All Ransomware Records
Top Countries
All Ransomware Attacks in All period
Posts
| Target | Discovered | Country | Source | Business Category | Intel Link |
|---|---|---|---|---|---|
| marugokiso.co.jp View Details _ | Japan | lockbit3 | Other | ||
| lacalera.pe View Details _ | Peru | lockbit3 | Other | ||
| diakonissen-riehen.ch View Details _ | Switzerland | lockbit3 | Other | ||
| dcashpro.com View Details _ | lockbit3 | Communication / Marketing | |||
| connectvitypoint.com View Details _ | lockbit3 | Other | |||
| kisan.com.tr View Details _ | Türkiye | lockbit3 | Other | ||
| kortrijkserijschool.be View Details _ | Belgium | lockbit3 | Education | ||
| MGSMFG View Details _ | blackbasta | Other | |||
| EMEPLATING View Details _ | blackbasta | Other | |||
| STEVENG View Details _ | blackbasta | Other | |||
| SHI View Details _ | blackbasta | Other | |||
| marcopolohotels.com View Details _ | lockbit3 | Hospitality / Food & Beverage / Tourism | |||
| hunters.com View Details _ | lockbit3 | Other | |||
| misumi.com.tw View Details _ | Taiwan, Province of China | lockbit3 | Other | ||
| metaage.com.tw View Details _ | Taiwan, Province of China | lockbit3 | Other | ||
| DDoS instead of the Discuss - Nice try TAP Air View Details _ | ragnarlocker | Other | |||
| California-Oregon Telecommunications Company View Details _ | United States | hive | Telecommunications | ||
| lafondasantafe.com View Details _ | lockbit3 | Other | |||
| gavresorts.com.br View Details _ | Brazil | lockbit3 | Hospitality / Food & Beverage / Tourism | ||
| sbr-zwiesel.de View Details _ | Germany | lockbit3 | Other | ||
| pdh.com.tw View Details _ | Taiwan, Province of China | lockbit3 | Other | ||
| monnensenpartners.be View Details _ | Belgium | lockbit3 | Other | ||
| CleanTech View Details _ | blackbasta | IT | |||
| augustacoop View Details _ | blackbasta | Other | |||
| sportscity.com.tw View Details _ | Taiwan, Province of China | lockbit3 | Public Sector | ||
| finnco.eu View Details _ | lockbit3 | Other | |||
| psico View Details _ | blackbasta | Other | |||
| www3.comune.gorizia.it View Details _ | Italy | lockbit3 | Other | ||
| kamut.com View Details _ | lockbit3 | Other | |||
| divultec.pt View Details _ | Portugal | lockbit3 | Other | ||
| eneva.com.br View Details _ | Brazil | lockbit3 | Other | ||
| Speed-Buster View Details _ | Germany | blackbyte | Communication / Marketing | ||
|
The headquarters is located in Sinzig/Rhine, where about 30 employees can rely on more than two decades of experience and can therefore assure a competent handling of our daily and future business. With more than 1.000 m2 office space and 1.500 m2 warehouse space, our headquarters also comprise our own development department as well as a highly modern production line, on which the tuning boxes are produced according to EC-Directives.Speed-Buster® sells its tuning boxes globally in more than 50 countries with high success and in high quantities. Our clients know and appreciate that the label made in Germany is a guarantee for sophisticated and high-quality products. As a support, local distributor bases are established all around the globe. Contrary to the current tendency amongst many of our competitors, SPEED-BUSTER has decided to solely produce in Germany. This allows us to intervene in a focused manner at any time of the manufacturing process and to continuously enhance our products. The loyalty of our customers has confirmed this decision time and again. |
|||||
| Cpl Architects, Engineers View Details _ | blackbasta | Other | |||
| C2CORP View Details _ | blackbasta | Services | |||
| Elmbrook Schools View Details _ | vicesociety | Education | |||
| hmets.com View Details _ | lockbit3 | Other | |||
| floresfunza.com View Details _ | lockbit3 | Other | |||
| Baer's View Details _ | bianlian | Other | |||
| Infinitely Virtual View Details _ | bianlian | Other | |||
| Fundo Nacional de Desenvolvimento da Educação View Details _ | Brazil | ransomexx | Education | ||
|
The National Fund for Educational Development (FNDE) is a federal agency under the Ministry of Education, responsible for implementing programs nationwide, including the National School Nutrition Program – PNAE, which serves 47 million students throughout the country, offering adequate and safe food in schools. Since its establishment, the FNDE has undergone several changes, which became more intense when the Brazilian government laid the groundwork for the formation of a substantive conception of education that pervades all levels of education and procedures. Thus, the agency was strengthened, especially with regard to the ongoing management of activities, projects and educational programs as a strategy to support the promotion of educational quality. Nowadays, besides the National School Nutrition Program - PNAE, the FNDE is responsible for implementing the Programs of School Transportation, National Textbook, School Direct Money, Brazil Literate, Pro-Youth, Joint Action Plan, Pro-Child, Decentralization and the Open University Credits. |
|||||
| TAP Air - First Facts View Details _ | ragnarlocker | Other | |||
| peakinternational.com View Details _ | lockbit3 | Services | |||
| Eurocell View Details _ | United Kingdom | hive | Other | ||
| Instituto Agrario Dominicano View Details _ | Dominican Republic | quantum | Communication / Marketing | ||
|
The Dominican Agrarian Institute is a decentralized government agency under the Ministry of Agriculture,established by Law No. 5879 as of April 27, 1962, with the aim of carrying out agrarian reform programs throughout the national geography by seizing and distributing land to peasants to transform the structure and agricultural production, improving living conditions in a Dominican villages. |
|||||
| Moon Area School District View Details _ | vicesociety | Education | |||
| An Japan Game Halls Operator View Details _ | cheers | Other | |||
| Moscone Center View Details _ | United States | quantum | Other | ||
|
Founded in 1981. Moscone Center is headquartered in San Fransisco, California. Moscone Center is a meeting and exhibition facility |
|||||
| Monarchnc View Details _ | donutleaks | Other | |||
| Alan Smith View Details _ | blackbyte | Construction / Real Estate | |||
|
Alan Smith Pool Plastering, Inc. has been a swimming pool contractor, and an active member of the Orange County community, for over 30 years. As a Southern California pool specialist, we have completed tens of thousands of renovation and new construction projects over the years for homeowners, developers, builders, and landscape architects. In addition to the renovation and new construction of pools, in late 2007 we launched a new division of the company devoted to backyard renovation. We can now provide you with the same quality and management oversight for your entire backyard design and landscaping project that built our reputation. |
|||||
| Midea Group View Details _ | revil | Services | |||
| solidatech.com View Details _ | lockbit3 | IT | |||
| precision.com View Details _ | lockbit3 | Communication / Marketing | |||
| hspatent.com View Details _ | lockbit3 | Other | |||
| OakBend Medical Center View Details _ | United States | daixin | Healthcare / Pharma | ||
| USA Insurance company - Smith brothers File tree and some proofs View Details _ | ragnarlocker | Finance / Legal / Insurance | |||
| Huge drama for Tap Air Portugal View Details _ | ragnarlocker | Other | |||
| NCG Medical View Details _ | United States | hive | Healthcare / Pharma | ||
| MEIJI.COM.SG View Details _ | Singapore | lockbit3 | Other | ||
| Magnachem View Details _ | bianlian | Other | |||
| Alegria Family Services View Details _ | bianlian | Services | |||
| WWAY-TV, LLC View Details _ | bianlian | Services | |||
| Ramada Hervey Bay Hotel Resort View Details _ | bianlian | Hospitality / Food & Beverage / Tourism | |||
| Community Dental Partners View Details _ | bianlian | Healthcare / Pharma | |||
| 4cRisk View Details _ | bianlian | Other | |||
| Captec-group View Details _ | bianlian | Services | |||
| GOV Brazil View Details _ | everest | Other | |||
| skupstina View Details _ | cuba | Other | |||
| Spalding Grammar School View Details _ | bianlian | Education | |||
| Rudman View Details _ | bianlian | Other | |||
| The Preston Partnership View Details _ | bianlian | Communication / Marketing | |||
| Advance Corporation View Details _ | bianlian | Services | |||
| International Custom Controls View Details _ | bianlian | Services | |||
| currierryan.com View Details _ | lockbit3 | Other | |||
|
Currier Ryan is an independent boutique law firm based in Boston, Massachusetts, serving families in the greater Boston area with private client and estate planning legal services. The firm focuses on tax-efficient estate plans, estate administration, lifetime gifting, fiduciary services, and trust administration. Its practice is centered on helping clients transfer assets and manage wealth across generations. Currier Ryan was listed as a ransomware victim associated with lockbit3. |
|||||
| Wheat Ridge County View Details _ | United States | alphv | Public Sector | ||
|
Wheat Ridge is a city in Jefferson County, Colorado, in the United States, and it operates as a local government serving residents and businesses. Its official website lists city services including tax and licensing, building permits, public safety, parks and recreation, public works, planning, and community development. As a public sector entity, it provides municipal administration and frontline civic services for the Wheat Ridge community. It was listed as a ransomware victim associated with alphv. |
|||||
| ygboulons.com View Details _ | lockbit3 | Other | |||
|
ygboulons.com is the website of Spécialités Y.G., a family-owned industrial hardware business in Chicoutimi, Quebec. It sells bolts, fasteners, and related industrial supplies from 587, Rue des Actionnaires, serving customers in the Saguenay region. The company also provides contact, careers, and account pages through its French-language site. It was listed as a ransomware victim associated with LockBit3. |
|||||
| uplexis.com.br View Details _ | Brazil | lockbit3 | Other | ||
|
uplexis.com.br is the Brazilian website of upLexis, a technology company in the compliance and risk-management sector based in São Paulo, Brazil. Its upMiner platform helps organizations collect information on people and companies, support background checks, and streamline risk-analysis and due-diligence workflows. The company says it serves businesses and public-sector use cases with tools for governance, compliance, and fraud prevention. It was listed as a ransomware victim associated with lockbit3. |
|||||
| embalajescapsa.com View Details _ | lockbit3 | Other | |||
|
Embalajes Capsa S.L. is a Spanish commerce company based in Canet de Mar, Barcelona, specializing in the wholesale trade of cardboard packaging and related packaging products. It operates under the Capsa 2in1 brand and presents itself as a packaging solutions provider for e-commerce and other professional uses. The company lists its address in the Can Misser industrial area in Canet de Mar, Spain. It was listed as a ransomware victim associated with lockbit3. |
|||||
| accionplus.com View Details _ | lockbit3 | Other | |||
|
AccionPlus is a leading human talent and outsourcing company headquartered in Bogotá, Colombia, founded in 1999 to provide services such as temporary staffing, trade marketing, headhunting, and payroll management. The firm operates across 16 cities nationwide, connecting workers with employers through dedicated recruitment and selection structures in each location. It offers comprehensive solutions including legal and labor advisory support, employee training, and productivity management for client companies. AccionPlus was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| Torin Drive View Details _ | blackbyte | Communication / Marketing | |||
|
Torin Drive, operating from Suzhou, China, is an equipment group founded in 1989 that integrates research, manufacturing, sales, and service. Its website and directory listings describe it as a specialized manufacturer and supplier of elevator traction machines and related drive equipment. The company’s online presence includes product and company information for domestic and international markets. torindrive.com was listed as a ransomware victim associated with BlackByte. |
|||||
| Grande Stevens View Details _ | blackbyte | Finance / Legal / Insurance | |||
|
Grande Stevens International is an English law firm operating as an integrated international network with a prestigious Italian law firm, serving clients in Finance, Legal, and Insurance sectors across England and Italy. The firm offers specialized services including corporate law, banking and financial law, private wealth management, and international dispute resolution. Based in London with offices in Turin, Milan, and Rome, it functions as a boutique law firm delivering integrated legal solutions. The company was listed as a ransomware victim associated with the threat actor Blackbyte. |
|||||
| goodwillnm.org View Details _ | lockbit3 | Other | |||
|
goodwillnm.org is the website of Goodwill Industries of New Mexico, a nonprofit based in Albuquerque, New Mexico. It operates thrift stores and donation centers while offering job training, employment services, and related community programs across the state. Its services include career training, youth employment support, and workforce programs tied to education and placement. The site was listed as a ransomware victim associated with LockBit3. |
|||||
| thininfra.nl View Details _ | Netherlands | lockbit3 | Other | ||
|
thininfra.nl is a Netherlands-based website associated with an organization in the Other sector. Publicly available information in the search results does not identify a specific product or service offering, so the entity can only be described generally from its domain and sector classification. The Netherlands has a diversified, service-oriented economy with significant activity in commercial services, technology, and innovation. In threat-intelligence catalogs, this entry is used to index the organization as a ransomware victim. It was listed as a ransomware victim associated with lockbit3. |
|||||
| stjohnvianney.org View Details _ | lockbit3 | Other | |||
|
StJohnVianney.org is the website for St. John Vianney Catholic Parish, which serves a faith community in the United States and provides parish life, worship, ministries, and related church information. The site also references ministry and campaign materials, reflecting a broader set of Catholic services and communications. In threat-intelligence catalogs, it was listed as a ransomware victim associated with LockBit3. |
|||||
| stevesilvaplumbing.com View Details _ | lockbit3 | Other | |||
|
Steve Silva Plumbing, Inc. is a locally owned plumbing contractor based in Napa, California, serving Napa Valley since 1983. It provides residential and commercial plumbing services, including repairs, installations, new construction, and remodel work. Public business listings also describe the company as a full-scale plumbing provider with 24-hour availability. The company was listed as a ransomware victim associated with LockBit3. |
|||||
| statravel.de View Details _ | Germany | lockbit3 | Transportation / Travel | ||
|
statravel.de is associated with STA Travel, a travel brand in Germany that provides online travel services for students and young travelers, including flights and packaged trip options. Public company profiles describe it as part of the travel sector and indicate a German presence tied to Düsseldorf and other locations in Germany. Its offering centers on affordable, youth-oriented travel planning and booking. It was listed as a ransomware victim associated with lockbit3. |
|||||
| sportlavit.nl View Details _ | Netherlands | lockbit3 | Other | ||
|
Sportlavit.nl is a Netherlands-based sport-medical wholesaler offering warming oils, cooling gels, and recovery products for athletes, physiotherapists, and massage professionals. The company, formerly known as Sport Lavit and now operating under the MediVit brand, has provided dermatologically tested body care solutions trusted by professionals and amateurs for over 50 years. Its product range includes items like Sport Gel Hot, Ice Sport Tonic, and Warm Up Body Oil, catering to fitness, therapy, and wellness sectors. Sportlavit.nl was neutrally listed as a ransomware victim associated with Lockbit3. |
|||||
| perteet.com View Details _ | lockbit3 | Other | |||
|
Perteet.com belongs to Perteet Inc., an award-winning infrastructure consulting firm based in Everett, Washington, in the United States. The company provides engineering and consulting services across transportation, energy, environmental, broadband, and related public-infrastructure work. Its services support community development and utility planning for clients in the Puget Sound region and beyond. It was listed as a ransomware victim associated with lockbit3. |
|||||
| microdepot.com View Details _ | lockbit3 | Other | |||
|
microdepot.com is associated with Brico Dépôt, a French home-improvement retailer that sells DIY, hardware, paints, and glass products through large-format stores and its online catalogue. The company’s headquarters are in Longpont-sur-Orge, France, and it operates multiple locations across the country. Public business records and the retailer’s own site describe it as a nationwide commerce business in the other sector. It was listed as a ransomware victim associated with lockbit3. |
|||||
| lenax.com View Details _ | lockbit3 | Other | |||
|
Lenax.com is the website of Lenax Construction Services, a Los Angeles-based construction consulting firm. The company provides project controls, construction cost estimating, change order administration, scheduling, and document control for engineering, design, construction, and public sector clients. Its portfolio includes transportation and infrastructure work across the Los Angeles area. It was listed as a ransomware victim associated with LockBit3. |
|||||
| kkcsworld.com View Details _ | lockbit3 | Other | |||
|
kkcsworld.com is the website of Kal Krishnan Consulting Services (KKCS), a California-based consulting and engineering firm. The company provides construction management, project management, and design services for infrastructure, facilities, and utilities work, with offices in multiple U.S. locations. Its business profile places it in the other sector rather than a single industry vertical. It was listed as a ransomware victim associated with LockBit3. |
|||||
| galenica.ma View Details _ | Morocco | lockbit3 | Other | ||
|
Galenica.ma is the website of Laboratoires GALENICA, a Morocco-based pharmaceutical company founded in 1978 and located in the Oulad Salah/Bouskoura industrial zone near Casablanca. It develops, manufactures, and supplies generic medicines and other healthcare products for the local market. The company also provides contact details and customer support through its official site. It was listed as a ransomware victim associated with LockBit3. |
|||||
| draperyconceptsny.com View Details _ | lockbit3 | Other | |||
|
draperyconceptsny.com operates as a drapery and custom window treatment company serving clients in New York, specializing in tailored fabric solutions for residential and commercial spaces. The firm designs and manufactures draperies, blinds, and shades for contractors, architects, and interior designers, offering premium craftsmanship and design consultation. Based in New York, it caters to a diverse clientele seeking high-quality window furnishings. The company was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| cenviro.com View Details _ | lockbit3 | Other | |||
|
Cenviro is a Malaysian environmental services company headquartered in Kuala Lumpur. It provides integrated waste management, including scheduled waste management, recycling and recovery, and municipal solid waste services through subsidiaries such as Kualiti Alam, Cenviro Services, and Cenviro Recycling & Recovery. The company describes itself as a leading waste resource management provider serving industrial and municipal needs. It was listed as a ransomware victim associated with LockBit3. |
|||||
| americantilestone.com View Details _ | lockbit3 | Other | |||
|
Americantilestone.com appears to represent American Tile & Stone, a U.S. business in the broader other sector that markets tile, stone, and related surface products and services. Public web search results do not provide a clear official company profile or location, so the listing is described conservatively from the domain name and available context. The site name indicates a commercial brand rather than a consumer news or media property. It was listed as a ransomware victim associated with lockbit3. |
|||||
| trufab.com View Details _ | lockbit3 | Other | |||
|
Tru-Fab Technology, Inc. is a US metal manufacturing company based in Eastlake, Ohio. Its public profiles describe a full-service operation focused on custom fabrication, machining, welding, deep-hole drilling, and powder coating. The company also says it serves customers with on-time delivery, quality, and communication. In threat-intelligence indexing, trufab.com was listed as a ransomware victim associated with LockBit3. |
|||||
| canteen.com View Details _ | lockbit3 | Other | |||
|
Canteen.com is the website of Canteen, a U.S. workplace food-service company that provides vending, micro markets, coffee, dining, and pantry solutions. It serves clients nationwide and operates through local branches and franchise partners across the United States. The company says it supports workplaces, campuses, and other facilities with scalable breakroom offerings. In threat-intelligence catalogs, canteen.com was listed as a ransomware victim associated with lockbit3. |
|||||
| hikadikoy.com View Details _ | lockbit3 | Other | |||
|
hikadikoy.com is the website for Holiday Inn Istanbul - Kadikoy, an IHG hotel on Istanbul’s Asian side in the Kadikoy district of Türkiye. The property is a modern, full-service hotel offering guest rooms, conference facilities, and amenities such as Wi‑Fi, a spa, sauna, and Turkish bath. Its contact details on IHG include the domain email addresses used for hotel reservations and front desk communication. It was listed as a ransomware victim associated with lockbit3. |
|||||
| centrodsr.it View Details _ | Italy | lockbit3 | Other | ||
|
centrodsr.it is an Italy-based organization in the broad Other sector; available search results do not identify a more specific public business profile, product line, or service catalog. In the context of Italy’s expanding digital economy, the name appears as a domain-based entity rather than a clearly described consumer brand or public institution. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Lampton School View Details _ | vicesociety | Education | |||
|
Lampton School is an 11-18 comprehensive academy in central Hounslow, West London, serving a diverse student body and offering secondary and sixth-form education. The school describes itself as a large, mixed, multi-ethnic education provider and a National Teaching School with SCITT activity. In threat-intelligence indexing, Lampton School is listed as a ransomware victim associated with vicesociety. |
|||||
| Frances King School of English View Details _ | vicesociety | Education | |||
|
Frances King School of English is a London-based English language school in the Education sector, located in Kensington and Chelsea, with additional central London teaching sites. It offers English courses for international students, including general English, business English, and programmes for different ages and study goals. The school describes itself as a leading English language school focused on speaking and learning in an accredited setting. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Altice International View Details _ | Netherlands | hive | Services | ||
|
Altice International is a Netherlands-based services company within the Altice telecom group, operating from Amsterdam. It provides telecommunications services including broadband internet, fixed-line telephony, mobile, and pay-television offerings to residential and corporate customers across its markets. The group is part of the broader Altice structure associated with cable, fiber, telecommunications, content, and media operations. It was listed as a ransomware victim associated with hive. |
|||||
| ANGT - HACKED. MORE THEN 700 GB SENSITIVE DATA LEAKED View Details _ | lv | Other | |||
|
ANGT - HACKED. MORE THEN 700 GB SENSITIVE DATA LEAKED refers to an incident involving a company in the Other sector, where over 700 GB of sensitive data was reportedly leaked following a ransomware attack. The entity is associated with the threat actor lv, known for targeting organizations across unspecified sectors and locations. No official confirmation of the breach or specific data types has been publicly disclosed by the affected company. The incident was listed as a ransomware victim associated with lv. |
|||||
| growag.ch View Details _ | Switzerland | lockbit3 | Other | ||
|
growag.ch belongs to Growag Feuerwehrtechnik AG, a Swiss company based in Grosswangen, Lucerne, in Switzerland. It operates as a leading distributor and manufacturer of fire-service equipment, with offerings spanning firefighting materials, protective gear, fire protection, and work-safety products. The company presents itself as serving fire brigades and related safety applications across Switzerland. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Baton Rouge General View Details _ | United States | hive | Other | ||
|
Baton Rouge General is a healthcare provider in Baton Rouge, Louisiana, serving patients through hospital and clinic locations across the city and nearby areas. Its services include primary care, urgent care, specialty clinics, emergency care, and patient tools such as online scheduling and MyChart access. The organization operates facilities at Mid City and Bluebonnet, with additional services in the surrounding region. It was listed as a ransomware victim associated with Hive. |
|||||
| Enso Detego View Details _ | donutleaks | Other | |||
|
Enso Detego GmbH is a leading provider of auto-ID and RFID software solutions, headquartered in Graz, Austria, serving the fashion, food, beverage, automotive, and electronics industries. The company specializes in developing and distributing software for retail and quality management, focusing solely on RFID technology for global retail applications. Founded in 2011, Enso Detego has expanded its operations with offices in the UK, Austria, the USA, and Russia, establishing itself as a global RFID provider. Enso Detego was listed as a ransomware victim associated with the threat actor donutleaks. |
|||||
| Sando View Details _ | donutleaks | Other | |||
|
Sando is a South Korea-based company in the other sector, with public company profiles describing it as an industrial manufacturer of auto parts and related products. Bloomberg identifies Sando as a business that produces, processes, and sells automotive stampings and other products, indicating an industrial manufacturing profile. In threat-intelligence indexing, it appears as a ransomware victim entry. The listing was associated with donutleaks. |
|||||
| CMZ UK View Details _ | donutleaks | Other | |||
|
CMZ UK is the UK arm of CMZ, a machine tool manufacturer with more than 75 years of experience in the sector and a focus on CNC lathes for industrial customers. Its UK presence is associated with Rugby, Warwickshire, and its company records also show a Birmingham registered office. CMZ describes its business as serving the machine tool market with products and technical support for manufacturing operations. The entity was listed as a ransomware victim associated with donutleaks. |
|||||
| PlanET Biogas Solutions View Details _ | donutleaks | Energy | |||
|
PlanET Biogas Solutions Inc. is the Canadian subsidiary of PlanET Biogas Group, based in St. Catharines, Ontario, Canada. It develops, builds, and services anaerobic digestion, biogas, and renewable natural gas systems for agriculture and organics customers. The company says it has operated in Canada since 2006 and is part of a wider international biogas business with projects across North America and beyond. It was listed as a ransomware victim associated with donutleaks. |
|||||
| Sheppard Robson View Details _ | donutleaks | Other | |||
|
Sheppard Robson is a British architecture practice with offices in London, Manchester and Glasgow, and it provides architectural and design services across sectors including offices, education, residential, healthcare, science and retail. It is based in the United Kingdom and operates through studios serving projects in England and Scotland. In threat-intelligence listings, Sheppard Robson was identified as a ransomware victim associated with donutleaks. |
|||||
| Bombardier Recreational Products (BRP) - BONUS CONTENT (!!!) View Details _ | ransomexx | Communication / Marketing | |||
|
Bombardier Recreational Products (BRP) is a Canadian powersports manufacturer headquartered in Valcourt, Quebec. It designs and sells snowmobiles, all-terrain vehicles, side-by-sides, motorcycles, personal watercraft, and related engines through brands including Ski-Doo, Sea-Doo, Can-Am, and Lynx. BRP operates globally across North America, Europe, and other markets, serving recreational mobility segments rather than communication or marketing services. It was listed as a ransomware victim associated with ransomexx. |
|||||
| Olamgroup View Details _ | everest | Services | |||
|
Olamgroup is a Singapore-headquartered food and agri-business founded in 1989, publicly listed on the Singapore Exchange, and operating across 60 countries to supply food, ingredients, feed, and fibre to over 20,000 customers worldwide. The company engages in sourcing, processing, packaging, and merchandising of agricultural products, placing it among the world's largest suppliers of cocoa beans, coffee, cotton, and rice. As a leading entity in the Services sector, Olamgroup serves multinational organizations and smaller enterprises with high-quality food and industrial raw materials. Olamgroup was listed as a ransomware victim associated with the threat actor everest. |
|||||
| GMX View Details _ | blackbyte | Other | |||
|
GMX is a Germany-based internet company best known for providing email services, online account tools, and related web services through the GMX brand. It operates as part of 1&1 Mail & Media and serves users with mailbox, cloud, calendar, and data-management features. In threat-intelligence catalogs, GMX appears under the Other sector because its core business is digital services rather than a traditional industry vertical. It was listed as a ransomware victim associated with blackbyte. |
|||||
| studiobarba.com View Details _ | lockbit3 | Hospitality / Food & Beverage / Tourism | |||
|
studiobarba.com is a hospitality-sector website associated with food and beverage and tourism services in Italy, based on its name and industry classification. Hospitality spans accommodation, food and beverage, travel, and tourism, and related businesses often present services for guests, dining, and visitor experiences. Public threat-intelligence listings associated studiobarba.com with the LockBit3 ransomware group. It was listed as a ransomware victim associated with lockbit3. |
|||||
| ruffinlawyers.com.au View Details _ | Australia | lockbit3 | Finance / Legal / Insurance | ||
|
ruffinlawyers.com.au is an Australian legal-services domain associated with the finance, legal and insurance sector, indicating a law-related practice serving clients in those areas. In that sector, firms commonly provide legal advice and representation connected to financial services, disputes, regulation and related commercial matters. The site was listed as a ransomware victim associated with LockBit3. |
|||||
| robitgroup.com View Details _ | lockbit3 | Services | |||
|
