All Ransomware Records
Top Countries
All Ransomware Attacks in All period
Posts
| Target | Discovered | Country | Source | Business Category | Intel Link |
|---|---|---|---|---|---|
| TeladanPrima Argo Group View Details _ | avoslocker | Communication / Marketing | |||
|
750GB+ of stolen data include contracts, confidential , intellectual property data, and more |
|||||
| Sunland Asphalt And Construction View Details _ | avoslocker | Construction / Real Estate | |||
|
Human Resources, Projects, Documents, and more. If Sunland Asphalt refuses to pay the ransom, every data will be published to the public. |
|||||
| Stratford University View Details _ | avoslocker | Education | |||
|
samples of: Confidential agreements Military personnel (white house service members) related files taxation data |
|||||
| Xybion View Details _ | avoslocker | Communication / Marketing | |||
|
Xybion's Emidence TM platform satisfies our current and evolving future needs with the unique adoption technique of "Your Process - Your Way", Joseph F. Molloy Vice President, Workforce Safety. We wanted to go paperless without impacting our existing business processes. It was a smooth transition for our users thanks to Labwise XD. |
|||||
| Our Lady of Lake University View Details _ | avoslocker | Education | |||
|
Our Lady of the Lake University, founded in 1895 by the Congregation of Divine Providence, is a coeducational institution. - DB - Health - Finance - Admissions - IT - HR And many of more... |
|||||
| Paul Smiths College View Details _ | avoslocker | Education | |||
|
At Paul Smith's College, it's about the experience. We are the only four-year institution offering broad-based higher education in the Adirondacks. Our programs... |
|||||
| Northwest University View Details _ | avoslocker | Education | |||
|
Confidential, taxation, and financial data |
|||||
| Emtec Inc View Details _ | avoslocker | Telecommunications | |||
|
Global IT company with terrible IT security. How can Emtec secure clients when they don't secure their own network? MISRA SUNIL SSN:050-66-2655 Email:[email protected] JOHNSON RICK SSN:252-33-1704 Email:[email protected] DESAI DINESH SSN:516-74-2061 Email:[email protected] CHANDLER GREGORY SSN:220-02-8854 Email:[email protected] BALLINGER VICKI SSN:208-46-9296 Email:[email protected] |
|||||
| American International Industry View Details _ | avoslocker | Communication / Marketing | |||
|
The leading manufacturer and distributor of innovative, quality beauty and skin care products for men and women. With 45 years of industry experience.The leading manufacturer and distributor of innovative, quality beauty and skin care products for men and women. With 45 years of industry experience. |
|||||
| Zeus Scientific Inc View Details _ | avoslocker | Services | |||
|
https://www.zeusscientific.com/about Zeus Scientific, Inc. manufactures clinical diagnostic solutions. The Company offers flexible solutions for autoimmune and infectious disease testing. AvosLocker team publishes the first part of exfiltrated files from Zeus Scientific Servers, NDA contracts etc |
|||||
| Hughes Systems Industrial View Details _ | avoslocker | Manufacturing / Engineering | |||
|
All company projects includes drawings, contracts, and all details employees social security number 401K plans company financial data includes bank accounts information, and taxation reports and more |
|||||
| DLS Motors View Details _ | Paraguay | avoslocker | Communication / Marketing | ||
|
We downloaded 50GB of internal files from DLS Motors. -- Just 83 years ago, the company Sobera S.A. entered the Paraguayan market, bringing new business opportunities, new projects, new sources of employment and contributing to the sustained economic growth of our country. |
|||||
| Cosmopoint College View Details _ | avoslocker | Education | |||
|
We downloaded about 80 gigabytes of internal school documents, including teacher and student contact information, student loan contracts, internal school financial documents, etc |
|||||
| ALVAC SA View Details _ | avoslocker | Telecommunications | |||
|
Website - https://alvac.es Company name: ALVAC S.A. Companies System Administrator trying to hide the cyberattack on the ALVAC S.A. servers. Vídeos confidenciales https://vimeo.com/752214614 AvosLocker team is ready to leak more files on the blog, publish video-files and attack networks again. We should agree with you to decrypt your networks and remove all ALVAC S.A. exfiltrated files from AvosLocker team servers. https://twitter.com/PedroFe12181764/status/1575117531957846017 https://twitter.com/search?q=%40alvac&src=typed_query&f=live |
|||||
| Atlatec SA de CV View Details _ | Mexico | royal | Communication / Marketing | ||
|
We are the most important company in Mexico that integrates water infrastructure projects, with more than 60 years of experience, having developed more than 90 public and private projects. We provide solutions with the highest technology and innovation for water and wastewater treatment. |
|||||
| Republic of Vanuatu View Details _ | Vanuatu | ransomhouse | Healthcare / Pharma | ||
|
We are a leading multinational health group committed to keeping communities healthy through our own Comprehensive Health Model, which is based on prevention, identification and management of health risks, and control and management of the disease and the dependency. |
|||||
| aristopharma.com View Details _ | lockbit3 | Healthcare / Pharma | |||
|
1 part of:750GB, Personal folders of key employees, all infrastructure\personal data\accounting, etc.Md. Azharul Islam_6581 36gb - Senior Executive,Production at Aristopharma Ltd. Md. Rubel_10790 4gb - Executive, Production at Aristopharma Ltd... |
|||||
| Myofficeplace Inc. View Details _ | bianlian | Communication / Marketing | |||
|
Managed, Dedicated enterprise-class Cloud hosting for businesses. Citrix Hosting, Virtual Servers. |
|||||
| SEMITEC Corporation View Details _ | Viet Nam | bianlian | Manufacturing / Engineering | ||
|
Semitec Vietnam (SEV) is the 15th subsidiary of Semitec Corporation, headquartered in Japan. The company specializes in manufacturing electronics, sensors. |
|||||
| ***** View Details _ | bianlian | Healthcare / Pharma | |||
|
International provider of analytics, technology solutions and contract research services for the healthcare industry. |
|||||
| Realstar Holdings Partnership View Details _ | Canada | bianlian | Construction / Real Estate | ||
|
Realstar is a company that operates in the Real Estate industry. It employs 251-500 people and has $50M-$100M of revenue. The company is headquartered in Toronto, Ontario, Canada. |
|||||
| excentiahumanservices.org View Details _ | lockbit3 | Services | |||
|
Revenue 14kkExcentia Human Services is a nonprofit organization in Lancaster County that provides services for people with developmental needs and autism throughout the lifespan. These services can begin at birth with therapeutic and educati... |
|||||
| bavelloni.com View Details _ | lockbit3 | Communication / Marketing | |||
|
Bavelloni SpA provides glass processing technology and services for the architectural, furniture and domestic appliance and solar industries.We encrypted the network of this company. We also stole about 200GB of the date. Financial information. Sal... |
|||||
| Aegea Group companies View Details _ | Brazil | royal | Communication / Marketing | ||
|
Founded in 2010, Aegea is one of Brazil’s largest private sanitation companies. In each town it operates, it takes more health and quality of life to the population, always respecting the environment and local culture. Today, more than 21 million people are served in 154 cities across Brazil.Aegea manages sanitation assets through full or partial common concessions, sub-concessions and public-private partnerships (PPPs) and manages public concessions in the entire water cycle, i.e., supply, collection and treatment of sewage according to the profile and needs of each town. |
|||||
| Rech Informatica Ltda View Details _ | Brazil | royal | Services | ||
|
Rech Informática Ltda is a company that operates in the Staffing and Recruiting industry. It employs 51-100 people and has $10M-$25M of revenue. Headquarters: 460 Rua Tupanciretã, Novo Hamburgo, Rs, 93334-480, Brazil |
|||||
| thedonovancompany.com View Details _ | lockbit3 | Services | |||
|
A small boutique CPA firm located in Irvine California. We provide tax and accounting services to individuals and their businesses. Hands on assistance with tax planning, tax compliance and various other matters. We believe getting to know our client... |
|||||
| Strem Chemicals View Details _ | ransomhouse | Manufacturing / Engineering | |||
|
Strem established in 1964, is a company that manufactures and markets specialty chemicals of high purity. Strem was acquired by Ascensus Specialties in 2021. Its clients include academic, industrial and government research and development laboratories as well as commercial scale businesses in the pharmaceutical, microelectronic and chemical / petrochemical industries. Strem also provides custom synthesis (including high pressure synthesis) and cGMP manufacturing services. |
|||||
| Pinnacle Communications View Details _ | royal | Communication / Marketing | |||
|
Pinnacle Communications merged with Justin Hannesson and Pinnacle West LLC to become the company that we are today. This dynamic strength exhibited within both companies merging into one has positioned Pinnacle as one of the most valued brands in the hospitality industry. Through all of 30-plus years, we continue to grow and our reputation for quality service and a robust product line keeps us in the forefront of the niche hospitality market. Pinnacle’s employees have always been the core and heartbeat of the company since the day we started. Along with an unmatched work-ethic, talent and ingenuity, Pinnacle’s all-star staff has survived the many economic and turbulent challenges of the past 30 years. Through it all our proven leadership team and staff have shown great determination and passion for our company, and we look forward to a bright future. |
|||||
| Every one of you been a good customer this year View Details _ | monti | Other | |||
| maxionwheels.com View Details _ | lockbit3 | Other | |||
|
Founded in 1908 and headquartered in Novi, Michigan, MAXION Wheels wheel manufacturer for passenger cars, light trucks, buses, commercial trucks, and trailers. |
|||||
| SOFTEQ.COM View Details _ | clop | Construction / Real Estate | |||
|
Custom Software Development Company - Softeq |
|||||
| MARCELSOLUTION.COM View Details _ | clop | Other | |||
| ORDEREXPRESS.COM.MX View Details _ | Mexico | clop | Communication / Marketing | ||
| LOESCHGROUP.DE View Details _ | Germany | clop | IT | ||
|
Loeschgroup – Beschläge, Sicherheits- und Türschließtechnik |
|||||
| SOUTH-STAFFS-WATER.CO.UK View Details _ | United Kingdom | clop | Other | ||
|
South Staffs Water - South Staffordshire Water |
|||||
| APPLEXUS.COM View Details _ | clop | Services | |||
|
SAP Software Solutions - SAP Consulting & Implementation Company |
|||||
| SPINNEYS.COM View Details _ | clop | Retail / E-commerce | |||
|
Spinneys UAE - Supermarket and Grocery Delivery in Dubai, Abu Dhabi, Al Ain & Fujairah |
|||||
| PRICEDEX.COM View Details _ | clop | Communication / Marketing | |||
|
Home - Pricedex Software |
|||||
| FERRAN-SERVICES.COM View Details _ | clop | Services | |||
|
AC & Heating Services in Orlando, FL - HVAC Installation throughout Volusia, Winter Park, Windermere, Oviedo & Lake Mary, FL |
|||||
| LATOURNERIE-WOLFROM.COM View Details _ | France | clop | Other | ||
|
Latournerie Wolfrom Avocats - France et International depuis 25 ans |
|||||
| ENSSECURITY.COM View Details _ | clop | Other | |||
|
ENS Security Camera is a Distributor Manufacturer surveillance supplier |
|||||
| FTSUMNERK12.COM View Details _ | clop | Other | |||
|
Fort Sumner Home Page |
|||||
| NEWCOURSECC.COM View Details _ | clop | Communication / Marketing | |||
|
Newcourse Communications - Full-service Data-Processing Print Provider |
|||||
| PERBIT.COM View Details _ | clop | Communication / Marketing | |||
|
Die HR Software mit Wir-Prinzip |
|||||
| 888VOIP.COM View Details _ | clop | Other | |||
|
Your value-added distributor - 888VoIP |
|||||
| AFJCONSULTING.NET View Details _ | clop | Services | |||
| ORBITELECTRIC.COM View Details _ | clop | Other | |||
|
Orbit Industries, Inc. |
|||||
| FAIR-RITE.COM View Details _ | clop | Other | |||
|
Index - Fair Rite |
|||||
| JDAVIDTAXLAW.COM View Details _ | clop | Finance / Legal / Insurance | |||
|
Access denied |
|||||
| THENOC.NET View Details _ | clop | Telecommunications | |||
|
The Network Operations Company – Providing Managed IT Services |
|||||
| ZISSERFAMILYLAW.COM View Details _ | clop | Finance / Legal / Insurance | |||
|
Family Lawyers in Jacksonville, FL - Zisser Family Law |
|||||
| SA1SOLUTIONS.COM View Details _ | clop | Services | |||
|
SA1 Solutions - Award Winning IT Support in Swansea, Cardiff and South Wales |
|||||
| OAKDELL.COM View Details _ | clop | Agriculture / Food | |||
|
Oakdell Egg Farms - Home |
|||||
| ALTERNATIVETECHS.COM View Details _ | clop | IT | |||
|
403 Forbidden |
|||||
| DRIVEANDSHINE.COM View Details _ | clop | Other | |||
|
Home - Drive & Shine |
|||||
| DRC-LAW.COM View Details _ | clop | Finance / Legal / Insurance | |||
|
Homepage - Dymond Reagor, PLLC |
|||||
| ALEXIM.COM View Details _ | clop | Other | |||
| CAPCARPET.COM View Details _ | clop | Retail / E-commerce | |||
|
CAP Carpet & Flooring Store - Hardwood, Waterproof Tile & Plank Floors, Ceramic Tile, Custom Area Rugs |
|||||
| JBINSTANTLAWN.NET View Details _ | clop | Finance / Legal / Insurance | |||
|
JB Instant Lawn - Resources |
|||||
| JCWHITE.COM View Details _ | clop | Other | |||
|
403 Forbidden |
|||||
| DUTTONFIRM.COM View Details _ | clop | Finance / Legal / Insurance | |||
|
Dutton Law Firm - Waterloo Lawyers - Iowa Personal Injury Lawyers |
|||||
| ENPRECIS.COM View Details _ | clop | Communication / Marketing | |||
|
Database Error |
|||||
| MTMRECOGNITION.COM View Details _ | clop | Other | |||
| MUSCHERT-GIERSE.DE View Details _ | Germany | clop | Other | ||
|
Unternehmen |
|||||
| SWIRESPO.COM View Details _ | clop | Other | |||
| EDAN.COM View Details _ | clop | Other | |||
|
EDAN 理邦仪器 |
|||||
| MCH-GROUP.COM View Details _ | clop | Services | |||
|
403 Forbidden |
|||||
| SLIMSTOCK.COM View Details _ | clop | Services | |||
|
Slimstock - Experts In Inventory Management Solutions |
|||||
| QUANTUMGROUP.COM View Details _ | clop | Services | |||
|
403 Forbidden |
|||||
| NATUS.COM View Details _ | clop | Other | |||
|
Welcome to Natus - Natus |
|||||
| SMARTERASP.NET View Details _ | clop | Other | |||
|
SmarterASP.net - Unlimited ASP.NET Web Hosting |
|||||
| TONLYELE.COM View Details _ | clop | Other | |||
|
通力科技股份有限公司 |
|||||
| SSMSJUSTICE.COM View Details _ | clop | Other | |||
|
Singleton Schreiber - Fearless Advocacy |
|||||
| ABSOLUTERESULTS.COM View Details _ | clop | Other | |||
|
Absolute Results - Helping Dealers Sell Cars Today and Tomorrow |
|||||
| BOLTONUSA.COM View Details _ | clop | Other | |||
|
Bolton |
|||||
| STRATISVISUALS.COM View Details _ | clop | Other | |||
| EMPIRICAL-RESEARCH.COM View Details _ | clop | Other | |||
|
403 Forbidden |
|||||
