Ransomware Group intelligence
Rhysida
ActiveTrack Rhysida with 297 published victims and 7 known leak locations in a single intelligence view.
Overview
Rhysida is tracked by Breach House as a ransomware group with 297 published victims.
United States is currently the most targeted country in this dataset.
7 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 12 37.5%
- Pending 20 62.5%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (7)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 7 | Onion service | Up checked 5h ago | rhysidaqho36b6i6mvpmy5di4ro5zglovtxixrirky6q3fgack7q5uyd.onion |
| Leak location 4 | Onion service | Up checked 5h ago | rhysidafc6lm7qa2mkiukbezh7zuth3i4wof4mh2audkymscjm6yegad.onion |
| Leak location 1 | Onion service | Up checked 5h ago | rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion |
| Leak location 2 | Onion service | Up checked 5h ago | rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion |
| Leak location 3 | Onion service | Up checked 5h ago | rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion |
| Leak location 6 | Onion service | Down checked 5h ago | rhysidaeoxtkejwuheks3a7htk4zn3dfuynt5mqw6oawlcx6kcxjdeyd.onion |
| Leak location 5 | Onion service | Down checked 5h ago | grhysidafc6lm7qa2mkiukbezh7zuth3i4wof4mh2audkymscjm6yegad.onion |
Top Activity Sectors (17)
- Not identified 47
- Education 44
- Communication / Marketing 41
- Healthcare / Pharma 33
- Public Sector 27
- Manufacturing / Engineering 17
- Finance / Legal / Insurance 16
- Services 14
- Retail / E-commerce 7
- IT 7
- NGOs / Associations 6
- Transportation / Travel / Logistics 6
- Construction / Real Estate 5
- Telecommunications 3
- Hospitality / Food & Beverage / Tourism 3
- Energy 2
- Agriculture / Food 1
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Rhysida, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: rhysida executes malicious commands via PowerShell scripts to stage payloads and manipulate system behavior.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: rhysida modifies registry run keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: rhysida disables antivirus tools and security software to prevent detection and hinder incident response efforts.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: rhysida inserts junk code into legitimate binaries to evade static analysis and detection by security tools.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: rhysida deletes Volume Shadow Copies and backup directories via vssadmin and native commands to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: rhysida performs remote system discovery to identify additional hosts for lateral movement within the victim network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: rhysida scans network shares using Windows tools to identify victim files and expand foothold across the network.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: rhysida exfiltrates stolen data via encrypted channels to pressure victims into paying ransom.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: rhysida encrypts victim files using custom ransomware binaries targeting critical data across affected systems.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Tools Observed (8)
▼Software Rhysida has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
CriticalBreachDetected.txt
Critical Breach Detected - Immediate Response Required Dear company, This is an automated alert from cybersecurity team Rhysida. An unfortunate situation has arisen - your digital ecosystem has been compromised, and a substantial amount of confidential data has been exfiltrated from your network. The potential ramifications of this could be dire, including the sale, publication, or distribution of your data to competitors or media outlets. This could inflict significant reputational and financial damage. However, this situation is not without a remedy. Our team has developed a unique key, specifically designed to restore your digital security. This key represents the first and most crucial step in recovering from this situation. To utilize this key, visit our secure portal: rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion with your secret key [snip] It's vital to note that any attempts to decrypt the encrypted files independently could lead to permanent data loss. We strongly advise against such actions. Time is a critical factor in mitigating the impact of this breach. With each passing moment, the potential damage escalates. Your immediate action and full cooperation are required to navigate this scenario effectively. Rest assured, our team is committed to guiding you through this process. The journey to resolution begins with the use of the unique key. Together, we can restore the security of your digital environment. Best regards
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (297)