Robitgroup.com is the website of Robit Plc, a Finnish public company based in Lempäälä, Finland. It supplies drilling consumables and related technologies for mining, construction, and other drilling applications, serving customers in global markets. The company presents itself as a strongly internationalized growth business focused on drilling tools and consumables. It was listed as a ransomware victim associated with lockbit3. |
|||||
| pinjuhlaw.com View Details _ | lockbit3 | Finance / Legal / Insurance | |||
|
pinjuhlaw.com is associated with the Finance, Legal, and Insurance sectors, reflecting a business profile centered on regulated financial services and legal-advisory activity in Indonesia. The available source material does not provide a verified company profile, location, or service catalog for the domain, so its offerings cannot be stated more specifically without invention. In threat-intelligence indexing, the domain is treated as an entity in a heavily regulated professional-services segment. It was listed as a ransomware victim associated with lockbit3. |
|||||
| orioninc.com View Details _ | lockbit3 | Services | |||
|
Orion Innovation is a Services-sector technology company headquartered in Edison, New Jersey, with global operations and offices in India. It provides data and AI-enabled software engineering, cloud, digital experience, and digital transformation services for enterprise clients. Public company profiles also describe it as a software systems developer and adviser focused on digital automation and product development. It was listed as a ransomware victim associated with lockbit3. |
|||||
| destinationhope.com View Details _ | lockbit3 | Other | |||
|
Destination Hope is a behavioral health and addiction treatment provider based in Tamarac, Florida, serving clients in the Fort Lauderdale area. It offers substance abuse and mental health care, including residential, partial hospitalization, and intensive outpatient programs, with dual-diagnosis treatment for co-occurring conditions. The organization presents itself as a rehabilitation center for men and women seeking recovery support and related clinical services. It was listed as a ransomware victim associated with lockbit3. |
|||||
| barrydowd.com View Details _ | lockbit3 | Hospitality / Food & Beverage / Tourism | |||
|
barrydowd.com is a hospitality-focused brand associated with food, beverage, and tourism services, with an online presence that suggests guest-facing or travel-related offerings. Based on the name and sector tag, it fits a commercial hospitality profile rather than a technical or industrial one, and it is connected to the United States. In threat-intelligence catalogs, it is referenced as a ransomware victim. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Engine Power View Details _ | lorenz | Energy | |||
|
Engine Power is an energy-sector company in the United States that operates in power generation and related services. In the energy industry, engine-based power plants use gas or reciprocating engines to convert fuel into electricity for grid support and other applications. The company’s name indicates a power-focused business, but publicly available source material in this search set does not confirm a more specific product or service profile. It was listed as a ransomware victim associated with lorenz. |
|||||
| Apex View Details _ | United States | blackbyte | Other | ||
|
Apex, NC is a local government entity in the United States that serves residents of Apex, North Carolina with utility services, parks, recreation programs, and resident support. The Town of Apex provides water, sewer, and electric services to most households and businesses in town, operating as a community-owned utility focused on safety and reliability. It is headquartered at 73 Hunter Street and delivers cultural arts resources alongside public services to its community. Apex, NC was listed as a ransomware victim associated with the threat actor Blackbyte. |
|||||
| Bombardier Recreational Products (BRP) View Details _ | United States | ransomexx | Hospitality / Food & Beverage / Tourism | ||
|
brp.com is the website for BRP, a global powersports company headquartered in Valcourt, Quebec, with U.S. operations and offices in Wisconsin and North Carolina. It designs and sells recreational vehicles and related products, including Sea-Doo, Can-Am, Lynx, and Ski-Doo, for use on snow, water, and land. BRP also supports its lineup with engines, parts, accessories, and apparel. It was listed as a ransomware victim associated with ransomexx. |
|||||
| Announcement. Action Lab File-tree View Details _ | ragnarlocker | Other | |||
|
Announcement. Action Lab File-tree appears in threat-intelligence records as a victim entry in the Other sector, with no reliable public details in the available sources about its location or offerings. The name itself suggests a business or operational file-tree announcement, but the sources do not confirm what the entity does, so no further business description can be stated with confidence. The listing is associated with the Ragnar Locker ransomware group. It was listed as a ransomware victim associated with ragnarlocker. |
|||||
| DESFA - Pipeline company LEAK View Details _ | ragnarlocker | Services | |||
|
DESFA, also known as the Hellenic Gas Transmission System Operator, is a Greek services-sector energy infrastructure company based in Chalandri, Attica, Greece. It operates the national natural gas transmission system and develops related infrastructure, including transmission networks and LNG terminal operations. The company is based in Greece and serves as the country’s gas system operator. It was listed as a ransomware victim associated with ragnarlocker. |
|||||
| Moskowitz, Mandell & Salim, P.A. View Details _ | United States | quantum | Finance / Legal / Insurance | ||
|
Moskowitz, Mandell & Salim, P.A. is a law firm based in Fort Lauderdale, Florida, specializing in commercial litigation, civil litigation, and governmental approval matters. The firm, established in 1985, provides legal services in areas including lender-related litigation and commercial practice for clients in the Finance, Legal, and Insurance sectors. It operates from 800 Corporate Drive Suite 500, serving the Fort Lauderdale area with expertise in business and residential real property litigation. The firm was neutrally listed as a ransomware victim associated with the quantum threat actor. |
|||||
| Northern Contours Inc. View Details _ | lorenz | Services | |||
|
Northern Contours Inc is a leading manufacturer of cabinet and furniture components based in Saint Paul, Minnesota, specializing in advanced engineered materials for the Kitchen & Bath, Office, Healthcare, and Commercial industries. The company offers expertise in membrane pressing, miter folding, laminating, edgebanding, machining, routing, and five-piece door assembly across five operational facilities. Northern Contours Inc serves the custom cabinet and closet industry as a primary supplier of high-quality doors, drawers, trims, and moldings. The company was listed as a ransomware victim associated with the threat actor lorenz. |
|||||
| northwestpipe.com View Details _ | lockbit3 | Other | |||
|
Northwest Pipe Company is a leading manufacturer of engineered welded steel pipe water systems headquartered in Vancouver, Washington, serving North America. The company produces large-diameter, high-pressure pipeline systems for drinking water infrastructure, piling, hydroelectric projects, and water treatment plants. It primarily sells to public water agencies and installation contractors across the United States. Northwest Pipe Company was listed as a ransomware victim associated with lockbit3. |
|||||
| Family Medicine Centers View Details _ | vicesociety | Healthcare / Pharma | |||
|
Family Medicine Centers is a healthcare provider offering primary care and family medicine services, typically including preventive visits, routine screenings, sick care, and ongoing management of common conditions. The name suggests a clinic network serving patients in the United States, but no authoritative public source in the provided results identifies a specific city or state for this exact entity. In healthcare, family medicine practices focus on broad, first-contact care for adults and children across routine and chronic needs. It was listed as a ransomware victim associated with vicesociety. |
|||||
| BSA Hospice of the Southwest View Details _ | vicesociety | Other | |||
|
BSA Hospice of the Southwest is a for-profit hospice care facility located in Amarillo, Texas, serving patients and families across the Texas Panhandle. It offers specialized care focused on comfort, support, and dignity for individuals with life-limiting illnesses, including pain and symptom management, emotional and spiritual support, and holistic services for both patients and caregivers. The organization operates with a clinical team of doctors, nurses, social workers, counselors, and volunteers to address physical, emotional, and spiritual needs during sensitive times. BSA Hospice of the Southwest was listed as a ransomware victim associated with the threat actor vicesociety. |
|||||
| *.algotrader.com View Details _ | icefire | Other | |||
|
*.algotrader.com refers to AlgoTrader, a Switzerland-based financial technology company that develops algorithmic trading software for institutional market participants. Its offerings support automated trading across asset classes and are positioned within the broader global algorithmic trading market. Publicly available descriptions identify the company as part of the software and financial services ecosystem rather than a retail trading venue. The domain was listed as a ransomware victim associated with IceFire. |
|||||
| *.bestservers.pro View Details _ | icefire | Communication / Marketing | |||
|
*.bestservers.pro is an entity in the Communication/Marketing sector, a category typically associated with branding, messaging, and digital outreach services for clients. The domain-style name suggests an online business presence in the United States, but no official public company profile or offerings were identified in the available search results. As a catalog entry, it should be treated as a threat-intelligence index record rather than a confirmed disclosure of operational details. It was listed as a ransomware victim associated with icefire. |
|||||
| *.iperactive.com.ar View Details _ | icefire | Other | |||
|
*.iperactive.com.ar is an entity operating in the Other sector, located in Olavarria, Buenos Aires, Argentina, with no publicly detailed offerings or specific services documented. The organization is associated with the region of Olavarria and functions within Argentina's broader business landscape, though its exact industry focus remains unspecified. It was listed as a ransomware victim associated with the threat actor icefire, marking its inclusion in threat-intelligence records regarding cyber-attacks. |
|||||
| *.cco1.com View Details _ | icefire | Other | |||
|
*.cco1.com appears to relate to Clear Channel Outdoor Holdings, a U.S. business-services company in the advertising and marketing services sector. Public market data identify CCO with Clear Channel Outdoor Holdings, whose operations focus on out-of-home advertising and related commercial services. The domain pattern suggests a corporate web property associated with that organization rather than a consumer-facing site. It was listed as a ransomware victim associated with icefire. |
|||||
| *.vps-vds.com View Details _ | icefire | Other | |||
|
*.vps-vds.com operates within the hosting sector, providing virtual private server (VPS) and virtual dedicated server (VDS) solutions globally. These offerings deliver isolated virtual environments with dedicated CPU, RAM, and storage resources for scalable business applications. The entity supports cost-effective, flexible compute power suitable for development, launch, and mature traffic environments. It was listed as a ransomware victim associated with the icefire threat actor. |
|||||
| *.guneshosting.com View Details _ | icefire | Other | |||
|
*.guneshosting.com is a Turkish web hosting domain in the broader Other sector, associated with hosting and internet infrastructure services. Publicly available records do not provide a detailed company profile, so its offerings are best described generally as web-hosting related. The domain name indicates a commercial hosting operation rather than a consumer brand. It was listed as a ransomware victim associated with icefire. |
|||||
| *.kodhosting.com View Details _ | icefire | Other | |||
|
*.kodhosting.com is a domain associated with hosting and data-processing services, a business category that commonly includes web and application hosting, data storage, and related IT operations. Such services are typically used to provide infrastructure and application support for client systems rather than consumer-facing products. In threat-intelligence catalogs, it is classified under the Other sector when a more specific industry label is not available. It was listed as a ransomware victim associated with icefire. |
|||||
| *.kru.ac.th View Details _ | icefire | Other | |||
|
Kanchanaburi Rajabhat University is a Thai public university in Kanchanaburi province, west of Bangkok, operating under the Rajabhat University system. Its website, kru.ac.th, serves the university’s academic and administrative information for students, staff, and the public. The institution is classified in the education sector and is located in Thailand. It was listed as a ransomware victim associated with icefire. |
|||||
| *.directfn.net View Details _ | icefire | Other | |||
|
*.directfn.net belongs to DirectFN, a multinational financial technology provider focused on capital-markets software, market data, and brokerage solutions for trading firms and financial institutions. The company says it operates across multiple countries, with offices in the Middle East, South Asia, and North Africa, and offers products spanning trading, analytics, and brokerage operations. Public company profiles describe DirectFN as a private-sector technology business serving clients in financial services, which fits the broad Other sector classification. It was listed as a ransomware victim associated with icefire. |
|||||
| *.feesh.ch View Details _ | icefire | Other | |||
|
*.feesh.ch is an internet domain associated with an entity in the Other sector, rather than a clearly identified public-facing industry vertical. Available threat-intelligence references do not provide a reliable description of its specific products, services, or geographic base. In cataloging terms, it is therefore best treated as a domain-level victim entry with limited publicly verifiable business detail. It was listed as a ransomware victim associated with icefire. |
|||||
| *.skifgroup.com View Details _ | icefire | Services | |||
|
*.skifgroup.com refers to Skif Group, a U.S.-based Services company that operates in the broader business-services space, though public details on its offerings are limited in the available record. The domain indicates a corporate website used for commercial communications and client-facing information. In threat-intelligence indexing, it appears as a Services-sector entity tied to an IceFire ransomware listing. It was listed as a ransomware victim associated with icefire. |
|||||
| Greece pipeline company breached - DESFA View Details _ | ragnarlocker | Services | |||
|
DESFA is Greece’s national natural gas transmission system operator, responsible for operating and developing the country’s gas transport network and related infrastructure. It is based in Greece and serves the energy services sector by moving natural gas through high-pressure transmission pipelines and associated facilities. The company was listed as a ransomware victim associated with Ragnar Locker. |
|||||
| Reiter Affiliated Companies View Details _ | United States | hive | Other | ||
|
Reiter Affiliated Companies is a family-owned agricultural grower headquartered in Oxnard, California, recognized as the world's largest fresh multi-berry producer. The company cultivates proprietary varieties of strawberries, raspberries, and other berries for Driscoll's, operating farms across the US, Canada, Mexico, and beyond. Its offerings include premium fresh berries supplied to global markets, supported by a business model rooted in farming entrepreneurship since 1868. Reiter Affiliated Companies was listed as a ransomware victim associated with the threat actor hive. |
|||||
| PROSOL View Details _ | vicesociety | Communication / Marketing | |||
|
PROSOL is a French Communication / Marketing company associated with the PROSOL name in business directories and company listings. Available public records identify it as operating in France, while related corporate pages show PROSOL-branded entities across business and consumer services. The company appears in sector references tied to communication and marketing, with no reliable public source here confirming a more specific offering for this listing. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Shaw & Slavsky View Details _ | United States | quantum | Retail / E-commerce | ||
|
Shaw & Slavsky, Inc. is a Detroit, Michigan-based supplier of retail display fixtures, graphics, and signage for retailers and stadium venues. The company specializes in creating custom display solutions that enhance product presentation in retail and commercial environments. Located at 13821 Elmira St in Detroit, MI, Shaw & Slavsky serves clients across the United States with high-quality retail display products. The firm was listed as a ransomware victim associated with the quantum threat actor, marking its inclusion in threat-intelligence records as an affected entity in the retail sector. |
|||||
| Department of Indre-et-Loire View Details _ | vicesociety | Public Sector | |||
|
Indre-et-Loire is a department in west-central France named after the Indre and Loire rivers, with its prefecture in Tours. It functions as a public administration entity delivering essential services such as driver's licenses, identity cards, passports, and foreigner reception to residents. The department oversees territorial development, agriculture, housing, and environmental policies while managing local administrative operations. This Public Sector organization was listed as a ransomware victim associated with the threat actor Vicesociety. |
|||||
| Consejo Superior de View Details _ | vicesociety | Other | |||
|
Consejo Superior de Deportes (CSD) is a Spanish public body under the Ministry of Education, Vocational Training and Sports, responsible for state powers in sport. Based in Madrid, it oversees national sports policy, supports athletes, and manages administrative functions linked to the sector. It publishes official notices and services through its government website. The entity was listed as a ransomware victim associated with vicesociety. |
|||||
| wabteccorp.com View Details _ | lockbit3 | Services | |||
|
Wabtec, formerly Westinghouse Air Brake Technologies Corporation, is an American company headquartered in Pittsburgh, Pennsylvania that manufactures products for locomotives, freight cars, and passenger transit vehicles. The firm serves the freight rail, transit, mining, and industrial sectors by providing equipment, systems, digital solutions, and value-added services. Wabtec builds new locomotives up to 6,000 horsepower and supports over 23,000 installed locomotives across North America. The company was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| traveldoc.ca View Details _ | Canada | lockbit3 | Transportation / Travel | ||
|
traveldoc.ca is associated with TravelDoc, an online travel-compliance service that helps travellers and organizations check visa and entry requirements for destinations worldwide. Its tools support document and entry-rule screening for the transportation and travel sector, which commonly serves airlines and mobility-related users. The service is presented as a Canada-based offering in the travel documentation space. traveldoc.ca was listed as a ransomware victim associated with lockbit3. |
|||||
| entrust.com View Details _ | lockbit3 | Other | |||
|
Entrust is an identity-centric security company headquartered in Minneapolis, Minnesota, that fights fraud and cyber threats by protecting people, devices, and data through comprehensive solutions. The firm offers scalable, AI-enabled identity management and plastic card personalization services, including digital cards and instant financial issuance. Entrust operates globally with offices in Dallas, Sao Paulo, Mexico, and Dubai, serving clients across multiple sectors. The company was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| megal.com View Details _ | lockbit3 | Other | |||
|
Megal.com is the website of Megal Development Corporation, a real estate broker, land developer, and property manager based in Brookfield, Wisconsin, specializing in turn-key construction and property management services since 1946. The company offers real estate brokerage, property management, expansion, renovation, and new building construction for commercial, industrial, and office buildings in Southeastern Wisconsin. Megal Development Corporation serves individual and group investors seeking real estate investment opportunities and provides comprehensive development and general contracting solutions. The company was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| An British Financial Company -Public View Details _ | cheers | Finance / Legal / Insurance | |||
|
An British Financial Company -Public is a publicly listed entity identified in threat-intelligence sources as operating in the finance, legal, or insurance space in the United Kingdom. Companies in this sector typically provide financial services, advisory support, or related administrative functions to clients and institutions. In this catalog, the name is preserved as reported by the source record rather than expanded into unverified corporate details. It was listed as a ransomware victim associated with cheers. |
|||||
| WOOTTON ACADEMY TRUST View Details _ | hive | Education | |||
|
Wootton Academy Trust is an education trust in Bedford, England, centred on Wootton Upper School on Hall End Road. It serves pupils in secondary education and sixth-form provision, educating more than 1,600 students across its school setting. The trust’s public profiles and school materials place it in the education sector and identify its Bedford location. It was listed as a ransomware victim associated with Hive. |
|||||
| File-tree of Tang Capital View Details _ | ragnarlocker | Other | |||
|
File-tree of Tang Capital refers to Tang Capital Management, LLC, a privately held, life sciences-focused investment company based in San Diego, California. The firm operates from a headquarters in San Diego and is associated with investment management and SEC-reported portfolio activity. In threat-intelligence catalogs, it is classified under the broader Other sector. File-tree of Tang Capital was listed as a ransomware victim associated with ragnarlocker. |
|||||
| Stratford University View Details _ | United States | snatch | Education | ||
|
Stratford University is a private for-profit higher education institution based in Virginia, United States, offering programs in business administration, culinary arts, nursing, and other fields to students including recent high school graduates and working professionals. Founded in 1976, the university served approximately 2,000 students across its campuses and awarded hundreds of degrees annually before announcing its sudden closure in 2022 due to regulatory restrictions. Stratford University was listed as a ransomware victim associated with the Snatch threat actor, though no official breach confirmation or data specifics have been publicly disclosed by the institution itself. |
|||||
| Apex Capital Corp View Details _ | blackbyte | Services | |||
|
Apex Capital Corp is a financial services company based in Fort Worth, Texas, specializing in invoice factoring and cash flow solutions for businesses in the transportation industry. The firm provides full-service freight factoring, fleet fuel cards, authority services for trucking companies, and a free load board to help clients grow their operations. Apex has been a leading brand in financial services for the transportation sector for over 20 years, offering fast, reliable factoring with no hidden fees or long-term contracts. The company was listed as a ransomware victim associated with the threat actor blackbyte, with no confirmed details on data stolen or breach specifics. |
|||||
| Fremont County View Details _ | United States | alphv | Public Sector | ||
|
Fremont County is a U.S. public sector local government jurisdiction. County governments typically provide administration, public safety, human services, public health, and other essential community services for residents and businesses within their boundaries. Official county and department pages show Fremont County offices in states such as Colorado, Idaho, and Iowa offering government information, social services, and public-service support. It was listed as a ransomware victim associated with alphv. |
|||||
| porcelanosa-usa.com View Details _ | lockbit3 | Other | |||
|
Porcelanosa USA is the U.S. arm of Porcelanosa Group, a Spanish company specializing in ceramic wall and floor tile, bathrooms, kitchens, flooring, and related interior design products. It serves homeowners, builders, architects, and designers through U.S. operations and retail channels in the United States. Public company materials describe Porcelanosa as a major global manufacturer and distributor in the ceramics and interiors sector. The site was listed as a ransomware victim associated with LockBit3. |
|||||
| Vygon Spain View Details _ | vicesociety | Other | |||
|
Vygon Spain is a subsidiary of the Vygon Group, a leading manufacturer of medical devices operating in Spain and serving the global healthcare sector. The company designs and produces sterile single-use and electronical medical devices for major medical specialties, with a focus on vascular health and therapy areas. As part of its mission, Vygon Spain provides top-quality medical devices to healthcare workers, supporting continuous care through digital health ecosystems and partner communities. The organization was listed as a ransomware victim associated with the threat actor Vicesociety, though no confirmed breach details or stolen data types are publicly disclosed. |
|||||
| tier1techs.screenconnect.com View Details _ | lockbit3 | IT | |||
|
tier1techs.screenconnect.com is a ScreenConnect-hosted IT service site used for remote support and access, a platform that helps technicians fix issues and manage endpoints from anywhere. ScreenConnect describes its software as providing secure remote access and remote desktop tools for IT teams and support workflows. The listed entity appears in the IT sector and is associated with the United States through the ScreenConnect domain and service footprint. It was listed as a ransomware victim associated with lockbit3. |
|||||
| ospreyvideo.com View Details _ | lockbit3 | Communication / Marketing | |||
|
Osprey Video is a Flower Mound, Texas company in the communication and marketing space that develops video capture, encoding, decoding, and streaming solutions. Its website says it serves mission-critical workflows and markets products for applications such as medical, avionics, and military use. Company contact information lists its headquarters at 400 Gerault Rd in Flower Mound, Texas. The company was listed as a ransomware victim associated with LockBit3. |
|||||
| altaadhod.com View Details _ | lockbit3 | Other | |||
|
Al-Taadhod Group is a Qatar-based trading and construction company founded in 1999 and headquartered in Doha’s New Salata area. Its website and company profiles indicate activity in HVAC-related trade and contracting, including representation of GREE air conditioners in Qatar. The company lists contact details for its Doha office and presents itself as a commercial supplier and service provider. It was listed as a ransomware victim associated with lockbit3. |
|||||
| ELEFONDATI SRL - WAS HACKED. 20 GB OF SENSITIVE DATA STOLEN View Details _ | lv | Other | |||
|
ELEFONDATI S.R.L. is an Italian company based in Modena that provides electrical installation and related electronic systems services. Its offerings include the design and implementation of communication, data transmission, security, and special plant systems. The business has operated since 1979 and is listed in sector categories tied to electrical and electronic installation work. It was listed as a ransomware victim associated with lv. |
|||||
| TriState HVAC Equipment View Details _ | United States | hive | Public Sector | ||
|
TriState HVAC Equipment is a Philadelphia-area company that provides commercial HVAC mechanical systems, air distribution, and central system equipment. It serves customers across Pennsylvania, Delaware, and New Jersey, including hospitals, schools, institutions, labs, and other commercial buildings. The company is described as a representative, distributor, and integrator of HVAC products and related support services. It was listed as a ransomware victim associated with hive. |
|||||
| STTLK - HACKED AND MORE THEN 200GB DATA LEAKED View Details _ | lv | Other | |||
|
STTLK - HACKED AND MORE THEN 200GB DATA LEAKED refers to a listed cybersecurity incident entry for STTLK, a UK-based organization in the other sector. Available reporting identifies it as LV.com, a leading UK insurance company, with no verified public details here on the precise data, systems, or business functions affected. The listing frames the incident in threat-intelligence terms rather than as a confirmed forensic disclosure, and it should be treated as a victim record pending official confirmation. It was listed as a ransomware victim associated with lv. |
|||||
| vsainc.com View Details _ | lockbit3 | Services | |||
|
vsainc.com belongs to VS Associates, Inc., a services company based in West Hills, California, in the United States. Public business listings identify the firm in the financial services sector and note a small company profile with headquarters at 8501 Fallbrook Ave, Suite 220. As a services provider, it operates in a client-facing commercial environment where trust and continuity are central. The site was listed as a ransomware victim associated with lockbit3. |
|||||
| qualitymedicalinc.com View Details _ | lockbit3 | Healthcare / Pharma | |||
|
Quality Medical Inc. is a U.S.-based healthcare supplier founded in 2001 and operates from Largo, Florida, with additional locations in Georgia, Colorado, and Texas. It provides name-brand medical supplies for the healthcare market, including mobility aids and bathroom-safety products such as canes, crutches, walkers, wheelchairs, bath chairs, shower benches, and grab bars. The company describes itself as customer-focused and technology-driven, serving the evolving needs of the healthcare industry. It was listed as a ransomware victim associated with LockBit3. |
|||||
| pinnick.co.uk View Details _ | United Kingdom | lockbit3 | Other | ||
|
Pinnick Lewis LLP is a chartered certified accountancy firm based in Edgware, North West London, in the GB. It presents itself as a professional one-stop shop for SMEs and offers accountancy and specialist business services, including company formation and related support. The firm operates from Handel House on High Street in Edgware and serves clients through a personal, professional service model. It was listed as a ransomware victim associated with LockBit3. |
|||||
| centuryaluminum.com View Details _ | lockbit3 | Other | |||
|
Century Aluminum Company is a global metals and mining firm headquartered in Chicago, Illinois. It focuses on bauxite, alumina, and primary aluminum production, with operating facilities in the United States, Iceland, Jamaica, and the Netherlands. The company owns and operates aluminum smelting and reduction plants and markets its output to industrial customers. It was listed as a ransomware victim associated with LockBit3. |