| BRPRINTERS.COM View Details _ | clop | Communication / Marketing | |||
|
403 Forbidden |
|||||
| BLUEBONNETNUTRITION.COM View Details _ | clop | Communication / Marketing | |||
|
Bluebonnet Nutrition-Vitamins-Minerals-Proteins-Herbs-Supplements |
|||||
| SUNSETHCS.COM View Details _ | clop | Healthcare / Pharma | |||
|
Sunset Healthcare Solutions |
|||||
| BPATPA.COM View Details _ | clop | Other | |||
|
Benefit Plan Administrators, Inc. |
|||||
| GENESISNET.COM View Details _ | clop | Other | |||
| COMPASSNRG.COM View Details _ | clop | Other | |||
|
403 Forbidden |
|||||
| COULSONGROUP.COM View Details _ | clop | Services | |||
|
Coulson Group - Leaders in Innovation |
|||||
| STORAFILE.CO.UK View Details _ | United Kingdom | clop | Services | ||
|
National Document Management Specialist » Stor-a-File |
|||||
| KLEINBERGLANGE.COM View Details _ | clop | Finance / Legal / Insurance | |||
|
Kleinberg Lange Cuddy & Carlo LLP - Entertainment Law Firm |
|||||
| WDMANOR.COM View Details _ | clop | Construction / Real Estate | |||
|
W.D. Manor Mechanical Contractors - W.D. MANOR MECHANICAL CONTRACTORS, INC. |
|||||
| MMALTZAN.COM View Details _ | clop | Other | |||
| KSSENTERPRISES.COM View Details _ | clop | Communication / Marketing | |||
|
Janitorial Supplies and Equipment - KSS Enterprises |
|||||
| PARAGONGRI.COM View Details _ | clop | Other | |||
|
Home - Paragon Global Resources |
|||||
| PENBENS.COM View Details _ | clop | Other | |||
|
Pension Benefit Consultants, Inc. – Actuaries and Retirement Plan Administrators |
|||||
| GOABCO.COM View Details _ | clop | Manufacturing / Engineering | |||
|
ABCO Automation - Specializing In Factory Automation |
|||||
| ZUCCHETTIKOS.IT View Details _ | Italy | clop | Other | ||
|
Home - ZucchettiKos |
|||||
| RMICO.COM View Details _ | clop | Other | |||
|
403 Forbidden |
|||||
| VALLEYTRUCKANDTRACTOR.COM View Details _ | clop | Agriculture / Food | |||
|
Agriculture & Turf Equipment & Services - Papé Machinery |
|||||
| KSSARCHITECTS.COM View Details _ | clop | Other | |||
|
KSS Architects |
|||||
| NFT.CO.UK View Details _ | United Kingdom | clop | Other | ||
| UTILITYTRAILER.COM View Details _ | clop | Energy | |||
|
403 Forbidden |
|||||
| AUROBINDO.COM View Details _ | clop | Healthcare / Pharma | |||
|
Pharmaceutical Manufacturing and Exports, Research and Development in Pharma – Aurobindo Pharma |
|||||
| FOODLAND.COM View Details _ | clop | Agriculture / Food | |||
|
Foodland Homepage - Foodland |
|||||
| NIPRO.COM View Details _ | Japan | clop | Communication / Marketing | ||
|
Renal & Vascular Medical Devices - Nipro Medical |
|||||
| PNCPA.COM View Details _ | clop | Other | |||
|
Postlethwaite & Netterville (P&N ) - Louisiana - Mississippi - Texas CPA |
|||||
| SHELL.COM View Details _ | clop | Other | |||
|
Shell Global |
|||||
| STANFORD.EDU View Details _ | United States | clop | Education | ||
|
Stanford University |
|||||
| MIAMI.EDU View Details _ | United States | clop | Education | ||
|
University of Miami |
|||||
| COLORADO.EDU View Details _ | United States | clop | Education | ||
|
Home - University of Colorado Boulder |
|||||
| FLAGSTAR.COM View Details _ | clop | Other | |||
|
Access denied |
|||||
| BOMBARDIER.COM View Details _ | clop | Hospitality / Food & Beverage / Tourism | |||
|
Homepage - Bombardier |
|||||
| JONESDAY.COM View Details _ | clop | Other | |||
|
Access denied |
|||||
| DANAHER.COM View Details _ | clop | Other | |||
| SINGTEL.COM View Details _ | clop | Telecommunications | |||
|
Mobile, Fibre Broadband and TV services provider - Singtel |
|||||
| SYMRISE.COM View Details _ | clop | Agriculture / Food | |||
|
Symrise I Food & Beverage I Pet Food I Aqua Feed I Fragrance I Cosmetic Ingredients I Aroma Molecules - Symrise |
|||||
| ELANDRETAIL.COM View Details _ | clop | Retail / E-commerce | |||
|
ELAND RETAIL |
|||||
| PARKLAND.CA View Details _ | Canada | clop | Other | ||
|
Home - Parkland |
|||||
| SOFTWAREAG.COM View Details _ | clop | IT | |||
|
Software & Technology Services and Solutions - Software AG |
|||||
| INDIABULLS.COM View Details _ | India | clop | Finance / Legal / Insurance | ||
|
Housing Finance - Home Loan Company in India - Indiabulls Home Loans |
|||||
| EXECUPHARM.COM View Details _ | clop | Other | |||
| SGS-LAW.COM View Details _ | clop | Finance / Legal / Insurance | |||
|
Not Acceptable! |
|||||
| RFF.ORG View Details _ | clop | Healthcare / Pharma | |||
|
Resources for the Future—Healthy Environment, Thriving Economy |
|||||
| BOUTINEXPRESS.COM View Details _ | clop | Communication / Marketing | |||
|
Accueil - Transport Boutin |
|||||
| SIUMED.EDU View Details _ | United States | clop | Healthcare / Pharma | ||
|
SIU School of Medicine Home - SIU School of Medicine |
|||||
| TRAVELSTORE.COM View Details _ | clop | Transportation / Travel | |||
|
TravelStore: Business and Vacation Travel Consultants - TravelStore |
|||||
| DURHAM.CA View Details _ | Canada | clop | Other | ||
|
Region of Durham |
|||||
| UNIVERSITYOFCALIFORNIA.EDU View Details _ | United States | clop | Education | ||
|
Home - University of California |
|||||
| UMD.EDU View Details _ | United States | clop | Education | ||
|
The University of Maryland - A Preeminent Public Research University |
|||||
| YU.EDU View Details _ | United States | clop | Education | ||
|
Home - Yeshiva University |
|||||
| MARNELLCOMPANIES.COM View Details _ | clop | Construction / Real Estate | |||
|
Marnell Companies - Industry-Leading Casino Architecture and Design Best Architect and Designer in Las Vegas, NV. |
|||||
| RACETRAC.COM View Details _ | clop | Other | |||
|
RaceTrac - Whatever Gets You Going |
|||||
| EDAG.COM View Details _ | clop | Manufacturing / Engineering | |||
|
Ihr ganzheitlicher Engineering-Partner - EDAG Group |
|||||
| WRIGHT.COM View Details _ | clop | Healthcare / Pharma | |||
|
Wright Medical Group N.V. - a global medical device company |
|||||
| QUALYS.COM View Details _ | clop | Other | |||
|
IT Security and Compliance Platform - Qualys, Inc. |
|||||
| MMOSER.COM View Details _ | clop | Other | |||
|
Home - M Moser Associates |
|||||
| KINZE.COM View Details _ | clop | Other | |||
| NOWFOODS.COM View Details _ | clop | Agriculture / Food | |||
|
NOW Foods - Vitamins and Supplements - Essential Oils |
|||||
| CSX.COM View Details _ | clop | Services | |||
|
CSX rail, intermodal and rail-to-truck transload services - CSX.com |
|||||
| CSAGROUP.ORG View Details _ | clop | Services | |||
|
403 Forbidden |
|||||
| TRANSPORT.NSW.GOV.AU View Details _ | Australia | clop | Transportation / Travel / Logistics | ||
|
Homepage - Transport for NSW |
|||||
| CGG.COM View Details _ | clop | IT | |||
|
CGG: Global Technology and HPC leader |
|||||
| STERIS.COM View Details _ | clop | Other | |||
|
403 - Forbidden: Access is denied. |
|||||
| PENTAIR.COM View Details _ | clop | Other | |||
|
Pentair |
|||||
| FUGRO.COM View Details _ | clop | Services | |||
|
Global offshore and onshore geotechnical and survey services |
|||||
| EAGLE.ORG View Details _ | clop | Transportation / Travel / Logistics | |||
|
American Bureau of Shipping (ABS) Eagle.org |
|||||
| THE7STARS.CO.UK View Details _ | United Kingdom | clop | Other | ||
|
403 Forbidden |
|||||
| AMEY.CO.UK View Details _ | United Kingdom | clop | Communication / Marketing | ||
|
Personal pride in our public service - Amey plc |
|||||
| NOVABIOMEDICAL.COM View Details _ | clop | Healthcare / Pharma | |||
|
Nova Biomedical develops, manufactures, and sells advanced technology blood testing analyzers and meters. |
|||||
| ALLSTATEPETERBILT.COM View Details _ | clop | Public Sector | |||
|
Midwest New and Used Truck Dealer Group - Allstate Peterbilt Group |
|||||
| PRETTL.COM View Details _ | clop | Communication / Marketing | |||
|
Prettl - Think global. Act local. |
|||||
| NETZSCH.COM View Details _ | clop | Other | |||
|
Just a moment... |
|||||
| PROMINENT.COM View Details _ | clop | Communication / Marketing | |||
|
Experts in Metering Technology and Water Treatment - ProMinent |
|||||
| PLANATOL.DE View Details _ | Germany | clop | Other | ||
|
Ihr Klebstoffhersteller aus Rohrdorf & Herford - PlanatolPlanatol |
|||||
| TWL.DE View Details _ | Germany | clop | Communication / Marketing | ||
|
Technische Werke Ludwigshafen AG (TWL) - Technische Werke Ludwigshafen AG - Meine Energiequelle: Privatkunden |
|||||
| INRIX.COM View Details _ | clop | Transportation / Travel / Logistics | |||
|
Leading Transportation Analytics Solutions - INRIX |
|||||
| MHMR Authority Of Brazos Valley View Details _ | hive | Public Sector | |||
|
The MHMR Authority of Brazos Valley is a public non-profit community MHMR center. Through the Texas Department of State Health Services and Texas Department of |
|||||
| Cervecería Regional View Details _ | Venezuela, Bolivarian Republic of | play | Other | ||
|
Maracaibo, Zulia, Venezuela |
|||||
| F???????, ???, D????????, T???????, S????????????? View Details _ | play | Other | |||
| Berlina Tbk View Details _ | bianlian | IT | |||
|
Berlina Tbk provides one stop solution for plastic packaging with state-of-the-art technology and machinery, complete product design & development, Tube, Injection Moulding, Blow Moulding, Cap, Decoration and Mould making facilities. |
|||||
| Alvaria View Details _ | United States | hive | IT | ||
|
Alvaria, (pronounced: ahl-vahr-ee-uh), a global leader delivering optimized customer experience and workforce engagement software and cloud services technology solutions. |
|||||
| M***** View Details _ | bianlian | Manufacturing / Engineering | |||
|
Consultancy and engineering services firm. |
|||||
| M*******l*** View Details _ | bianlian | Other | |||
|
Hosting, quick book hosting, sql hosting, exchange hosting. |
|||||
| S****** Electronics" View Details _ | Japan | bianlian | Manufacturing / Engineering | ||
|
Corporation manufactures and sells electronic components in Japan and internationally |
|||||
| ATLAS View Details _ | royal | Other | |||
|
Passports / SSN / Confidential Docs |
|||||
| Goodwill industries View Details _ | karakurt | Energy | |||
|
Centrisys is a USA manufacturer of decanter centrifuges for sludge dewatering and thickening. Since 1987 Centrisys has been a leader in decanter centrifuge service and repair for all brands of centrifuges on the market today. CNP - Technology Water and Biosolids, a subsidiary of Centrifuge-Systems, LLC, designs and supplies innovative nutrient recovery and energy optimization systems for wastewater treatment. In this release we can offer you 403 GB of their corporate data. |
|||||
| G.R. Sponaugle View Details _ | unsafe | Other | |||
|
country: US - revenue: 22.00M |
|||||
| Horwitz Horwitz & Associates View Details _ | unsafe | Finance / Legal / Insurance | |||
|
country: US - revenue: 8.00M |
|||||
| Wings Etc View Details _ | unsafe | Other | |||
|
country: US - revenue: 145.00M |
|||||
| Dooly County School System View Details _ | unsafe | Education | |||
|
country: US - revenue: 20.00M |
|||||
| Whatcom County Library System View Details _ | unsafe | Public Sector | |||
|
Whatcom County Library System (WCLS) is a public library system serving Whatcom County, Washington, in the United States. It operates library branches, mobile services, and online resources for books, media, digital content, and patron support. WCLS also offers accessibility services, public programs, and procurement-related information through its website. It was listed as a ransomware victim associated with unsafe. |
|||||
| The Chedi Muscat View Details _ | unsafe | Other | |||
|
chedimuscat.com is associated with The Chedi Muscat, a 5-star beach resort in Muscat, Oman, located on the Al Ghubra shoreline north of the old city. The property offers beachfront lodging, multiple pools, restaurants, lounges, a spa, and other guest amenities. Its website serves as a hospitality and booking presence for the resort and related guest services. It was listed as a ransomware victim associated with unsafe. |
|||||
| Barakat Travel Co View Details _ | unsafe | Transportation / Travel | |||
|
Barakat Travel Co. is a Kuwait-based travel management company established in 1988. It serves individual, corporate, and leisure travelers with services including flight and hotel bookings, holiday packages, cruise reservations, car hire, train tickets, and medical travel. The company presents itself as a local travel specialist with offices in Kuwait and a focus on tailored travel solutions. It was listed as a ransomware victim associated with unsafe. |
|||||
| Ucar View Details _ | France | unsafe | Other | ||
|
UCAR is a French vehicle-rental company based in Boulogne-Billancourt, in the Île-de-France area, with its head office on rue Louis Pasteur. Its website presents UCAR as a local car-rental network that lets customers book vehicles online, search offers by city or postal code, and find nearby agencies across France. The company promotes short-term rentals of cars and utility vehicles through a broad agency network and online reservation tools. It was listed as a ransomware victim associated with unsafe. |
|||||
| Interface View Details _ | United States | hive | Other | ||
|
Interface is a US-based commercial flooring company headquartered in Atlanta, Georgia. It designs, produces, and sells modular carpet tile, resilient flooring, and related hard-surface products for commercial spaces. The company describes itself as a global leader in modular flooring and highlights sustainability as a core part of its offering. In threat-intelligence listings, Interface was associated with the ransomware actor Hive as a victim. |
|||||
| LIBERTY PULTRUSIONS View Details _ | karakurt | Manufacturing / Engineering | |||
|
Liberty Pultrusions is a U.S. manufacturer based in Pittsburgh, Pennsylvania, that produces engineered fiberglass reinforced plastic (FRP) pultrusions. The company says it has more than 40 years of experience in the FRP industry and offers custom pultruded products in a range of shapes and sizes for manufacturing and engineering applications. In threat-intelligence listings, Liberty Pultrusions was identified as a ransomware victim associated with karakurt. |
|||||
| Wrapex Industrial - Leaked View Details _ | ragnarlocker | Manufacturing / Engineering | |||
|
Wrapex Industrial Services is a Western Canadian industrial services company that provides industrial insulation, glycol tracing, utilidor work, and scaffolding services. Its operations support manufacturing and engineering environments across industrial projects in Canada. The “Wrapex Industrial - Leaked” entry identifies the company in a threat-intelligence context as a manufacturing/engineering-sector target. It was listed as a ransomware victim associated with Ragnar Locker. |
|||||
| Zehnders of Frankenmuth View Details _ | royal | Retail / E-commerce | |||
|
Zehnder's of Frankenmuth is a Michigan hospitality and retail business based in Frankenmuth, with its main site on South Main Street in the city’s downtown district. Its brand includes Zehnder’s Marketplace, which sells food, gift items, fresh baked breads, pastries, sweet treats, and private-label products through in-store and online channels. The company traces its origins to 1929 and operates as a long-running regional destination for dining and retail. It was listed as a ransomware victim associated with royal. |