Search, filter and paginate the victim timeline for Rhysida. Showing 1–100 of 297.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | General Santos Doctors Hospital id32743 View details | Philippines | Healthcare / Pharma | leaked | ||
|
General Santos Doctors Hospital is a healthcare and medicine facility located in the Philippines, providing medical services and patient care within the sector. As a healthcare institution, it handles sensitive patient data and operational systems critical to community health delivery. This entity is cataloged in the threat-intelligence index as a ransomware victim associated with the threat actor rhysida. The listing reflects its designation within cybersecurity intelligence records without disclosing confirmed breach details, attack specifics, or operational impact. This entry supports threat monitoring and sector-specific risk awareness for healthcare organizations in the Philippines. |
||||||
| Ransomware | General Santos Doctors Hospital id32743 View details | Philippines | Healthcare / Pharma | leaked | ||
|
General Santos Doctors Hospital 3.502.636 files, total volume ~2.44 TBPatient data (PHI) � name-tagged scans across department shares (surgical pathology, hemodialysis charts, admission records), cancer-center dossiers with PhilHealth IDs, lab quotations incl. cancer-marker tests with birth dates, PhilHealth claims monitoring, neonatal (NICU) dataStaff and professionals � accredited physicians register (cell numbers, PRC licenses, PhilHealth IDs), named payroll workbooks (incl. the affiliated diagnostic center), HR dossiers, staff passport scans, drug-test filesMoney, audit and governance � audited financial statements personally signed by chairman/treasurer/CFO with BIR stamps, balance sheet, all bank accounts across six-plus banks, internal-audit memos on (cashier discrepancies and cash shortages), SEC stockholders' minutes, payroll bank-upload batches, related-party entities on the same sharesLeadership personal data � personal cell numbers of the president, hospital administrator and board members More |
||||||
| Ransomware | Professional Retail Services id32744 View details | Retail / E-commerce | pending | |||
|
Professional Retail Services operates within the Retail and E-commerce sector, providing professional services that support commercial transactions, customer engagement, and operational efficiency across retail environments. The entity functions as a service provider within this industry, handling aspects such as supply chain coordination, digital commerce support, and client-facing retail solutions. It is formally cataloged as a ransomware victim linked to the threat actor rhysida, reflecting cybersecurity exposure within the retail domain. This listing underscores the vulnerability landscape faced by retail and e-commerce organizations to ransomware threats, highlighting the importance of robust defensive measures and threat intelligence monitoring for sector-specific risks. |
||||||
| Ransomware | Professional Retail Services id32744 View details | Retail / E-commerce | pending | |||
|
Professional Retail Services Owner�s documents: employee evaluations, salary rates, bonuses, job offers, family documentsCFO�s documents: client credit reports, bankruptcy records, tax documents, father�s medical records (guardianship court case)Corporate financials: owner�s personal tax return, credit application, signed checks with MICR (BNB Bank)Corporate credit cards, drug testsMedical records, employee health insuranceAnd much more More |
||||||
| Ransomware | SAD'S Interim id32674 View details | France | — | leaked | ||
|
SAD'S Interim is an entity cataloged as a ransomware victim within a threat-intelligence index. Based on available naming context and sector indicators, it operates within a business sector where ransomware targeting is prevalent, with operational presence associated with France. The listing type identifies it specifically as a ransomware victim linked to the threat actor rhysida. This description provides neutral catalog context without confirming breach details, data specifics, or financial impact. The entry supports threat-intelligence analysis for monitoring actor-victim relationships and sector exposure. |
||||||
| Ransomware | SAD'S Interim id32674 View details | France | — | leaked | ||
|
SAD'S Interim Since 2000, SAD'S INTERIM has established itself as a key player in the temporary employment sector.Bank statements (relev�s) with SEPA credit transfersFactoring: invoice import batches, client receivables ledgers (encours) with EUR amounts and named clients, payment receipts (quittances)SQL backups of the BRANIPP ERP (the temp-workers payroll database)Payslips (bulletins de salaire) and payroll validation workbooksPermanent-staff employment contracts signed by the owners (Sadoun family)Temp-worker contracts, Pole Emploi attestationsPassports (EU and third-country nationals)CARTE BTP (construction-worker cards with photo and DOB)carte Vitale (health-insurance cards)RIB (bank account details)NIR (national insurance numbers)MDPH (disability recognition documents) More |