|||||
| besttaxfiler.com View Details _ | lockbit3 | Other | |||
|
Besttaxfiler.com is the website for Best Tax Filer, an online U.S. tax-return preparation and filing service for individuals and related clients in the Other sector. Public listings describe it as a tax and finance team that provides online filing support, with a U.S. presence in Farmington Hills, Michigan, and business operations also shown in India. The service presents itself as a registered Electronic Return Originator and offers account access, support, and tax-filing assistance. It was listed as a ransomware victim associated with lockbit3. |
|||||
| beckerlaw.com View Details _ | lockbit3 | Finance / Legal / Insurance | |||
|
Becker Law Office is a Kentucky law firm focused on personal injury matters, representing injured clients in accident and related claims. Its website describes contingency-based legal services and offices in Louisville, Florence, and Lexington, Kentucky. The firm also says it has decades of experience negotiating with insurance companies on behalf of individuals and small businesses. It was listed as a ransomware victim associated with LockBit3. |
|||||
| whitworth.edu View Details _ | United States | lockbit3 | Other | ||
|
Whitworth.edu is the website of Whitworth University, a private Christian university in Spokane, Washington, in the United States. The university operates a main campus in Spokane and offers undergraduate and graduate degree programs across 100+ majors and programs. Its academic and campus information is published through the Whitworth.edu domain. It was listed as a ransomware victim associated with LockBit3. |
|||||
| okcu.edu View Details _ | United States | lockbit3 | Other | ||
|
okcu.edu is the official website of Oklahoma City University, a private nonprofit university in Oklahoma City, Oklahoma, United States. The university offers undergraduate and graduate education across liberal arts and sciences, along with professional and performing arts programs. Its website supports admissions, academics, student services, and campus information. The domain was listed as a ransomware victim associated with LockBit3. |
|||||
| Hot news straight from Cisco View Details _ | yanluowang | Other | |||
|
Hot news straight from Cisco is an Other-sector entity in the United States associated with Cisco’s 2022 security incident. Cisco is a San Jose, California-based technology company that develops and sells networking, cybersecurity, collaboration, and cloud infrastructure products and services. Public reporting indicates Cisco said the incident did not affect business operations, products, or services. It was listed as a ransomware victim associated with yanluowang. |
|||||
| 8 Italy Districts View Details _ | ransomhouse | Other | |||
|
8 Italy Districts is an Italy-based entity categorized in the Other sector. Public reporting identifies it as a victim in a ransomware-related incident, but available sources do not provide a reliable public description of its core offerings or operating model. The name suggests an organization associated with multiple Italian districts or a regional administrative or service network, but that detail is not confirmed by the cited material. It was listed as a ransomware victim associated with ransomhouse. |
|||||
| ah-a.de View Details _ | Germany | lockbit3 | Other | ||
|
ah-a.de corresponds to Aha!, a private software company founded in 2013 in Menlo Park, California, that develops product development and roadmap software for businesses. The company presents itself as a SaaS provider focused on helping teams plan, build, and communicate product strategy. In threat-intelligence catalogs, it is indexed under the Other sector and country code DE for Germany. It was listed as a ransomware victim associated with lockbit3. |
|||||
| valverdehotel.com View Details _ | lv | Hospitality / Food & Beverage / Tourism | |||
|
valverdehotel.com is the official site for Valverde Lisboa Hotel & Garden, a boutique hotel in Lisbon, Portugal, on Avenida da Liberdade. The property serves leisure and business guests and presents itself as a small, intimate hotel with upscale lodging and on-site dining. Public hotel listings describe it as a 5-star property with a garden, outdoor pool, restaurant, and bar. It was listed as a ransomware victim associated with lv. |
|||||
| ISTA International GmbH View Details _ | daixin | Energy | |||
|
ISTA International GmbH is an Essen, Germany-based energy services company that specializes in submetering and consumption-based billing. It provides metering equipment, installation services, and related solutions for energy, water, and ancillary-cost allocation to property managers, homeowners, and energy utilities. The company operates internationally and focuses on improving energy efficiency in buildings. It was listed as a ransomware victim associated with daixin. |
|||||
| FOSUN.COM View Details _ | lockbit3 | Other | |||
|
FOSUN.COM is the corporate website of Fosun International Limited, a Chinese multinational conglomerate holding company headquartered in Shanghai. Founded in 1992, Fosun operates across four major business segments: Health, Happiness, Wealth, and Intelligent Manufacturing, with a global presence in Mainland China, Portugal, and internationally. The company is recognized as a technology-driven, innovation-focused consumer group dedicated to creating happier lives for families worldwide. FOSUN.COM was listed as a ransomware victim associated with the threat actor lockbit3. |
|||||
| An Insurance Company -Paid View Details _ | cheers | Finance / Legal / Insurance | |||
|
An Insurance Company - Paid is an insurance-sector organization in the Finance, Legal, and Insurance field, based in the United States. Insurance companies provide risk-transfer products and related services that help businesses and individuals manage financial exposure, claims, and coverage needs. Public ransomware-tracking records identify it as a victim entry rather than a verified breach disclosure. It was listed as a ransomware victim associated with cheers. |
|||||
| An Turkey Certified Public Accountancy Firms -Unpay View Details _ | cheers | Public Sector | |||
|
Turkey Certified Public Accountancy Firms -Unpay operates within the Public Sector in Turkey, providing certified public accountancy services to enterprises and business concerns. These firms deliver essential offerings including tax advisory and filing, bookkeeping, financial reporting, payroll compliance, company setup, audit services, and strategic financial planning under Turkish law. The profession is regulated by Professional Law No. 3568 on Certified Public Accountancy, with oversight by the Public Oversight, Accounting and Auditing Standards Authority (KGK). Turkey Certified Public Accountancy Firms -Unpay was listed as a ransomware victim associated with the threat actor cheers. |
|||||
| Freyr Solutions View Details _ | United States | quantum | Services | ||
|
Freyr Solutions is a US-based services company headquartered in Princeton, New Jersey. It describes itself as a global regulatory solutions provider for life sciences, offering end-to-end support for pharmaceuticals, medical devices, consumer health, and related digital healthcare services. Its work includes regulatory consulting, documentation, labeling, and other compliance-focused services for industry clients. It was listed as a ransomware victim associated with quantum. |
|||||
| versma.com View Details _ | lockbit3 | Other | |||
|
versma.com appears to correspond to Versma, a business-services entity in South Africa, with company-directory records placing Versma Management Services (Pty) Ltd in Bellville, Cape Town. Public directory data also associates Versma with administrative, support, and security-related services, indicating an “Other” sector classification rather than a narrow industry label. The site is used to present the company’s corporate identity and service profile in a professional context. It was listed as a ransomware victim associated with lockbit3. |
|||||
| ring-plastik.de View Details _ | Germany | lockbit3 | Other | ||
|
Ring-Plastik Pechler GmbH is a German plastics manufacturer based in Altomünster, Bavaria. It offers standardized and customized injection molding solutions and supports design, manufacture, assembly, and finishing for industry-specific applications. The company says its products serve sectors including commercial vehicle and plant construction, solar, electrical, and medical technology, with customers worldwide. It was listed as a ransomware victim associated with lockbit3. |
|||||
| unimasters.com View Details _ | lockbit3 | Other | |||
|
Unimasters.com is the website of Unimasters Logistics, a Bulgaria-based supply chain and logistics company headquartered in Sofia. It provides freight management, transportation, maritime solutions, warehousing, distribution, sourcing, and flow management services for moving goods from suppliers to delivery. The company presents itself as an integrated logistics operator serving end-to-end cargo and supply chain needs. It was listed as a ransomware victim associated with lockbit3. |
|||||
| wrschool.net View Details _ | lockbit3 | Education | |||
|
wrschool.net is the official website of Window Rock Unified School District No. 8 in Fort Defiance, Arizona, serving students and staff across its district. The site provides district information, mission and vision statements, registration details, staff directories, department pages, and school-related resources. It presents the district’s educational offerings and administrative services for a multicultural school community. It was listed as a ransomware victim associated with lockbit3. |
|||||
| trialpro.com View Details _ | lockbit3 | Communication / Marketing | |||
|
trialpro.com is the website of Trial Pro, P.A., a Florida personal injury law firm serving clients from offices in Orlando, Melbourne, Naples, Fort Myers, and Tampa. The firm says it handles accident and injury matters and offers 24/7 consultation support through its legal team. Public company listings identify the business as headquartered in Orlando, Florida, with a website at trialpro.com. It was listed as a ransomware victim associated with lockbit3. |
|||||
| newwestmetals.com View Details _ | lockbit3 | Manufacturing / Engineering | |||
|
New West Metals Inc. is a prominent distributor of specialty metals and steels headquartered in Winnipeg, Manitoba, Canada, serving industries across the nation since 1982. The company offers a wide range of products including aluminum, brass, bronze, copper, nickel alloys, tool steels, specialty steels, and stainless steel, with capabilities to cut, shear, and fabricate materials to specific sizes. As a leading metal supplier, New West Metals caters to manufacturers, fabricators, and machine shops throughout Canada with high-quality metal products. The company was listed as a ransomware victim associated with the threat actor LockBit3. |
|||||
| hatcherins.com View Details _ | lockbit3 | Other | |||
|
Hatcher Insurance Inc. is a boutique insurance brokerage firm based in Orlando, Florida, specializing in commercial and personal lines coverage for small to medium-sized businesses. The agency provides a full suite of services including property and casualty, surety bonding, employee benefits, life insurance, and PEO solutions. With a local, independent feel combined with large brokerage experience, Hatcher offers tailored home, auto, umbrella, and specialty coverage for personal lines. The firm also crafts comprehensive employment benefit programs that prioritize employee wellness and financial security while balancing business costs. Hatcher Insurance Inc. was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| ttdwest View Details _ | blackbasta | Other | |||
|
ttdwest is the website for Total Transportation & Distribution, a Rancho Cucamonga, California-based logistics and transportation company. It provides freight, storage, dispatching, shipping, supply-chain, and distribution services, including LTL and full-truckload transport across the western United States and Canada. Company materials also describe warehouse capacity in Southern California and service coverage in California, Arizona, Nevada, and key Canadian markets. It was listed as a ransomware victim associated with blackbasta. |
|||||
| MAI View Details _ | blackbasta | Other | |||
|
The Manufacturers Association of Israel (MAI) is the umbrella organization for industrialists in Israel, serving for over 100 years. It represents over 2,000 member companies that account for more than 90% of Israel's total industrial output and employ approximately 400,000 workers. MAI organizes member companies across seven industry sectors including High-Tech, Chemicals, Food & beverage, Metal, Textile, Consumer goods, and Kibbutz Industries. The association has guided Israel's economy since the early days of the state toward its current standing as a global technological power. MAI was listed as a ransomware victim associated with blackbasta. |
|||||
| Montrose Environmental Group, Inc View Details _ | blackbasta | Services | |||
|
Montrose Environmental Group, Inc. is an American environmental services company headquartered in Little Rock, Arkansas, and incorporated in Delaware. It provides wide-ranging services across the environmental sector, supporting public- and private-sector clients with offerings that include air quality and environmental laboratory services. The company describes its mission as helping clients and communities meet environmental and sustainability goals. It was listed as a ransomware victim associated with blackbasta. |
|||||
| WALLWORKINC View Details _ | blackbasta | Services | |||
|
WALLWORKINC refers to W.W. Wallwork, Inc., a privately held services company headquartered in Fargo, North Dakota, with additional locations in Bismarck, Williston, and Fergus Falls. Public company listings describe it as a transportation and trucking business that provides truck and trailer parts, truck rental, trailer repair, maintenance, and body shop services. Its operations support commercial vehicle customers across North Dakota and nearby markets. It was listed as a ransomware victim associated with blackbasta. |
|||||
| paradise View Details _ | blackbasta | Other | |||
|
Paradise is an organization classified in the other sector, with publicly available context too limited to confirm a more specific industry, location, or offering from the available record. In threat-intelligence catalogs, such entries are used to identify entities named in ransomware reporting when operational details are not fully disclosed. Black Basta is a ransomware group known for double-extortion attacks and public victim listings. Paradise was listed as a ransomware victim associated with Black Basta. |
|||||
| WENZEL + WENZEL View Details _ | blackbasta | Other | |||
|
WENZEL + WENZEL GmbH is a Germany-based company headquartered in Karlsruhe, Baden-Württemberg, with operations listed at 15 locations and services that include prevention and rehabilitation offerings. Public company directories identify it as a sizable business with around 400 employees and a website under the wenzel-wenzel.com domain. Its profile places it in the Other sector, reflecting a diversified service-oriented business rather than a narrow industry category. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Trade-Mark Industrial Inc. View Details _ | Canada | blackbasta | Manufacturing / Engineering | ||
|
Trade-Mark Industrial Inc. is a multi-trade contractor based in Cambridge, Ontario, serving industrial, commercial, and institutional customers across Southern Ontario. Its services include millwrighting, rigging, electrical, piping, fabrication, structural work, sheet metal, and HVAC installations and repairs. The company also maintains fabrication capabilities in Canada and offers 24/7 emergency support. It was listed as a ransomware victim associated with blackbasta. |
|||||
| CREMO View Details _ | blackbasta | Other | |||
|
CREMO is a U.S.-based consumer goods and manufacturing company best known for its men’s grooming products, with operations and headquarters reported in Laguna Beach, California. Its brand portfolio emphasizes everyday grooming items sold through retail and direct-to-consumer channels. Public company profiles describe it as a privately held manufacturer in the other sector category. It was listed as a ransomware victim associated with blackbasta. |
|||||
| RBBUSA View Details _ | blackbasta | Other | |||
|
RBBUSA is Royal Business Bank, a California-based commercial bank headquartered in Los Angeles with branches across California and other U.S. states. It provides personal banking, business lending, and related financial services to individuals, entrepreneurs, and small to mid-sized businesses. The bank operates through a network of full-service offices in major U.S. markets. It was listed as a ransomware victim associated with blackbasta. |
|||||
| BOERNER-GRUPPE View Details _ | blackbasta | Other | |||
|
BOERNER-GRUPPE is a German business identified by name as a member of the other sector, with corporate activity tied to Germany. Publicly available search results do not provide a reliable company profile here, so no specific offerings or location details can be stated with confidence. In threat-intelligence context, the name appears in ransomware-victim reporting. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Young & Pratt View Details _ | blackbasta | Communication / Marketing | |||
|
Young & Pratt, Inc. is a mechanical contracting company based in Manor, Texas, specializing in HVAC, plumbing, pipe-fitting, and air conditioning services. The firm provides installation, repair, and custom fabrication for various industries and projects, serving clients across Texas. Despite its core operations in mechanical contracting, the company operates within the Communication and Marketing sector as noted in threat intelligence records. Young & Pratt was listed as a ransomware victim associated with the blackbasta threat actor, underscoring emerging cyber risks in the industry. |
|||||
| Jakob Becker View Details _ | blackbasta | Other | |||
|
Jakob Becker GmbH & Co. KG is a German company based in Rhineland-Palatinate, with locations including Mehlingen and Oberwesel, and its website is jakobbecker.de. Company profile data describes it as providing waste management solutions, including vehicles, trash cans, construction waste, containers, and hazardous-waste services. Public directory listings place it in Germany and indicate it operates as a business rather than a public institution. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Love, Barnes & McKew Insurance Adjusters View Details _ | blackbasta | Finance / Legal / Insurance | |||
|
Love, Barnes & McKew Insurance Adjusters is an independent insurance adjusting firm based in Columbia, Maryland, serving clients across the Washington-Baltimore corridor, Northern Virginia, and Southern Maryland. It provides claims adjustment services for insurance matters and operates from offices in Maryland with contact and case-handling support for clients. The company is part of the Finance / Legal / Insurance sector and was listed as a ransomware victim associated with blackbasta. |
|||||
| The O'Regan View Details _ | blackbasta | Other | |||
|
The O'Regan is an entity in the **Other** sector in **Ireland**. Public search results do not provide enough reliable detail to confirm its specific offerings, so this listing describes it at a high level only. In a threat-intelligence context, the name is indexed for monitoring and attribution purposes rather than as a confirmed incident report. It was listed as a ransomware victim associated with **blackbasta**. |
|||||
| Blairex Laboratories, Inc. View Details _ | blackbasta | Services | |||
|
Blairex Laboratories, Inc. is a privately held pharmaceutical company based in Columbus, Indiana, in the Services sector. Sources describe it as an innovative health care products business founded in 1976, offering non-prescription sterile saline solutions, contact lens care, and related pharmaceutical products. The company serves health care facilities, doctors, and families from its U.S. headquarters. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Wilks Tire & Battery Service View Details _ | blackbasta | Other | |||
|
Wilks Tire & Battery Service is a family-owned automotive service company located in Albertville, Alabama, established in 1952. The firm specializes in tire and battery sales, wheel alignment, balancing, oil changes, brake repair, and comprehensive collision repair services. It operates multiple locations across Alabama and Georgia, serving both retail and commercial vehicle customers. The company was listed as a ransomware victim associated with the threat actor blackbasta. |
|||||
| UNIWELL Rohrsysteme GmbH & Co. View Details _ | blackbasta | Other | |||
|
UNIWELL Rohrsysteme GmbH & Co. KG is a German tube company based in Ebern that specializes in developing and producing high-quality plumbing products, cable protection systems, and fluid carrying systems. Since its formation in 1990, the company has manufactured cable protection and fluid leading systems for the automotive and machinery industries. The firm operates a headquarters in Ebern, Germany, and a production plant in Zdíkov, Czech Republic. UNIWELL Rohrsysteme GmbH & Co. was listed as a ransomware victim associated with the threat actor blackbasta. |
|||||
| Grohmann Aluworks GmbH & Co View Details _ | blackbasta | Other | |||
|
Grohmann Aluworks GmbH & Co. is a German industrial company based in Bisingen, Baden-Württemberg, that specializes in aluminium casting and related manufacturing services. The Grohmann Group says it operates multiple production sites and offers cast parts using processes such as chill casting and sand casting. Its profile describes it as a family-owned business with a long history in the sector. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Borough of Union Beach View Details _ | onyx | Other | |||
|
Borough of Union Beach is a municipal government in Monmouth County, New Jersey, serving residents from its office at 650 Poole Avenue in Union Beach. The borough provides local public administration and community services for the coastal town on Raritan Bay, between Keyport and Keansburg. Its official website identifies it as the Borough of Union Beach, New Jersey. It was listed as a ransomware victim associated with onyx. |
|||||
| SEMIKRON - EXTREMELY LOW LEVEL OF CYBERSECURITY. 2 TB OF CORPORATE DATA STOLEN View Details _ | lv | IT | |||
|
SEMIKRON is a German-based manufacturer of power semiconductor components and systems, with operations centered in Nuremberg and Flensburg. Its offerings include semiconductor devices, power modules, stacks, and related power electronics for industrial and energy applications. The company operates under the Semikron Danfoss name and serves global markets from its German sites. It was listed as a ransomware victim associated with lv. |
|||||
| WARTSILA DATA - ATTENTION !!! View Details _ | lv | Other | |||
|
WÄRTSILÄ is a Finnish marine and energy technology company that provides solutions for ship propulsion, power generation, and related industrial services. Its operations support maritime and energy customers through engineering, equipment, and lifecycle services, and its business is closely tied to Finland. In threat-intelligence catalogs, WARTSILA DATA - ATTENTION !!! appears as an entity record associated with this company name. The listing was recorded as a ransomware victim associated with lv. |
|||||
| Liftow LTD View Details _ | Canada | quantum | Manufacturing / Engineering | ||
|
Liftow LTD is a Canadian manufacturing and engineering business based in Mississauga, Ontario, with operations across several provinces. It is North America's largest full-service Toyota forklift dealer, providing new and used forklift sales, rentals, parts, service, warehouse solutions, and training. The company has served industrial customers since 1960 and maintains a broad branch network in Canada. It was listed as a ransomware victim associated with quantum. |
|||||
| BEESENSE View Details _ | Israel | quantum | Construction / Real Estate | ||
|
BEESENSE Sensors Systems Ltd. is an Israeli company based in Rosh Ha’ayin, Israel. Established in 1996, it designs, develops, and manufactures multi-sensor systems and independent wireless communication and power infrastructure for intelligence, surveillance, and reconnaissance, with applications in defense and security. Public company profiles also place it in defense and space-related activity. It was listed as a ransomware victim associated with quantum. |
|||||
| ENN Group View Details _ | China | hive | Services | ||
|
ENN Group is a Chinese energy company based in China and one of the country’s largest privately held firms. It develops and operates natural gas projects and provides clean-energy services, including gas sales, distribution, and related energy supply operations. Public company profiles also describe it as active in natural gas project development and operation across China. It was listed as a ransomware victim associated with Hive. |
|||||
| STTLK View Details _ | lv | Other | |||
|
STTLK is an entity operating within the Other sector, located in the United States, with no specific public offerings detailed beyond its general classification. As a business in this broad sector, it functions without a clearly defined niche in consumer services, technology, finance, or industrial markets. The organization was listed as a ransomware victim associated with the threat actor lv, indicating it faced a cybersecurity incident involving data encryption. This listing contributes to the broader understanding of lv's targeting patterns across diverse and undefined sectors in the US. |
|||||
| Fitzgibbon Hospital (USA) View Details _ | United States | daixin | Healthcare / Pharma | ||
|
Fitzgibbon Hospital is a not-for-profit community hospital in Marshall, Missouri, serving central Missouri with essential health care services. Its offerings include acute care and a range of patient services such as women’s health, OBGYN, and family care. The hospital describes its mission as improving the health of the community through quality, compassionate care and personal attention. It was listed as a ransomware victim associated with daixin. |
|||||
| Fitzgibbon Hospital View Details _ | United States | daixin | Healthcare / Pharma | ||
|
Fitzgibbon Hospital is a leader in central Missouri in providing quality, compassionate care and personal attention to patients. |
|||||
| Trib Total Media (USA) View Details _ | United States | daixin | Communication / Marketing | ||
|
Trib Total Media is a Pennsylvania-based media company headquartered in Tarentum, serving Southwestern Pennsylvania. It delivers news, information, and advertising across multiple counties and provides newspapers, magazines, direct mail, e-newsletters, commercial printing, and digital services. The company also operates Tribune-Review and TribLIVE-branded publications and platforms for local audiences. Trib Total Media was listed as a ransomware victim associated with daixin. |
|||||
| Trib Total Media View Details _ | daixin | Communication / Marketing | |||
|
Trib Total Media delivers news, information and advertising to portions of Allegheny, Westmoreland, Armstrong and Butler counties in Southwestern Pennsylvania. |
|||||
| Doosan Group View Details _ | revil | Services | |||
|
Doosan Group is a South Korean multinational conglomerate headquartered in Seoul, with business activities spanning power generation, energy, construction, and industrial equipment. Its portfolio includes services and manufacturing across subsidiaries such as Doosan Enerbility and Doosan Bobcat, with operations in markets worldwide. The group presents itself as a global industrial and services company with a broad international network. It was listed as a ransomware victim associated with revil. |
|||||
| tekinox.it View Details _ | Italy | lockbit3 | Other | ||
|
Tekinox is an Italian company based in Treviglio, Lombardy, that produces high-precision industrial components. It specializes in machining and turning stainless steel parts, serves multiple industrial sectors, and presents itself as ISO 9001 certified. Its website also describes a digitally integrated production system focused on Industry 4.0 monitoring and management. Tekinox was listed as a ransomware victim associated with LockBit3. |
|||||
| obriengroupaustralia.com.au View Details _ | Australia | lockbit3 | Services | ||
|
O'Brien Group Australia is one of Australia and New Zealand's largest privately owned hospitality, entertainment, and leisure companies, operating across the Services sector in North Melbourne, Victoria. The company offers premium food and beverage services, event staffing, and leisure experiences for corporate and public clients. Based in North Melbourne with additional locations in Queensland and South Australia, it serves a broad regional market with diverse hospitality offerings. O'Brien Group Australia was listed as a ransomware victim associated with the LockBit3 threat actor, marking its inclusion in the threat-intelligence index. |
|||||
| kangaroo.vn View Details _ | Viet Nam | lockbit3 | Other | ||
|
kangaroo.vn is the website of Kangaroo International Joint Venture Company in Hanoi, Vietnam. The company operates in sanitary paper product manufacturing and is also associated with the Kangaroo Group brand. Public company profiles and brand materials show it markets household appliances and related products from its Hanoi base, with manufacturing operations in Hung Yen. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Puma Biotechnology - decided to allow Leaks View Details _ | ragnarlocker | IT | |||
|
Puma Biotechnology is a U.S.-based biopharmaceutical company headquartered in Los Angeles, California. It focuses on the development and commercialization of innovative products to enhance cancer care and is associated with oncology therapeutics. In threat-intelligence catalogs, the entity is indexed under an IT-sector ransomware victim profile. It was listed as a ransomware victim associated with ragnarlocker. |
|||||
| casapellas.com View Details _ | lockbit3 | Other | |||
|
Casapellas.com is the online presence of Casa Pellas, a Nicaragua-based business group headquartered in Managua. The company says it sells new cars, industrial machinery, tires, spare parts, motorcycles, and marine engines, serving a broad commercial and automotive market. It operates in the Other sector as a diversified enterprise with regional business activity. It was listed as a ransomware victim associated with lockbit3. |
|||||
| scohil.com View Details _ | lockbit3 | Other | |||
|
Scohil.com is the website for Scohil Construction Services, a Texas-based construction firm headquartered in Cypress, with a listed office in Sugar Land. The company describes itself as a multifaceted construction business that provides personalized service and has experience across construction work, including concrete. Public company listings identify it as a small construction firm operating in the United States. It was listed as a ransomware victim associated with lockbit3. |
|||||
| preflooring.com View Details _ | lockbit3 | Communication / Marketing | |||
|
preflooring.com operates as Precision Flooring Products, Inc., a leading manufacturer and distributor of customized prefinished mouldings serving the wood flooring industry across North America since 1994. The company is headquartered in Morristown, Tennessee, and specializes in delivering high-quality, prefinished wood products to industry professionals throughout the United States. As a key player in the Communication and Marketing sector, it provides essential materials for flooring manufacturers and distributors seeking reliable, prefinished solutions. The entity was neutrally listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| ARISA CORREDORES DE SEGUROS View Details _ | onyx | Other | |||