|||||
| North Idaho College View Details _ | hive | Education | |||
|
North Idaho College is a public community college in Coeur d'Alene, Idaho, with additional locations in Post Falls and Rathdrum. It offers more than 80 degrees and certificates, including transfer programs and career and technical education. The college serves students through academic, workforce, and training programs across its regional campuses in northern Idaho. It was listed as a ransomware victim associated with Hive. |
|||||
| Innovative Education Management View Details _ | hive | Education | |||
|
Innovative Education Management (IEM) is a California education organization based in Placerville, California, that develops and operates charter schools. It has served California charter schools since 1998 and offers a tuition-free, individualized education model through independent-study and public charter programs. Public profiles describe it as focused on personalized learning and school management services for students and families. It was listed as a ransomware victim associated with Hive. |
|||||
| Dixons Allerton Academy View Details _ | hive | Education | |||
|
Dixons Allerton Academy is an all-through school and sixth form in Allerton, Bradford, West Yorkshire, England. It serves pupils from primary through post-16 education and operates within the education sector. The academy is located on Rhodesway in Bradford and is part of the Dixons Academies Trust. It was listed as a ransomware victim associated with Hive. |
|||||
| City Of Huntsville, Texas View Details _ | hive | Public Sector | |||
|
City Of Huntsville, Texas is a municipal public sector government in Huntsville, Texas, serving residents through city departments and administrative services. The city’s official website and municipal directory identify it as the City of Huntsville, with offices at 1212 Avenue M and a local government structure that supports public health, safety, and welfare. It operates as a city administration in the United States and provides public information, services, and community notices. The City of Huntsville, Texas was listed as a ransomware victim associated with hive. |
|||||
| Serena Hotels - Leaked View Details _ | ragnarlocker | Hospitality / Food & Beverage / Tourism | |||
|
Serena Hotels is a hospitality group operating hotels, resorts, safari lodges, camps, and forts across East Africa, Southern Africa, Central Asia, and South Asia. Its properties are positioned in travel and leisure destinations, serving guests through accommodation, dining, events, and resort experiences. The brand’s portfolio includes city hotels and destination lodges in countries such as Kenya and Tanzania. Serena Hotels - Leaked was listed as a ransomware victim associated with ragnarlocker. |
|||||
| FREDERICK Public Schools View Details _ | vicesociety | Education | |||
|
FREDERICK Public Schools is a public school district in Frederick County, Maryland, serving students across elementary, middle, high, charter, and other education centers. The district operates a K-12 public education system for the county’s residents and maintains multiple schools and support facilities. In threat-intelligence indexing, it is cataloged as a ransomware victim. It was listed as a ransomware victim associated with vicesociety. |
|||||
| McNamara & Thiel Insurance Agency View Details _ | vicesociety | Finance / Legal / Insurance | |||
|
McNamara & Thiel Insurance Agency is an independent insurance agency in Fond du Lac, Wisconsin, serving clients in the finance, legal, and insurance space. Its public company profiles describe it as a full-service agency offering personal, business, life, and health coverage, including auto, homeowners, farmowners, renters, and workers compensation insurance. The agency says it works with multiple carriers to match policies to client needs and budget. It was listed as a ransomware victim associated with vicesociety. |
|||||
| JEALSA View Details _ | Spain | vicesociety | Manufacturing / Engineering | ||
|
JEALSA is a Spanish family-owned enterprise founded in 1958, headquartered in Boiro, Galicia, ES, specializing in the manufacturing and commercialization of canned fish and seafood products. As a leading processor and manufacturer in the food and beverages sector, the company operates as a self-owned entity with over 1,000 employees, serving as a top canned food producer in Spain and second in Europe. JEALSA RIANXEIRA S.A. is part of its corporate structure, reflecting its role in the broader manufacturing and engineering landscape of the seafood industry. The company was listed as a ransomware victim associated with the threat actor vicesociety, marking it as an affected entity in recent cyber-threat intelligence reports. |
|||||
| Communications Solutions Company View Details _ | Saudi Arabia | vicesociety | Communication / Marketing | ||
|
Communications Solutions Company is a Saudi Arabian company based in Riyadh, Saudi Arabia. Public business profiles describe it as a communications and telecom-networking services provider specializing in telecommunication and networking field services. The company has operated since 1999 and serves as a specialist in communication services for enterprise and infrastructure environments. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Priority Building Services, LLC View Details _ | vicesociety | Communication / Marketing | |||
|
Priority Building Services, LLC is a commercial janitorial and facilities maintenance company headquartered in Brea, California, serving clients across California, Arizona, and Nevada. The firm provides tailored interior and exterior maintenance solutions for commercial real estate, healthcare, education, and retail sectors. With over three decades of experience, it supports Fortune 500 companies with comprehensive janitorial and landscaping services. Priority Building Services, LLC was listed as a ransomware victim associated with the threat actor vicesociety. |
|||||
| Waikato District Health Board View Details _ | New Zealand | vicesociety | Healthcare / Pharma | ||
|
Waikato District Health Board was a district health board that provided healthcare services to the Waikato region of New Zealand, operating from Hamilton as its headquarters. It offered a range of medical services within the hospital and healthcare sector, including surgical procedures, management of medical conditions, and support for patients during and after hospital stays. The organization also provided guidance on lifestyle factors and managed contractors and car parks while ensuring secure storage for medication and equipment. Waikato District Health Board was formally disestablished on 1 July 2022 when its functions were assumed by Health New Zealand. The board was listed as a ransomware victim associated with the threat actor vicesociety. |
|||||
| Whitehouse Independent School District View Details _ | vicesociety | Education | |||
|
Whitehouse Independent School District is a public school district in Whitehouse, Texas, in Smith County, serving students from pre-kindergarten through grade 12. It operates multiple schools and provides K-12 education and district support services for the local community. Whitehouse ISD is part of the education sector and maintains public-facing finance, enrollment, and school information for families and staff. It was listed as a ransomware victim associated with vicesociety. |
|||||
| SparJames Hall & CompanyHeron and Brearley View Details _ | vicesociety | Healthcare / Pharma | |||
|
SparJames Hall & CompanyHeron and Brearley operates within the Healthcare and Pharma sector, delivering essential health-related products and services. The entity is based in the United Kingdom and focuses on offerings aligned with consumer and pharmaceutical healthcare needs. It was listed as a ransomware victim associated with the threat actor vicesociety. |
|||||
| Higher School of the Public Ministry of the Union View Details _ | vicesociety | Public Sector | |||
|
Higher School of the Public Ministry of the Union is a Brazilian public-sector institution tied to the federal Public Ministry, based in Brazil and focused on training, research, and professional development for legal and public-service audiences. As a higher-education and institutional learning body, it offers courses and educational programs that support the ministry’s work and public-sector capacity building. In threat-intelligence listings, it was identified as a ransomware victim associated with vicesociety. |
|||||
| San Luis Coastal Unified School District View Details _ | vicesociety | Education | |||
|
San Luis Coastal Unified School District is a public school district in San Luis Obispo County, California, serving communities including San Luis Obispo, Morro Bay, Los Osos, and parts of Pismo Beach. It educates students from preschool through grade 12 and also operates an adult school. The district serves roughly 7,500 to 7,741 students across its schools and programs. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Consejo Superior de Investigaciones Cientificas View Details _ | Spain | vicesociety | Public Sector | ||
|
Consejo Superior de Investigaciones Científicas (CSIC) is Spain’s largest public research institution and a state agency focused on scientific and technical research. It is based in Madrid and operates across multidisciplinary institutes and centers throughout Spain, supporting research, collaboration, and technology development. As a public-sector organization, it serves scientific, technological, and advisory functions for the Spanish state. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Family Medicine CentersFMC Clinics View Details _ | vicesociety | Healthcare / Pharma | |||
|
Family Medicine CentersFMC Clinics is a healthcare provider in the United States that offers family medicine and primary care services for patients seeking routine and ongoing medical treatment. Public clinic listings for similarly named FMC locations show outpatient care, wellness visits, chronic-disease management, and same-day appointments in community settings. In healthcare and pharma, family medicine centers typically serve children and adults across general preventive and diagnostic care. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Sae-a View Details _ | cuba | Manufacturing / Engineering | |||
|
Sae-a is a South Korea-based global conglomerate with operations across clothing, food, home, paper and packaging, construction, infrastructure, technology, and cultural industries. Its apparel arm, Sae-A Trading, is a global clothing manufacturer and exporter with production in multiple countries. The group’s business profile places it in manufacturing and engineering-related activities through a broad industrial portfolio and international factory network. It was listed as a ransomware victim associated with cuba. |
|||||
| teknowsource.in View Details _ | India | lockbit3 | NGOs / Associations | ||
|
Teknowsource.in is a management consultancy based in Thane, Maharashtra, India, specializing in staffing, payroll, and team-building services for clients operating in India. The firm assists businesses in setting up captive units, office infrastructure, and acquiring performance teams, serving the NGO and association sector. It operates as a private limited company, Teknowsource Management Consultants Pvt Ltd, with a focus on high-performance team development. The entity was neutrally listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| Xavier University of Louisiana View Details _ | vicesociety | Education | |||
|
Xavier University of Louisiana is a private, historically Black, Catholic university in New Orleans, Louisiana, offering undergraduate and graduate programs across liberal arts, sciences, and professional fields. Its academic divisions include education and counseling, reflecting a broader focus on teaching, research, and student development. The university serves a mostly undergraduate student body in an urban campus setting and is known for its science and professional preparation programs. It was listed as a ransomware victim associated with vicesociety. |
|||||
| JAKKS Pacific Inc View Details _ | hive | Communication / Marketing | |||
|
JAKKS Pacific Inc. is a U.S.-based company headquartered in Santa Monica, California, that designs, develops, produces, and markets toys, games, leisure products, and other consumer products sold worldwide. The company operates as a multi-brand manufacturer and marketer with a broad consumer-facing portfolio. In threat-intelligence catalogs, it is listed as a ransomware victim associated with hive. |
|||||
| Stolle Machinery View Details _ | hive | Manufacturing / Engineering | |||
|
Stolle Machinery is a U.S.-based manufacturing and engineering company headquartered in Centennial, Colorado, with additional operations in Ohio and other global locations. It develops and supports machinery for the can-making industry, including equipment used to produce two-piece cans and ends. The company says it maintains facilities around the world to provide local service and support to customers. It was listed as a ransomware victim associated with hive. |
|||||
| Keralty View Details _ | ransomhouse | Healthcare / Pharma | |||
|
Keralty is a multinational healthcare group based in Colombia that delivers health services through hospitals, outpatient centers, emergency care, dental care, and related provider networks. The company says it operates a comprehensive health model focused on prevention, treatment, and rehabilitation, supported by more than 40 years of experience in care delivery and operations. Its offerings span managed health services and medical care across multiple markets. It was listed as a ransomware victim associated with ransomhouse. |
|||||
| Jeppesen View Details _ | blackbasta | Transportation / Travel / Logistics | |||
|
Jeppesen is a U.S.-based aviation and transportation company headquartered in Denver, Colorado, with additional operations in Gothenburg, Sweden. It provides flight information, navigation data, flight planning, and operations and logistics software and services for airlines and other air operators. The company is a Boeing subsidiary and has long served the global air-transport sector with tools designed to improve efficiency and reliability. Jeppesen was listed as a ransomware victim associated with blackbasta. |
|||||
| The Exchange Bank View Details _ | blackbasta | Finance / Legal / Insurance | |||
|
The Exchange Bank is a U.S. community bank in the Finance / Legal / Insurance sector, serving customers through local branches and standard banking services. Its offerings include deposit accounts and lending, with commercial, residential, and consumer loan options. The bank presents itself as a full-service institution focused on personal and business banking. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Sterling View Details _ | blackbasta | NGOs / Associations | |||
|
Sterling is a nonprofit-focused banking and support brand in Nigeria, known for serving NGOs and associations through fee-free corporate account services and related financial tools for charitable organizations. Its offerings are designed to help nonprofit groups reduce operating costs and manage everyday banking needs more efficiently. Public reporting describes Sterling CARES as a free banking service aimed at legal entities operating for social benefit, with a focus on supporting philanthropy and sustainable development work. Sterling was listed as a ransomware victim associated with blackbasta. |