||||||
| Ransomware | Rug & Home id32647 View details | United States | Retail / E-commerce | pending | ||
|
Rug & Home operates within the Retail and E-commerce sector, serving customers and managing commercial activities primarily from the United States. The entity is documented within this threat-intelligence index under the listing type ransomware victim, associated with the threat actor rhysida. This classification reflects the cybersecurity context in which Rug & Home was identified, contributing to broader awareness of potential retail and e-commerce threats. The description remains neutral and factual, focusing on the entity's sector, geographic location, and its recognized association with the specified threat actor without disclosing unverified incident details. Rug & Home was listed as a ransomware victim associated with rhysida. |
||||||
| Ransomware | Rug & Home id32647 View details | United States | Retail / E-commerce | pending | ||
|
Rug & Home Rug & Home is a leading destination in the USA for rugs, furniture, and home decor, offering a vast selection of unique designs and top brands.Database of 50,193 customers�full names, home addresses, email addresses, phone numbers, purchase amounts (CSV)~10,800 scans�signed delivery notes with customer addresses/phone numbersPlaintext passwords for ~60 B2B supplier portalsW-2, 1099, W-9 � tax forms with employees' and contractors' SSNsPayroll database for all employees (Sage EMPLOYEE/ESWAGE)Company bank details (First Citizens Bank deposits) and employee accounts (direct deposit)HR: background checks, terminations, workplace injuries, 401(k)And much more More |
||||||
| Ransomware | Szechenyi Programiroda Nonprofit Kf id32406 View details | Hungary | NGOs / Associations | — | leaked | |
|
Szechenyi Programiroda Nonprofit Kf operates within the NGO and associations sector, based in Hungary, providing nonprofit programming and organizational services. The entity is cataloged as a ransomware victim in this threat-intelligence index. Its inclusion reflects the ransomware incident associated with the threat actor rhysida. This listing documents the relationship between the organization and the identified threat actor without disclosing unverified technical or operational details. The record serves to inform stakeholders of the affected entity within the broader cybersecurity threat landscape. |
||||||
| Ransomware | Szechenyi Programiroda Nonprofit Kf id32406 View details | Hungary | NGOs / Associations | — | leaked | |
|
Szechenyi Programiroda Nonprofit Kf |
||||||
| Ransomware | Valley Health Team id32236 View details | — | leaked | |||
|
Valley Health Team operates within the healthcare sector, providing medical services and health-related offerings to patients and communities. As a ransomware victim, the entity is documented within this threat-intelligence index under association with the threat actor rhysida. The listing type indicates a cybersecurity incident classification relevant to monitoring healthcare infrastructure threats and active threat actor campaigns. This entry supports security analysts tracking ransomware exposure across critical service sectors. Neutral documentation reflects the indexed association without confirming specific breach details, data impacts, or operational outcomes. |
||||||
| Ransomware | Valley Health Team id32236 View details | — | leaked | |||
|
Valley Health Team 9,056,196 files3.28 TBLarge SQL databases containing the clinic's entire lifetime of information.Major databases:160,870 patients4.18 million diagnoses7.6 million unencrypted EHR scansSSN, passports, and other personal data.Financial statements, salaries, taxes.Dear customers, please submit your requests�there are plenty of files here that can be monetized. More |
||||||
| Ransomware | Berlin, Germany id32233 View details | Germany | — | leaked | ||
|
Berlin, Germany is a major European capital city and economic hub, serving diverse sectors including finance, government services, technology, media, and transportation. As a ransomware victim listing under the threat actor rhysida, this entry documents an affected entity within Berlin's operational landscape, reflecting cybersecurity exposure linked to this specific adversary group. The catalog entry provides neutral context on the entity's geographic and sectoral profile without disclosing unverified incident details. This record supports threat-intelligence analysis for monitoring ransomware activity across German infrastructure. |
||||||
| Ransomware | Berlin, Germany id32233 View details | Germany | — | leaked | ||
|