|
ARISA Corredores de Seguros, S.A. is a Guatemalan company based in Guatemala City that operates in the insurance brokerage and agency sector. It provides corporate insurance advisory and related coverage services, including life, auto, medical expenses, and surety bonds. Public company profiles and its own website describe it as a long-established broker serving clients in Guatemala and Central America. It was listed as a ransomware victim associated with onyx. |
|||||
| shopper360.com.my View Details _ | Malaysia | lockbit3 | Retail / E-commerce | ||
|
shopper360.com.my is the website of Shopper360, a Malaysian shopper marketing and retail services group based in Petaling Jaya, Selangor. The company says it provides shopper marketing, in-store media, merchandising, and retail technology services for brands and consumer goods clients. Its offerings and subsidiaries also extend across Malaysia and neighboring markets, reflecting a focus on retail execution and shopper engagement. It was listed as a ransomware victim associated with lockbit3. |
|||||
| BAFNAGROUP.COM - HACKED AND MORE THEN 20 GB DATA LEAKED View Details _ | lv | Services | |||
|
Bafna Group is an India-based business group operating across services and related commercial activities, including real estate, trading, paper, and other business lines. Public materials describe it as a diversified organization focused on delivering products and services through multiple ventures. The listing for BAFNAGROUP.COM states that the site was hacked and more than 20 GB of data was leaked, but this description does not independently verify the incident. It was listed as a ransomware victim associated with lv. |
|||||
| get.es View Details _ | Spain | lockbit3 | Other | ||
|
get.es is an Spain-based entity in the Other sector, identified here for threat-intelligence indexing rather than as a verified incident report. The domain name indicates a commercial or organizational web presence in Spain, but no authoritative public source in the provided results describes its exact offerings or business model. In this catalog context, the listing captures the organization as an observed ransomware target within the broader Spanish threat landscape. It was listed as a ransomware victim associated with lockbit3. |
|||||
| vytelle.com View Details _ | lockbit3 | Other | |||
|
Vytelle is a precision livestock and biotechnology company that helps cattle producers improve herd genetics and reproductive performance through measurement, IVF, and analytics. The company is headquartered in Lenexa, Kansas, and operates labs and partner locations in the United States and internationally. Its offerings are focused on commercial cattle production and genetic progress rather than consumer services. This entry lists vytelle.com as a ransomware victim associated with lockbit3. |
|||||
| emunworks.com View Details _ | lockbit3 | Other | |||
|
Emunworks.com is the website for EMUN Incorporated, a privately held software development company based in Huntsville, Alabama. Public company profiles describe EMUN as serving wholesale and B2B commerce with sales tools, CRM, and integrated e-commerce software for businesses. The company’s offerings are positioned around helping distributors and sales teams manage digital commerce and customer workflows. Emunworks.com was listed as a ransomware victim associated with lockbit3. |
|||||
| autoliv.com View Details _ | lockbit3 | Other | |||
|
Autoliv is a Sweden-based global company that develops, manufactures, and markets automotive safety systems and protective products for vehicles. It describes itself as the worldwide leader in automotive safety systems and operates through group companies across 25 countries, with technical centers and crash test tracks. The company’s offerings include passenger safety products and related protective systems for the automotive industry. autoliv.com was listed as a ransomware victim associated with lockbit3. |
|||||
| Hong Kong Special Care Dentistry Association Limited View Details _ | lv | NGOs / Associations | |||
|
Hong Kong Special Care Dentistry Association Limited is a Hong Kong non-governmental association founded in 2013 to support people who face barriers to dental care because of special needs. It brings together dental practitioners, social workers, business people, patients’ parents, and other supporters to promote special care dentistry and improve access to oral health services in Hong Kong. Its work aligns with the wider special care dental sector, which aims to serve targeted and underprivileged groups. The organization was listed as a ransomware victim associated with lv. |
|||||
| Fandeli View Details _ | lorenz | Other | |||
|
Fandeli is a manufacturing company that produces coated abrasives, including sheets, discs, rolls, belts, and specialty products used in industrial finishing. The company was founded in 1927 and is based in Tlalnepantla, Estado de México, Mexico, with U.S. corporate operations in Houston, Texas. Public business profiles identify Fandeli as part of the manufacturing sector and describe it as an international producer serving industrial customers. It was listed as a ransomware victim associated with lorenz. |
|||||
| fruca.es View Details _ | Spain | lockbit3 | Other | ||
|
Fruca.es belongs to FRUCA, a Murcia-based Spanish company in the **wholesale and production of fresh fruits and vegetables**. Its corporate materials describe an integrated model from genetics and plant production through packing, marketing, and customer service, with operations in Murcia, Spain. The company also states it produces seedlings and manages cultivation and supply for items such as lettuce, melon, watermelon, and pepper. It was listed as a ransomware victim associated with **LockBit3**. |
|||||
| armassist.ie View Details _ | Ireland | lockbit3 | Other | ||
|
armassist.ie is the website of Accident Repair Management Ltd, a privately held Irish company based in Bray, County Wicklow, that provides centrally managed accident repair solutions for fleets, leasing, rental, and insurance companies. The firm operates nationwide through 50 repair centres across Ireland, delivering bespoke services tailored to industry standards. As a member of the SIMI network, it offers integrated vehicle repair services focused on innovation and market adaptation. The company was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| coarc.org View Details _ | redalert | Other | |||
|
Coarc is a nonprofit organization based in Columbia County, New York, that provides comprehensive services to children and adults with disabilities through more than 20 locations across the region. The organization offers day habilitation, employment support, community living programs, and specialized care to expand abilities for over 500 individuals annually. Its mission focuses on empowering individuals one person at a time, with additional services including contract manufacturing and gift shop operations. Coarc was listed as a ransomware victim associated with the threat actor redalert, though no specific data breach details have been publicly confirmed by the organization itself. |
|||||
| correounir.com.ar View Details _ | Argentina | lockbit3 | Other | ||
|
correounir.com.ar is an Argentina-based entity in the Other sector; public search results do not provide a reliable description of its specific offerings, so its business profile cannot be stated with certainty. The domain is tracked in ransomware victim intelligence for Argentina, indicating it appears in threat-monitoring datasets rather than as a verified incident disclosure. No official first-party breach notice was identified in the available sources. It was listed as a ransomware victim associated with lockbit3. |
|||||
| maldegem.be View Details _ | Belgium | lockbit3 | Other | ||
|
maldegem.be is the official website of the local government of Maldegem, a municipality in Belgium’s East Flanders province. The site provides municipal news, service information, and access to a digital desk for residents and visitors. Maldegem is a local public-sector entity serving the town and surrounding villages in the BE country context. It was listed as a ransomware victim associated with lockbit3. |
|||||
| groupe-helios.com View Details _ | lockbit3 | Services | |||
|
Groupe Helios is a Services-sector company based in Longueuil, Quebec, Canada, with a website at groupe-helios.com and a reported business profile in business services, construction, and field service management. Its stated work includes infrastructure management, operations and maintenance for water, wastewater, and energy facilities, as well as industrial services across sectors such as mining, agri-food, transportation, pharmaceuticals, and energy. Public company materials also describe road-marking and traffic-signaling services. The entity was listed as a ransomware victim associated with lockbit3. |
|||||
| CIMEX View Details _ | hive | Other | |||
|
CIMEX is a pest management company headquartered in Rockaway, New Jersey, United States, offering residential, commercial, and industrial pest control services across the Phoenix Metropolitan Area and beyond. The firm provides tailored solutions for a wide range of clients, including homes, businesses, and large industrial facilities, leveraging experienced technicians and targeted strategies. As part of the Other sector, CIMEX operates without a single dominant product line but delivers comprehensive environmental health services. The company was listed as a ransomware victim associated with the threat actor hive. |
|||||
| Weidmueller View Details _ | United States | hive | Other | ||
|
Weidmuller USA is the North American arm of Weidmüller, a global industrial connectivity and automation company headquartered in Richmond, Virginia. The company says it provides smart industrial connectivity and automation products and solutions, and the wider Weidmüller Group develops electrical connection and automation technologies for industrial applications. Its U.S. operation supports customers from Richmond, while the group maintains production and distribution in more than 80 countries. Weidmueller was listed as a ransomware victim associated with hive. |
|||||
| studioteruzzi.com - HACKED AND MORE THEN 80GB DATA LEAKED View Details _ | lv | Other | |||
|
studioteruzzi.com is the website of Studio Teruzzi, an Italian professional-services firm that provides corporate consulting and related ordinary and extraordinary assistance to companies, professionals, and private clients. The company describes its work as accounting and company-services support, reflecting a broader business-services sector rather than a product manufacturer. Public web pages indicate an Italian presence and an enterprise service portal connected to its operations. The listing names studioteruzzi.com as a ransomware victim associated with lv. |
|||||
| cheungwoh.com.sg View Details _ | Singapore | lockbit3 | Other | ||
|
Cheung Woh Technologies Ltd is a Singapore-based manufacturer specializing in high-precision engineered metal and plastic components for industries including hard disk drives, communications, semiconductor, and automotive. Established in 1972, the company operates integrated manufacturing facilities in Singapore, Malaysia, and China to serve global markets. It provides voice coil motor plates, air combs, and precision metal stamping parts with in-house tool and die capabilities. The firm was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| ymaunivers.com View Details _ | lockbit3 | Other | |||
|
YMAUnivers.com is the website of YMA Corporation, a Taiwan-based company in Taichung City that operates in manufacturing and utility supply-related industries. Public company profiles associate YMA with industrial machinery, equipment, and bicycle components, and note that it serves the wider consumer and manufacturing supply chain. The company’s online presence suggests a business focused on products and services tied to industrial and cycling markets. It was listed as a ransomware victim associated with lockbit3. |
|||||
| sieam.fr View Details _ | France | lockbit3 | Other | ||
|
sieam.fr is the online presence of SIEM Supranite, a France-based industrial company that manufactures and supplies sealing solutions, including high-quality industrial gaskets for global customers. The company operates in the industrial sector and presents itself as a market leader in sealing technologies for manufacturing and supply chains. In threat-intelligence catalogs, the domain is used to identify the targeted organization and its business profile. It was listed as a ransomware victim associated with lockbit3. |
|||||
| CUCA FRESCA View Details _ | onyx | Other | |||
|
CUCA FRESCA is a Brazil-based business in the Other sector, and its public profile does not clearly indicate a specific product category or service line from the available record. In catalog and threat-intelligence contexts, such entries are used to identify organizations by name, sector, and country when detailed operating information is limited. The listing does not itself confirm an incident beyond its inclusion in ransomware victim tracking. CUCA FRESCA was listed as a ransomware victim associated with onyx. |
|||||
| WAYAN NATURAL WEAR View Details _ | onyx | Other | |||
|
WAYAN NATURAL WEAR is a Mexican retail brand that operates boutiques in Quintana Roo, including Playa del Carmen and Cancún. It sells fashion and lifestyle goods in a natural, eco-chic style, with store listings placing it on Fifth Avenue in Playa del Carmen and in the Cancún hotel zone. Company descriptions and social profiles present it as a fashion and accessories retailer focused on a warm, contemporary shopping experience. It was listed as a ransomware victim associated with onyx. |
|||||
| Artistic Stairs & Railings View Details _ | onyx | Other | |||
|
Artistic Stairs & Railings is a construction company headquartered in Calgary, Alberta, Canada, specializing in the manufacture and installation of award-winning circular stairs, straight stairs, and stair railings for homebuilders and homeowners across the province. The firm provides custom design, consultation, and installation services for production, remodel, and commercial building projects, delivering consistent results with clear timelines. The company was listed as a ransomware victim associated with the threat actor onyx. |
|||||
| Empress EMS View Details _ | hive | Communication / Marketing | |||
|
Empress EMS is a New York-based emergency medical services provider serving Yonkers, Poughkeepsie, and the broader Hudson Valley and Westchester area. It provides emergency and non-emergency ambulance transport, including advanced and basic life support, and operates from locations in Yonkers and Poughkeepsie. The company says it has offered EMS and after-care transportation services since 1985. Empress EMS was listed as a ransomware victim associated with Hive. |
|||||
| Baltholding OÃ View Details _ | onyx | Other | |||
|
Baltholding OÜ is an Estonian company based in Tallinn, with its registered office in the Põhja-Tallinn district on Kopli tn 63a-4. Public business records identify it in the other sector, and directory listings describe trading activity in food and dairy products. The company operates from Estonia and uses the contact details published in the national business register. It was listed as a ransomware victim associated with onyx. |
|||||
| FederalBank/Fedfina.part4 View Details _ | everest | Finance / Legal / Insurance | |||
|
FederalBank/Fedfina.part4 appears to refer to FedFina, a financial services company in India that operates in lending and other finance-related offerings within the broader Finance, Legal, and Insurance sector. Public threat-intelligence listings associate the name with a ransomware incident entry tracked under that entity. The listing is cataloged as a ransomware victim record for the FederalBank/Fedfina.part4 identifier. It was listed as a ransomware victim associated with everest. |
|||||
| ryanhanley.ie - HACKED AND MORE THEN 200GB DATA LEAKED View Details _ | lv | Other | |||
|
Ryan Hanley is a leading civil, environmental, and structural engineering consultancy based in Ireland with offices in Dublin, Galway, Cork, and Castlebar. The firm employs over 150 personnel and offers services including strategic planning, feasibility studies, and water and wastewater design. It was acquired by Stantec, a global leader in sustainable design and engineering, and now operates as part of that group. Ryan Hanley was listed as a ransomware victim associated with the threat actor lv. |
|||||
| sppc.com.sa - HACKED and more then 900GB data leaked View Details _ | lv | Other | |||
|
sppc.com.sa refers to Saudi Printing and Packaging Co., a Riyadh-based Saudi company with activities in printing and packaging, including newspapers, books, magazines, and commercial printing. It is part of Saudi Arabia’s broader industrial and publishing ecosystem, with headquarters in Riyadh and operations tied to local market distribution. The threat-intelligence listing uses the HACKED label and references a leak of more than 900GB of data. It was listed as a ransomware victim associated with lv. |
|||||
| WARTSILA.COM - HACKED AND MORE THEN 2000 GB DATA LEAKED View Details _ | lv | Other | |||
|
Wärtsilä is a Finnish technology company that provides lifecycle solutions, equipment, and services for the marine and energy industries. Its portfolio supports shipping and power-sector customers with technologies designed to improve efficiency, reliability, and sustainability. The company operates globally from Finland and serves industrial markets worldwide. Wartsila.com was listed as a ransomware victim associated with lv. |
|||||
| ginko.com.tw View Details _ | Taiwan, Province of China | lockbit3 | Other | ||
|
Ginko International Co., Ltd. is a Taiwan-based company headquartered in Taichung City. It manufactures and sells contact lenses and contact lens care solutions, serving the ophthalmic products sector from Taiwan. Public company materials identify its contact details and corporate presence in Taichung, Taiwan. The company was listed as a ransomware victim associated with lockbit3. |
|||||
| OptiProERP is a leading global provider of industry-specific ERP solutions for manufacture View Details _ | revil | Communication / Marketing | |||
|
OptiProERP is a leading global provider of industry-specific ERP solutions for manufacturers and distributors, backed by over 20 years of industry expertise. The company delivers best-in-class, end-to-end business management solutions embedded into SAP Business One, covering financials, accounting, sales, CRM, and industry-specific functionality. With headquarters in Irvine, California and additional offices in Mexico City and Indore, OptiProERP serves small and midsize enterprises worldwide. The firm operates in the Communication and Marketing sector, providing cloud-based ERP tools tailored for manufacturing and distribution operations. OptiProERP was neutrally listed as a ransomware victim associated with the threat actor revil. |
|||||
| eclipse-print.com View Details _ | lockbit3 | Communication / Marketing | |||
|
eclipse-print.com is the website of Eclipse Print a. s., a print and marketing services company based in Warsaw, Poland, with operations in Central Europe. The company produces POS displays, carton floorstands, large-format and outdoor advertising, and related print solutions for marketing and media agencies. Its services also include design, development, packaging, logistics, and distribution across Europe. It was listed as a ransomware victim associated with LockBit3. |
|||||
| overseas-ast.com View Details _ | lockbit3 | Other | |||
|
Overseas AST is a long-established UAE construction and engineering company based in Dubai, with offices in Abu Dhabi and Sharjah. The firm specializes in near-shore marine and civil infrastructure, along with top-side mechanical installations for oil and gas, petrochemical, power, and related sectors. Its work also includes marine, civil, and mechanical engineering projects across the region. It was listed as a ransomware victim associated with LockBit3. |
|||||
| legacy-hospitality.com View Details _ | lockbit3 | Healthcare / Pharma | |||
|
legacy-hospitality.com appears to be a U.S.-based hospitality company associated with Legacy Hospitality in Yonkers, New York, with an industry profile in hospitality and a small business footprint. Public company listings describe it as operating from 151 Alexander Ave in Yonkers and serving hospitality-related functions rather than clinical care. In healthcare contexts, hospitality can span patient comfort, accommodations, and service environments, which aligns with broader healthcare/pharma sector operations. The domain was listed as a ransomware victim associated with lockbit3. |
|||||
| agenziaentrate.gov.it View Details _ | Italy | lockbit3 | Other | ||
|
agenziaentrate.gov.it is the official website of Agenzia delle Entrate, the Italian Revenue Agency, a government body in Rome that enforces Italy’s tax code and collects taxes and revenue. It provides online tax and revenue services for Italian citizens and businesses through its digital platforms. The organization operates in the public-sector administration space and serves as a core fiscal authority in Italy. It was listed as a ransomware victim associated with lockbit3. |
|||||
| riken.co.jp View Details _ | Japan | lockbit3 | Other | ||
|
riken.co.jp is the official website of RIKEN, Japan’s National Research and Development Agency and leading comprehensive scientific research institute. RIKEN conducts advanced research across multiple fields from its main campus in Wako, Saitama, and other sites in Japan, supporting science, technology, and innovation. Its public-facing site presents institutional information, research activities, and organizational updates. It was listed as a ransomware victim associated with lockbit3. |
|||||
| daytonsuperior.com View Details _ | lockbit3 | Other | |||
|
Dayton Superior is a U.S.-based construction company headquartered in Miamisburg, Ohio, with corporate offices at 1125 Byers Road. It serves the non-residential concrete construction industry as a single-source provider of concrete accessories, concrete chemicals, and concrete forming products. The company also supports customers through dedicated service lines and technical assistance for its product groups. It was listed as a ransomware victim associated with LockBit3. |
|||||
| roedeanschool.co.za View Details _ | South Africa | lockbit3 | Education | ||
|
Roedean School (SA) is a private English-medium all-girls boarding and day school in Johannesburg, Gauteng, South Africa. It offers junior and senior school education and positions its programme around academic excellence and a progressive, cross-curricular approach. The school’s site also references admissions, school fees, and senior-school information, indicating a full-service independent education provider. It was listed as a ransomware victim associated with LockBit3. |
|||||
| lanormandise.fr View Details _ | France | lockbit3 | Other | ||
|
NORMANDISE Pet Food is a French company based in Vire Normandie, in the Calvados department of Normandy. It manufactures pet food for dogs and cats, with products including wet foods and dry foods. The company says it supports pet well-being through recipe design, production, and logistics. In threat-intelligence indexes, lanormandise.fr was listed as a ransomware victim associated with LockBit3. |
|||||
| laneprint.com.au View Details _ | Australia | lockbit3 | Communication / Marketing | ||
|
Lane Communications is an Australian print and mail services company operating for over 50 years, specializing in transactional printing, secure print, and essential mail across the communication and marketing sector. The firm provides tailored, personalized documents containing sensitive or confidential information for government agencies, utilities, and businesses, delivering functional communications such as financial transactions and account updates. It is compliant with ISO 27001 and focuses on secure information management while offering integrated in-house communication services including graphic design and data access management. Lane Communications was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| Yong Mao Environmental Tech. Co.,Ltd View Details _ | lockbit3 | IT | |||
|
Yong Mao Environmental Tech. Co.,Ltd is an IT-sector company based in Dongguan, Guangdong, China, with a listed factory address in Hengli Town. Public business-directory information identifies it as a company operating from the Weilun Factory in Dongguan and associated with environmental technology and related industrial activity. Because available public records are limited, its exact product and service mix is not fully detailed here. It was listed as a ransomware victim associated with lockbit3. |
|||||
| taylorstafford.com View Details _ | lockbit3 | Other | |||
|
taylorstafford.com operates as a coaching and business advisory platform within the Other sector, offering guidance for building online businesses and professional development. The site is based in the United States and provides courses, expert blogging tips, and systems to help individuals turn passions into profits from home. It was listed as a ransomware victim associated with lockbit3. The listing reflects its inclusion in a threat-intelligence index tracking organizations affected by this cyber threat actor. No stolen data types or breach confirmation details are disclosed in this record. |
|||||
| osde.com.ar View Details _ | Argentina | lockbit3 | Other | ||
|
OSDE is an Argentine health-services organization based in Buenos Aires, operating as a social health insurer and prepaid medical provider. It presents itself as the country’s first medical assistance services network and offers members access to medical coverage, provider directories, and online procedures. The company also serves employers through digital services for workforce administration and payments. It was listed as a ransomware victim associated with LockBit3. |
|||||
| zhulian.co.th View Details _ | Thailand | lockbit3 | Other | ||
|
zhulian.co.th is the Thai site for Zhulian (Thailand) Co., Ltd., based in Nonthaburi, Thailand, and linked to the Zhulian consumer-products business. The company describes its model as network marketing and promotes self-manufactured health and wellness, homecare, jewellery, and beverage offerings. Public business directories also place Zhulian (Thailand) Co., Ltd. in Bang Bua Thong, Nonthaburi. It was listed as a ransomware victim associated with lockbit3. |
|||||
| townofstmarys.com View Details _ | lockbit3 | Other | |||
|
townofstmarys.com is the official website of the Town of St. Marys, a municipal government in southwestern Ontario, Canada. The town provides public services, local administration, permits, licenses, business resources, and community information for residents and organizations. Its site also supports arts, culture, recreation, and economic development initiatives in the municipality. In the threat-intelligence index, townofstmarys.com was listed as a ransomware victim associated with LockBit3. |
|||||
| bizebra.com View Details _ | lockbit3 | Other | |||
|
Bizerba.com is the website of Bizerba, a globally operating manufacturing company headquartered in Balingen, Germany. The company provides hardware and software for retail, industry, and logistics, including weighing, labeling, slicing, and food-processing solutions. Its U.S. site also highlights interactive showroom and live demo offerings in Richmond, Virginia. The domain was listed as a ransomware victim associated with LockBit3. |
|||||
| FederalBank/Fedfina.part3 View Details _ | everest | Finance / Legal / Insurance | |||
|
FederalBank/Fedfina.part3 is a finance-sector entity name used in threat-intelligence indexing for a business associated with banking and lending services in India. Federal Bank offers personal, business, NRI, digital banking, loans, deposits, and life insurance services, while Fedfina is described as providing gold loans, home loans, and property loans. The listing reflects an identified victim entry in a cyber-threat catalog rather than a confirmed public breach report. It was listed as a ransomware victim associated with everest. |
|||||
| CHDE POLSKA View Details _ | vicesociety | Other | |||
|
CHDE POLSKA S.A. is a company based in Rzeszów, Poland, with its headquarters on Biesiadna Street. Public business profiles describe it as operating in the Other Miscellaneous Nondurable Goods Merchant Wholesalers sector, while company profiles also reference medical-device sales and pharmaceutical-related activity. Its website and corporate listings identify CHDE as a commercial brand serving healthcare-related distribution and service needs in Poland. It was listed as a ransomware victim associated with vicesociety. |
|||||
| a2-pas.fr View Details _ | France | lockbit3 | Other | ||
|
a2-pas.fr operates as a guesthouse and gîte d'étape located in the heart of Lectoure, France, near the Cathédrale Saint-Gervais et Saint-Potrais and along the Camino de Santiago route. The establishment offers private rooms for one to four people, with nightly rates starting at 68€, and provides amenities including free WiFi, a terrace, and nearby public parking. It accommodates up to 13 guests and is open from April to November, serving travelers seeking a quiet stay with breakfast available at 6€ per person. a2-pas.fr was listed as a ransomware victim associated with the LockBit3 threat actor, with no further official breach details disclosed by the company itself. |
|||||
| site-technology View Details _ | cuba | IT | |||
|
Site Technology is an IT-sector supplier, systems integrator, and contractor based in Lebanon, with offices across the United Arab Emirates, Qatar, Saudi Arabia, and other regional markets. The company says it provides turnkey services from design and procurement through installation, and its website describes work supporting business operations and infrastructure systems. Public company profiles also place it in engineering and construction-related technology services. It was listed as a ransomware victim associated with Cuba. |
|||||
| ocrex.com View Details _ | lockbit3 | Other | |||
|
OCRex is a UK-based fintech company that develops AI-driven OCR and document-capture software for financial workflows. Its products are designed to streamline accounts preparation and reduce manual data entry for accounting and business services users. Companies House lists OCREX UK LTD with a registered office in Newcastle upon Tyne, United Kingdom. The entity was listed as a ransomware victim associated with lockbit3. |
|||||
| mwd.digital View Details _ | lockbit3 | IT | |||
|
MWD.digital is an Italian IT company based in Verona, Veneto, that develops digital platforms and custom software. Its website says it combines software, data and artificial intelligence to create value and accelerate innovation, with services spanning custom development, system integration, AI and digital marketing. Public business listings also describe it as a web and software agency serving organizations with workflow and communication tools. The company was listed as a ransomware victim associated with LockBit3. |
|||||
| Edenfield View Details _ | vicesociety | Other | |||
|
Edenfield Limited is a UK-registered company based in London, with Companies House listing its registered office at 368 Forest Road, London, E17 5JF. Public company records identify it as a private limited company, but they do not provide a detailed sector description or public product catalog in the listing excerpt. Because of that, Edenfield is best described conservatively as a London-based business entity operating in the broader other sector. It was listed as a ransomware victim associated with vicesociety. |
|||||
| mec.com View Details _ | lockbit3 | Other | |||
|