|||||
| MARK-TAYLOR View Details _ | royal | Communication / Marketing | |||
|
MARK-TAYLOR is a communication and marketing company that provides branding, messaging, and related services for business audiences. Public company materials also place Mark-Taylor, Inc. in the United States, reflecting its commercial footprint in the U.S. market. In a threat-intelligence index, the entity is cataloged under the Communication / Marketing sector. It was listed as a ransomware victim associated with royal. |
|||||
| polyflor.co.nz View Details _ | New Zealand | lockbit3 | Communication / Marketing | ||
|
Polyflor.co.nz operates as a vinyl flooring specialist in New Zealand, offering commercial and residential flooring solutions since launching in Australia and New Zealand in 1963. The company provides tailored flooring products for diverse needs including aged care and commercial projects, with support throughout customer projects. Based in New Zealand, Polyflor.co.nz serves clients across the Communication and Marketing sector with durable vinyl flooring options. The entity was listed as a ransomware victim associated with Lockbit3, reflecting its inclusion in threat-intelligence records of affected organizations. |
|||||
| catalyst-group.co.nz View Details _ | New Zealand | lockbit3 | Services | ||
|
Catalyst Group is a New Zealand services company based in Auckland that provides commercial property solutions, including end-to-end design and build, project delivery, and fit-out consultancy. The company says it has delivered commercial property work nationwide since 1999 and maintains in-house expertise across architects, designers, engineers, builders, and contract managers. Public business listings also place its headquarters in Auckland and identify it as a New Zealand company. It was listed as a ransomware victim associated with lockbit3. |
|||||
| stmc.edu.hk View Details _ | lockbit3 | Education | |||
|
stmc.edu.hk is the website of Sha Tin Methodist College, a government-subsidized secondary school in Sha Tin, Hong Kong, sponsored by the Methodist Church, Hong Kong. Founded in 1983, it serves local students and provides secondary education, with school information, academic details, and contact resources published on its site. The institution operates in Hong Kong’s education sector and is associated with the local school system. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Monte Cristalina S.A. View Details _ | lockbit3 | Other | |||
|
Monte Cristalina S.A. is a Brazil-based manufacturing company, according to business directory and company-profile sources that identify it in the manufacturing sector. Available profiles place the company in Brazil and describe it as a small operating business, but do not provide a detailed public product or service line. The company name is also associated with Brazilian corporate records and directory listings. It was listed as a ransomware victim associated with lockbit3. |
|||||
| jka.co.uk View Details _ | United Kingdom | lockbit3 | Retail / E-commerce | ||
|
jka.co.uk is a retail and e-commerce business operating in Great Britain, offering online shopping services to customers across the UK. The company is based in Great Britain and focuses on delivering retail products through its digital platform. It was listed as a ransomware victim associated with the threat actor lockbit3. |
|||||
| mayflowerdentalgroup.com View Details _ | lockbit3 | Healthcare / Pharma | |||
|
Mayflower Dental Group is a dental care provider in Nova Scotia, Canada, with offices in Sydney, Sydney River, Sydney Mines, North Sydney, and Glace Bay. It offers general dentistry services across multiple locations serving patients in Cape Breton. The practice presents itself as a local provider focused on accessible family dental care. It was listed as a ransomware victim associated with lockbit3. |
|||||
| agriobtentions.com View Details _ | lockbit3 | Agriculture / Food | |||
|
Agri Obtentions is a French seed company based in Guyancourt, France, and a subsidiary of INRAE. Founded in 1983, it develops, promotes, and commercializes varietal innovations for agriculture, including crop and seed solutions for farming systems. Its work supports research-led breeding and the supply of plant varieties to the agricultural and food chain. It was listed as a ransomware victim associated with LockBit3. |
|||||
| womgroup.com View Details _ | India | lockbit3 | Communication / Marketing | ||
|
womgroup.com is the website of Worldwide Oilfield Machine (WOM), a multinational oilfield equipment manufacturer with operations in India and other global locations. The company says it provides custom solutions for drilling, testing, production, and intervention equipment for the upstream oil and gas sector. Its India presence is reflected in its Pune, Maharashtra location and broader manufacturing and engineering footprint. It was listed as a ransomware victim associated with lockbit3. |
|||||
| rgvfirm.com View Details _ | lockbit3 | Finance / Legal / Insurance | |||
|
RGV Firm operates as a Texas trial law firm serving clients in business and commercial litigation, construction industry litigation, insurance litigation, and personal injury matters. Its website and professional listings show a practice centered on insurance and civil disputes, with offices in McAllen, Texas. The firm serves the Finance / Legal / Insurance sector and presents itself as a litigation-focused legal services provider. It was listed as a ransomware victim associated with lockbit3. |
|||||
| businesscentral.org.nz View Details _ | New Zealand | lockbit3 | Services | ||
|
Business Central NZ is a New Zealand business membership association based in Wellington and serving employers and clients across the country. It provides business support services including employment relations advice, human resources consulting, health and safety support, legal guidance, and export services. The organisation also offers an AdviceLine and other member-focused support through its Business Central and Wellington Chamber network. It was listed as a ransomware victim associated with lockbit3. |
|||||
| mercuryit.co.nz View Details _ | New Zealand | lockbit3 | Communication / Marketing | ||
|
Mercury IT is a New Zealand ICT services organisation that provides IT support, IT infrastructure, private and public cloud, cybersecurity, internet services, telecommunications, and software development. It serves organisations across New Zealand from offices in Auckland, Wellington, Hamilton, Christchurch, Tauranga, Queenstown, and Melbourne. The company presents itself as a full-service IT provider for business customers seeking managed technology support. It was listed as a ransomware victim associated with lockbit3. |
|||||
| senateshj.com View Details _ | lockbit3 | Communication / Marketing | |||
|
senateshj.com belongs to SenateSHJ, an Australian communication and public relations consultancy based in Melbourne and Sydney. The firm helps organisations manage reputation, change, and engagement through communication services. Public profiles describe it as one of Australasia’s successful independent consultancies serving clients across the sector. It was listed as a ransomware victim associated with lockbit3. |
|||||
| accuro.co.nz View Details _ | New Zealand | lockbit3 | Communication / Marketing | ||
|
Accuro.co.nz is the website for Accuro, a 100% New Zealand-owned, not-for-profit health insurer now operating under UniMed. It provides health insurance for individuals, families, children, visitors, work visa holders, and businesses, with products such as SmartCare, SmartCare+, KidSmart, SmartStay, StaffCare, and StaffCare+. The company serves members from New Zealand and offers cover and claims support through its member portal and related policy services. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Doctors Center Hospital View Details _ | projectrelic | Healthcare / Pharma | |||
|
Doctors Center Hospital is a healthcare provider in Puerto Rico, with locations in San Juan and Dorado under the Doctors' Center Hospital Orlando Health name. Its facilities offer hospital care and related services such as imaging, laboratory testing, a pharmacy, and other patient services. The organization serves patients across the island through coordinated clinical and support operations. It was listed as a ransomware victim associated with projectrelic. |
|||||
| TLC View Details _ | karakurt | Communication / Marketing | |||
|
TLC is a communication and marketing company based in the United States. Public business listings describe it as a boutique firm that provides marketing consulting and related promotional services to help local businesses connect with customers. In industry directories, TLC is also characterized as offering creative marketing support and communications services. It was listed as a ransomware victim associated with karakurt. |
|||||
| Bevolution Group View Details _ | United States | karakurt | Hospitality / Food & Beverage / Tourism | ||
|
Bevolution Group is a Chicago, Illinois-based food and beverage manufacturer serving the hospitality, foodservice, and tourism markets. It produces beverage solutions including smoothie bases, cocktail mixes, juices, concentrates, and related shelf-stable and frozen products. Public company profiles also describe operations in manufacturing and distribution for institutional and commercial customers. The company was listed as a ransomware victim associated with Karakurt. |
|||||
| OPUS IT Services View Details _ | play | Services | |||
|
OPUS IT Services Pte Ltd is a Singapore-based services company that provides IT services and solutions, with a principal activity in computer and peripheral maintenance and help desk services. Public company profiles also describe its offerings as enterprise IT support outsourcing and customer support. The company is registered in Singapore and operates from Kaki Bukit Avenue 1. It was listed as a ransomware victim associated with play. |
|||||
| H-Hotels View Details _ | play | Hospitality / Food & Beverage / Tourism | |||
|
H-Hotels GmbH is a family-run hotel company with nearly 50 years of experience, operating over 60 properties across Germany, Austria, Switzerland, France, and Hungary. The company manages facilities under its own brands including HYPERION, H4 Hotels, and H2, serving the Hospitality, Food & Beverage, and Tourism sectors. As one of the largest privately managed hotel companies in Germany, it is headquartered in Berlin and was acquired by Berlin-based HR Group in February 2026. H-Hotels was listed as a ransomware victim associated with the Play threat actor. |
|||||
| C???e????? ????????????? View Details _ | play | Other | |||
|
C???e????? ????????????? is an organization in the Other sector, based in South Africa, with activities reflected in its listing name and business profile. Public threat reports describe Play as a ransomware group that targets organizations across sectors and uses double extortion to pressure victims. In this index, C???e????? ????????????? is listed as a ransomware victim associated with Play. |
|||||
| Creta Farm View Details _ | Greece | play | Agriculture / Food | ||
|
Creta Farm is a Greek food company based in Athens, Greece, and it operates in the agriculture and food sector. Company profiles describe it as a producer of packaged food products, including pork meat, cold cuts, and other meat products, and note its food-services activity. It has also been described as a major Greek meat producer. Creta Farm was listed as a ransomware victim associated with play. |
|||||
| Conform View Details _ | royal | Other | |||
|
Conform is an Other-sector company based in the United States. Publicly available search results do not provide enough authoritative detail to verify its specific offerings or operations. Royal is a ransomware variant first observed in 2022 and used against organizations across multiple sectors worldwide. Conform was listed as a ransomware victim associated with Royal. |
|||||
| S?????????? View Details _ | play | Other | |||
|
S?????????? is an Other-sector organization. Publicly available sources in the threat-intelligence record do not provide enough verified detail here to identify its location or offerings without risking speculation. Play is a financially motivated ransomware group known for double-extortion attacks, and this listing records S?????????? as one of its victims. The entry notes S?????????? as a ransomware victim associated with play. |
|||||
| All Seasons Global Solutions View Details _ | royal | Services | |||
|
All Seasons Global Solutions is a Kearny, New Jersey-based services company that provides moving, storage, furniture installation, warehousing, and hospitality project support. Its public materials describe turnkey services for commercial and residential relocations, FF&E work, logistics, and project management. The company operates from 909 Newark Tpke in Kearny and serves clients across related service lines. It was listed as a ransomware victim associated with royal. |
|||||
| Australian Real Estate Group Pty Ltd View Details _ | Australia | bianlian | Construction / Real Estate | ||
|
Australian Real Estate Group Pty Ltd is an Australian company in the Construction / Real Estate sector, with a registered presence in Victoria, Australia. ABN Lookup lists the entity under that name and classifies it as active, indicating it operates as a corporate business in the Australian market. Companies in this sector commonly provide property-related services, development, investment, or project delivery. It was listed as a ransomware victim associated with bianlian. |
|||||
| University Institute of Technology of Paris View Details _ | vicesociety | Education | |||
|
University Institute of Technology of Paris is a French higher-education institution in the education sector, based in Paris. As a university technical institute, it offers post-secondary programs designed to provide professional and technical training linked to specific careers. Its mission emphasizes academic quality, innovation, and professionalization for students. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Arsat View Details _ | play | Other | |||
|
Arsat (Empresa Argentina de Soluciones Satelitales S.A.) is Argentina’s state-owned telecommunications company, headquartered in Benavídez, Buenos Aires Province. It provides satellite communications, operates data centers, and manages the Federal Fiber Optic Network and digital terrestrial television infrastructure. The company supports national connectivity and digital services across Argentina. It was listed as a ransomware victim associated with play. |
|||||
| JMicron View Details _ | play | Other | |||
|
JMicron Technology Corporation is a Taiwan-based fabless IC design company headquartered in Hsinchu Science Park, Hsinchu, Taiwan. Founded in 2001, it develops semiconductor solutions for high-speed data and signal interfaces, including bridge controllers and storage-related chips. The company operates in the Other sector and serves global electronics markets. It was listed as a ransomware victim associated with play. |