Berlin, Germany Total capacity 5.79 TBArchive scale: ~1.44 million files scanned; by category � Maps/Geo 124,823, Legal/complaints 77,939, Financial 55,553, Contracts 46,522, HR 27,299,Government supervisory 13,142, Confidential 11,777, Infrastructure 8,110, Passwords 5,941, Health 2,738, Contacts 2,287.PII leak: 16,389 e-mails, 11,963 phone numbers, 12,076 individuals, 148 IBANs.Credentials in plaintext: Geb�udeAtlas, the ePayment PAYONE payment database, personal 'password safes' (danz, kramell � Z_ADMIN database accounts, franssen), leadership credentials.Disciplinary proceedings: the ANDERSON case (432 files, 2025�2026, lawsuit at VG Berlin administrative court), the politically motivated misconduct case involving the LKA Staatsschutz (state security police), the forestry cases BLAUTH/M�LLER/FIELICKE.State secrets: Bundesrat committee protocols with declassification correspondence, Geheimschutz (classified-material handling) data.Passports/IDs (recent, from personnel files and GI-Vertraulich).KRITIS: vulnerability analyses of Berlin's water supply.Mass personal data: Personalakten (personnel files) >5,000, Convotis payroll, OWi (administrative-offence) files >5,000, Postbuch SQL dumps 2020�2026, PST archives, leadership private data (IBANs, ID cards, Behrendt's bank card).NDA: 3,226 documentsLegal violation map (GDPR Art. 32/9/33, VSA/StGB upon VS classification confirmation, BSIG/KRITIS) More |
||||||
| Ransomware | CRI Electric id31956 View details | United States | — | leaked | ||
|
CRI Electric CRI Electric is a veteran-owned business based in San Antonio, providing professional electrical services since 1998. They cater to both residential and commercial clients, offering services such as emergency electrical repairs, EV charger installations, and home rewiring. We are pleased to present:Employee's federal account artifacts** (`HR-Confidential\Israel's Forms`): Login.gov personal recovery key (VA identity), TSP (retirement savings), ID.me, DoD DS Logon, PIEE (DoD contract payments)151 vendor W-9 forms** (SSN/EIN), payroll docs, HR-lawyer (privileged) correspondence, OSHA-adjacent injury/incident reports with photos.Public-sector bid pricing** (2025�2026: SAWS HQ EV charging, SAISD, NISD) � bid-competitiveness and Davis-Bacon certified-payroll context.Corporate docs (SDVOSB certification, Articles, bylaws, stock ledgers), QuickBooks financials, a Power of Attorney More |
||||||
| Ransomware | Coming soon id31965 View details | — | leaked | |||
|
Coming soon Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits, legal opinionsFinance 55,553 Budget, invoices, ProFISKAL, debt collectionContracts 46,522 Contracts, NDAs, procurementHR/Personnel 27,299 Personnel files, payroll, performance reviewsOversight/Government 13,142 Inquiries from the House of Representatives, GWTVConfidential-Secret 11,777 GI-Confidential folders, security classificationInfrastructure/Critical Information Infrastructure 8,110 KRITIS, risk analysis, emergency plansPasswords/secrets 5,941 files containing login credentialsHealth/insurance 2,738 medical benefitsContacts/Addresses 2,287 address databases, phone listsExtracted from the content: 16,389 unique email addresses, 11,963 phone numbers, 12,076 individuals with names, 148 IBANs, 820+ monetary amounts (up to �30 million).And a wealth of other valuable data. More |
||||||
| Ransomware | Fairview Dental Group id31968 View details | United States | — | pending | ||
|
Fairview Dental Group Fairview Dental Group offers a range of dental services including family dentistry, cosmetic treatments, dental implants, and invisible braces.We are pleased to present:Full patient database, patient X-rays, scanned forms/consents/invoices, health records (PHI) of the entire practice, unencrypted. More |
||||||
| Ransomware | Battle Creek Public Schools id31970 View details | United States | — | pending | ||
|
Battle Creek Public Schools Battle Creek Public Schools in Nebraska provides educational services for students from pre-kindergarten through 12th grade. We are pleased to present:Student records of named minors:** IEP/special-ed files, disability determination notices, discipline/suspension records.Federal funds compliance trail (ESSA/Title I application), staff health-spending claims (payflex/EHA) More |
||||||
| Ransomware | Pierce Township id31710 View details | United States | Public Sector | pending | ||
|
Pierce Township is a local government entity located in the United States, operating within the public sector to provide various services to its community. As a public sector organization, it is responsible for delivering essential services and amenities to its residents. Pierce Township was listed as a ransomware victim associated with rhysida |
||||||
| Ransomware | Pierce Township id31710 View details | United States | Public Sector | pending | ||
|
Pierce Township Pierce Township is a growing community in Ohio that blends rural charm with suburban living, covering 23.5 square miles and home to over 16,000 residents.We are pleased to present:Judicial materials - Grand Jury subpoena response incl. hospital records (Mercy Hospital), public records requests, fire investigation reportsEmployee PII - Social Security numbers (SSA-1945, W-4, Ohio Tax forms), CDL licenses, health insurance waivers, new-hire packetsLegal settlements - Logan Creek v. Pierce Township, Purdue opioid settlement, easement and lease agreementsFinancial records - budgets, tax levies, appropriation reports, invoices, paymentsInternal email archives of township officials and administration More |