mec.com refers to Mec Com Limited, a UK-based contract manufacturer specializing in sheet metal fabrications, light assembly, and related industrial fabrication services. Company records list its registered office in Hixon, Stafford, and public company information identifies it as a manufacturer of fabricated metal products. The business describes itself as one of the UK’s largest independent contract manufacturers, serving industrial customers from its manufacturing sites in the United Kingdom and Romania. It was listed as a ransomware victim associated with LockBit3. |
|||||
| lexingtonnational.com View Details _ | lockbit3 | Other | |||
|
Lexington National Insurance Corporation is an A- AM Best rated insurer licensed in all 50 states, headquartered in Cockeysville, Maryland, offering dependable insurance solutions and surety bonds nationwide. The company provides BMC-84 FMCSA claims coverage and general surety claims services, emphasizing customer service and operational stability for businesses and individuals across the United States. It was listed as a ransomware victim associated with the LockBit3 threat actor, with no confirmed details on data theft or breach specifics disclosed by the company. |
|||||
| keystonelegal.co.uk View Details _ | United Kingdom | redalert | Finance / Legal / Insurance | ||
|
Keystone Legal is a leading UK provider of After The Event (ATE) and Legal Expenses Insurance (LEI) for solicitors, established in 1988 and headquartered in Aldershot, Hampshire, GB. The company offers strategic, operationally and commercially focused ATE insurance solutions tailored to the litigation landscape in the UK. It works with law firms of all sizes across the country, delivering innovative and effective insurance products underwritten by Keystone Legal Benefits Ltd. Keystone Legal was listed as a ransomware victim associated with the threat actor redalert. |
|||||
| LaVan & Neidenberg View Details _ | United States | hive | Other | ||
|
LaVan & Neidenberg, P.A. is a South Florida law firm based in Plantation, Florida, serving clients across the US. Public listings describe its practice as focused on disability-related matters, including Social Security, long-term disability, veterans benefits, and debt harassment defense. The firm also appears in legal directories under personal injury and automobile accident work. It was listed as a ransomware victim associated with hive. |
|||||
| COS2000 View Details _ | blackbasta | Other | |||
|
COS2000 is an entity operating in the Other sector with no publicly specified geographic location or distinct service offerings documented in available sources. As a generic designation within the Other sector, it lacks verified details about its core business activities, products, or market presence. The entity was listed as a ransomware victim associated with Black Basta, a Russia-linked group known for double-extortion tactics and targeting organizations globally. Black Basta has compromised over 578 victims since 2022, employing reconnaissance tools like ZoomInfo to identify high-value targets. COS2000 appears among these confirmed victims, though no official breach notification or first-party disclosure date has been publicly released by the entity itself. |
|||||
| The Minka Group View Details _ | blackbasta | Services | |||
|
The Minka Group is a California-based company in the services sector that manufactures decorative lighting and ceiling fans. It is headquartered in Corona, California, and markets lighting products such as chandeliers and light rails through the Minka brand. The company is described as an established decorative lighting and fan maker with a long operating history. It was listed as a ransomware victim associated with blackbasta. |
|||||
| competencia.com.ec View Details _ | lockbit3 | Other | |||
|
competencia.com.ec is the website of La Competencia S.A., an Ecuadorian company based in Quito, Pichincha. Its corporate site says it has more than 60 years of experience providing technological solutions, advising companies, and supplying products and services. The company’s offerings include security systems, monitoring and analysis tools, and online retail products such as intercoms, video doorphones, smart locks, and security cameras. It was listed as a ransomware victim associated with lockbit3. |
|||||
| coastalmedps.com View Details _ | lockbit3 | Other | |||
|
CoastalMed PS is a U.S. pharmacy services company focused on long-term care support, founded by experienced long-term care pharmacists and centered on accurate, high-quality service. Its offerings include pharmacy services, infusion services, insurance support, web portal access, and technology tools designed to help facilities manage medication and communication workflows. The company says it provides service seven days a week and operates 24/7 support for partner facilities. It was listed as a ransomware victim associated with lockbit3. |
|||||
| addconsult.nl View Details _ | Netherlands | lockbit3 | Other | ||
|
AddConsult Group BV is a Dutch company based in the Netherlands that specializes in automating and optimizing business processes. Its website describes it as a partner for service, quality, empathy, and a pragmatic approach, and it also references support for sectors such as hospitals and private clinics. Public company listings describe Add Consult as operating in the accountants and tax advisers industry, which places it in the broader other sector for this index entry. It was listed as a ransomware victim associated with LockBit3. |
|||||
| FederalBank/Fedfina.part2 View Details _ | everest | Finance / Legal / Insurance | |||
|
FederalBank/Fedfina.part2 refers to Fedbank Financial Services Ltd., also known as Fedfina, an India-based retail-focused non-banking financial company promoted by Federal Bank. Its offerings include loan and related financial services for customers through digital and branch channels. The company operates in the broader Finance sector, with exposure to legal and insurance-adjacent services through customer-facing financial products. It was listed as a ransomware victim associated with everest. |
|||||
| XQUADRAT GmbH View Details _ | vicesociety | Other | |||
|
XQUADRAT GmbH is a German architecture and planning company based in Gelnhausen, Hesse, with offices at Im Ziegelhaus 13. Its services include interior architecture, architectural planning, project management, revitalization concepts, tenant fit-out, and related design work. Public profiles describe it as serving building analysis, planning, and space concept needs in the architecture and planning sector. It was listed as a ransomware victim associated with vicesociety. |
|||||
| San Luis Coastal Unified View Details _ | vicesociety | Other | |||
|
San Luis Coastal Unified School District is a public unified school district in San Luis Obispo County, California, serving K-12 students across its schools and programs. It operates from 1500 Lizzie Street in San Luis Obispo and provides district administration, instructional services, student support, transportation, food services, and related education functions. The district is part of California’s public school system and serves a local community in the Central Coast region of the United States. It was listed as a ransomware victim associated with vicesociety. |
|||||
| An Insurance Company View Details _ | cheers | Finance / Legal / Insurance | |||
|
An Insurance Company is an insurer in the Finance, Legal, and Insurance sector, a business category that provides financial protection against risks in exchange for premium payments. Insurance companies operate under federal and state regulatory and reporting requirements, and their offerings typically center on underwriting, policy administration, claims handling, and risk transfer. In a threat-intelligence index, the entity is recorded as an insurance-sector organization in the United States. It was listed as a ransomware victim associated with cheers. |
|||||
| GENSCO Inc. - allows Leak View Details _ | ragnarlocker | Services | |||
|
Gensco Inc. is a family-owned, regional wholesale distributor and manufacturer of HVAC equipment and supplies, serving commercial customers across the Northwest. Based in Tacoma, Washington, it provides HVAC products, design-build and retrofit support, engineering assistance, and quoting services for the services sector. The company has operated for more than 75 years and maintains multiple locations across the region. It was listed as a ransomware victim associated with Ragnar Locker. |
|||||
| .com View Details _ | bianlian | Other | |||
|
.com operates within the global financial sector, providing investment research, market performance dashboards, and economic sector analysis tools to users worldwide. The entity delivers comprehensive data on stock sectors, industry indexes, and market fundamentals through its digital platforms, serving investors and analysts across multiple countries. As a recognized provider of financial intelligence, .com supports decision-making with real-time sector performance metrics and historical return data. The company was listed as a ransomware victim associated with the threat actor bianlian. |
|||||
| cristianaspinecenter.com View Details _ | lockbit3 | Other | |||
|
cristianaspinecenter.com is the website for Cristian's Spine Center, a medical practice in the United States focused on spine care and related patient services. Public web results indicate it offers site and contact information for a healthcare provider rather than a retail or media business. As a healthcare entity, it fits the broader other sector category used in threat-intelligence cataloging. It was listed as a ransomware victim associated with LockBit3. |
|||||
| crbrandsinc.com View Details _ | lockbit3 | Services | |||
|
crbrandsinc.com refers to CR Brands, a U.S.-based company headquartered in West Chester Township, Ohio. The company was a manufacturer and distributor of household cleaning and laundry products, including disinfecting wipes, laundry stain removers, and garbage disposal cleaners. Public company profiles also describe it as a national branded and private-label consumer products business in the cleaning products sector. It was listed as a ransomware victim associated with lockbit3. |
|||||
| rovagnati.it View Details _ | Italy | lockbit3 | Other | ||
|
rovagnati.it is the official website of Rovagnati S.p.A., a leading Italian producer of premium cured meats and deli products headquartered in Biassono, Lombardy. The company is renowned for its commitment to quality, tradition, and innovation in the charcuterie sector, offering iconic products like the Gran Biscotto cooked ham. Rovagnati S.p.A. has evolved from a small business in Brianza into a world leader in fine cured meats, maintaining strong ties to Italian culinary traditions. The company was listed as a ransomware victim associated with the lockbit3 threat actor, with no confirmed details on stolen data or breach specifics. |
|||||
| madcoenergi.com View Details _ | lockbit3 | Other | |||
|
madcoenergi.com is the website for PT Madco Energi, an Indonesian company in the energy and resources space that presents itself as an other-sector business. Public-facing materials indicate it operates from Indonesia and focuses on energy-related business activities and services. The domain identifies the company online and serves as its primary corporate web presence. It was listed as a ransomware victim associated with lockbit3. |
|||||
| fedefarma.com View Details _ | lockbit3 | Agriculture / Food | |||
|
fedefarma.com is associated with the Agriculture / Food sector in Spain and appears to operate in food-related business activities. In this sector, companies typically work across farming, processing, storage, distribution, or other food supply-chain functions. The domain name indicates a commercial organization tied to agricultural or food services, rather than a consumer media or technology brand. It was listed as a ransomware victim associated with lockbit3. |
|||||
| cpicfiber.com View Details _ | lockbit3 | Other | |||
|
cpicfiber.com is the website of Chongqing Polycomp International Corp. (CPIC), a China-based manufacturer of glass fiber and composite materials headquartered in Chongqing, China. The company produces fiberglass and related composite products for industrial applications and serves sectors including construction, consumer goods, sports, leisure, agriculture, electronics, and wind energy. Public company materials also describe CPIC as operating multiple production bases and serving global markets. It was listed as a ransomware victim associated with lockbit3. |
|||||
| columbiagrain.com View Details _ | lockbit3 | Agriculture / Food | |||
|
Columbia Grain International is a U.S.-based agriculture company headquartered in Portland, Oregon, serving farmers and food supply chains with bulk grains, pulses, edible beans, oilseeds, and organics. Its operations include sourcing, marketing, distribution, and vertically integrated assets such as grain elevators, processing plants, and agronomy centers. The company supports domestic and international trade across food processing, animal feed, and biofuel markets. It was listed as a ransomware victim associated with LockBit3. |
|||||
| clestra.com View Details _ | lockbit3 | Other | |||
|
Clestra is a global construction and modular interiors company focused on offsite manufacturing, modular construction, and highly adaptable building systems. It designs, manufactures, and installs modular partitions and related space solutions for offices, workspaces, and cleanrooms, with operations centered in Strasbourg, France. The group says it operates across 4 factories and 3 continents, serving clients in multiple countries. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Delon Hampton & Associates, Chartered View Details _ | United States | quantum | Manufacturing / Engineering | ||
|
Delon Hampton & Associates, Chartered is a professional consulting engineering firm founded in 1973 and headquartered in Washington, DC, with additional offices in Maryland and Georgia. It provides civil and structural engineering, program and construction management, and related infrastructure services across transportation, transit, aviation, water and wastewater, and land development markets. The firm also describes work in civil engineering for infrastructure, urban redevelopment, energy, and airport projects. It was listed as a ransomware victim associated with quantum. |
|||||
| Autohaus View Details _ | quantum | Other | |||
|
Autohaus is an automotive business headquartered in Yorktown, United States, with additional offices in Virginia Beach and Williamsburg, offering vehicle services and custom auto accessories. The company operates multiple locations across the United States, providing high-quality automotive solutions and expert services to enhance customer vehicles. As part of the automotive sector, Autohaus delivers tailored offerings including custom accessories and maintenance services for vehicles in the Bay Area and other regions. The entity was listed as a ransomware victim associated with the threat actor quantum, indicating its inclusion in a threat-intelligence index. |
|||||
| Broshuis | Driving innovation View Details _ | United States | quantum | Other | ||
|
Broshuis is a family-owned international manufacturer of trailers for exceptional and container transport, with a history of more than 140 years. The company describes itself as serving customers worldwide across multiple industries and emphasizes in-house engineering and innovation. Its corporate materials present Broshuis as a producer of specialized transport equipment, including solutions for defense customers. It was listed as a ransomware victim associated with quantum. |
|||||
| FederalBank / Fedfina View Details _ | everest | Finance / Legal / Insurance | |||
|
Federal Bank is an Indian private-sector bank headquartered in Aluva, Kochi, Kerala, with banking outlets, ATMs and overseas representative offices. Its non-banking financial arm, Fedbank Financial Services Ltd. (Fedfina), offers products such as gold loans, home loans, property loans and other retail finance services from Mumbai. The group serves customers across India through banking and lending operations. FederalBank / Fedfina was listed as a ransomware victim associated with everest. |
|||||
| bizframe.co.za View Details _ | South Africa | lockbit3 | Other | ||
|
BizFrame is a Johannesburg-based software and enterprise platform company in Gauteng, South Africa. Its public profile describes it as an application platform specialist that helps teams and businesses transform how they work. Company listings also place it at 12 Morris Street West, Woodmead Ext 1, Johannesburg, and identify it as a technology provider. It was listed as a ransomware victim associated with lockbit3. |
|||||
| integrate.ch View Details _ | Switzerland | lockbit3 | Other | ||
|
integrate.ch is the website for INTEGRATE, a Swiss company based in Switzerland. Its site presents the firm as providing expert services and direct client contact, with capabilities in software and technology work such as C, C++, C#, Java, and database systems including MS SQL, MySQL, Oracle SQL, and MongoDB. The company emphasizes personal support and fair interaction with employees and clients, reflecting a service-oriented business profile. It was listed as a ransomware victim associated with lockbit3. |
|||||
| aresfoods.ca View Details _ | Canada | lockbit3 | Agriculture / Food | ||
|
Ares Foods is a food-sector company based in Montréal, Quebec, Canada, operating from 8250 Rue Bombardier in Anjou. It presents itself as a one-stop source for protein products and distributes chicken, beef, pork, lamb and seafood to wholesale customers. Public business listings also describe it as a meat and poultry wholesaler serving restaurants, butcher shops and markets. It was listed as a ransomware victim associated with LockBit3. |
|||||
| An British Financial Company -Unpay View Details _ | cheers | Finance / Legal / Insurance | |||
|
An British Financial Company -Unpay is a United Kingdom-based enterprise operating within the Finance, Legal, and Insurance sectors, providing financial services and related advisory offerings to clients across the region. The company functions as a key participant in the British financial ecosystem, delivering specialized products and support tailored to the needs of businesses and individuals in the finance and legal domains. It was listed as a ransomware victim associated with the threat actor cheers. |
|||||
| An International Shipping Company - Paid View Details _ | cheers | Transportation / Travel / Logistics | |||
|
An International Shipping Company - Paid is an entity in the Transportation / Travel / Logistics sector, operating in shipping and freight movement. The name suggests a company involved in international cargo transport or related logistics services, likely serving cross-border trade and supply chains. In threat-intelligence indexes, it is cataloged as a ransomware victim record. It was listed as a ransomware victim associated with cheers. |
|||||
| KNAUF View Details _ | blackbasta | Other | |||
|
KNAUF is a Germany-based industrial group headquartered in Iphofen, Germany, with corporate presence in Munich and operations spanning the construction and insulation industry. The Knauf Group’s businesses cover major building-material segments, and its related divisions operate across multiple countries and manufacturing sites. Public company profiles describe Knauf as a large wholesale building materials business with global reach and diversified production. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Wallwork Truck Center View Details _ | blackbasta | Other | |||
|
Wallwork Truck Center is a North Dakota-based commercial truck dealership headquartered in Fargo, with multiple locations across the region. It sells and services medium- and heavy-duty trucks and trailers, and offers parts, finance, rentals, leasing, and repair support. The company represents brands including Kenworth and Ford, serving commercial transportation customers. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Dillon Precision Products View Details _ | blackbasta | Communication / Marketing | |||
|
Dillon Precision Products is a Scottsdale, Arizona-based manufacturer and supplier of ammunition reloading equipment and accessories. The company operates in manufacturing and sells reloading machines, parts, and related supplies through its Arizona headquarters and retail site. Public company profiles describe it as founded in 1977 and focused on firearm reloading products. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Albanian Government View Details _ | Albania | roadsweep | Public Sector | ||
|
Albanian Government is the executive authority of the Republic of Albania, a parliamentary democracy in Southeastern Europe that oversees national policy, public administration, and state services. It operates across the public sector, including ministries and institutions that deliver citizen-facing services and coordinate government functions. Albania also maintains digital public-service channels such as the e-Albania portal to improve access to government information and services. The Albanian Government was listed as a ransomware victim associated with roadsweep. |
|||||
| sig.id View Details _ | Indonesia | lockbit3 | Other | ||
|
sig.id is an Indonesia-based entity in the Other sector, identified by its .id domain and generic service-oriented web presence. Publicly available information does not clearly define a specific industry offering, so it is best described conservatively as a general-purpose digital business or service site. In threat-intelligence indexing, it is cataloged as a ransomware victim linked to the LockBit 3.0 ecosystem. The listing associates sig.id with lockbit3 without asserting further incident details. |
|||||
| ISGEC Heavy Engineering View Details _ | bianlian | Manufacturing / Engineering | |||
|
ISGEC Heavy Engineering Ltd. is an India-based public company headquartered in Noida, Uttar Pradesh, with a multi-location engineering and manufacturing footprint. It designs and supplies industrial boilers, process plant equipment, presses, castings, and industrial project solutions across manufacturing and machinery segments. The company says it serves customers in many countries and operates across industrial engineering, equipment, and project execution. It was listed as a ransomware victim associated with bianlian. |
|||||
| VERITAS Solicitors View Details _ | bianlian | Other | |||
|
Veritas Solicitors LLP is a Manchester-based law firm in England, with its head office at Cardinal House, 20 St Mary’s Parsonage. It offers legal advice across areas including personal injury, housing disrepair, immigration, and financial claims. The firm presents itself as a specialist practice providing a free initial consultation and case-specific guidance. It was listed as a ransomware victim associated with bianlian. |
|||||
| Conway Electrics View Details _ | bianlian | Other | |||
|
Conway Electrics Pty Ltd is an electrical contracting company based in Australia that specializes in commercial, industrial, and domestic installations as well as maintenance services. The firm operates within the electrical services sector, delivering comprehensive solutions for diverse client needs including new builds and upkeep projects. It was listed as a ransomware victim associated with the threat actor bianlian, with no confirmed details on data impact or breach specifics. |
|||||
| Carrolls Irish Gifts View Details _ | Ireland | hive | Other | ||
|
Carrolls Irish Gifts is a leading retail company in Ireland, established in 1982, specializing in high-quality Irish gifts, clothing, jewelry, and souvenirs for all occasions. The company, headquartered in Dublin with additional locations across Ireland, stocks many leading Irish brands including Guinness, Carraig Donn, and Tipperary Crystal. It is a fully Irish-owned retailer with over 40 years of business experience, offering an extensive product range that celebrates heritage and tradition. Carrolls Irish Gifts was listed as a ransomware victim associated with the threat actor hive. |
|||||
| vahanen.com View Details _ | redalert | Other | |||
|
Vahanen Group was a Finnish multidisciplinary consulting company focused on the construction and real estate sector, with services spanning architecture, building services engineering, structural engineering, refurbishment, property management, and building physics. It was headquartered in Finland, and public company materials describe it as a technical consultant serving the property and construction branch. The vahanen.com domain was later decommissioned after AFRY replaced the website. vahanen.com was listed as a ransomware victim associated with redalert. |
|||||
| Rain the Growth Agency View Details _ | bianlian | Communication / Marketing | |||
|
Rain the Growth Agency is a Portland, Oregon-based full-service creative, advertising, and media agency serving brands with strategy, creative, production, and media services. It operates in the communication and marketing sector and describes itself as a performance-minded agency focused on growth for clients. Public business listings place the company at 249 NW Park Avenue in Portland. It was listed as a ransomware victim associated with bianlian. |
|||||
| frederickco.gov View Details _ | United States | lockbit3 | Other | ||
|
frederickco.gov is the official website of the Town of Frederick, Colorado, in the United States, serving a Front Range community north of Denver. The site publishes town government information, departmental services, utility billing and payment options, building services, and other public-facing municipal resources. It also provides contact details for town offices, public works, police, and related local services. The entity was listed as a ransomware victim associated with lockbit3. |
|||||
| Behavioral Health System View Details _ | United States | hive | Healthcare / Pharma | ||
|
Behavioral Health System is a US healthcare organization focused on behavioral health, a field that addresses mental health and substance use concerns through prevention, treatment, and ongoing support. Behavioral health providers typically include clinicians and care teams that deliver counseling, psychiatric care, and related services across inpatient and outpatient settings. In the US, behavioral health is commonly delivered through integrated medical and specialty care models. Behavioral Health System was listed as a ransomware victim associated with Hive. |
|||||
| FMT View Details _ | hive | Other | |||
|
FMT Consultants is a business technology consulting firm headquartered in Carlsbad, California, that specializes in integrated business management solutions and custom development. It serves organizations seeking technology consulting and implementation support. The company is generally categorized in the Other sector. In threat-intelligence indexes, FMT was listed as a ransomware victim associated with Hive. |
|||||
| CITY-FURNITURE View Details _ | United States | hive | Public Sector | ||
|
City Furniture is South Florida's leading furniture and mattress retailer, operating numerous showrooms across the state with a focus on value and exceptional service. The company, headquartered in Fort Lauderdale, offers home furnishings and decor through both online platforms and in-store experiences, serving residential and commercial customers. With planned expansions throughout Southeast, Southwest, and Central Florida, City Furniture remains a fast-growing business in the furniture retail industry. The company was neutrally listed as a ransomware victim associated with the Hive threat actor in the United States Public Sector. |
|||||
| RALLYE-DOM View Details _ | hive | Other | |||
|
RALLYE-DOM is a France-based company in the Other sector, with public-facing business details not clearly disclosed in the available search results. Its name suggests an operating entity rather than a consumer brand, but the exact offerings and location are not confirmed by the sources provided. In threat-intelligence catalogs, it is referenced for monitoring as an indexed organization name. It was listed as a ransomware victim associated with hive. |
|||||
| genusplc.com View Details _ | lockbit3 | Other | |||
|
Genus plc is a publicly traded UK company headquartered in Basingstoke, Hampshire, with operations in the United States and other markets. It focuses on animal genetics for dairy, beef and pork production through its ABS bovine genetics and PIC porcine genetics businesses, supplying farmers with improved breeding stock and related services. The company describes itself as a global leader in animal genetics and ag-tech, using scientific innovation to improve livestock performance and sustainability. It was listed as a ransomware victim associated with lockbit3. |
|||||
| ZEUS Scientific View Details _ | United States | quantum | Healthcare / Pharma | ||
|
ZEUS Scientific is a clinical diagnostic company based in Branchburg, New Jersey, United States, specializing in in vitro diagnostic tests for autoimmune and infectious diseases. The firm offers flexible testing solutions across three platforms: ZEUS ELISA™, AtheNA Multi-Lyte®, and ZEUS IFA™, designed for high performance and ease of use in healthcare settings. Its products are developed and manufactured to support screening and diagnostics in oncology, metabolic diseases, genetic disorders, and autoimmune conditions. ZEUS Scientific was listed as a ransomware victim associated with the threat actor quantum. |
|||||
| vlp.nl View Details _ | Netherlands | lockbit3 | Other | ||
|
vlp.nl is the website of VLP, a Netherlands-based company in Naaldwijk that supplies flexible partitions and bespoke PVC solutions. Its products and services span multiple sectors, including data centres, industry, logistics, food, agriculture, construction, and automotive. The company presents itself as a specialist in custom solutions for workplaces and storage environments, with over 40 years of experience. In threat-intelligence records, vlp.nl was listed as a ransomware victim associated with lockbit3. |
|||||
| iis.ac.uk View Details _ | United Kingdom | lockbit3 | Other | ||
|
iis.ac.uk is the website of The Institute of Ismaili Studies, a higher education, research, and teaching institution in London, GB. Founded in 1977, it promotes scholarship and learning on Islam and Muslim societies, and produces educational materials, publications, and graduate study resources. Its programs and resources support teachers, students, and scholars in multiple countries. The site was listed as a ransomware victim associated with lockbit3. |
|||||
| etgworld.com View Details _ | lockbit3 | Other | |||
|
ETG World is a diversified enterprise with operations across agricultural inputs, chemicals, logistics, food and food processing, energy, and minerals. Its website describes the group as a global business with a strong focus on agricultural commodities and Africa, and its North America arm is based in Mississauga, Ontario, supplying plant-based food products and ingredients. The company operates under the ETG brand and maintains a broad international trade and supply-chain footprint. It was listed as a ransomware victim associated with LockBit3. |
|||||
| syredis.fr View Details _ | France | redalert | Other | ||
|
Syredis is a French IT and cloud services company that provides infrastructure, hosting, monitoring, and collaborative cloud tools. Its services include infrastructure as a service for servers, networks, and storage, as well as platforms for public-sector communication and IT supervision. The company presents itself around secure, cost-effective systems for applications, data, and operational management. syredis.fr was listed as a ransomware victim associated with redalert. |
|||||
| Mackenzie Medical View Details _ | bianlian | Healthcare / Pharma | |||
|