|||||
| Mol View Details _ | royal | Other | |||
|
Mol is a business in the Other sector; the available search results do not provide a reliable public profile for its country, offerings, or operating footprint. Because the entity name is not clearly identifiable from the results, no additional company details can be stated with confidence. Royal is a ransomware threat group known for targeting organizations across multiple sectors. Mol was listed as a ransomware victim associated with Royal. |
|||||
| Publicare View Details _ | vicesociety | Public Sector | |||
|
Publicare is a public sector organization in the United States, a category that includes government-run services and institutions that support the public. Public-sector bodies typically provide essential services such as education, transportation, utilities, health, and other civic functions. In this index, Publicare is cataloged as a ransomware victim associated with the threat actor vicesociety. |
|||||
| Spa View Details _ | bianlian | Other | |||
|
Spa is an other-sector entity with no additional public profile provided in the available sources, so its exact location and offerings cannot be confirmed here. BianLian is a highly active ransomware and extortion group that has targeted organizations across multiple sectors, including professional services, manufacturing, healthcare, and property development, with activity reported in North America, Europe, India, and Australia. Public reporting describes BianLian as an extortion-focused actor that pressures victims through data theft and leak-site exposure, rather than relying solely on encryption. Spa was listed as a ransomware victim associated with BianLian. |
|||||
| Company, LLC View Details _ | bianlian | Services | |||
|
Company, LLC is a limited liability company in the Services sector, a business form that separates the company from its owners and is commonly used by small and midsize firms. As an LLC, it operates as a distinct legal entity under state law, with the flexibility and liability protection associated with this structure. Public details on its offerings and location are not available in the provided sources. It was listed as a ransomware victim associated with bianlian. |
|||||
| Q.E.P View Details _ | royal | Communication / Marketing | |||
|
Q.E.P. Co., Inc. is a U.S.-based company headquartered in Boca Raton, Florida, and it presents itself as a global brand serving the home-improvement and flooring market. Its business focuses on tile installation tools and related products, with operations and facilities in the United States, Canada, Europe, and Asia. Public company materials and branding pages also identify marketing communications as a corporate function within the organization. Q.E.P. was listed as a ransomware victim associated with Royal. |
|||||
| The Keenan Agency Inc View Details _ | United States | royal | Communication / Marketing | ||
|
The Keenan Agency Inc is a long-established insurance agency based in Dublin, Ohio, providing commercial and personal insurance solutions to thousands of clients across Central Ohio. Founded in 1938, the agency offers home, auto, business, and renters insurance through partnerships with major carriers like Travelers and Liberty Mutual. It operates as an independent insurance services office serving the Communication and Marketing sector within the US market. The Keenan Agency Inc was neutrally listed as a ransomware victim associated with the threat actor royal. |
|||||
| Lamtec View Details _ | royal | Communication / Marketing | |||
|
Lamtec Corporation is a privately owned building materials supplier based in Mount Bethel, Pennsylvania, in the United States. It describes itself as a global supplier of insulation vapor retarders and facings for leading manufacturers, laminators, and fabricators. Company profiles also place it in wholesale building materials and note its work serves the building products market. In threat-intelligence listings, Lamtec was reported as a ransomware victim associated with Royal. |
|||||
| Naulty, Scaricamazza and McDevitt, LLC View Details _ | United States | royal | Communication / Marketing | ||
|
Naulty, Scaricamazza & McDevitt, LLC is a client-focused regional defense litigation law firm based in Philadelphia, Pennsylvania, serving clients across Pennsylvania, New Jersey, and Delaware. The firm operates in the legal services sector and is described in industry listings as a full-service defense law practice in the Philadelphia metropolitan area. It was listed as a ransomware victim associated with royal. |
|||||
| Cristal Controls View Details _ | royal | Communication / Marketing | |||
|
Cristal Controls is a Quebec-based company that develops energy management, lighting control, temperature control, humidity control, and automation systems for commercial and industrial buildings. Its website says it has operated in Quebec since 1991 and describes solutions for lighting, heating, and energy management, alongside SCR/SSR controllers and related products. Company materials also list an office in Quebec City, Canada, and an online service for selling electronic products and accessories. It was listed as a ransomware victim associated with royal. |
|||||
| M2S Electronics View Details _ | royal | Communication / Marketing | |||
|
M2S Electronics operates in the Communication / Marketing sector and presents supply-chain-focused services through its Canadian business. Its public materials describe customized programs designed to anticipate uncertainty, reduce supply-chain risk, and support inventory planning. The company name is also used in industry pages for electronics-related operations, but the public record provided here is limited. It was listed as a ransomware victim associated with royal. |
|||||
| Los Angeles Business Journal View Details _ | royal | Services | |||
|
Los Angeles Business Journal is a Los Angeles, California-based business news publisher that covers the local economy and provides editorial, research, print, and digital subscription offerings. It operates from Santa Monica Boulevard and publishes business news, lists, and special supplements for readers and subscribers in the region. Its coverage focuses on the companies, industries, and market activity shaping the Los Angeles area. The organization was listed as a ransomware victim associated with royal. |
|||||
| Virginia Farm Bureau View Details _ | royal | Agriculture / Food | |||
|
Virginia Farm Bureau is a Virginia-based organization focused on agriculture and rural communities, with headquarters in Richmond, Virginia. It promotes the future of Virginia agriculture and supports farmers through membership, advocacy, and related services. Its agriculture programs include grain purchasing from Virginia farmers, while its broader family of companies also includes insurance and health-related offerings. Virginia Farm Bureau was listed as a ransomware victim associated with royal. |
|||||
| McAndrews Law Offices View Details _ | royal | Finance / Legal / Insurance | |||
|
McAndrews Law Offices is a Pennsylvania law firm founded in 1982 and based in Berwyn, with a Forest City office also listed in public profiles. The firm provides legal representation in special education, estate planning, elder law, disability matters, and related family-focused services. Its website describes a national practice serving clients across Pennsylvania and nearby states. McAndrews Law Offices was listed as a ransomware victim associated with Royal. |
|||||
| Law Firm of Friedman + Bartoumian View Details _ | United States | royal | Finance / Legal / Insurance | ||
|
The Law Firm of Friedman + Bartoumian is a US-based legal entity operating within the Finance, Legal, and Insurance sectors, specializing in litigation, regulatory, and transactional representation for multinational and Fortune Top 100 clients. The firm offers broad legal expertise including workers' compensation defense, business litigation, insurance law, employment law, and general liability defense. It is headquartered in Agoura Hills, California, and has been recognized for its expertise in insurance law and service to major insurance carriers. The firm was recently renamed to The Law Offices of Heywood G. Friedman, reflecting its evolution while maintaining its core practice areas. The Law Firm of Friedman + Bartoumian was listed as a ransomware victim associated with the royal threat actor. |
|||||
| Tubular Steel Inc View Details _ | Canada | royal | Manufacturing / Engineering | ||
|
Tubular Steel Inc is a steel products company in the manufacturing and engineering sector, headquartered in St. Louis, Missouri, with operations in Canada as listed in this index. It distributes and processes carbon, alloy, and stainless steel pipe, tubing, and bar products for industrial customers, and says it provides tube and pipe solutions that help reduce fabrication and manufacturing costs. Company materials also describe multiple operating sites and a broad inventory of pipe and tube combinations. It was listed as a ransomware victim associated with royal. |
|||||
| RMCLAW View Details _ | royal | Finance / Legal / Insurance | |||
|
RMCLAW appears to operate in the Finance, Legal, and Insurance space in the United States, serving clients where regulatory, contractual, and security controls are critical. Public-facing source material does not provide a reliable description of its specific offerings, so the company is best characterized by its sector and location. In threat-intelligence catalogs, it is indexed because of a ransomware event attribution. RMCLAW was listed as a ransomware victim associated with royal. |
|||||
| Cates Control Systems View Details _ | royal | Services | |||
|
Cates Control Systems is a U.S.-based industrial automation and controls company in the Services sector, headquartered in Plano, Texas. It designs and implements control systems, with offerings that include system integration, panel fabrication, process automation, instrumentation, and control products for manufacturers. The company says it has supported industrial automation and control applications for more than 40 years. It was listed as a ransomware victim associated with royal. |
|||||
| Trussbilt LLC View Details _ | royal | Services | |||
|
Trussbilt LLC is a U.S.-based manufacturer serving the building construction and security market, with headquarters in Vadnais Heights, Minnesota, and operations in Huron, South Dakota. It produces detention and security products, including security wall panels, detention doors and frames, security ceilings, security floors, and related specialty systems for new construction and retrofit projects. The company also provides services for architects and offers design/build support for security-focused applications. Trussbilt LLC was listed as a ransomware victim associated with Royal. |
|||||
| Duplicator Sales & Service View Details _ | royal | Retail / E-commerce | |||
|
Duplicator Sales & Service is a family-owned office technology company based in Louisville, Kentucky, serving Louisville, Lexington, Elizabethtown, and Southern Indiana. Founded in 1959, it provides office equipment, service, supplies, and related print and IT support for businesses and organizations. The company also operates from additional Kentucky locations, including Lexington. It was listed as a ransomware victim associated with royal. |
|||||
| PGT Innovations View Details _ | royal | Other | |||
|
PGT Innovations is a Florida-based manufacturer and supplier in the fenestration and garage door industries, best known for windows and doors. The company was headquartered in Nokomis, Florida, and described its portfolio as focused on impact-resistant and technically advanced products. It operated as a national brand before being acquired by MITER Brands. PGT Innovations was listed as a ransomware victim associated with Royal. |
|||||
| Summit View Details _ | royal | Other | |||
|
Summit Companies is a U.S.-based fire protection and life safety services provider headquartered in Mendota Heights, Minnesota. It operates nationally, serving facilities across industries and regions with fire suppression, alarm, inspection, and related safety services. Public company information describes it as a specialized provider focused on full fire and life safety coverage. It was listed as a ransomware victim associated with royal. |
|||||
| Adams-Friendship Area School District View Details _ | royal | Education | |||
|
Adams-Friendship Area School District is a public K-12 school district located in Friendship, Wisconsin, serving approximately 1,286 students across Adams County with grades from PK to 12. The district operates three schools and provides comprehensive educational programs to its community, with a corporate office at 201 W 6th St in Friendship. It is part of the broader Education sector in the United States, focusing on early literacy and middle school initiatives. Adams-Friendship Area School District was neutrally listed as a ransomware victim associated with the Royal threat actor. |
|||||
| Vincent Fister View Details _ | royal | Services | |||
|
Vincent Fister, Inc. is a family-owned moving and storage company established in 1953, headquartered in Lexington, Kentucky. The firm provides full-service packing, unpacking, crating, and debris removal, with specialized transport for medical centers, schools, and military relocations. It serves residential, commercial, and long-distance clients across Central Kentucky and beyond. Vincent Fister, Inc. was listed as a ransomware victim associated with the royal threat actor. |
|||||
| Leo Hamel Fine Jewelers View Details _ | royal | Other | |||
|
Leo Hamel Fine Jewelers is a jewelry retailer based in San Diego, California, with locations in the San Diego area. Its offerings include vintage and new jewelry, luxury watches, custom designs, jewelry repairs, appraisals, and estate buying. The company has operated in San Diego since 1980 and serves customers through its storefronts and jewelry-buying services. It was listed as a ransomware victim associated with royal. |
|||||
| Gage Brothers View Details _ | karakurt | Other | |||
|
Gage Brothers is a Sioux Falls, South Dakota company known for precast concrete manufacturing and related construction products for commercial and infrastructure projects. The business has operated in Sioux Falls since 1915 and has maintained its plant on North Bahnson Avenue, serving the regional construction market with engineered concrete solutions. Public company information also identifies it as part of the broader concrete manufacturing sector. It was listed as a ransomware victim associated with karakurt. |
|||||
| Rudman View Details _ | bianlian | Other | |||
|
Rudman is a United States business in the broad “Other” sector, but publicly available sources in this search set do not clearly identify its core offerings, so the company should be described conservatively. The name appears in a threat-intelligence context rather than as a widely documented operating brand, and no verified first-party incident details are available here. In cataloging terms, Rudman is treated as a ransomware victim entry for intelligence indexing and entity correlation. It was listed as a ransomware victim associated with bianlian. |
