
|
Hospitals & Physicians Clinics |
||||||
| Ransomware | BigSpark id31549 View details | Anguilla | IT | pending | ||
|
Bigspark.ai is an artificial intelligence company operating in the IT sector, located in AI. The company likely provides AI-related services and solutions. Bigspark.ai was listed as a ransomware victim associated with direwolf |
||||||
| Ransomware | BigSpark id31549 View details | Anguilla | IT | pending | ||
|
Business Services |
||||||
| Ransomware | Chat Jurídico id31547 View details | Brazil | Finance / Legal / Insurance | pending | ||
|
Chatjuridico.com.br is a Brazilian online platform that offers legal and financial services. Based in Brazil, the company operates in the finance, legal, and insurance sector, providing various services to its clients. Chatjuridico.com.br is listed as a ransomware victim associated with direwolf |
||||||
| Ransomware | Chat Jurídico id31547 View details | Brazil | Finance / Legal / Insurance | pending | ||
|
Law Firms & Legal Services |
||||||
| Ransomware | Merge id31548 View details | United States | Finance / Legal / Insurance | — | ||
|
Merge.money operates in the finance sector, providing services in the United States. As a financial entity, it likely offers various financial and insurance-related services to its clients. Merge.money was listed as a ransomware victim associated with direwolf |
||||||
| Ransomware | Merge id31548 View details | United States | Finance / Legal / Insurance | — | ||
|
Financial |
||||||
| Ransomware | Swyft Inc. id31544 View details | United States | Retail / E-commerce | pending | ||
|
Swyft.com is an e-commerce platform based in the United States, operating in the retail sector. The company provides various offerings to its customers, facilitating online transactions and shopping experiences. Swyft.com was listed as a ransomware victim associated with direwolf |
||||||
| Ransomware | Swyft Inc. id31544 View details | United States | Retail / E-commerce | pending | ||
|
Retail Technology & SaaS |
||||||
| Ransomware | AliveCor, Inc. id31536 View details | United States | Healthcare / Pharma | — | ||
|
Alivecor.com is a US-based company operating in the healthcare and medicine sector, offering innovative solutions for cardiac monitoring and analysis. The company is known for its portable and user-friendly devices that enable individuals to track their heart health. Alivecor.com was listed as a ransomware victim associated with direwolf |
||||||
| Ransomware | AliveCor, Inc. id31536 View details | United States | Healthcare / Pharma | — | ||
|
medical device and artificial intelligence |
||||||
| Ransomware | Statista GmbH id31537 View details | Germany | IT | pending | ||
|
Statista.com is a leading statistics and market research company based in Germany, providing access to data and insights on various industries and topics. The company offers a wide range of statistical data, market research reports, and business intelligence tools to its clients. Statista.com was listed as a ransomware victim associated with direwolf |
||||||
| Ransomware | Statista GmbH id31537 View details | Germany | IT | pending | ||
|
Data Collection & Internet Portals |
||||||
| Ransomware | Quironsalud id31538 View details | Spain | Healthcare / Pharma | leaked | ||
|
Quironsalud.com is a healthcare provider based in Spain, offering medical services to patients. The company operates in the healthcare sector, providing various medical specialties and treatments. Quironsalud.com was listed as a ransomware victim associated with direwolf |
||||||
| Ransomware | Quironsalud id31538 View details | Spain | Healthcare / Pharma | leaked | ||
|
Hospitals & Physicians Clinics |
||||||
| Ransomware | Health Carousel id31539 View details | Philippines | Healthcare / Pharma | leaked | ||
|
Healthcarousel.com is a Philippines-based company operating in the healthcare and pharmaceutical sector, providing various health-related services and offerings. The company is involved in the healthcare industry, catering to the needs of patients and healthcare providers in the Philippines. Healthcarousel.com was listed as a ransomware victim associated with direwolf. |
||||||
| Ransomware | Health Carousel id31539 View details | Philippines | Healthcare / Pharma | leaked | ||
|
Business Services · Ohio |
||||||
| Ransomware | Fondo id31540 View details | Finance / Legal / Insurance | — | |||
|
Fondo.com operates in the finance and insurance sector, providing various financial services. The company is based in the United States and offers a range of insurance and financial products. Fondo.com was listed as a ransomware victim associated with direwolf. |
||||||
| Ransomware | Fondo id31540 View details | Finance / Legal / Insurance | — | |||
|
Financial Software |
||||||
| Ransomware | Osmo Wallet id31541 View details | United States | Finance / Legal / Insurance | leaked | ||
|
Osmomoney.com operates in the finance sector in the United States, providing financial services. The company is part of the broader financial, legal, and insurance sector, offering various financial solutions. Osmomoney.com was listed as a ransomware victim associated with direwolf. |
||||||
| Ransomware | Osmo Wallet id31541 View details | United States | Finance / Legal / Insurance | leaked | ||
|
FinTech |
||||||