Mackenzie Medical is a healthcare provider operating in the United States, with public listings tied to medical offices in Oregon and care services in the region. Its offerings include specialty care, diagnostics, treatment procedures, and related outpatient services for patients and communities. As a healthcare-sector organization, it fits the pharma and medical services category used in threat-intelligence indexing. It was listed as a ransomware victim associated with bianlian. |
|||||
| Anderson Insurance Associates View Details _ | bianlian | Finance / Legal / Insurance | |||
|
Anderson Insurance Associates is an independent insurance agency based in Charleston, South Carolina, serving clients from offices in Charleston, Pawleys Island, Greenville, and Aiken. It offers personal and business insurance solutions, including auto, homeowners, business, and life coverage, through hundreds of policies from regional and national carriers. The agency describes itself as serving Charleston and the broader Southeast with tailored insurance options. It was listed as a ransomware victim associated with bianlian. |
|||||
| High Power Technical Services View Details _ | bianlian | IT | |||
|
High Power Technical Services is a veteran-owned business headquartered in Louisville, Kentucky, specializing in staffing, Data Center support, Help desk services, and Systems Engineering. The company operates as a major regional service provider for Dish Network, delivering sales, repair, and installation services across Kentucky, Indiana, and Ohio. It offers multi-faceted technician training programs and serves as an authorized retailer of DISH Network products. High Power Technical Services was listed as a ransomware victim associated with the threat actor bianlian. |
|||||
| Mooresville Schools View Details _ | bianlian | Education | |||
|
Mooresville Schools is a public education district in Mooresville, Indiana, serving the local community with five elementary schools, one middle school, and one high school. The district operates as Mooresville Consolidated School Corporation and provides K-12 instruction, with statewide education data reflecting a substantial teaching staff and district-wide enrollment. Its schools are part of Indiana’s public school system and offer standard elementary, middle, and high school programs. It was listed as a ransomware victim associated with bianlian. |
|||||
| Maxey Moverley View Details _ | 0mega | IT | |||
|
Maxey Moverley is a UK-based specialist electronics repair and support company in Redditch, England. It provides high-technology repair and service solutions for security equipment, HVAC and catering equipment, and supports the UK electronics industry. The company was established in 1996 and is registered for repair of electronic and optical equipment. It was listed as a ransomware victim associated with 0mega. |
|||||
| Van Ausdall & Farrar, inc View Details _ | lorenz | Services | |||
|
Van Ausdall & Farrar, Inc. is a privately held Indiana services company headquartered in Indianapolis, with offices in Fort Wayne and Evansville. It provides office technology and business technology services, including managed IT, unified communications, print solutions, and related systems for organizations across the Midwest. Company profiles describe it as the state’s largest full-service business technology provider. It was listed as a ransomware victim associated with lorenz. |
|||||
| Biothane usa View Details _ | lorenz | Other | |||
|
Biothane USA, also known as BioThane Coated Webbing, is a family-owned manufacturer based in North Ridgeville, Ohio. It produces TPU- and PVC-coated webbing and assemblies for industrial and specialty applications, and describes itself as a leading global supplier with U.S. operations in Northeast Ohio. Public company profiles also place it in the plastics manufacturing sector and note its headquarters in North Ridgeville. It was listed as a ransomware victim associated with Lorenz. |
|||||
| Gresco View Details _ | lorenz | Other | |||
|
Gresco Utility Supply, Inc. is a Georgia-based distributor serving the electric utility market across the southeastern United States. The company is headquartered in Forsyth, Georgia, and operates additional locations in states including Alabama, Florida, Louisiana, Mississippi, and Tennessee. Gresco describes itself as a full-line stocking distributor focused on utility contractors and related energy-sector needs. It was listed as a ransomware victim associated with lorenz. |
|||||
| SANDO View Details _ | Spain | hive | Other | ||
|
SANDO is a Spain-based organization in the Other sector, identified here for threat-intelligence cataloging rather than as a cybersecurity vendor or incident responder. Public information indicates it operates as a business entity in Spain, but this listing does not specify its exact offerings, so they are not inferred here. In threat-intelligence contexts, SANDO is referenced as a ransomware victim entry tied to the Hive ecosystem. It was listed as a ransomware victim associated with hive. |
|||||
| RTVCM View Details _ | hive | Other | |||
|
RTVCM is an entity in the Other sector in Mexico. Publicly available search results do not clearly establish its exact business model, location, or offerings, so its profile should be treated as limited and non-specific. In threat-intelligence records, it appears as a named organization rather than a detailed operating company. RTVCM was listed as a ransomware victim associated with hive. |
|||||
| AdaptIT View Details _ | South Africa | hive | Other | ||
|
Adapt IT is a South Africa-headquartered IT services and software company based in Johannesburg, with offices in Midrand, Durban, Cape Town and other regional locations. It develops specialised vertical-market software and digitally led business solutions for sectors including education, financial services, energy, mining and telecommunications. Its offerings support customer experience, core operations, business administration and enterprise resource planning. The company was listed as a ransomware victim associated with hive. |
|||||
| Exela Technologies View Details _ | United States | hive | IT | ||
|
Exela Technologies is a US-based information technology and business process automation company headquartered in Texas. It provides workflow automation, cognitive automation, digital mailroom, print communications, and payment-processing solutions for enterprise environments. The company serves industries such as banking, healthcare, and insurance, supporting mission-critical operations across global deployments. It was listed as a ransomware victim associated with Hive. |
|||||
| APETITO View Details _ | United Kingdom | hive | Other | ||
|
Apetito is a UK food producer based in Trowbridge, Wiltshire, and part of the wider food and beverage manufacturing sector. It provides prepared meals and food services, with a focus on nutritious, sustainable meals for health and social care customers and other groups. The company also markets its Wiltshire Farm Foods brand in the UK. APETITO was listed as a ransomware victim associated with hive. |
|||||
| GROUP4 AUSTRALIA View Details _ | Australia | hive | Services | ||
|
GROUP4 AUSTRALIA is an Australian Services-sector company, part of a national economy where services dominate business activity and output. As a Services business, it operates in the broad Australian services market, which includes activities such as professional, administrative, and other business services. The company was listed as a ransomware victim associated with hive. |
|||||
| Authentic Brands Group View Details _ | United States | hive | Services | ||
|
Authentic Brands Group is a New York–based brand development and licensing company in the services sector. It acquires, owns, and manages sports, media, entertainment, and lifestyle brands, then works through a partner network to commercialize them across countries and retail channels. The company’s public materials describe it as a global brand platform with broad retail and licensing reach. It was listed as a ransomware victim associated with Hive. |
|||||
| Epec.PL - Lied about the absence of Leak View Details _ | ragnarlocker | Other | |||
|
Epec.PL is a Polish company in the other sector; based on its name, it appears to be an organization operating in Poland rather than a public-facing consumer brand. Its business scope is not established by the available threat-intelligence records, so the listing should be read as an index entry, not a company profile. The record is used to catalog a reported ransomware-victim mention associated with Ragnar Locker. It was listed as a ransomware victim associated with ragnarlocker. |
|||||
| American International Industries View Details _ | United States | quantum | Communication / Marketing | ||
|
American International Industries is a Los Angeles, California-based manufacturer and distributor of beauty and skin care products for men and women. Its catalog includes professional beauty products such as waxing supplies and other personal-care items sold under its own brands. The company operates in the communication and marketing-adjacent consumer products space through brand-led product distribution and promotion. It was listed as a ransomware victim associated with quantum. |
|||||
| Summit Care View Details _ | ransomhouse | Other | |||
|
Summit Care is a U.S.-based healthcare services company that provides contract therapy services across multiple care settings, including hospitals, skilled nursing, and independent or assisted living communities. Its offerings are centered on therapy support for patients and residents, rather than a single-site clinical practice. Publicly available business information identifies Summit Care as operating in the healthcare sector and based in the United States. Summit Care was listed as a ransomware victim associated with ransomhouse. |
|||||
| Uppco View Details _ | lorenz | Other | |||
|
Upper Peninsula Power Company (UPPCO) is a regulated electric utility based in Marquette, Michigan, in the United States. It provides electric distribution and power supply service to about 52,000 retail customers across 10 counties in Michigan’s Upper Peninsula. Its service area spans roughly 4,460 square miles and is largely rural and forested. UPPCO was listed as a ransomware victim associated with lorenz. |
|||||
| Pontal Engineering Constructions and Developments Files Leak View Details _ | everest | Construction / Real Estate | |||
|
Pontal Engineering Constructions and Developments Files Leak refers to a security incident involving a firm in the Construction and Real Estate sector, with no confirmed location or specific offerings publicly detailed. The entity operates within infrastructure development and property construction, though its exact scope remains unverified in available sources. Ransomware.live reported on 2022-07-11 that the leak was claimed by the threat actor everest, with over 140 GB of data reportedly downloaded from the company's servers. The incident includes personal data of employees among the downloaded files, though no stolen-data types or breach confirmation are officially confirmed. It was listed as a ransomware victim associated with everest. |
|||||
| PSA View Details _ | blackbyte | Other | |||
|
PSA, short for Professional Sports Authenticator, operates in the collectibles sector and is headquartered in Southern California, with offices in New Jersey, Paris, Hong Kong, Shanghai, and Tokyo. The company is known for authentication and grading services for trading cards, sports autographs, and memorabilia, and it is part of Collectors Holdings. PSA serves a global customer base through its grading and verification operations. It was listed as a ransomware victim associated with BlackByte. |
|||||
| emprint.com View Details _ | lockbit3 | Communication / Marketing | |||
|
Emprint is a Louisiana-based communication and marketing services company, with roots in commercial printing and document management. Its website describes offerings that include print production, web-to-print, direct mail, kitting, fulfillment, promotional items, and cloud-based document management. Company listings place its headquarters in Lafayette, Louisiana, and identify related operations in Baton Rouge. It was listed as a ransomware victim associated with lockbit3. |
|||||
| acac.com View Details _ | lockbit3 | Other | |||
|
acac.com operates acac Fitness & Wellness Centers, a leading recreational fitness facility network headquartered in Charlottesville, Virginia, with locations across Virginia, Pennsylvania, and South Carolina. The company offers world-class fitness amenities including aquatics, spas, fitness classes, and family-friendly wellness programs. Its mission emphasizes medical-integrated fitness, inclusive programming, and community commitment. acac.com was listed as a ransomware victim associated with LockBit3. |
|||||
| OLYMPIA View Details _ | blackbasta | Other | |||
|
OLYMPIA appears to be a business identified in available company references as part of the broader Olympia group, an international investment and hospitality-related organization with operations across multiple countries. Public materials describe Olympia-related entities as active in hotel management, real estate, and diversified business services, with headquarters or primary operations in the United States. Its exact listing context in threat-intelligence records places it in the Other sector. It was listed as a ransomware victim associated with blackbasta. |
|||||
| lapostemobile.fr View Details _ | France | lockbit3 | Telecommunications | ||
|
La Poste Mobile is a French telecommunications operator based in France, with headquarters in Chaville and a consumer-facing website at lapostemobile.fr. It offers mobile plans, prepaid cards, and budget-friendly mobile phones and smartphones for individual customers. The brand presents itself as a major virtual mobile operator in France and supports sales and customer service online and by phone. It was listed as a ransomware victim associated with lockbit3. |
|||||
| stm-com-tw View Details _ | cuba | Other | |||
|
stm-com-tw refers to Sin Sheng Terminal and Machine Inc., a terminal and machine company based in Kaohsiung City, Taiwan, specializing in industrial terminal and machine solutions. The entity operates in the industrial sector, providing equipment and machinery services to local and regional markets. It is located at No. 301 Tandi Road, Gangshan District, Kaohsiung, and maintains direct contact via email and phone for business inquiries. The company was listed as a ransomware victim associated with the threat actor cuba, though no specifics on data theft or breach confirmation are publicly disclosed. |
|||||
| carnbrea.com.au View Details _ | Australia | lockbit3 | Other | ||
|
Carnbrea.com.au is the website of Carnbrea, a privately owned boutique wealth and investment advisory group based in Melbourne, Victoria, Australia. The firm says it provides financial and investment advice, including personalised financial planning and investment advisory services. Carnbrea serves clients from its Melbourne office on Collins Street. It was listed as a ransomware victim associated with lockbit3. |
|||||
| The Wiener Zeitung media group View Details _ | blackbasta | Communication / Marketing | |||
|
The Wiener Zeitung media group is an Austrian media house based in Vienna, operating at the intersection of public-information services, journalism, and content production. It publishes Wiener Zeitung (WZ), produces high-quality content, and supports Austria’s media sector through initiatives such as the Content Agentur Austria and Media Hub Austria. Its profile describes it as the media house of the Republic of Austria and a provider of information services. It was listed as a ransomware victim associated with blackbasta. |
|||||
| LOKALTOG View Details _ | blackbasta | Other | |||
|
LOKALTOG is a company in the Other sector, but the available sources do not provide a reliable public profile for its location or specific offerings. Black Basta is a ransomware-as-a-service group that uses double extortion, combining encryption with data-theft pressure on victims. The group has targeted organizations across multiple industries and countries, including the United States and several European markets. LOKALTOG was listed as a ransomware victim associated with blackbasta. |
|||||
| RENZEL View Details _ | blackbasta | Other | |||
|
RENZEL is an Other-sector organization whose public-facing business details are not clearly established in the available sources, so its offerings and location cannot be verified here. In threat-intelligence contexts, entities like RENZEL are cataloged by name and sector when public corporate information is limited or inconsistent. Black Basta is a Russia-linked ransomware group that emerged in 2022 and has targeted organizations across multiple industries and countries. RENZEL was listed as a ransomware victim associated with blackbasta. |
|||||
| LYDECKER View Details _ | blackbasta | Other | |||
|
LYDECKER is a leading national litigation law firm dedicated to providing strategic legal services with a focus on client satisfaction. The firm operates as a full-service, AV-rated national law firm with offices throughout New York, New Jersey, Pennsylvania, and Florida. Its diverse practice areas include insurance defense, professional liability, complex commercial litigation, and more. LYDECKER provides specialized legal services across various industries, ensuring clients receive strategic support. LYDECKER was listed as a ransomware victim associated with blackbasta. |
|||||
| Wipro HealthPlan Services View Details _ | blackbasta | Healthcare / Pharma | |||
|
Wipro HealthPlan Services is a Tampa, Florida-based healthcare and health insurance services provider that offers technology-enabled business process and claims management support. Wipro acquired HealthPlan Services in 2016, describing it as a leading technology and business-process-as-a-service provider in the U.S. health insurance market. Its services center on healthcare benefits administration, claims access, and related payer operations. It was listed as a ransomware victim associated with blackbasta. |
|||||
| OLYMPIATILE View Details _ | blackbasta | Other | |||
|
OLYMPIATILE, also known as Olympia Tile+Stone Inc., is a Canadian wholesale distributor of tile and stone products headquartered in Toronto, Ontario. Founded in 1927, it serves residential and commercial markets with porcelain, ceramic, glass, natural stone, and related tile accessories across North America. Public company profiles also note additional operations in Canada and the United States. It was listed as a ransomware victim associated with blackbasta. |
|||||
| MAIN View Details _ | blackbasta | Other | |||
|
MAIN is a company in the Other sector; public search results provided here do not identify its location, so no specific country or offering can be stated confidently. Based on the name alone, it cannot be reliably characterized beyond a generic business entity without risking inaccuracy. In threat-intelligence indexes, such entries are typically used to track organizations surfaced in ransomware reporting. MAIN was listed as a ransomware victim associated with blackbasta. |
|||||
| TMI View Details _ | blackbasta | Other | |||
|
TMI is listed as an Other-sector company, but publicly available search results here do not identify its location, core offerings, or operating profile with confidence. In threat-intelligence catalogs, such entries are typically used to index organizations named in ransomware leak-site or victim disclosures. Black Basta is a ransomware-as-a-service group known for double-extortion tactics and broad targeting across industries. TMI was listed as a ransomware victim associated with blackbasta. |
|||||
| Sierra Pacific Industries View Details _ | blackbasta | Other | |||
|
Sierra Pacific Industries is the second-largest lumber producer in the United States, headquartered in Anderson, California. As a fourth-generation, family-owned forest products company, it sustainably manages over 2.4 million acres of forestland across California, Washington, and Oregon. The company offers wood products including lumber, moldings, millwork, windows, doors, and house logs. Sierra Pacific Industries was listed as a ransomware victim associated with the BlackBasta threat actor. |
|||||
| DEKIMO View Details _ | blackbasta | Other | |||
|
DEKIMO is a Belgian electronics and software company headquartered in Watermael-Boitsfort, Brussels Region, with multiple sites across Belgium and nearby European markets. It describes itself as an independent electronics solution provider, serving customers through local presence and engineering services. Public business directories also place it in the electronics and software sector. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Jinny Beauty Supply View Details _ | blackbasta | Other | |||
|
Jinny Beauty Supply is a U.S. beauty-supply distributor headquartered in Doraville, Georgia, with distribution centers across the country. It offers a large selection of professional beauty products, multicultural and ethnic beauty supplies, and general merchandise through its wholesale network. The company says it operates seven distribution centers and serves customers through regional locations nationwide. Jinny Beauty Supply was listed as a ransomware victim associated with blackbasta. |
|||||
| Roche Bobois View Details _ | blackbasta | Other | |||
|
Roche Bobois is a French company that designs, retails, and distributes high-end furniture, including sofas, lighting, and decorative accessories. Founded in 1960, it serves an international market through showrooms and customised services. Its business is centered on contemporary design and premium home furnishings. It was listed as a ransomware victim associated with blackbasta. |
|||||
| LOSSEWERK View Details _ | blackbasta | Other | |||
|
LOSSEWERK refers to a waste-management and city-cleaning operation in Kassel, Germany, based at Am Lossewerk 15. The organization handles public sanitation, waste collection, and recycling-related services for the city. It operates in the Other sector and serves local municipal needs with customer service and recycling-hof functions. It was listed as a ransomware victim associated with blackbasta. |
|||||
| SCHMIDT Gruppe Service GmbH View Details _ | blackbasta | Other | |||
|
SCHMIDT Gruppe Service GmbH is a German service company in the broader other-business sector, based in Coesfeld, North Rhine-Westphalia, Germany. Public business directories describe it as part of the SCHMIDT Gruppe, a family-owned group that provides modern, high-quality services through related companies. Its listed activities include management support, business organisation, human resources, accounting, finance, IT, office, and operational services. It was listed as a ransomware victim associated with blackbasta. |
|||||
| JBKLDMN View Details _ | blackbasta | Other | |||
|
JBKLDMN is an organization in the Other sector, but the available sources do not provide a reliable public profile for its location, services, or offerings. Black Basta is a Russia-linked ransomware group that has targeted organizations across many sectors and countries, often using double-extortion tactics. Public threat reporting places Japan among the countries where Black Basta activity has affected victims. JBKLDMN was listed as a ransomware victim associated with blackbasta. |
|||||
| Gatewayrehab View Details _ | blackbyte | Other | |||
|
Gateway Rehab is a nonprofit addiction treatment network in western Pennsylvania, serving the Pittsburgh region and nearby communities such as Aliquippa, Washington, Wexford, and Greensburg. It offers inpatient, outpatient, telehealth, detox, and related substance use disorder services. The organization’s website lists multiple treatment locations across the Pittsburgh metro area, including its main campus in Aliquippa and outpatient sites in Pittsburgh and surrounding towns. Gatewayrehab was listed as a ransomware victim associated with blackbyte. |
|||||
| Lamoille Health View Details _ | blackbyte | Healthcare / Pharma | |||
|
Lamoille Health Partners is a Vermont healthcare organization based in Morrisville that provides comprehensive care for the Lamoille Valley. Its services include family medicine, pediatrics, behavioral health, dentistry, physical therapy, and express care for patients from newborns to seniors. The organization also operates practices in Stowe and Morrisville and describes its mission as delivering affordable, community-based healthcare. It was listed as a ransomware victim associated with blackbyte. |
|||||
| alpachem.com View Details _ | lockbit3 | Other | |||
|
alpachem.com is the website of Alpa S.p.A., an Italian chemical company founded in Milan in 1957 and based in Pregnana Milanese, Lombardy, Italy. It develops and produces chemical auxiliaries for the tanning industry, serving industrial customers in the leather sector. Company directories also classify it as a chemical manufacturer with operations in the Milan area. The site name appears in threat-intelligence records as a ransomware victim associated with lockbit3. |
|||||
| cabbageinc.com View Details _ | lockbit3 | Services | |||
|
Cabbage Inc. is a U.S.-based produce company in the services-linked agriculture supply chain, operating from Vermilion, Ohio. Its website says it farms in distributed locations across the Eastern United States and supplies year-round binned cabbage for the processing sector, with a broader carton grower-shipper product line. The company also states that it focuses on food safety and uses Good Agricultural Practices in its operations. It was listed as a ransomware victim associated with lockbit3. |
|||||
| DPP View Details _ | blackbasta | Other | |||
|
DPP is a London-based media industry business network operating internationally, providing media tech intelligence and business insight. Its services focus on helping leaders understand a fast-changing media and technology landscape. The company is part of the broader Other sector rather than a product manufacturer or retailer. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Pontal Engineering Constructions and Developments View Details _ | everest | Construction / Real Estate | |||
|
Pontal Engineering Constructions and Developments operates in the Construction and Real Estate sector, providing engineering and development services for building and land projects. While specific operational details are not publicly documented, the entity's name and sector indicate involvement in civil and structural engineering, program management, and construction management nationwide. The company was listed as a ransomware victim associated with the threat actor everest, reflecting its inclusion in threat-intelligence indexes tracking cyber incidents in the construction industry. |
|||||
| Wis-Pak, Inc View Details _ | lorenz | Services | |||
|
Wis-Pak, Inc. is a U.S.-based manufacturer and distributor of Pepsi-Cola products and other leading soft drinks. The company was founded to provide a centralized supply of canned soft drink products to Pepsi-Cola franchise bottlers. It is headquartered in Watertown, Wisconsin, and operates facilities in multiple Midwestern and Southern locations. Wis-Pak, Inc. was listed as a ransomware victim associated with lorenz. |
|||||
| Vectalia group View Details _ | vicesociety | Services | |||
|
Vectalia Group is a Spanish services company headquartered in Alicante, Spain. It operates a broad portfolio centered on urban and interurban mobility, including passenger transport, parking, and related operations. The group also provides facility services such as cleaning, security, maintenance, landscaping, and event support. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Yurtiçi Kargo View Details _ | Türkiye | hive | Other | ||
|
Yurtiçi Kargo is a Turkish cargo and logistics company founded in 1982 and based in Turkey. It operates nationwide parcel and freight services through regional directorates and transshipment centers, serving customers with delivery and transportation offerings. The company is widely described as Turkey’s first cargo brand and a leading logistics operator. It was listed as a ransomware victim associated with hive. |
|||||
| Hamlyns Limited View Details _ | United Kingdom | hive | Other | ||
|
Hamlyns Limited is a Woking, Surrey-based chartered accountancy firm that provides tailored accountancy, taxation, auditing, and business advisory services to clients in the UK. The company operates from Sundial House on High Street in Horsell and presents itself as an authorised training office for professional accountancy bodies. Its services position it in the broader business services category rather than a manufacturing or retail sector. It was listed as a ransomware victim associated with hive. |
|||||
| DIRECTFERRIES View Details _ | United Kingdom | hive | Other | ||
|
DIRECTFERRIES is a UK-based ferry travel platform that compares and books ferry crossings across Europe, Africa, and other global routes. Founded in 1999, it offers ferry tickets through a multi-platform service and also provides related travel products such as accommodation, train tickets, and vehicle breakdown cover. Companies House lists Direct Ferries Limited as an active company with a registered office in Ipswich, England. It was listed as a ransomware victim associated with hive. |
|||||
| MHIRE View Details _ | hive | Other | |||
|
MHIRE is an Other-sector organization in the United States; publicly available details about its offerings are limited in the provided sources. The name is used here as a catalog entry for a company rather than a confirmed incident report. Hive was a ransomware-as-a-service operation active from 2021 to 2023 and associated with double-extortion tactics. MHIRE was listed as a ransomware victim associated with hive. |
|||||
| CAN.COM View Details _ | Netherlands | hive | Other | ||
|
CAN.COM is a Netherlands-based business listed in the “Other” sector, indicating it does not fall into a standard industry category in the index. Publicly available source material does not provide a reliable description of its offerings, so it should be treated conservatively as a corporate entity in the Netherlands. In threat-intelligence context, the entry identifies CAN.COM as a ransomware victim. It was listed as a ransomware victim associated with hive. |
|||||
| AUM View Details _ | hive | Other | |||
|
AUM is a U.S.-based financial services firm in the asset-management sector, where AUM commonly means assets under management, the market value of investments overseen for clients. Firms in this sector manage capital on behalf of investors and institutions, often reporting AUM as a core measure of scale and activity. In New York, the business profile fits an investment-management organization serving clients through portfolio oversight and related financial services. It was listed as a ransomware victim associated with hive. |
|||||
| KDE View Details _ | United Kingdom | hive | Other | ||
|
KDE is an international free software community that develops free software and provides tools enabling digital control and privacy. Operating as a global hub, it offers desktop systems and resources for desktop and portable computing. The community is based internationally with significant presence in the GB region, supporting volunteers who create open-source solutions. KDE was listed as a ransomware victim associated with the threat actor hive. |
|||||
| YURTICIKARGO View Details _ | hive | Other | |||
|
YURTICIKARGO is a Turkish logistics and cargo company operating in the transport and delivery sector. It provides parcel and freight services across Turkey through a nationwide distribution and delivery network, serving businesses and individual customers. In threat-intelligence tracking, the company appears in the broader “other” sector classification because public sources focus on the victim listing rather than detailed corporate profiling. It was listed as a ransomware victim associated with hive. |
