Ransomware Group intelligence
Vexy Ransomware
ActiveTrack Vexy Ransomware with 12 published victims and 1 known leak locations in a single intelligence view.
Overview
Vexy Ransomware is tracked by Breach House as a ransomware group with 12 published victims.
India is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 4h ago | vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd.onion |
Top Activity Sectors (4)
Victims (12)
Search, filter and paginate the victim timeline for Vexy Ransomware. Showing 1–12 of 12.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Mega Velocity id32605 View details | Mexico | Transportation / Travel / Logistics | — | |
|
megavelocity.net operates within the Transportation, Travel, and Logistics sector and is identified as a ransomware victim within a threat-intelligence index. The entity represents infrastructure relevant to mobility and supply chain continuity, making it significant for cyber-risk analysis in sectors where operational disruption carries high economic and safety implications. This listing reflects an association with Vexy Ransomware, a threat actor documented for targeting organizations through ransomware-based attacks. No specific incident details, such as data exfiltration scope, ransom demands, or confirmed breach evidence, are included to maintain factual neutrality and avoid speculative claims. The entry serves catalog and intelligence purposes for monitoring threat actor activity and sector exposure. |
|||||
| Ransomware | Mega Velocity id32605 View details | Mexico | Transportation / Travel / Logistics | — | |
|
New Delhi–based private technology company incorporated in 2013. Its registered business classification is software publishing, consultancy and supply, including software development, maintenance and web-page design. Its network records also identify MEGA VELOCITY PVT LTD as an Internet/hosting network operator. |
|||||
| Ransomware | Palsana Enviro (PEPL) id32582 View details | India | Services | — | |
|
palsanaenviro.com operates within the Services sector and is situated in India. The entity is cataloged within a threat-intelligence index under the listing type ransomware victim, explicitly linked to the Vexy Ransomware threat actor. This classification reflects its documented association with this specific cyber threat campaign without disclosing unverified incident details. The entry provides context for security teams monitoring ransomware activity across service-oriented organizations in the affected region. It neutrally records the relationship between palsanaenviro.com and Vexy Ransomware for analytical and defensive reference purposes. |
|||||
| Ransomware | Palsana Enviro (PEPL) id32582 View details | India | Services | — | |
|
Environmental services company operating a Common Effluent Treatment Plant (CETP) for textile-processing industries. PEPL collects, treats and disposes of industrial wastewater and also recycles treated water for member industries. Its current stated treatment capacity is 150 MLD, with 50 MLD recycling capacity. |
|||||
| Ransomware | Annapurna Fashion id32583 View details | India | Retail / E-commerce | — | |
|
annapurnafashion.com operates within the Indian retail and e-commerce sector, providing online fashion-related products and commerce services. As a ransomware victim linked to Vexy Ransomware, this entity appears in threat-intelligence indexes documenting cyber incidents affecting digital commerce infrastructure. The listing type identifies the relationship between the organization and the Vexy Ransomware threat actor, contextualizing security exposure within retail technology environments. No specific incident details such as data stolen, ransom demands, or breach confirmation are provided here, maintaining factual neutrality. This entry serves catalog and analytical purposes for monitoring cyber threats impacting e-commerce and retail domains globally. |
|||||
| Ransomware | Annapurna Fashion id32583 View details | India | Retail / E-commerce | — | |
|
Manufacturer, supplier and exporter/distributor of fabrics and apparel-related products, including cotton fabrics, shirting, suiting, jacquard, sherwani fabrics, uniforms, ladies' tops and readymade garments |
|||||
| Ransomware | Sancity Soft Touch id32584 View details | United States | Retail / E-commerce | — | |
|
Softtouch4u.com operates within the United States retail and e-commerce sector, providing digital commerce and customer engagement services typical of modern retail platforms. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor identified as Vexy Ransomware. This classification reflects the cybersecurity context in which the organization was documented, linking its sector profile to a recognized ransomware campaign without disclosing unverified incident details. The entry serves to inform threat researchers and security professionals about potential exposure pathways within retail and e-commerce environments targeted by Vexy Ransomware. It was listed as a ransomware victim associated with Vexy Ransomware. |
|||||
| Ransomware | Sancity Soft Touch id32584 View details | United States | Retail / E-commerce | — | |
|
IT services company providing web design & development, software/application development, payment gateway services, digital marketing, mobile applications, software testing and cloud-related services. |
|||||
| Ransomware | McDonald's Ecuador id32450 View details | Ecuador | Hospitality / Food & Beverage / Tourism | — | |
|
mcdonalds.com.ec represents a domain associated with the McDonald's brand operating within the Hospitality, Food & Beverage, and Tourism sectors, primarily linked to the Economic Community of Africa (EC) region. This entity functions as a digital presence serving food service operations and customer engagement across its geographic market. Within threat-intelligence indexing frameworks, mcdonalds.com.ec is cataloged specifically as a ransomware victim, with the associated threat actor identified as Vexy Ransomware. The listing type reflects observed security event correlation rather than confirmed breach details, maintaining neutrality regarding unverified incident specifics. This entry documents the cybersecurity risk profile of an organization in the food and hospitality industry facing ransomware threats from the Vexy Ransomware group. |
|||||
| Ransomware | McDonald's Ecuador id32450 View details | Ecuador | Hospitality / Food & Beverage / Tourism | — | |
|
McDonald's Ecuador is the local franchise operation of the global McDonald's brand. The company operates fast-food restaurants across Ecuador, offering products such as burgers, fries, beverages, breakfast items, and children's meals. It operates under the McDonald's franchise model through Arcos Dorados, the largest McDonald's franchise operator in Latin America and the Caribbean. |
|||||
| Ransomware | Engefitas id32444 View details | Brazil | Services | — | |
|
engefitas.com.br operates within the Services sector and is headquartered in Brazil. The entity represents a business organization whose infrastructure or digital assets were identified within the threat-intelligence index as a ransomware victim linked to the Vexy Ransomware threat actor. This listing type indicates that the organization was affected by this specific malware campaign, contributing contextual data for analysts tracking cyber incidents across service-oriented sectors in Brazil. The description avoids speculative claims regarding breach details, data exfiltration, or financial impact, focusing solely on the verified association between the entity and the threat actor as documented in the index. Such catalog entries support threat-resilience efforts by mapping victim profiles to active ransomware campaigns. |
|||||
| Ransomware | Engefitas id32444 View details | Brazil | Services | — | |
|
Engefitas is a Brazilian company that produces various adhesive tapes and adhesives for industries like packaging, automotive, construction, electronic, and manufacturing sectors. |
|||||