||||||
| Ransomware | SIA Medical Centre id31666 View details | Latvia | Healthcare / Pharma | leaked | ||
|
SIA Medical Centre is a medical facility located in Latvia, operating in the healthcare sector. It provides medical services to patients in the region. SIA Medical Centre was listed as a ransomware victim associated with rhysida |
||||||
| Ransomware | SIA Medical Centre id31666 View details | Latvia | Healthcare / Pharma | leaked | ||
|
SIA Medical Centre SIA Medical was established in 1993 and was founded by Dr Martin Sia in Melbourne's northwest. 9 clinics - Box Hill, Burwood, Croydon, Essendon, Footscray, Moonee Ponds, Montrose, Mulgrave and Berwick.We are pleased to present:~20,000 patient medical records - names, dates of birth, Medicare numbers, clinical notes, insurance and work-cover files, full patient dossiersStaff identity documents - passports, driver's licenses, police checks, tax file declarations of doctors and employeesPlaintext credentials - logins and passwords for clinical systems (Synapse imaging, PRODA, terminal server, doctor accounts)HR records - signed employment contracts, staff incident reports, immunisation registersLegal & financial - subpoenas, complaints, Bupa contracts, bank details (BSB/ABN), provider payment forms More |
||||||
| Ransomware | SIA Medical Centre id31666 View details | Australia | Healthcare / Pharma | leaked | ||
|
SIA Medical Centre SIA Medical was established in 1993 and was founded by Dr Martin Sia in Melbourne's northwest. 9 clinics - Box Hill, Burwood, Croydon, Essendon, Footscray, Moonee Ponds, Montrose, Mulgrave and Berwick.We are pleased to present:~20,000 patient medical records - names, dates of birth, Medicare numbers, clinical notes, insurance and work-cover files, full patient dossiersStaff identity documents - passports, driver's licenses, police checks, tax file declarations of doctors and employeesPlaintext credentials - logins and passwords for clinical systems (Synapse imaging, PRODA, terminal server, doctor accounts)HR records - signed employment contracts, staff incident reports, immunisation registersLegal & financial - subpoenas, complaints, Bupa contracts, bank details (BSB/ABN), provider payment forms More |
||||||
| Ransomware | Lawson Roofing id29977 View details | Construction / Real Estate | — | — | ||
|
Lawson Roofing |
||||||
| Ransomware | IDS Group id29519 View details | United States | Services | leaked | ||
|
IDS Group IDS Group is an award-winning multi-discipline design, engineering, and management consulting firm based in Southern California. More |
||||||
| Ransomware | Landeshauptstadt Stuttgart id29258 View details | Germany | Public Sector | — | — | |
|
Landeshauptstadt Stuttgart Stuttgart is the capital city of Baden-Wurttemberg in southwestern Germany. |
||||||
| Ransomware | Tower View Primary School id29170 View details | United Kingdom | Education | — | — | |
|
Tower View Primary School Tower View Primary School is an educational institution that serves approximately 380 pupils across 14 classes. |
||||||
| Ransomware | Stelia North America id28583 View details | United States | Manufacturing / Engineering | — | — | |
|
Stelia North America |
||||||
| Ransomware | Southold Town Senior ServicesSouthold Police Department id26970 View details | Public Sector | — | — | ||
|
Southold Town Senior ServicesSouthold Police Department The Town of Southold, New York provides various government services including forms and permits, online payments, and notifications for residents. Southold Police Department is a company that operates in the Local industry. |
||||||
| Ransomware | Rohner id26735 View details | Switzerland | Manufacturing / Engineering | — | — | |
|
Rohner Rohner designs and builds high-quality, custom paint booths and manufactured industrial paint systems. Our quality and service, cutting-edge technology, and engineering experience provide the best value in the finishing equipment industry. |
||||||
| Ransomware | Cheyenne & Arapaho Tribes id26632 View details | United States | Public Sector | — | — | |
|
Cheyenne & Arapaho Tribes The Cheyenne and Arapaho Tribes are a federally recognized united nation of two distinct peoples-the Tsistsistas (Cheyenne) and Hinono'ei (Arapaho)-with a historic alliance formed in the early 19th century. |
||||||
| Ransomware | Phoenix Art Museum id26463 View details | United States | Other | — | — | |
|
Phoenix Art Museum Phoenix Art Museum is an art museum that showcases art from around the U.S. in Phoenix, Arizona. |
||||||
| Ransomware | Leading Edge Speciali id26237 View details | Other | — | — | ||
|
Leading Edge Speciali |
||||||
| Ransomware | Lakeside Union School District id26102 View details | United States | Education | — | — | |
|
Lakeside Union School District |
||||||