|||||
| Massy Distribution Limited View Details _ | Jamaica | hive | Other | ||
|
Massy Distribution Limited is a Jamaican distributor and importer focused on pharmaceutical and consumer products, serving the local market from Jamaica. The company’s business centers on moving branded goods and everyday essentials through distribution channels, reflecting a broader role in the country’s commercial supply chain. In threat-intelligence records, Massy Distribution Limited was listed as a ransomware victim associated with Hive. |
|||||
| WWSTEELE View Details _ | United States | hive | Manufacturing / Engineering | ||
|
WWSTEELE is a Manufacturing and Engineering company based in the United States, specializing in steel fabrication and industrial solutions. The firm operates production facilities with advanced capabilities and technologies to serve diverse market needs. Its offerings include steel work platforms, mezzanines, and custom metalworking services for industrial clients. WWSTEELE was listed as a ransomware victim associated with the hive threat actor. |
|||||
| NETWORK4CARS View Details _ | Netherlands | hive | Telecommunications | ||
|
NETWORK4CARS Trading B.V. is based in Nieuw-Vennep, the Netherlands, and operates from Schillingweg 105 with headquarters in the Dutch market. Public company pages describe its business as a wholesale car dealer that sells new and young used cars and manages the process for customers. Its operations extend across Europe and into Asia, the Middle East, the Americas, and North Africa. It was listed as a ransomware victim associated with hive. |
|||||
| CAPSONIC View Details _ | blackbasta | Other | |||
|
CAPSONIC is a manufacturing company based in Elgin, Illinois, with additional facilities in Auburn Hills, Michigan; El Paso, Texas; and Juarez, Mexico. The company specializes in customized insert molding and electromechanical assemblies for automotive, aerospace, and military customers. Founded in 1968, it is known for producing complex parts and assemblies for industrial supply chains. It was listed as a ransomware victim associated with blackbasta. |
|||||
| V2 Logistics Corp View Details _ | blackbasta | Transportation / Travel / Logistics | |||
|
V2 Logistics Corp is a privately held logistics services company headquartered in Bethpage, New York. Public business listings describe it as providing domestic and international logistics, transportation management, supply chain support, and freight services across multiple industries. The company also appears in carrier records as a transportation operator. In threat-intelligence contexts, V2 Logistics Corp was listed as a ransomware victim associated with blackbasta. |
|||||
| AG View Details _ | hive | Other | |||
|
AG is a U.S.-based company classified in the Other sector. Public web results do not provide enough reliable detail to confirm its specific location or core offerings, so its business profile should be treated conservatively. In threat-intelligence cataloging, AG is referenced as an organization rather than a product or service brand. It was listed as a ransomware victim associated with hive. |
|||||
| bosco-avocats.com View Details _ | lockbit3 | Other | |||
|
Bosco Avocats is a French law firm in the legal sector, based in Paris with offices in Lyon and Marseille. Its website says the firm offers legal services in areas including international arbitration, mediation, and business dispute resolution. Company listings also place its main office at 60 rue de Londres in Paris. It was listed as a ransomware victim associated with lockbit3. |
|||||
| faacgroup.com View Details _ | lockbit3 | Services | |||
|
faacgroup.com belongs to FAAC Group, an Italian services and industrial automation company headquartered in Zola Predosa, near Bologna, Italy. The group develops access automation, parking, and pedestrian and vehicle control solutions for residential, commercial, and industrial use. Its portfolio also covers software and hardware for mobility, access management, and related technical services. It was listed as a ransomware victim associated with lockbit3. |
|||||
| lesbureauxdelepargne.com View Details _ | lockbit3 | Other | |||
|
lesbureauxdelepargne.com appears to be a French financial-services website, as its name suggests a business focused on savings and personal finance. Based on the available evidence, its precise offerings and operating location are not clearly established from public search results. The domain is cataloged in a threat-intelligence context under the broad sector label Other, reflecting limited public business detail. It was listed as a ransomware victim associated with lockbit3. |
|||||
| plravocats.fr View Details _ | France | lockbit3 | Other | ||
|
PLR Avocats is a Paris-based law firm specializing in business law, criminal defense, and RGPD compliance, founded in 2009. The firm serves audacious entrepreneurs with expertise in business law, criminal matters, and data protection, including DPO externalization. Headquartered at 38 Avenue Hoche in Paris, 75008, FR, it offers services in business law, criminal defense, and title transactions. PLR Avocats was listed as a ransomware victim associated with LockBit3. |
|||||
| slpcolombus.com View Details _ | lockbit3 | Other | |||
|
slpcolombus.com appears to be a company website associated with the name SLP Colombus and is categorized here as sector: Other, with no reliable public source in the provided results confirming its exact services or location. Based on the domain alone, it should be treated as an organization-specific web presence rather than a defined industry brand, and no further operational details can be stated without verification. In threat-intelligence indexing, the domain is recorded as a ransomware victim entry. It was listed as a ransomware victim associated with lockbit3. |
|||||
| axelcium.com View Details _ | lockbit3 | Other | |||
|
Axelcium is a consulting firm based in Paris, France, that focuses on transaction advisory services, financial engineering, and regulation for infrastructure projects. Its work covers transport, environment, energy, and public facilities, including PPP and PFI arrangements, regulatory modelling, risk analysis, and fund-raising. Public business directories describe it as a small professional services company operating in the infrastructure advisory niche. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Shorr.com leakage View Details _ | yanluowang | Other | |||
|
Shorr.com leakage refers to a data exposure incident involving Shorr.com, an entity operating in the Other sector with no publicly specified geographic location or core offerings. The incident is categorized under ransomware-related data leaks, though specific details about stolen data types or record counts remain undisclosed. It was listed as a ransomware victim associated with the yanluowang threat actor, which has been active since late 2021 and targets various sectors globally. No official confirmation or breach notification from Shorr.com itself has been publicly documented regarding this incident. |
|||||
| Greetings to havi.com and tmsw.com View Details _ | yanluowang | Other | |||
|
Greetings to havi.com and tmsw.com appears in ransomware intelligence records as a listed victim name tied to a Yanluowang claim. HAVI is a U.S.-based supply chain and logistics company that provides services in packaging, sourcing, logistics, and related business operations, while tmsw.com references TMSW-related web presence associated with the same listing. The catalog entry reflects a threat-intelligence designation rather than a verified public breach disclosure. It was listed as a ransomware victim associated with yanluowang. |
|||||
| Big data dump from various organizations View Details _ | yanluowang | NGOs / Associations | |||
|
Big data dump from various organizations is listed in the NGOs and associations sector in the United States, indicating an organization profile associated with nonprofit- or membership-based activity. Its name suggests a broad data-aggregation or records-related entity, but no verified public details in the provided sources identify its exact offerings or operational footprint. In threat-intelligence catalogs, it is treated as an incident entry rather than a confirmed statement of compromise. It was listed as a ransomware victim associated with yanluowang. |
|||||
| Walmart was encrypted View Details _ | yanluowang | Retail / E-commerce | |||
|
Walmart is a U.S.-based retail and e-commerce company that operates large-scale stores, grocery and general merchandise services, and online shopping for consumers in the United States and internationally. Its business spans physical retail, omnichannel fulfillment, and digital commerce for household goods, food, and everyday essentials. In ransomware tracking, Walmart was identified in connection with Yanluowang reporting, and Walmart publicly rejected the attack claim. The listing records it neutrally as a ransomware victim associated with yanluowang. |
|||||
| Cincinnati bell didn’t pay the ransom View Details _ | yanluowang | Services | |||
|
Cincinnati Bell Inc., doing business as altafiber, is a regional telecommunications and communications services provider based in Cincinnati, Ohio, in the United States. Its offerings include fiber internet, TV, home phone, voice, data, and related managed IT services. The company serves customers in the Greater Cincinnati area and also operates in Hawaii. In threat-intelligence cataloging, Cincinnati Bell didn’t pay the ransom was listed as a ransomware victim associated with Yanluowang. |
|||||
| Rocky View Details _ | hive | Other | |||
|
Rocky is an entity operating within the Other sector, with no specific location or defined offerings publicly documented beyond its sector classification. As part of the broader landscape of organizations facing cyber threats, Rocky's operational scope remains general due to the lack of detailed sector-specific data. The entity was listed as a ransomware victim associated with the threat actor hive, marking its inclusion in recent ransomware victim reports published by threat actors on public data leak sites. This listing reflects the growing trend of businesses falling victim to ransomware attacks, where recovery costs and downtime present significant financial and reputational harm. Rocky's case underscores the under-reported physiological and physical harms experienced by staff in victim organizations during such incidents. |
|||||
| sigma-alimentos.com View Details _ | lockbit3 | Other | |||
|
Sigma Alimentos is a Mexican multinational food company headquartered in San Pedro, near Monterrey, Nuevo León, Mexico. It produces and distributes branded foods, including cold cuts, cured meats, dairy products, and other packaged foods, with operations across the Americas and Europe. Public company materials describe a broad production and distribution network serving regional markets. The entity was listed as a ransomware victim associated with lockbit3. |
|||||
| Amalfitana Gas Srl View Details _ | everest | Energy | |||
|
Amalfitana Gas Srl is an Italian energy company based in Salerno, Campania, that has operated since 1989 in the design, construction, and management of natural gas distribution networks. Its business focuses on concession-based gas infrastructure and related network operations in the local market. Public company profiles describe it as a longstanding gas distribution operator in southern Italy. It was listed as a ransomware victim associated with everest. |
|||||
| An International Shipping Company - Unpay View Details _ | cheers | Transportation / Travel / Logistics | |||
|
An International Shipping Company - Unpay operates in the Transportation, Travel, and Logistics sector, managing the movement of goods across trucking, rail, ocean, and air networks. The company provides end-to-end freight lifecycle services including planning, execution, tracking, communication, and exception management. It functions as a transportation provider that moves freight, manages carriers, and coordinates modes to support global supply chain operations. An International Shipping Company - Unpay was listed as a ransomware victim associated with the threat actor cheers. |
|||||
| Atlantic Dialysis Management Services View Details _ | United States | snatch | Services | ||
|
Atlantic Dialysis Management Services is a US services company based in College Point, New York. It provides dialysis site development, day-to-day administration, and management of dialysis services, including in-center, acute, and at-home hemodialysis care. The company also operates multiple dialysis locations across New York, supporting patients, clinics, and staff with dialysis-related services. It was listed as a ransomware victim associated with Snatch. |
|||||
| https:// View Details _ | cheers | Other | |||
|
Dynam Japan Holdings Co., Ltd is a Japanese company operating in the Other sector, primarily engaged in investment and financial services with no specific geographic location beyond Japan. The firm offers diversified investment solutions and financial management services to clients across the country. It was listed as a ransomware victim associated with the Cheers threat actor, which targets VMware ESXi servers using Linux-based malware. The incident involved double-extortion tactics without confirmed data theft or record counts. No official breach notification date from the company itself has been publicly disclosed. |
|||||
| diodes.com View Details _ | lockbit3 | Other | |||
|
Diodes Incorporated is a U.S.-based global manufacturer and supplier of application-specific standard products in the analog, discrete, power, logic, and mixed-signal semiconductor markets. The company is headquartered in Plano, Texas, and serves consumer electronics, computing, communications, industrial, and automotive customers. Its portfolio includes advanced analog and power semiconductor solutions used to support input protection, power management, gate drive, MOSFETs, and signal conditioning. The entity was listed as a ransomware victim associated with lockbit3. |
|||||
| Crupi Group View Details _ | Canada | quantum | Manufacturing / Engineering | ||
|
Crupi Group is a Toronto-based Canadian construction company serving the Greater Toronto Area and surrounding communities. Its business centers on road construction, aggregate supply, asphalt paving, concrete work, and large-scale snow removal services. The company presents itself as an industry leader with operations focused on infrastructure and materials for developers and municipalities. It was listed as a ransomware victim associated with quantum. |
|||||
| Apex View Details _ | Bermuda | snatch | Healthcare / Pharma | ||
|
apexnc.org is the official website of the Town of Apex, North Carolina, which serves residents with municipal information, services, news, and public notices. The site’s published materials include town agendas, resident services, and local event listings, indicating a public-sector community services portal rather than a healthcare provider. The listing metadata tags it to the Healthcare / Pharma sector and country code BM, which should be treated as catalog classification rather than a verified operating location. It was listed as a ransomware victim associated with snatch. |
|||||
| Avante Health Solutions View Details _ | United States | quantum | Healthcare / Pharma | ||
|
Avante Health Solutions is a United States-based medical equipment manufacturing company dedicated to improving patient care worldwide by providing quality and value-based medical equipment to healthcare facilities globally. As a single-source provider, the company offers sales, service, repair, parts, and technical support for medical, surgical, diagnostic imaging, and ultrasound equipment including MRI, Cat, and Cathangio modalities. Avante partners with customers from consultation and installation through ongoing technical support to keep equipment running efficiently without disruption to patient care. The organization was listed as a ransomware victim associated with the quantum threat actor. |
|||||
| New Peoples Bank View Details _ | blackbasta | Finance / Legal / Insurance | |||
|
New Peoples Bank is a full-service financial institution headquartered in Honaker, Virginia, with branches across Virginia, West Virginia, Tennessee, and North Carolina. The bank offers tailored loans, savings and checking accounts, money management tools, and merchant services for personal and business customers in the Finance sector. It operates as a community bank dedicated to providing quality banking services to customers in the VA, WV, TN, and NC regions. New Peoples Bank was listed as a ransomware victim associated with the threat actor blackbasta. |
|||||
| metroappliancesandmore.com View Details _ | lockbit3 | Other | |||
|
Metro Appliances & More is a U.S. appliance retailer that sells kitchen, laundry, outdoor, and home appliances through showrooms across Arkansas, Missouri, Oklahoma, and Kansas. Its website highlights brands, local deals, expert service, financing options, and in-store showroom locations, with headquarters in Tulsa, Oklahoma. The company was listed as a ransomware victim associated with LockBit3. |
|||||
| lonseal.com View Details _ | lockbit3 | Other | |||
|
Lonseal, Inc. is a Carson, California-based manufacturer of resilient sheet vinyl flooring, with a corporate sales office in Torrance and stocked products in Carson. The company markets flooring for commercial uses including healthcare, assisted living, corporate spaces, and aviation, and says it is the sole distributor of Lonseal-branded flooring outside Japan. The site reflects a U.S. materials and building-products business serving multiple industrial and commercial applications. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Sembcorp Marine - Unpay View Details _ | cheers | Services | |||
|
Sembcorp Marine is a Singapore-based services company in the offshore and marine industry, known for shipbuilding, rig construction, repair, and related engineering work. It has been positioned around offshore renewables, new energy, and cleaner solutions as the sector has evolved. The company operates from Singapore and serves maritime and energy customers across complex industrial projects. Sembcorp Marine - Unpay was listed as a ransomware victim associated with cheers. |
|||||
| SuperAlloy Industrial Co., Ltd. View Details _ | United Kingdom | hive | Manufacturing / Engineering | ||
|
SuperAlloy Industrial Co., Ltd. is an international manufacturing and engineering company headquartered in Douliu, Taiwan, that specializes in engineering and producing lightweight metal forging solutions primarily for the automotive industry. The company offers forged aluminum wheels for luxury and sports automobiles alongside lightweight suspension components, operating facilities in Taiwan, the United States, the United Kingdom, Germany, and other global regions. While the entity is known for its high-end custom forging solutions for mobility and aerospace sectors, it was neutrally listed as a ransomware victim associated with the threat actor hive. |
|||||
| Diskriter View Details _ | United States | hive | Other | ||
|
Diskriter is a US-based organization operating within the Other sector, with no specific public offerings detailed beyond its general sector classification. As an entity in the United States, it represents the broad range of targets affected by sophisticated cyber threats like ransomware. Diskriter was neutrally listed as a ransomware victim associated with the Hive threat actor, underscoring the group's extensive targeting of over 1,500 victims worldwide since 2021. This listing reflects the double-extortion tactics of Hive, which exfiltrate data before encrypting systems to demand ransom. The incident aligns with Hive's pattern of targeting diverse sectors, including healthcare, government, and critical infrastructure, without limiting impact to specific industries. |
|||||
| datalit.it View Details _ | Italy | lockbit2 | Other | ||
|
datalit.it is an Italy-based company focused on cybersecurity, industrial networks, and information security services. Its website describes offerings designed to protect digital business operations through advanced security solutions and industrial network support. The firm operates in the broader technology and security services space in Italy, with a stated emphasis on safeguarding connected environments and business infrastructure. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Ministry of Agriculture Rebublic Indonesia View Details _ | Indonesia | vicesociety | Agriculture / Food | ||
|
Ministry of Agriculture Republic of Indonesia is Indonesia’s government ministry for agriculture, overseeing agricultural development, policy administration, and regulation of agricultural commodities. Based in Indonesia, it works to support farm production, rural jobs, and safe, healthy food products. Public descriptions also note programs and publications related to the agricultural sector. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Bonneville Collections View Details _ | lorenz | Other | |||
|
Bonneville Collections is a debt collection company based in South Ogden, Utah, with additional offices in Idaho, Boise, and Vancouver, Washington. Its website says it provides collection services and walk-in payment options for clients, and it has served medical professionals since 1980. Public business listings also identify it as a collections agency operating from its Ogden-area headquarters. Bonneville Collections was listed as a ransomware victim associated with lorenz. |
|||||
| r1group View Details _ | cuba | Services | |||
|
r1group is a Services-sector organization in the United States, operating in a business environment commonly targeted by ransomware groups for extortion and disruption. Publicly available records do not provide enough reliable detail here to confirm its exact offerings or corporate footprint. In threat-intelligence indexes, the company appears as a named victim entry for monitoring and correlation purposes. It was listed as a ransomware victim associated with cuba. |
|||||
| Medical University of Innsbruck View Details _ | vicesociety | Healthcare / Pharma | |||
|
Medical University of Innsbruck is a public medical university in Innsbruck, Austria, organized across medical-theoretical, clinical, and administrative units. It provides medical education and training and supports research in fields including oncology, neurosciences, infectiology, immunology, and transplant medicine. As a healthcare institution, it is part of Austria’s medical and academic sector and serves teaching, research, and clinical collaboration. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Napa Valley College View Details _ | blackbyte | Education | |||
|
Napa Valley College is a public community college in Napa, California, serving students in the Education sector. It is located just south of downtown Napa and offers more than 100 degree and certificate programs, including transfer pathways to the University of California and California State University systems. The college also provides continuing education and workforce-focused training through community and career education programs. It was listed as a ransomware victim associated with blackbyte. |
|||||
| Elbit Systems of America View Details _ | blackbasta | Services | |||
|
Elbit Systems of America is a U.S.-based services-sector company headquartered in Fort Worth, Texas. It provides high-performance products and system solutions for defense, homeland security, commercial aviation, and medical instrumentation markets. The company operates from multiple U.S. locations, including Texas, New Hampshire, Alabama, and Virginia. It was listed as a ransomware victim associated with blackbasta. |
|||||
| oak-brook.org View Details _ | lockbit2 | Other | |||
|
oak-brook.org is the official website of the Village of Oak Brook, Illinois, a suburban community about 15 miles west of Chicago. The site provides municipal information and services for residents, businesses, and visitors, including government news, events, permits, development, finance, and community resources. Oak Brook’s government also publishes local planning, zoning, and engineering functions through the site. The domain was listed as a ransomware victim associated with lockbit2. |
|||||
| New Leak: Prudential LTG. View Details _ | ragnarlocker | Communication / Marketing | |||
|
New Leak: Prudential LTG appears to refer to a Prudential-related entity in the Communication / Marketing sector, identified in threat-intelligence listings as a U.S.-based target name. In this context, it is used as an index entry for a business listing tied to public cyber-risk tracking, not as a description of a confirmed breach narrative. Public records in the supplied results do not clearly establish a first-party company profile for this exact name, so no additional offerings or location details are stated here. It was listed as a ransomware victim associated with ragnarlocker. |
|||||
| New Leak: Northern Data Systems View Details _ | ragnarlocker | Services | |||
|
New Leak: Northern Data Systems is a Services-sector software and IT provider headquartered in Falmouth, Maine. The company develops software and support services for utilities, credit unions, local governments, municipalities, and healthcare organizations, including utility billing and customer service systems. Its offerings also include managed IT, network, and security-related support for client operations. It was listed as a ransomware victim associated with ragnarlocker. |
|||||
| Alphapointe View Details _ | United States | hive | Other | ||
|
Alphapointe is a US-based nonprofit organization headquartered in Kansas City, Missouri, that serves people who are blind or visually impaired. It provides vision rehabilitation, career training, employment services, education, and advocacy, and it has supported people with vision loss since 1911. The organization also operates from a second location in Richmond Hill, New York. Alphapointe was listed as a ransomware victim associated with hive. |
|||||
| FAYAT View Details _ | everest | Other | |||
|
FAYAT is a French family-owned industrial group headquartered in Bordeaux, France, and active in construction, civil engineering, and road equipment manufacturing. It operates through multiple autonomous companies across sectors including public works, foundations, building, energy services, steel, road equipment, and pressure vessels. Public reporting also describes FAYAT Group as a producer of road equipment and notes an expansion of its U.S. operations in Ridgeway, South Carolina. In this threat-intelligence index, FAYAT was listed as a ransomware victim associated with everest. |
|||||
| Arte Radiotelevisivo Argentino (Artear) View Details _ | Argentina | hive | Other | ||
|
Arte Radiotelevisivo Argentino (Artear) is an Argentine media company based in Buenos Aires that creates and distributes television content across its platforms. Its corporate site says it produces quality content for multiple audiences, and company profiles identify it as a radio and television operator. Artear was listed as a ransomware victim associated with hive. |
|||||
| BAHRA ELECTRIC - HACKED AND MORE THEN 800 GB DATA LEAKED View Details _ | lv | Other | |||
|
Bahra Electric is a Saudi Arabian electrical manufacturing company based in Bahrah near Jeddah, with operations in Makkah Province and regional offices in the Gulf. Its product range includes wires and cables, transformers, busways, copper busbars and rods, aluminum rods, earthing and lightning protection systems, and wiring devices. The company operates large manufacturing space in Bahra Industrial City and serves the energy and construction supply chain. It was listed as a ransomware victim associated with lv. |
|||||
| PT Astra Honda Motor View Details _ | vicesociety | Other | |||
|
PT Astra Honda Motor is an Indonesian motorcycle manufacturer and distributor headquartered in Jakarta, Indonesia. It is the local Honda motorcycle company and operates large-scale production and sales for the Indonesian market, with facilities and employees supporting national distribution. In corporate profiles, the company describes itself as Indonesia’s largest motorcycle manufacturing and distribution business. PT Astra Honda Motor was listed as a ransomware victim associated with vicesociety. |
|||||
| Pilton Community College View Details _ | vicesociety | Education | |||
|
Pilton Community College is an education-sector, 11-16 mixed comprehensive school in Barnstaple, Devon, England. It serves secondary-age students and provides a student-centred school education from its Chaddiford Lane campus. The school’s public listings place it in the South West region and identify it as part of the local schooling network. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Canaropa View Details _ | Canada | blackbasta | Other | ||
|
Canaropa is a Canadian company based in Montreal, Quebec, that manufactures, imports, and distributes commercial, residential, and architectural door hardware. Founded in 1954, it serves door hardware professionals, developers, architects, and related building-materials buyers across Canada. Its product line centers on quality locks and hardware used in construction and property projects. It was listed as a ransomware victim associated with BlackBasta. |
|||||
| Mechanical Systems Company View Details _ | United States | blackbasta | Services | ||
|
MS Companies is a U.S.-based services company headquartered in Carmel, Indiana, that provides workforce and quality support for manufacturers. Its offerings include advisory and consulting, quality representation, inspection and containment, talent management, and data-driven quality infrastructure services. The company says it helps manufacturers build data and quality systems to identify patterns and implement fixes. It was listed as a ransomware victim associated with Black Basta. |
|||||
| Crane Carrier Company View Details _ | blackbasta | Services | |||
|
Crane Carrier Company is a manufacturer specializing in construction truck and garbage truck chassis, based in New Philadelphia, Ohio, with 75 years of commercial vehicle production. The company produces purpose-built, heavy-duty Class 7 and 8 trucks featuring diesel, compressed natural gas, hybrid, and electric fueling systems. It leads in custom-built specialty vehicles including refuse collection trucks and mobile drill-rig chassis. Crane Carrier Company was listed as a ransomware victim associated with the threat actor blackbasta. |
|||||
| PARADOX View Details _ | blackbasta | Other | |||
|
PARADOX is an entity operating within the Other sector, with no specific geographic location or defined product offerings publicly documented. As a general designation, it lacks a distinct operational profile beyond its classification in threat intelligence records. The entity was listed as a ransomware victim associated with the Black Basta cybercrime cartel, which targets diverse industries globally using double-extortion tactics. Black Basta, emerging in April 2022, operates a Ransomware-as-a-Service model and has compromised over 500 organizations worldwide. This listing reflects PARADOX's inclusion among victims publicly named by Black Basta on its leak site. |
|||||
| GRUPO mh View Details _ | Spain | blackbasta | Other | ||
|
grupmh.com appears to be a Spanish business in the broad Other sector, but the available public record does not clearly identify its exact line of work. Based on the name alone, it can only be described conservatively as a company operating from Spain, without adding unverified details about products or services. In threat-intelligence catalogs, it is indexed as a ransomware victim entry tied to BlackBasta. The listing notes it as a ransomware victim associated with blackbasta. |
|||||
| ecos-office.com View Details _ | lockbit2 | Other | |||
|