|||||
| Meisenkothen View Details _ | bianlian | Other | |||
|
Meisenkothen refers to Early, Lucarelli, Sweeney & Meisenkothen, a U.S. law firm with offices in New York, New York, and New Haven, Connecticut. The firm focuses on legal services for mesothelioma victims and their families, including asbestos-related claims and related representation. Its practice is centered on plaintiff-side asbestos and mesothelioma matters, making it part of the professional services sector in the United States. It was listed as a ransomware victim associated with bianlian. |
|||||
| Hci Systems Inc View Details _ | United States | bianlian | Services | ||
|
hcisystems.net belongs to HCI Systems, Inc., a California-based services company that operates as a licensed systems integration contractor. The company says it provides fire protection, life safety, security, nurse call, and related services, with headquarters in Ontario and additional California offices. Its offerings include sales, engineering, installation, service, and maintenance for commercial and industrial facilities. It was listed as a ransomware victim associated with bianlian. |
|||||
| Eureka Casino Resort View Details _ | bianlian | Hospitality / Food & Beverage / Tourism | |||
|
Eureka Casino Resort is a hospitality property in Mesquite, Nevada, offering hotel accommodations, a casino, dining, and resort amenities for visitors and local guests. Its website highlights guest rooms, restaurants, special offers, and leisure services, reflecting a tourism-focused entertainment venue. The property is associated with the eurekamesquite.com domain and is located on Mesa Boulevard in Mesquite. It was listed as a ransomware victim associated with bianlian. |
|||||
| Emilio Sanchez American School View Details _ | bianlian | Education | |||
|
Emilio Sanchez American School is a private international school in the education sector, with campuses in El Prat de Llobregat near Barcelona, Spain, and in Naples, Florida, in the United States. It offers an international curriculum, including Advanced Placement programs, and operates within the Emilio Sánchez Academy environment, where sports form part of the school experience. The school presents itself as a cross-border option for students seeking an international education in a bilingual, college-preparatory setting. It was listed as a ransomware victim associated with bianlian. |
|||||
| Aria systems View Details _ | bianlian | Services | |||
|
Aria Systems is a San Francisco, California-based software company in the services sector. It provides Aria Billing Cloud, a SaaS billing automation platform built to support complex usage and subscription business models. The company also promotes related go-to-market services and support through its platform. In threat-intelligence listings, Aria Systems was identified as a ransomware victim associated with BianLian. |
|||||
| CIMT College View Details _ | bianlian | Education | |||
|
CIMT College is a private career college in Ontario, Canada, with campuses in Mississauga, Brampton and nearby Greater Toronto Area locations. Its official site describes diploma programs and certificate courses in business, PSW, IT, healthcare, telecom and trades, serving students seeking job-oriented training. The college presents itself as a registered career college with multiple campus locations and career-focused offerings. It was listed as a ransomware victim associated with bianlian. |
|||||
| ZXP Technologies View Details _ | bianlian | IT | |||
|
ZXP Technologies is a Texas-based company headquartered in Highlands, Texas, that operates in specialty lubricant manufacturing, blending, packaging, and distribution. Public company profiles describe it as a provider of premium lubricant-based products and related supply services for industrial and commercial customers. Its business is listed in the IT sector for this catalog entry, reflecting the indexing framework rather than a public corporate classification. It was listed as a ransomware victim associated with bianlian. |
|||||
| Universidade Catolica Portuguesa View Details _ | vicesociety | Other | |||
|
Universidade Catolica Portuguesa is a prestigious private university established in 1967, headquartered in Lisbon, Portugal, with four campuses across Lisbon, Braga, Porto, and Viseu. The institution offers undergraduate and graduate programs in diverse fields including business, economics, human sciences, political science, and social and cultural communication studies. It is home to 19 faculties, with 8 located at its Palma de Cima campus in central Lisbon, and is recognized as the best university in Portugal for four consecutive years. Universidade Catolica Portuguesa was listed as a ransomware victim associated with the threat actor vicesociety. |
|||||
| mcft.com View Details _ | lockbit3 | Other | |||
|
MCFT is a UK business that specializes in the maintenance, procurement, and servicing of commercial kitchen and refrigeration equipment. Its website describes global commercial kitchen equipment maintenance services and notes a UK head office in Maidenhead, Berkshire. The company says it supports foodservice operators with industry-focused IT solutions and equipment transparency. It was listed as a ransomware victim associated with LockBit3. |
|||||
| Mark-Taylor View Details _ | hive | Other | |||
|
Mark-Taylor is a privately held real estate company based in Scottsdale, Arizona, focused on multifamily development, ownership, investment, and property management. It operates in the residential rental sector and is known for luxury apartment communities across Arizona and other U.S. markets. The company presents itself as a regional developer and manager of premier multifamily communities. It was listed as a ransomware victim associated with hive. |
|||||
| Expand Group View Details _ | hive | Services | |||
|
Expand Group is a Services-sector company based in the United States. Publicly available business context for the name is limited in the provided results, so this listing uses only the confirmed sector and country. It is indexed here for threat-intelligence reference under the Hive ransomware ecosystem. The company was listed as a ransomware victim associated with hive. |
|||||
| Petmate View Details _ | blackbasta | Other | |||
|
Petmate is a Texas-based pet products company headquartered in Arlington, Texas, with a history dating to 1959-1960. It manufactures and markets a broad range of pet supplies, including toys, bowls, collars, leashes, beds, feeders, and other accessories, serving retail partners in the pet care market. Public company materials describe it as a global leader and a leading supplier and manufacturer of pet products. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Ban Leong Technologies Ltd View Details _ | mallox | IT | |||
|
Ban Leong Technologies Ltd is a Singapore-based technology products distributor in the IT sector. It is headquartered at Ubi Biz-Hub on Ubi Avenue 4 in Singapore and distributes IT accessories, multimedia, and data storage products across the region. The company has operated for more than three decades and is listed on the SGX Main Board. It was listed as a ransomware victim associated with mallox. |
|||||
| Batesville Products View Details _ | United States | karakurt | Communication / Marketing | ||
|
Batesville Products, Inc. is a US-based company headquartered in Lawrenceburg, Indiana, that operates as a full-service custom aluminum casting supplier. It produces permanent mold aluminum castings and offers services that include concept support and manufacturing for customer requirements. Public company profiles also describe in-house engineering and metal casting capabilities. In a threat-intelligence index, batesvilleproducts.com was listed as a ransomware victim associated with Karakurt. |
|||||
| Pella View Details _ | United States | blackbasta | Other | ||
|
pellastl.com is a U.S.-based website for Pella Windows & Doors of Greater St. Louis, a local window and door sales and installation business serving the residential building products market. The company promotes replacement and new-construction windows, patio doors, and entry doors for home improvement projects. Its offerings center on product selection, consultation, and installation support for customers in Missouri and the surrounding region. It was listed as a ransomware victim associated with blackbasta. |
|||||
| ITONCLOUD - LEAKED View Details _ | ragnarlocker | IT | |||
|
ITONCLOUD - LEAKED is a threat-intelligence index entry for an IT-sector organization in the United States, presented as a ransomware-victim listing. The name indicates a cloud-related IT business, but public sources in this dataset do not provide a verified corporate profile, product catalog, or service description. Ragnar Locker is a ransomware group known for encrypting systems and threatening data leaks, and its leak-site listings are used to publicize alleged victims. ITONCLOUD - LEAKED was listed as a ransomware victim associated with ragnarlocker. |
|||||
| VFS View Details _ | play | Other | |||
|
VFS Global is a visa and passport administration outsourcing company that serves governments and diplomatic missions worldwide, headquartered in Dubai and Zurich with operations in the United States and beyond. The firm provides comprehensive visa application, passport processing, and related administrative services for diplomatic entities across multiple countries. It operates visa application centers in locations such as Washington, DC, Malawi, and Ethiopia, facilitating visa and residence cases for nations including Norway, Austria, and France. VFS Global is majority owned by Blackstone, the world's largest alternative asset manager, and serves a global clientele in the Other sector. The company was listed as a ransomware victim associated with the threat actor play. |
|||||
| Cetrogar View Details _ | play | Other | |||
|
Cetrogar is an Argentine retail company based in Resistencia, Chaco, with operations in Argentina. It sells technology products, household appliances, and motorcycles through a network of branches and online channels. Company profiles describe it as a retail-sector business founded in 1980 in Chaco. In the threat-intelligence index, Cetrogar was listed as a ransomware victim associated with play. |
|||||
| Modular Mining Systems View Details _ | bianlian | Services | |||
|
Modular Mining Systems is a Tucson, Arizona–based services company that develops and supports mine management technology for the global mining industry. Its offerings include software and systems for fleet management, operations, planning, maintenance, safety, and information management. Public company profiles describe it as a privately held provider of interoperable mining solutions and a subsidiary of Komatsu. It was listed as a ransomware victim associated with bianlian. |
|||||
| BRYCON Construction View Details _ | bianlian | Construction / Real Estate | |||
|
BRYCON Construction is a general contractor founded in 1990 in New Mexico, specializing in cleanroom, warehouse, and industrial building construction across the Southwest. The company operates from Rio Rancho and Albuquerque, offering self-perform teams focused on quality, safety, and reliability for advanced technology projects. BRYCON has grown to be one of the largest industrial contractors in the region, serving clients in construction and real estate sectors. The firm was listed as a ransomware victim associated with the threat actor bianlian. |
|||||
| *****a*** law View Details _ | bianlian | Finance / Legal / Insurance | |||
|
*****a*** law is a U.S.-based firm serving the Finance, Legal, and Insurance sectors, with legal-insurance offerings that can connect individuals and families to attorney networks for advice, document review, and representation. In practice, legal-insurance programs help customers access qualified counsel through prepaid or group plans, often as a workplace benefit. The firm was listed as a ransomware victim associated with bianlian. |
|||||
| veolus.com View Details _ | lockbit3 | Other | |||
|
Veolus is a Mexico-based company with headquarters in México, Distrito Federal, and a listed industry in electric power generation. It describes itself as a 100% Mexican-owned firm that develops, implements, and manages integrated solutions for sustainable growth. Its services include energy generation, energy efficiency, sustainable facility design, and operation and maintenance for infrastructure across multiple sectors. Veolus was listed as a ransomware victim associated with LockBit3. |
|||||
| tdtu.edu.vn View Details _ | Viet Nam | lockbit3 | Other | ||
|
tdtu.edu.vn is the official website of Ton Duc Thang University, a public university in Vietnam. The university is based in Ho Chi Minh City and also operates campuses in Khanh Hoa and Lam Dong provinces. It offers undergraduate, graduate, and international programs across a broad range of disciplines, with some study paths taught in Vietnamese and English. The domain was listed as a ransomware victim associated with lockbit3. |
|||||
| sentecgroup.com View Details _ | lockbit3 | Services | |||
|
Sentecgroup.com is the corporate website of Sentec Group, a Taiwan-based company established in 1968 that serves the automotive, electronics, and semiconductor sectors. The firm, headquartered in Taoyuan City, provides integrated manufacturing solutions including surface mount technology assembly and mechatronics foundry services for OEM partners. With operations spanning Taiwan, India, China, and Thailand, Sentec Group employs over 1,000 people and delivers specialized services to global clients in the motor vehicle parts and energy industries. The company was neutrally listed as a ransomware victim associated with the Lockbit3 threat actor in the threat-intelligence index. |
|||||
| rkfoodland.com View Details _ | India | lockbit3 | Agriculture / Food | ||
|
RK Foodland operates in India’s Agriculture / Food sector as a supply-chain and logistics company for food brands, retailers, QSRs, and related industries. Its website describes cold-chain storage, dry warehousing, distribution, and integrated transport services across a pan-India network. The company presents itself as a technology-driven partner for food distribution and supply-chain management. rkfoodland.com was listed as a ransomware victim associated with lockbit3. |
|||||
| luxeprint.com.tw View Details _ | Taiwan, Province of China | lockbit3 | Communication / Marketing | ||
|
LUXE PRINTING CO., LTD. operates in Taiwan and is based in Taipei. Its company site says it has produced membrane switches, graphic overlays, and touch screens for Taiwan’s industrial field since 1976. The business is associated with the communication and marketing sector through its listed classification and commercial branding. The domain luxeprint.com.tw was listed as a ransomware victim associated with LockBit3. |
|||||
| k-toko.com View Details _ | lockbit3 | Other | |||
|