| Ransomware | Elabs id26075 View details | Sweden | Services | — | — | |
|
Elabs Elabs is a pioneer in IT services in Germany, delivering innovative IT solutions that enable businesses to harness modern technology for added value and transformation. |
||||||
| Ransomware | MACT Health Board id25909 View details | United States | Healthcare / Pharma | — | — | |
|
MACT Health Board |
||||||
| Ransomware | Cytek Biosciences id25762 View details | United States | Services | leaked | ||
|
Cytek Biosciences Cytek Biosciences is a leading cell analysis solutions company founded in 1992 and headquartered in Fremont, California with global offices across North America, Europe, and Asia. Sold 0% All data was sold, stay with us, we will upload new Companies later More |
||||||
| Ransomware | Jet-care International id25673 View details | Switzerland | Services | — | — | |
|
Jet-care International |
||||||
| Ransomware | Charles Leonard Steel Services id25342 View details | United States | Manufacturing / Engineering | — | — | |
|
Charles Leonard Steel Services |
||||||
| Ransomware | Falk, Waas, Hernandez, Cortina, Solomon & Bonner Overview Metrics id25222 View details | United States | Other | — | — | |
|
Falk, Waas, Hernandez, Cortina, Solomon & Bonner Overview Metrics |
||||||
| Ransomware | Larry Pitt & Associates id24914 View details | United States | Other | — | — | |
|
Larry Pitt & Associates |
||||||
| Ransomware | YOKOSUKA GAKUIN id24798 View details | Japan | Other | — | — | |
|
YOKOSUKA GAKUIN |
||||||
| Ransomware | ***** *********** id24750 View details | Other | — | — | ||
|
***** *********** |
||||||
| Ransomware | United Keetoowah Band of Cherokee Indians in Oklahoma id24732 View details | United States | Other | — | — | |
|
United Keetoowah Band of Cherokee Indians in Oklahoma |
||||||
| Ransomware | Woodard, Emhardt, Henry, Reeves & Wagner, LLP id24706 View details | United States | Other | — | — | |
|
Woodard, Emhardt, Henry, Reeves & Wagner, LLP |
||||||
| Ransomware | Harbour Town Doctors id24698 View details | Australia | Healthcare / Pharma | — | — | |
|
Harbour Town Doctors |
||||||
| Ransomware | Kane's Furniture id24533 View details | United States | Other | — | — | |
|
Kane's Furniture |
||||||
| Ransomware | SODISE id24475 View details | France | Other | — | — | |
|
SODISE |
||||||
| Ransomware | Bo Beuckman Ford id24407 View details | United States | Other | — | — | |
|
Bo Beuckman Ford |
||||||
| Ransomware | Cleveland County Sheriff's Office id24363 View details | United States | Public Sector | — | — | |
|
Cleveland County Sheriff's Office |
||||||
| Ransomware | AGS id24242 View details | Other | — | — | ||
|
AGS |
||||||
| Ransomware | Marlex Human Capital id24198 View details | Poland | Other | — | — | |
|
Marlex Human Capital |
||||||
| Ransomware | Collge Superieur De Montreal id24172 View details | Canada | Other | — | — | |
|
Collge Superieur De Montreal |
||||||
| Ransomware | St. Joseph's Healthcare Hamilton id24137 View details | Canada | Healthcare / Pharma | — | — | |
|
St. Joseph's Healthcare Hamilton |
||||||
| Ransomware | Wachusett School District MA id24087 View details | United States | Education | — | ||
|
Wachusett School District MA Wachusett School District MA is a public school district. More |
||||||
| Ransomware | Smoll & Banning, CPAs id23958 View details | United States | Finance / Legal / Insurance | — | — | |
|
Smoll & Banning, CPAs Smoll & Banning, CPA's, LLC is an independent accounting firm located in Dodge City, Kansas. |
||||||
| Ransomware | Heart South Cardiovascular Group id23773 View details | United States | Communication / Marketing | — | ||
|
Heart South Cardiovascular Group Heart South is a leading provider of comprehensive cardiac and vascular care in Central Alabama. More |
||||||
| Ransomware | LMHT Associates id23759 View details | United States | Other | — | — | |
|
LMHT Associates |
||||||
| Ransomware | KISS FM id23620 View details | Spain | Communication / Marketing | — | — | |
|
KISS FM Spanish radio station KISS FM, which broadcasts popular music and entertainment programs. The radio is available online, as well as traditionally on radio waves in Spain. The station is owned by the Spanish media group Mediaset Espana. |
||||||
| Ransomware | Automated Logistics Systems id23591 View details | United States | Transportation / Travel / Logistics | — | — | |
|
Automated Logistics Systems |
||||||
| Ransomware | Invacare id23587 View details | United States | Healthcare / Pharma | — | ||
|
Invacare Invacare, founded in 1885 and headquartered out of Elyria, Ohio, is a manufacturer and distributor of home and long term care medical products. More |
||||||
| Ransomware | Spindletop Center id23500 View details | United States | Healthcare / Pharma | — | — | |
|
Spindletop Center Spindletop Center is a non-profit healthcare organization focused on providing behavioral healthcare, as well as programs for individuals with intellectual and developmental disabilities and substance use recovery services. Over 100,000 patient records (address, phone number, passport number, social security number, diagnosis, medical history, etc.) |