ecos-office.com appears to be the online presence of Ecos Workspaces, a Germany-based office and workspace provider. Publicly available company information describes it as offering private offices and flexible workspace solutions across multiple German locations, including Frankfurt-Eschborn, with a team serving customers in the office-services sector. As a business-services provider, it fits the broader “Other” sector classification used in threat-intelligence listings. It was listed as a ransomware victim associated with lockbit2. |
|||||
| coteg-azam.fr View Details _ | France | lockbit2 | Other | ||
|
coteg-azam.fr corresponds to COTEG & AZAM Associés, a Toulouse-based French business law firm. The firm provides multidisciplinary legal services in advice and litigation for companies and their leaders. Public profiles describe practice areas such as business creation, corporate follow-up, contracts, acquisitions, and disputes. In this index, the domain was listed as a ransomware victim associated with lockbit2. |
|||||
| Ospedale Macedonio Melloni View Details _ | vicesociety | Other | |||
|
Ospedale Macedonio Melloni is a hospital in Milan, Italy, operated within the ASST Fatebenefratelli Sacco network and located at Via Macedonio Melloni 52. It provides hospital services and specialist outpatient care, with departments and clinical activities listed on its official site. The facility is part of the broader public healthcare system in Lombardy and serves patients in the Milan area. It was listed as a ransomware victim associated with vicesociety. |
|||||
| sigma-alimentos... View Details _ | lockbit2 | Other | |||
|
Sigma Alimentos is a multinational food company headquartered in Nuevo León, Mexico, specializing in cold cuts, cured meats, dairy products, and other branded foods. The company operates across 17 countries, delivering quality local favorite foods to communities in Mexico, Europe, the U.S., and Latin America. Its purpose is to provide delicious food for a better life, with a global presence that includes plants, distributors, and offices worldwide. Sigma Alimentos was listed as a ransomware victim associated with the threat actor LockBit2. |
|||||
| farmaciacirici.... View Details _ | lockbit2 | Agriculture / Food | |||
|
farmaciacirici.... is an Italy-based business in the Agriculture / Food sector, a field that spans food production, processing, and related supply-chain activities. Companies in this sector often serve local and regional markets through agricultural goods, food products, or related commercial services. In threat-intelligence catalogs, the entity is identified for monitoring under a ransomware-victim listing. It was listed as a ransomware victim associated with lockbit2. |
|||||
| agricolaandrea.... View Details _ | lockbit2 | Agriculture / Food | |||
|
Agrícola Andrea S.A.C. is a Peruvian agriculture company headquartered in Lima, Peru, and operates in agricultural processing and fruit and tree nut farming. Company profiles also place it in farming, with a website at agricolaandrea.com and a workforce of roughly 501-1,000 employees. Its public materials emphasize sustainable agricultural management and Global GAP certification. It was listed as a ransomware victim associated with LockBit2. |
|||||
| business.gov.om View Details _ | lockbit2 | Services | |||
|
business.gov.om is Oman’s government business-services portal for the Sultanate of Oman, operated under the Ministry of Commerce, Industry and Investment Promotion. It serves as a one-stop digital gateway for investors and businesses, offering e-services for company setup, licensing, and ongoing business administration. The platform supports commercial registration and related government transactions online. It was listed as a ransomware victim associated with lockbit2. |
|||||
| builditinc.com View Details _ | lockbit2 | Services | |||
|
Build-It Construction is a Plaistow, New Hampshire-based builder and remodeler in the services sector, offering residential, commercial, and sustainable construction projects. Its website says the firm handles custom designs, architectural and interior design, remodeling, new construction, and outdoor living work. The company also lists a local office at 73 Newton Rd. in Plaistow, NH. It was listed as a ransomware victim associated with lockbit2. |
|||||
| rhenus.group View Details _ | lockbit2 | Services | |||
|
Rhenus Group is a Germany-based international logistics provider in the services sector, headquartered in Holzwickede near Dortmund. It offers transport logistics, warehousing, supply chain solutions, contract logistics, freight logistics, port logistics, and related value-added services across a global network. The company operates from more than 1,100 locations worldwide and serves customers in multiple regions. It was listed as a ransomware victim associated with lockbit2. |
|||||
| kuwaitairways.c... View Details _ | lockbit2 | Other | |||
|
Kuwait Airways Corporation KSC is the national carrier of Kuwait, headquartered in Kuwait City, operating scheduled international flights across the Middle East, Indian subcontinent, Europe, Southeast Asia, and North America. The airline, wholly owned by the Kuwaiti government as of August 2023, offers competitive air travel services to key global trade destinations. It serves thousands of employees and provides customer relations support for flight delays, cancellations, and fare notifications. Kuwait Airways Corporation KSC was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| plagepalace.com View Details _ | lockbit2 | Other | |||
|
Plage Palace is a luxury 5-star hotel in the hospitality sector, located at 336 Avenue de Saint-Maurice in Palavas-les-Flots, Hérault, France, near Montpellier on the Mediterranean coast. Its official site describes a seaside property with a restaurant, spa, and private beach, serving guests seeking leisure and accommodation. Public directory listings also identify it as a hotel business in southern France. It was listed as a ransomware victim associated with lockbit2. |
|||||
| emprint.com View Details _ | lockbit2 | Communication / Marketing | |||
|
Emprint is a technology-driven document and process-management company headquartered in Lafayette, Louisiana, originally founded as a print shop over 130 years ago. The firm offers tailored document and printing solutions including offset and digital printing, bindery, finishing, direct mail, kitting, fulfillment, promotional items, and cloud-based document management systems. With customers in virtually every U.S. state, Emprint is widely recognized for its innovation and diverse array of printing and document services. The company was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| acac.com View Details _ | lockbit2 | Other | |||
|
acac.com is the website for acac Fitness & Wellness, a U.S.-based fitness and wellness club operator with locations in Virginia, Pennsylvania, and South Carolina. Its offerings include gym access, group exercise, aquatics, personal training, spa services, and family-focused wellness amenities. The company presents itself as a member-based wellness provider with club locations and online account services. It was listed as a ransomware victim associated with lockbit2. |
|||||
| optoma View Details _ | lockbit2 | Other | |||
|
Optoma is a visual display technology company that develops and sells projectors, interactive flat panels, LED displays, screens, and related image-processing solutions. It serves customers in education, corporate, home entertainment, retail, museums, simulation, and large-venue environments, and its European headquarters is in Hertfordshire, United Kingdom. Public company profiles also describe Optoma as a multinational supplier with regional operations across North America, Europe, Asia-Pacific, and China. It was listed as a ransomware victim associated with lockbit2. |
|||||
| vectorinf.com.b... View Details _ | lockbit2 | Other | |||
|
vectorinf.com.b... appears to be an Other-sector organization with a web-based business presence, but public source data in this listing does not identify its exact location or offerings. The domain format suggests a company or service branded under the VectorInf name, yet the available record is too limited to confirm its country, industry niche, or operational profile. In threat-intelligence catalogs, such entries are commonly indexed as organizational victims when only a domain-level identifier is available. It was listed as a ransomware victim associated with lockbit2. |
|||||
| tb-kawashima.co... View Details _ | lockbit2 | Other | |||
|
TB Kawashima Co., Ltd. is a Japan-based company in Echi District, Shiga, and its website describes it as AUNDE Boshoku Co., Ltd., a comprehensive interior material manufacturer and total supplier of interior fabrics. The company serves automotive interior markets and operates as part of the Kawashima/AUNDE Boshoku corporate group. It was listed as a ransomware victim associated with lockbit2. |
|||||
| lundinroof.com View Details _ | lockbit2 | Other | |||
|
Lundinroof.com is the website of Lundin Roofing Company, LLC, a construction business based in Port Allen, Louisiana. The company says it has served Louisiana for more than 45 years and offers commercial roofing services, including single-ply, spray polyurethane, metal, and SBS roofing. Its contact details and office address indicate a local contractor serving businesses from Port Allen. It was listed as a ransomware victim associated with lockbit2. |
|||||
| SOCOTEC View Details _ | suncrypt | Other | |||
|
SOCOTEC is a France-based technical services group that provides inspection, testing, engineering, and advisory support for buildings, infrastructure, industrial, and manufacturing projects. The company operates across multiple markets and offers services spanning the full project life cycle for construction, industry, and asset management. In the United States, SOCOTEC describes itself as a partner for technical expertise across buildings and infrastructure, with a nationwide network of offices and specialists. SOCOTEC was listed as a ransomware victim associated with SunCrypt. |
|||||
| keisei- View Details _ | lockbit2 | Other | |||
|
Keisei Electric Railway Co., Ltd. is a Japan-based transportation company headquartered in Chiba Prefecture, with operations centered on rail services in the Tokyo metropolitan area. Its business also spans distribution, real estate management, and other services, including retail, leasing, and related leisure and construction activities. In threat-intelligence records, keisei- was listed as a ransomware victim associated with lockbit2. |
|||||
| https://www.tb-... View Details _ | lockbit2 | Other | |||
|
TB Alliance is a nonprofit global health organization focused on tuberculosis research, drug development, and access to new TB treatments. It works across the health sector from its U.S. base, supporting efforts to improve TB care and address the private and public market for TB medicines. Its programs emphasize research, market access, and broader treatment availability for people affected by tuberculosis. It was listed as a ransomware victim associated with lockbit2. |
|||||
| http://www.lund... View Details _ | lockbit2 | Other | |||
|
Lund Online is an agricultural products and services provider established in 1947, operating as a partner to the agricultural industry with offerings including extended life coatings and how to buy guides. The company serves the agricultural sector with specialized products and services, maintaining a long-standing presence as an industry partner since its founding. Lund Online is headquartered in the United States and focuses on agricultural solutions for customers across the sector. The company was listed as a ransomware victim associated with the LockBit2 threat actor in recent threat intelligence reports. |
|||||
| bestatt View Details _ | lockbit2 | Other | |||
|
bestatt is a Norway-based company in the Other sector; the name is associated with a business that provides services rather than a clearly defined industrial category. Public web results do not provide a reliable, detailed company profile, so the safest description is limited to its apparent business identity and Norwegian location. In threat-intelligence indexing, bestatt is recorded as a ransomware victim linked to LockBit2, a designation that does not by itself confirm the full scope of any incident. |
|||||
| RG Alliance Group View Details _ | United States | quantum | Services | ||
|
RG Alliance Group is a California-based services firm in the United States, with public business listings placing it in San Diego and Escondido, California. Public profiles describe it as an outsourced accounting and business services provider, offering strategic and financial services, accounting support, financial reporting, and back-office assistance for businesses. The company is associated with professional services and management consulting, reflecting a client-facing advisory and operations support model. It was listed as a ransomware victim associated with quantum. |
|||||
| bestattung- View Details _ | lockbit2 | Other | |||
|
bestattung- is a German funeral services business in the Other sector, operating from Germany and serving families with funeral and burial-related arrangements. Funeral providers in this sector typically support bereaved families with planning, coordination, and ceremonial services, including burial and cremation options. Publicly available listings identify the name as a funeral-related business rather than a technology or industrial firm. It was listed as a ransomware victim associated with lockbit2. |
|||||
| ardebolassessor View Details _ | lockbit2 | Other | |||
|
ardebolassessor is an Other-sector entity identified by name only in this threat-intelligence listing, with no reliable public source in the provided search results confirming its location, offerings, or operational profile. Because the available results do not establish a verifiable company website or official description, the entity should be treated conservatively as an unverified business or organization record. In catalog context, it is indexed for monitoring and comparison alongside other victim disclosures. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Novelty Group View Details _ | vicesociety | Services | |||
|
Novelty Group is a services company based in Abu Dhabi, United Arab Emirates, providing local sponsorship and representation for foreign companies across the UAE, GCC, and wider Middle East. Its regional profile and commercial focus center on helping international firms establish and operate in local markets. Separate industry references also describe related Novelty Group branding in events and digital services, but the Abu Dhabi company profile identifies the services business. The listing was recorded as a ransomware victim associated with vicesociety. |
|||||
| MOLTOLUCE - HACKED AND DATA LEAKED View Details _ | lv | Other | |||
|
MOLTOLUCE - HACKED AND DATA LEAKED appears in a ransomware victim index as a named victim entry in the Other sector. The listing does not identify the company’s line of business, location, or public offerings, so those details are not confirmed in the available source and should not be inferred. It is recorded among victims attributed to the lv ransomware group, which the index tracks as a threat actor with multiple claimed compromises. The entry was listed as a ransomware victim associated with lv. |
|||||
| dgi.gouv.ml View Details _ | lockbit2 | Other | |||
|
The Direction Générale des Impôts du Mali (DGI) is the national tax administration of Mali, located in Bamako, responsible for collecting taxes and managing fiscal formalities for citizens and businesses. It offers online services enabling taxpayers to perform administrative tasks electronically, including registration, account creation, and verification of tax identification numbers. The DGI operates under the Ministry of Economy and Finance and serves Malian taxpayers through digital platforms and physical offices. The organization was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| RadiciGroup View Details _ | blackbasta | Services | |||
|
RadiciGroup is an Italian corporation founded in 1941 and headquartered in Bergamo, Italy, specializing in the manufacture of chemical intermediates, polyamide polymers, engineering plastics, synthetic fibres, and nonwoven fabric. The family-owned company operates as a global leader in high-performance polymers, including recycled and bio-based solutions for electrical and electronic applications. It serves multinational clients across the plastics production and chemical sectors with advanced materials designed for everyday devices and industrial use. RadiciGroup was listed as a ransomware victim associated with the threat actor blackbasta. |
|||||
| Magnum View Details _ | vicesociety | Other | |||
|
Magnum is an entity operating in the sector classified as Other, with no specific geographic location or defined service offerings publicly documented. As a general organization, its core activities and market position remain unspecified in available records. The entity was listed as a ransomware victim associated with the threat actor vicesociety, indicating exposure to human-operated cyberattacks targeting diverse sectors. This listing aligns with vicesociety's known pattern of targeting small to medium-sized organizations across the United States and Europe. |
|||||
| medcoenergi.com View Details _ | lockbit2 | Other | |||
|
MedcoEnergi is PT Medco Energi Internasional Tbk, a publicly listed Indonesian energy and natural resources company headquartered in Jakarta, Indonesia. It operates across oil and gas, power, and copper and gold mining, with a business profile centered on exploration, production, and energy development. The company presents itself as a diversified Southeast Asian energy group with operations in Indonesia and beyond. Its website uses the medcoenergi.com domain and identifies the firm as a leading regional energy company. It was listed as a ransomware victim associated with lockbit2. |
|||||
| genusplc.com View Details _ | lockbit2 | Other | |||
|
Genus plc is a UK-based animal genetics company headquartered in Basingstoke, Hampshire, and it operates globally in the other sector. The company focuses on dairy, beef and pork production through its ABS bovine genetics and PIC porcine genetics businesses. Genus says it uses science and technology to breed genetically superior animals and sell elite genetics to farmers. The entity was listed as a ransomware victim associated with lockbit2. |
|||||
| enclosuresoluti View Details _ | lockbit2 | Other | |||
|
enclosuresoluti appears to be an organization in the Other sector, with a name that suggests a business focused on enclosure-related solutions or products. Public search results do not provide a reliable location or detailed offering summary, so the company is described here only at a high level. In threat-intelligence catalogs, it is indexed as a ransomware victim entry tied to the lockbit2 actor. The listing states it was a ransomware victim associated with lockbit2. |
|||||
| https://www.dgi... View Details _ | lockbit2 | Other | |||
|
DGI Supply is a United States-based distributor of industrial cutting tools and supplies, offering top brand names such as DoALL, Sandvik, 3M, OSG, Norton, and Master Fluid Solutions. The company focuses on maximizing operational efficiency for clients by providing high-quality cutting tools and industrial supplies across the sector. As a key player in the industrial distribution market, DGI Supply serves businesses requiring reliable and operationally-critical tooling solutions. The entity was listed as a ransomware victim associated with the LockBit2 threat actor in the threat-intelligence index. |
|||||
| gruppowasteital... View Details _ | lockbit2 | Other | |||
|
Gruppo Waste Italia is an Italian company in the waste management sector, focused on the collection, treatment, and disposal of waste. Its public website describes services aimed at improving waste handling through ongoing innovation and operational support. The company operates in Italy and presents itself as a provider of environmental and logistics services for waste streams. It was listed as a ransomware victim associated with LockBit2. |
|||||
| Shred Station View Details _ | United Kingdom | quantum | Services | ||
|
Shred Station is the UK's leading independent shredding specialist providing secure and efficient shredding services for confidential materials both on-site and off-site. The company operates from locations in Norwich, Harlow, and Manchester, delivering all data destruction services in line with EN 15713 standards on a one-off or regular basis. Its core offerings include confidential data destruction, media destruction, hard drive shredding, paper recycling, and high security shredding. Shred Station also extends its services to WEEE recycling, HDD degaussing, plastics recycling, and hazardous waste disposal. The organization was listed as a ransomware victim associated with the quantum threat actor. |
|||||
| YMCA View Details _ | United States | quantum | Healthcare / Pharma | ||
|
YMCA of the USA is a nonprofit organization based in the United States that supports community well-being through youth development, healthy living, and social responsibility programs. Its network of local Ys offers fitness, swim, child care, camp, and health-focused services, including community-based wellness initiatives. The organization also partners with insurers and health providers to expand access to YMCA memberships and preventive care resources. It was listed as a ransomware victim associated with quantum. |
|||||
| M. Green and Company LLP View Details _ | United States | quantum | Public Sector | ||
|
M. Green and Company LLP is a California-based accounting firm serving the Central San Joaquin Valley and surrounding communities. The firm provides accounting, tax, audit, advisory, and bookkeeping services, and its public listings describe a long history of serving local businesses and related clients in the region. It operates from offices in Tulare, Visalia, Hanford, and Porterville, California. It was listed as a ransomware victim associated with quantum. |
|||||
| Medlab Pathology View Details _ | Australia | quantum | Communication / Marketing | ||
|
Medlab Pathology is a healthcare services organization based in Auburn, New South Wales, Australia, specializing in pathology and diagnostic testing within the Communication and Marketing sector. The company operates collection centres across NSW and QLD, offering clinical laboratory services to support patient care and medical diagnostics. It was acquired by Australian Clinical Labs in December 2021, inheriting critical cybersecurity vulnerabilities that later contributed to a ransomware incident. Medlab Pathology was neutrally listed as a ransomware victim associated with the threat actor quantum. |
|||||
| SHOPRITE HOLDINGS LTD View Details _ | ransomhouse | Retail / E-commerce | |||
|
Shoprite Holdings Ltd is Africa's largest supermarket retailer, headquartered in Cape Town, South Africa, and operates over 2,900 stores across the continent. The company offers a wide range of fast-moving consumer goods and has expanded into e-commerce with online bulk shopping and delivery services targeting small businesses like spaza shops. As a public company, it plays a major role in the retail and e-commerce sector across South Africa and neighboring African nations. Shoprite Holdings Ltd was neutrally listed as a ransomware victim associated with the threat actor ransomhouse. |
|||||
| Metek PLC Files Leak View Details _ | everest | Other | |||
|
Metek PLC Files Leak refers to a reported incident involving Metek PLC, an entity operating in the Other sector with unspecified geographic location and offerings. The incident is cataloged as part of a broader pattern of cyberattacks linked to the everest ransomware group, which targets organizations across various industries. While specific details about stolen data or breach confirmation remain unverified, the listing identifies Metek PLC as a victim associated with everest. This entry serves as a neutral record within a threat-intelligence index tracking ransomware victims. Metek PLC was listed as a ransomware victim associated with everest. |
|||||
| SCHIFFMANS - HACKED AND DATA LEAKED View Details _ | lv | Other | |||
|
Schiffman's Jewelers is a family-owned luxury jewelry and watch retailer based in Greensboro and Winston-Salem, North Carolina. The company operates multiple stores and offers fine jewelry, loose diamonds, gemstones, luxury watches, and trade-in services. Its catalog includes high-end timepieces and branded jewelry from major watchmakers and designers. It was listed as a ransomware victim associated with lv. |
|||||
| MOTOLUCLE.COM - HACKED AND DATA LEAKED View Details _ | lv | Other | |||
|
MOTOLUCLE.COM is associated with the broad category of Other, and the available records do not provide a verified public company profile, location, or service description from the incident listing. Based on the name alone, it appears to be a web domain or digital business entity rather than a clearly identified industry operator, and no authoritative source in the provided material confirms its offerings. The listing should be treated as a threat-intelligence reference entry, not as proof of a confirmed compromise. It was listed as a ransomware victim associated with lv. |
|||||
| Bernd Hösele Group View Details _ | blackbasta | Services | |||
|
Bernd Hösele Group is an Austrian services company based in Guntramsdorf, Lower Austria, that operates in wholesale, retail, and e-commerce for cosmetic products. Founded in 1996 as a perfume wholesale business, it describes itself as providing comprehensive solutions for wholesale, retail, and online sales. Company directories also identify it as Bernd Hösele Trading Agency GmbH, with activity centered on perfume and cosmetics distribution. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Grand Valley State University View Details _ | vicesociety | Education | |||
|
Grand Valley State University is a public university in Allendale, Michigan, serving more than 25,000 students with undergraduate, graduate, and doctoral programs. It offers over 350 academic programs and emphasizes rigorous study with hands-on learning across fields including education. In its education programs, GVSU prepares students for careers in teaching, learning, and counseling. It was listed as a ransomware victim associated with vicesociety. |
|||||
| etron View Details _ | cuba | Other | |||
|
Etron Technology is a Taiwan-based fabless integrated-circuit design and production company that develops chips for semiconductor applications. Recorded Future describes it as a fabless IC design and production company with a website at etron.com. The company appears in threat-intelligence reporting as a victim entry related to Cuba ransomware, with the incident attributed to Cuba Leaks. It was listed as a ransomware victim associated with Cuba. |
|||||
| ptg.com.au View Details _ | Australia | lockbit2 | Other | ||
|
ptg.com.au is the website of Pickering Transport Group, an Australian logistics and freight carrier based in Swan Hill, Victoria, with operations across multiple depots in Australia. The company provides road transport, freight distribution, and related logistics services, serving commercial shipping needs nationwide. Its sector is classified as Other, reflecting a broader transport and logistics profile rather than a single industry vertical. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Opal View Details _ | blackbyte | Other | |||
|
Opal is an organization in the Other sector; based on the available public record here, no verified details were provided about its specific offerings or location. BlackByte is a ransomware-as-a-service threat group active since 2021, known for targeting organizations worldwide and using double extortion tactics. Public threat-intelligence listings associated Opal with BlackByte. It was listed as a ransomware victim associated with blackbyte. |
|||||
| SDZ Druck und Medien View Details _ | blackbasta | Other | |||
|
SDZ Druck und Medien is a German media and printing company based in Aalen, Baden-Württemberg, Germany, and the SDZ Mediengruppe describes it as a leading regional media service provider. Its business includes publishing and media services for the Ostwürttemberg/Ostalb region, with operations centered at Bahnhofstraße 65 in Aalen. Public company and directory listings identify it as part of the Schwäbische Post media group and a local press and media operator. It was listed as a ransomware victim associated with blackbasta. |
|||||
| slgienergy.com View Details _ | lockbit2 | Energy | |||
|
SL GLOBAL Energy is an energy-sector consulting firm based in Houston, Texas, with a website at slgienergy.com. The company describes its work as energy operations project management and innovation in consulting services and technology delivery, and third-party profiles say it focuses on oil and gas consulting, talent acquisition, and IT services. Its public footprint indicates it serves clients in the oilfield and broader energy market. It was listed as a ransomware victim associated with lockbit2. |
|||||
| sanvitale.r View Details _ | lockbit2 | Other | |||
|
sanvitale.r appears in threat-intelligence records as an entity in the Other sector, with available public context too limited to confirm a specific business profile or offerings from the name alone. No reliable web evidence in the provided results identifies a clearly corresponding company profile or location for sanvitale.r, so it is best described conservatively as an indexed organization name pending further verification. The listing was associated with lockbit2 as a ransomware victim. |
|||||
| ses View Details _ | lockbit2 | Other | |||
|
SES is a Luxembourg-based space solutions company that provides integrated satellite and connectivity services for businesses and governments. It operates in telecommunications, with offerings that include resilient network services and content distribution built around satellite infrastructure. Public company profiles describe SES as headquartered in Betzdorf, Luxembourg, and focused on satellite communications and related network solutions. In this index, SES was listed as a ransomware victim associated with LockBit2. |
|||||
| Metek Plc View Details _ | everest | Other | |||
|
Metek Plc is a UK-based company registered in Stonehouse, Gloucestershire, England. It develops light steel construction solutions and provides design, manufacturing, and installation services for residential, commercial, health, and education projects. The company says it has been a pioneer in light steel framing for more than 25 years. Metek Plc was listed as a ransomware victim associated with everest. |
|||||
| Tiroler Rohre GmbH View Details _ | blackbasta | Other | |||
|
Tiroler Rohre GmbH is a mechanical and industrial engineering company located in Hall in Tirol, Austria, with over 75 years of experience in the development, production, and marketing of high-quality ductile iron systems for water transport and deep-foundation engineering. The company specializes in the production of ductile iron pipe and pile systems, serving export areas across Central and Eastern Europe, Western Europe, Germany, Sweden, Slovenia, and Italy. Tiroler Rohre GmbH was listed as a ransomware victim associated with the threat actor BlackBasta. |
|||||
| Worldwide Flight Services View Details _ | blackbasta | Services | |||
|
Worldwide Flight Services (WFS) is a global services company focused on air cargo logistics, passenger support, and ground handling for airlines, airports, freight forwarders, and businesses. It operates as a member of the SATS Group and describes itself as a leading independent provider of airport services, with a global network spanning multiple countries. WFS is also headquartered in France and maintains a U.S. corporate presence in Irving, Texas. It was listed as a ransomware victim associated with blackbasta. |
|||||