TOKO CO., LTD. is an industrial machinery manufacturer based in Higashikagawa, Kagawa Prefecture, Japan, with a Tokyo office. The company designs, manufactures, and sells hydraulic cutter systems, vacuum-forming machines, forming machines, punching dies, and related industrial equipment. Its website presents TOKO as a long-established manufacturer serving production and forming applications across industrial use cases. The domain k-toko.com is listed as a ransomware victim associated with lockbit3. |
|||||
| jieh.vn View Details _ | Viet Nam | lockbit3 | Other | ||
|
Jieh.vn is the official website of Japan International Eye Hospital, a private ophthalmology hospital in Hanoi, Vietnam. The hospital, established in 2014 and invested in by Japan-based Paris Miki Holdings, provides eye examinations, treatment, and surgical services. Its published services include refractive surgery, cataract care, and other eye treatments for patients in the capital. It was listed as a ransomware victim associated with lockbit3. |
|||||
| financierareyes.com.mx View Details _ | Mexico | lockbit3 | Other | ||
|
financierareyes.com.mx appears to be a Mexico-based business or service site in the broad “Other” sector, rather than a public-sector or regulated financial institution. The domain name suggests a branded commercial presence in Mexico, but the available evidence does not clearly identify its exact offerings or corporate profile. In threat-intelligence indexing, it is cataloged as a Mexico (MX) entity tied to the wider business landscape. It was listed as a ransomware victim associated with lockbit3. |
|||||
| dof.ca.gov View Details _ | United States | lockbit3 | Other | ||
|
dof.ca.gov is the official website of the California Department of Finance, a US state government agency based in California. The department advises the Governor on fiscal policy and helps prepare, explain, and administer the state budget. Its public services include budgeting, accounting, forecasting, revenue analysis, and related finance guidance for state operations. The entity was listed as a ransomware victim associated with LockBit3. |
|||||
| amazing-global.com View Details _ | Venezuela, Bolivarian Republic of | lockbit3 | Services | ||
|
Amazing Global de Venezuela is a strategic business consulting and services firm located in Caracas, Venezuela, offering digital invoicing solutions, JD Edwards ERP consulting, and advanced infrastructure technologies. As a premier business partner of IBM and Oracle, the company delivers integrated information technology services across software and hardware domains for critical mission platforms. The organization has over 45 years of experience in the Venezuelan market, specializing in hybrid cloud solutions and fiscal compliance optimization. Amazing Global de Venezuela was neutrally listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| 2networkit View Details _ | cuba | Telecommunications | |||
|
2networkit appears to operate in the Telecommunications sector and provides technology-related services, including IT consultation, remote access design and implementation, and web hosting. Publicly available business references also describe 2Networkit as a cloud computing and IT services company. Its profile suggests a communications-focused organization with offerings tied to network support and digital infrastructure. It was listed as a ransomware victim associated with Cuba. |
|||||
| Una Seguros View Details _ | play | Other | |||
|
Una Seguros is an insurance company headquartered in Lisbon, Portugal, specializing in coverage for motorcycles, cars, and other assets. The firm focuses on expanding its customer base and portfolio within the Portuguese insurance sector. It provides tailored insurance solutions to individuals and businesses seeking protection for their vehicles and property. Una Seguros was listed as a ransomware victim associated with the play threat actor. The company operates under the insurance sector with its main office located at Avenida De Berna 24 d, Lisbon. |
|||||
| Antwerpen View Details _ | play | Other | |||
|
Antwerpen is a Belgian city and major port hub in the Port of Antwerp-Bruges, a key center for industry and logistics in northern Europe. The port area is home to Europe’s largest integrated chemical cluster and supports energy, maritime, and industrial activity. Antwerp also serves as a base for environmental, business, and conference operations across the city and port region. In threat-intelligence records, Antwerpen was listed as a ransomware victim associated with play. |
|||||
| REC Silicon View Details _ | ransomexx | Other | |||
|
REC Silicon is a Norway-based silicon materials company that produces high-purity silicon products for the solar and electronics industries. It operates two U.S.-based manufacturing facilities and sales support offices, including a site in Moses Lake, Washington. The company describes itself as a provider of silane gas, polysilicon and related advanced silicon materials for energy and technology customers. It was listed as a ransomware victim associated with ransomexx. |
|||||
| Municipalidad de belen View Details _ | karakurt | Public Sector | |||
|
Municipalidad de Belén is an autonomous territorial institution in Costa Rica that promotes integral and equitable development while administering public services. Located in Belén, it offers essential municipal offerings including service administration and community development programs. The entity operates within the Public Sector, serving residents with efficient and innovative service delivery. Municipalidad de Belén was neutrally listed as a ransomware victim associated with the threat actor Karakurt. |
|||||
| William A. Kibbe & Associates View Details _ | karakurt | Other | |||
|
William A. Kibbe & Associates, Inc. is a professional design firm based in Saginaw, Michigan, with additional offices in Grand Rapids and Traverse City. The company provides architectural, engineering, surveying, energy conservation, and broader design services across disciplines. Its service portfolio includes civil, electrical, mechanical, structural, and BIM-related work for clients in the United States. It was listed as a ransomware victim associated with karakurt. |
|||||
| Infinitum View Details _ | karakurt | Other | |||
|
Infinitum is a Texas-based industrial technology company headquartered in Round Rock, United States. It develops air-core electric motor and fan technologies for commercial HVAC, industrial, and related applications, with a focus on efficiency and reduced energy use. The company was founded in 2016 and markets products for airflow and motor systems across industrial markets. It was listed as a ransomware victim associated with karakurt. |
|||||
| Hiersun Jewelry Co Ltd View Details _ | karakurt | Services | |||
|
Hiersun Jewelry Co Ltd is a Beijing-based jewelry company in China, operating in the luxury goods and jewelry sector. Company profiles describe Hiersun as an established domestic diamond and jewelry business founded in 1999, with offerings that include jewelry products such as diamond and gold pieces. Its business presence is associated with retail and wholesale jewelry activity in the services sector. It was listed as a ransomware victim associated with karakurt. |
|||||
| Energy Transfer Durafin Tubes View Details _ | karakurt | Energy | |||
|
Energy Transfer Durafin Tubes, formerly known as Energy Transfer, is a primary supplier of finned tubes, pipes, and heat exchanger parts located in Minerva, Ohio, within the Energy sector. The company provides heat transfer solutions to the HVAC industry that improve heating and cooling efficiency, prevent system failures and overheating, and ensure compliance with industry standards. Since 1984, it has served as a trusted OEM partner in manufacturing finned and enhanced tubes, with operations entirely based in the United States. In 2022, the company renamed itself Durafin Tube to reflect its corporate focus while continuing its legacy offerings. The entity was listed as a ransomware victim associated with the threat actor karakurt. |
|||||
| KINSHOFER GmbH View Details _ | karakurt | Other | |||
|
KINSHOFER GmbH is a German manufacturer based in Holzkirchen, Bavaria, with headquarters at Raiffeisenstraße 12. It offers attachments for loader cranes, hydraulic excavators, and related equipment, and its group serves construction, landscaping, demolition, recycling, scrap, material handling, foundation, and drilling markets. The company says administration, development, sales, and marketing are based at its Holzkirchen headquarters, with production in Waakirchen-Marienstein. It was listed as a ransomware victim associated with karakurt. |
|||||
| APSM Systems View Details _ | karakurt | Services | |||
|
APSM Systems is a Phoenix, Arizona–based company that provides custom sheet metal fabrication and related manufacturing services, including prototyping, assembly, coating, and circuit board work. Public business profiles also describe it as a contract manufacturer serving industrial and technology-related needs in the Services sector. APSM is associated with operations in the United States and has been reported with a Phoenix address. It was listed as a ransomware victim associated with karakurt. |
|||||
| Latitude 37 View Details _ | karakurt | Other | |||
|
Latitude 37 is an Australia-based luxury home builder headquartered in Melbourne, Victoria. It designs and constructs bespoke residential homes, with a focus on custom projects and complex sites. The company presents itself as a one-stop provider for luxury home design and construction, serving clients across the Melbourne area. Latitude 37 was listed as a ransomware victim associated with karakurt. |
|||||
| South Jersey Glass & Doors View Details _ | karakurt | Other | |||
|
South Jersey Glass & Doors is a New Jersey-based glass and glazing contractor founded in 1927, specializing in commercial and residential glass, windows, doors, and hardware sales and installation. The company operates multiple locations across South Jersey, including Vineland, Glassboro, Berlin, Marmora, and Wildwood, providing 24-hour emergency repair services for buildings. It offers a wide range of building solutions, including custom shower doors, aluminum framing, storefronts, and coastal glass solutions for shore properties. South Jersey Glass & Doors was listed as a ransomware victim associated with the threat actor karakurt. |
|||||
| APECQ View Details _ | karakurt | Other | |||
|
APECQ, the Association patronale des entreprises en construction du Québec, is a bilingual, multisectoral association based in Montreal, Quebec, Canada. It represents and supports construction business leaders and offers services such as business start-up guidance, licensing support, and operational advice for the Quebec construction industry. The organization describes itself as a cross-sector hub for the province’s construction sector and a major business network. It was listed as a ransomware victim associated with karakurt. |
|||||
| Bergamo Metal View Details _ | karakurt | Manufacturing / Engineering | |||
|
Bergamo Metal is a Manufacturing and Engineering company located in Bergamo, Italy, specializing in metal fabrication and precision engineering solutions. The firm offers custom metalworking services, including laser cutting, stamping, and assembly for industrial clients. As part of the regional manufacturing sector, it supports OEMs and engineering projects with high-tolerance components. The company was listed as a ransomware victim associated with the threat actor karakurt, reflecting ongoing cybersecurity risks in the industry. |
|||||
| Metroclean View Details _ | karakurt | Other | |||
|
Metroclean is a Houston-based integrated facility management services provider that delivers commercial custodial, maintenance, and management services for education, healthcare, industrial/manufacturing, commercial, and government clients. The company says its headquarters are at 9000 Southwest Freeway, Suite 412, Houston, Texas, and it also lists operations in Austin and Nashville. Its website describes Metroclean as a full-service provider focused on quality work and customer peace of mind. It was listed as a ransomware victim associated with karakurt. |
|||||
| Davenport Community School View Details _ | karakurt | Education | |||
|
Davenport Community School District is a public school district in Davenport, Iowa, in the United States, serving students from preschool through high school. The district operates 32 schools, including elementary, intermediate, high school, preschool, and alternative education sites, and serves a large K-12 community. It is the third largest school district in Iowa and employs more than 2,000 education professionals. The district was listed as a ransomware victim associated with karakurt. |
|||||
| Qualified Staffing View Details _ | karakurt | Other | |||
|
Qualified Staffing is a U.S.-based recruiting and staffing services company headquartered in Flint, Michigan, with offices across multiple states. Founded in 1988, it provides temporary work, direct placement, executive recruitment, outsourcing, and vendor on-site staffing services. The company serves employers and job seekers through workforce placement and related employment support. It was listed as a ransomware victim associated with karakurt. |
|||||
| Özel GözAkademi Hastanesi View Details _ | karakurt | Other | |||
|
Özel GözAkademi Hastanesi is a healthcare provider in Merkezefendi, Denizli, Turkey, serving patients from its clinic on 29 Ekim Bulvarı. Public listings describe it as a hospital focused on eye health, with ophthalmology care and related medical specialties. The hospital also promotes laser eye surgery and other vision treatments through its own channels. It was listed as a ransomware victim associated with karakurt. |
|||||
| Medilife Hastanesi View Details _ | karakurt | Other | |||
|
Medilife Hastanesi is a private healthcare provider in Istanbul, Türkiye, with facilities in districts including Bağcılar and Beylikdüzü. Its services include hospital-based care, emergency treatment, intensive care, maternity and outpatient medical services. The network’s Bağcılar site opened in December 2014, and its listed contact details place the organization in Istanbul. Medilife Hastanesi was listed as a ransomware victim associated with karakurt. |
|||||
| ipb Baggenstos Montagen View Details _ | karakurt | Other | |||
|
ipb Baggenstos Montagen AG is an architectural and engineering company headquartered in Baar, Switzerland, specializing in installation and maintenance services for the electronics industry. The firm focuses on project, process, and service delivery, including the creation, upkeep, and financing of internal cable television and fiber-to-the-home distribution systems. It operates with fewer than 25 employees and serves commercial and residential construction sectors across Switzerland. The company was listed as a ransomware victim associated with the threat actor karakurt. |
|||||
| The Summit View Details _ | karakurt | Other | |||
|
The Summit Corporation Limited is a privately held Bangladeshi energy and infrastructure group based in Dhaka. It operates across power generation and related industrial infrastructure, and its public profile notes major firsts in the country, including a tank terminal, container terminal, and independent power plant. The company presents itself as part of the private sector with a broad industrial footprint. The Summit was listed as a ransomware victim associated with karakurt. |