||||||
| Ransomware | Gemini Group id23449 View details | United States | Services | — | — | |
|
Gemini Group |
||||||
| Ransomware | Bellflower Unified School District id23424 View details | United States | Education | — | ||
|
Bellflower Unified School District Headquartered Bellflower, California, Bellflower Unified School District is a general education district that offers K-12 classes. More |
||||||
| Ransomware | Abilene Family Medical Associates id23390 View details | United States | Healthcare / Pharma | — | — | |
|
Abilene Family Medical Associates |
||||||
| Ransomware | Peraso id23267 View details | Canada | Other | — | — | |
|
Peraso |
||||||
| Ransomware | Hematology Oncology Consultants id23182 View details | United States | Communication / Marketing | — | — | |
|
Hematology Oncology Consultants Michigan Hematology Oncology is a private practice dedicated to providing the highest level of quality care in a healing environment for the mind, body and spirit of patients dealing with cancer and blood disorders. |
||||||
| Ransomware | GEIGER id23164 View details | Germany | Communication / Marketing | — | — | |
|
GEIGER GEIGER Antriebstechnik is a leading manufacturer of innovative mechanical and electric drive solutions for sun protection products such as blinds, awnings, and shutters, employing over 250 staff. |
||||||
| Ransomware | Sibbalds id23144 View details | United Kingdom | Services | pending | ||
|
Sibbalds Sibbalds Chartered Accountants, based in Derby, specializes in providing a wide range of accountancy services to owner-managed businesses across England. More |
||||||
| Ransomware | Tex-Tube id23135 View details | United States | Manufacturing / Engineering | — | — | |
|
Tex-Tube Tex Tube has over 75 years of experience in manufacturing steel products, specifically electric resistance welded (ERW) steel pipes, adhering to API and ASTM specifications. Serving the North American continent, the company produces tubular steel products that meet both API and ASTM standards. |
||||||
| Ransomware | Furuno Electric id23013 View details | Japan | Communication / Marketing | — | — | |
|
Furuno Electric FURUNO strives to contribute to realisation of the pleasant society filled with safety and peace of mind by giving visual form to that previously invisible, such as underwater condition, situation around ships, accurate time, people's physical conditions, etc. |
||||||
| Ransomware | Sdii Global id22921 View details | United States | Manufacturing / Engineering | — | — | |
|
Sdii Global Since 1989, Sdii Global has set the standard in forensic engineering and consulting, renowned for our expertise and unwavering commitment to excellence. |
||||||
| Ransomware | JASCO Applied Sciences id22865 View details | Canada | Other | — | — | |
|
JASCO Applied Sciences |
||||||
| Ransomware | Medstar Health id22805 View details | United States | Healthcare / Pharma | — | — | |
|
Medstar Health |
||||||
| Ransomware | Peavey Electronics Corporation id22650 View details | United States | Communication / Marketing | — | — | |
|
Peavey Electronics Corporation Founded by Hartley Peavey in 1965 as a one-man shop, today Peavey Electronics Corporation is one of the largest makers and suppliers of musical instruments, amplifiers and professional audio systems in the world-distributing more than 2,000 products to more than 130 countries. |
||||||
| Ransomware | The Maryland Department of Transportation id22562 View details | United States | Transportation / Travel / Logistics | — | — | |
|
The Maryland Department of Transportation |
||||||
| Ransomware | Coastal Pacific Xpress id22251 View details | Canada | Communication / Marketing | — | — | |
|
Coastal Pacific Xpress |
||||||
| Ransomware | Elite Trailers id22141 View details | United States | Manufacturing / Engineering | — | — | |
|
Elite Trailers Elite Trailer MFG, LLC. specializes in the custom manufacturing of high-quality trailers, including horse, livestock, and specialty models. |
||||||
| Ransomware | Firelands Scientific id21997 View details | United States | Other | — | ||
|
Firelands Scientific |
||||||
| Ransomware | ZCORP id21984 View details | United States | Communication / Marketing | — | — | |
|
ZCORP ZCORP is a technology enterprise based in Princeton, NJ, specializing in providing innovative products, services, and tools to help clients navigate the challenges of a rapidly evolving marketplace. |
||||||
| Ransomware | Elkhart Independent School District id21866 View details | United States | Education | — | ||
|
Elkhart Independent School District Elkhart Independent School District is a public school district based in Elkhart, Texas (USA). The district is located in southwest Anderson County and extends into northern Houston County. More |
||||||
| Ransomware | Trans-Tex id21699 View details | Poland | Communication / Marketing | — | — | |
|
Trans-Tex Trans-Tex has been the leader in narrow web dye sublimation printing for over 25 years. |
||||||
| Ransomware | Alascom id21659 View details | Italy | Telecommunications | — | ||
|
Alascom It has been operating for over 20 years as a system integrator and supplier of technical consulting services in the ICT and industrial automation sector with a fundamental knowledge of telecommunication networks and IP technologies. |
||||||
| Ransomware | Cookeville Regional Medical Center id21658 View details | United States | Healthcare / Pharma | pending | ||
|
Cookeville Regional Medical Center At Cookeville Regional Medical Center, we are dedicated to providing the highest quality care to our patients and making a positive impact on our community. |
||||||
| Ransomware | First Baptist Church of Hammond id21657 View details | United States | Other | pending | ||
|
First Baptist Church of Hammond Established in 1887, The First Baptist Church was listed as 2009's 12th largest church in America in Outreach magazine. |
||||||
| Ransomware | Cardinal Services id21656 View details | United States | Services | — | ||
|
Cardinal Services Cardinal Services was established by Bud and Gail Freeman in Coos Bay, Oregon in 1984, and we've been helping local business owners and job seekers achieve marketplace success ever since. |
||||||
| Ransomware | Florida Hand Center id21655 View details | United States | Healthcare / Pharma | — | ||
|
Florida Hand Center Florida Hand Center specializes in non-surgical and minimally invasive treatments for hand, wrist, and elbow conditions, serving patients in Punta Gorda, Port Charlotte, and Fort Myers, Florida. |
||||||
| Ransomware | Welthungerhilfe id20885 View details | Germany | Communication / Marketing | — | ||
|
Welthungerhilfe Welthungerhilfe (WHH) is one of the largest private aid agencies in Germany; politically and religiously independent. More |
||||||
| Ransomware | Coreix id21654 View details | United Kingdom | IT | — | ||
|
Coreix Coreix Cloud Services Limited provides a wide range of cloud computing solutions including public cloud servers, dedicated servers, virtual private servers, and colocation services. |
||||||
| Ransomware | CNPC USA id21653 View details | United States | Other | — | ||
|
CNPC USA CNPC USA Corporation is a Houston-based company that was founded in 2011 to help connect North America with CNPC's worldwide operations. |
||||||
| Ransomware | Hudson River Housing id21652 View details | United States | Construction / Real Estate | pending | ||
|
Hudson River Housing Hudson River Housing provides quality, affordable rental housing for individual, families and seniors throughout the Mid-Hudson Valley region. |
||||||
| Ransomware | Cator Ruma & Associates id21651 View details | United States | Public Sector | — | ||
|
Cator Ruma & Associates Since our founding in 1959, Cator, Ruma & Associates has worked with many architects and clients to build thriving communities across the western and central United States. |
||||||
| Ransomware | Carrera Chevrolet id21650 View details | Brazil | Other | — | ||
|
Carrera Chevrolet |
||||||
| Ransomware | Florida Lung id21649 View details | United States | Healthcare / Pharma | pending | ||
|
Florida Lung The Mission of Florida Lung, Asthma & Sleep Specialists is to be a leader in the provision of comprehensive medical care to patients with pulmonary disease, critical illness, allergic diseases and sleep disorders. |
||||||
| Ransomware | Termolar id21648 View details | Brazil | Communication / Marketing | pending | ||
|
Termolar Termolar is the largest manufacturer of thermal conservation products in Latin America. |
||||||
| Ransomware | Sao Camilo Cachoeiro de Itapemirim id20012 View details | Brazil | Education | — | ||
|
Sao Camilo Cachoeiro de Itapemirim The Sao Camilo Espirito Santo Educational Center was founded in 1969, under the name Instituto Cachoeirense de Ensino, in the city of Cachoeiro de Itapemirim, ES. More |
||||||
| Ransomware | Mountain View Mushrooms id19946 View details | United States | Communication / Marketing | — | — | |
|
Mountain View Mushrooms Mountain View Mushrooms was established in 2003. We are the largest producer and wholesaler of fresh mushrooms in the Intermountain West. |
||||||
| Ransomware | Mediprobe Research id19756 View details | Canada | Communication / Marketing | pending | ||
|
Mediprobe Research Mediprobe Research Inc. is a world class dermatology research and clinical trials center. More |
||||||
| Ransomware | Kalin Hobeltechnik id19717 View details | Switzerland | IT | — | ||
|
Kalin Hobeltechnik Kalin operates throughout Europe and has established a solid reputation with planing machines and systems for solid wood processing. More |
||||||
| Ransomware | Government of Peru id19681 View details | Peru | Public Sector | — | — | |
|
Government of Peru Gob.pe is defined as the Single Digital Platform of the Peruvian State. |
||||||