|||||
| Urban View Details _ | karakurt | Other | |||
|
Urban is an entity operating in the Other sector, with its primary location in the United States. While specific offerings are not publicly detailed, Urban functions within a broad corporate or organizational framework typical of entities in this classification. The group has been identified as a target of cyber-extortion activities. Urban was listed as a ransomware victim associated with the karakurt threat actor, which primarily targets smaller US-based companies and corporate subsidiaries. |
|||||
| San Benito Consolidated Independent School District View Details _ | karakurt | Education | |||
|
San Benito Consolidated Independent School District is a public school district based in San Benito, Texas, in the United States. It serves students in PK-12 across multiple schools and provides district-wide education services, including administration, instruction, and student support. The district serves a large K-12 enrollment and operates as part of the public education system in its community. It was listed as a ransomware victim associated with karakurt. |
|||||
| Schrader-Pacific International View Details _ | karakurt | Services | |||
|
Schrader-Pacific International, doing business as Schrader Pacific Advanced Valves, is a U.S. company based in Altavista, Virginia, with operations in France. It designs and manufactures specialty fluid-control and air-control valves for automotive and industrial applications, serving customers worldwide. The company presents itself as a long-running supplier of valve technology and related components. It was listed as a ransomware victim associated with karakurt. |
|||||
| Vercity View Details _ | karakurt | Public Sector | |||
|
Vercity is a UK-based public sector services company focused on asset management, transition support, and contract-expiry planning for government and defence clients. It says it manages infrastructure projects across military and civilian headquarters, strategic command facilities, and other public-sector environments. The company also provides tailored services for education and helps public bodies plan service delivery changes. Vercity was listed as a ransomware victim associated with karakurt. |
|||||
| Deerberg View Details _ | karakurt | Other | |||
|
Deerberg is a German lifestyle retail company based in Velgen near Lüneburg, Lower Saxony. It sells women’s apparel and related fashion items, including tops, trousers, jackets, shoes, bags, and accessories, through its retail and online channels. The company has operated since 1986 and serves customers from its headquarters in Germany. Deerberg was listed as a ransomware victim associated with karakurt. |
|||||
| Trantor View Details _ | karakurt | Other | |||
|
Trantor is a technology services company founded in 2011 and headquartered in Menlo Park, California, with additional operations in India, Canada, and Costa Rica. Its services span web and mobile development, cloud, business intelligence, data, testing, and Salesforce consulting, serving clients through a dual-shore delivery model. Public company profiles also describe Trantor Software as developing tools that help lending companies automate loan origination, credit approval, collection, and renewal workflows. Trantor was listed as a ransomware victim associated with karakurt. |
|||||
| R1 Group View Details _ | karakurt | Services | |||
|
R1 Group is an ICT system integrator based in Rome, Italy, with 30 years of experience in the IT industry, offering project management and business process support services. The company operates as a network of specialized firms, including Eurome and Gway, delivering consulting, application world, and operational systems governance solutions. R1 Group was listed as a ransomware victim associated with the threat actor karakurt. |
|||||
| Club Asteria Belek View Details _ | karakurt | Other | |||
|
Club Asteria Belek is a hotel in Belek, Antalya, Turkey, set near the Mediterranean coast in the Üçkum Tepesi area. Travel listings describe it as a beachfront resort with its own beach area, spa facilities, and other guest amenities. The property is marketed as a large holiday complex serving leisure travelers in Turkey’s resort corridor. It was listed as a ransomware victim associated with karakurt. |
|||||
| Cheval Electronic Enclosure View Details _ | karakurt | Other | |||
|
Cheval Electronic Enclosure Co., Ltd. is a Thailand-based manufacturer specializing in the design and production of 19-inch enclosures and racks for data center infrastructure. Founded in 1987, the company operates its primary facility in Bangplee Industrial Estate, Samutprakarn, and has over 30 years of OEM/ODM experience in metal stamping and electronic enclosure solutions. It serves the global data center market with high-quality, configured racks assembled at its warehouse and logistic center. Cheval Electronic Enclosure was listed as a ransomware victim associated with the karakurt threat actor. |
|||||
| Cromwell Management Inc. View Details _ | karakurt | Services | |||
|
Cromwell Management Inc. is a Canadian real estate company headquartered in Montreal that owns, develops, and operates quality assets in major urban centers including Toronto, Montreal, and Quebec City. The company, founded in 1995, has diversified from multi-residential ownership into commercial, industrial, retail, and office properties across Canada. It is a private entity wholly owned by Georges Gantcheff, who has 25 years of experience in real estate investments. Cromwell Management Inc. was listed as a ransomware victim associated with the threat actor karakurt. |
|||||
| Ethigen Limited View Details _ | karakurt | Other | |||
|
Ethigen Limited is a pharmaceutical wholesale company based in East Kilbride, Scotland, with a registered office at 10/16 Colvilles Place. It supplies generic medicines and other pharmacy products to retail pharmacies across the UK and Ireland. Company sources also describe it as a leading UK pharmaceutical distributor with a broad wholesale offering. Ethigen Limited was listed as a ransomware victim associated with karakurt. |
|||||
| Abdullah Al-Othaim Markets View Details _ | karakurt | Retail / E-commerce | |||
|
Abdullah Al-Othaim Markets is a Saudi Arabia-based retail company headquartered in Riyadh. Its core business includes wholesale and retail sales through supermarkets, hypermarkets, and convenience stores, with a broader presence in e-commerce and consumer shopping services. The company operates in the retail and e-commerce sector and serves customers across the Kingdom of Saudi Arabia. It was listed as a ransomware victim associated with karakurt. |
|||||
| Legend Holdings View Details _ | karakurt | Other | |||
|
Legend Holdings is a China-based company primarily engaged in industrial operations, industrial incubations, and investments, with its headquarters located in Beijing. The firm operates as a diversified investment holding company, managing strategic and financial investments across sectors including IT and financial services. Its business model has evolved over more than three decades since starting in the IT industry, establishing an innovative approach to diversified holdings. Legend Holdings was listed as a ransomware victim associated with the threat actor karakurt. |
|||||
| PTSC View Details _ | Viet Nam | karakurt | Energy | ||
|
PTSC, or PetroVietnam Technical Services Corporation, is a Vietnam-based energy services company within the Petrovietnam group. It provides diversified technical services for the petroleum and wider energy sectors, including oil and gas support and offshore renewable energy development. The company is headquartered in Ho Chi Minh City, Vietnam, and describes itself as a leading provider of technical services in Vietnam and the region. PTSC was listed as a ransomware victim associated with karakurt. |
|||||
| Regulatory Authority for Telecommunications and Posts (ARTP) View Details _ | karakurt | Telecommunications | |||
|
Regulatory Authority for Telecommunications and Posts (ARTP) is Senegal’s independent public regulator for the telecommunications and postal sectors, based in Dakar. It has legal personality and financial autonomy, and it issues regulatory decisions, drafts rules, and oversees licensing, equipment, and market competition in communications and posts. As a sector authority, it helps shape fair access and compliance across the telecom environment. It was listed as a ransomware victim associated with karakurt. |
|||||
| Roxboro View Details _ | karakurt | Other | |||
|
Roxboro Excavation Inc. is a construction company based in Dorval, Quebec, specializing in concrete work and earthmoving services. The firm offers site preparation, sewer and aqueduct work, paving, crushing, and asphalt services across Canada. It operates as a key partner in project management with a focus on high-quality machinery and growth strategy. Roxboro Excavation Inc. was listed as a ransomware victim associated with the threat actor karakurt. |
|||||
| Stratus View Details _ | karakurt | Other | |||
|
Stratus is a U.S.-based business associated with the Other sector, with listed locations including Mentor, Ohio, and Rolling Meadows, Illinois. Public company profiles describe it as operating through multiple locations and serving customers as a commercial service provider. Its web presence and organizational details indicate a distributed U.S. footprint rather than a single-site operation. It was listed as a ransomware victim associated with Karakurt. |
|||||
| BauVal View Details _ | karakurt | Other | |||
|
BauVal is a company in the Other sector; public sources used for threat-intelligence indexing do not provide enough verified detail here to identify its precise offerings or headquarters. Karakurt is a data-extortion threat actor known for stealing data and pressuring victims through public-release threats rather than routine file encryption. In catalog context, BauVal is recorded as an affected organization in this ransomware-victim listing. It was listed as a ransomware victim associated with karakurt. |
|||||
| Centrisys cnp View Details _ | karakurt | Other | |||
|
Centrisys/CNP is a Wisconsin-based wastewater treatment equipment provider and manufacturer of decanter centrifuges for industrial and municipal applications. The company is headquartered in Kenosha, Wisconsin, and also operates locations in Stockton, California, and other countries. Its offerings include centrifuge systems, sludge thickening and dewatering equipment, and related service and maintenance. Centrisys CNP was listed as a ransomware victim associated with Karakurt. |
|||||
| KNOX College View Details _ | hive | Education | |||
|
Knox College is a private liberal arts college in Galesburg, Illinois, United States. It serves undergraduate students with a broad liberal arts curriculum and programs that include educational studies for future teaching licensure. The campus is city-based and the college describes itself as nationally ranked and devoted to personalized education. It was listed as a ransomware victim associated with Hive. |
|||||
| koda.com.tw View Details _ | Taiwan, Province of China | lockbit3 | Other | ||
|
KO DA Pharmaceutical Co., Ltd., operating under koda.com.tw, is a Taiwanese pharmaceutical manufacturer established in 1980 that specializes in Chinese herbal extracts, health food supplements, and herbal materials. The company implements strict source management systems, assessing agricultural environments in China and enforcing formal contracts with farmers to ensure quality. Its products meet Taiwan national quality requirements for heavy metals, pesticide residuals, and sulfur dioxide, serving hospitals, dispensaries, and over 80% of domestic TCM medical centers. KO DA Pharmaceutical Co., Ltd. was listed as a ransomware victim associated with LockBit3. |
|||||
| biotipo.com.br View Details _ | Brazil | lockbit3 | Other | ||
|
Biotipo is a Brazilian jeans brand based in São Paulo, Brazil, with retail and wholesale-oriented operations focused on denim apparel. Its catalog highlights jeans for men, women, and plus size customers, and the company presents itself as a manufacturer and seller of clothing. Public contact and store information indicate locations in the Brás district of São Paulo. In threat-intelligence records, biotipo.com.br was listed as a ransomware victim associated with lockbit3. |
|||||
| oltax.com View Details _ | lockbit3 | Other | |||
|
oltax.com appears to be a United States-based online tax-preparation service that offers federal and state filing, with IRS-authorized e-file support and paid assistance options. Public materials for the related OLT brand describe secure online tax return preparation, e-filing, and support for taxpayers. In threat-intelligence indexing, the domain is categorized in the Other sector. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Nexon Asia Pacific View Details _ | nokoyawa | Services | |||
|
Nexon Asia Pacific is an Australia-based digital consulting and managed services provider serving mid-market, enterprise, and government organisations across the country. It offers end-to-end IT services, including cloud, secure networks, unified communications, and managed security, from offices in Sydney and other Australian locations. The company operates in the Services sector and positions itself as a technology partner for improving productivity and continuity. It was listed as a ransomware victim associated with nokoyawa. |
|||||
| rhotelja.com View Details _ | lockbit3 | Hospitality / Food & Beverage / Tourism | |||
|
rhotelja.com is the website of R Hotel Kingston, a hospitality business in Kingston 10, Jamaica, at 2 Renfrew Road. The hotel presents itself as a leisure, business, and extended-stay property with 48 rooms and suites, plus dining and event services. Its offerings include accommodations, reservations, and Caribbean-fusion and international dining at District 5 Restaurant and a poolside sky lounge. The site and company materials place it in the hospitality sector serving travelers, business guests, and local diners. It was listed as a ransomware victim associated with lockbit3. |
|||||
| hawanasalalah.com View Details _ | lockbit3 | Other | |||
|
hawanasalalah.com is the website for Hawana Salalah, a tourism and hospitality destination in Dhofar, Oman, promoted as a large and fast-growing community with freehold homes and hotels. Public-facing materials show hotel reservations and hospitality services tied to the Hawana Salalah brand. The site also references a hospitality training center, indicating broader tourism development activity in the Salalah area. It was listed as a ransomware victim associated with lockbit3. |
|||||
| Maney | Gordon | Zeller, P.A. View Details _ | blackbasta | Communication / Marketing | |||
|
Maney | Gordon | Zeller, P.A. is an immigration law firm serving clients nationwide, with offices in Tampa, Florida, and Philadelphia, Pennsylvania. The firm describes more than 100 years of combined legal experience and offers legal help for visas, naturalization, and other immigration matters. Its public contact information also lists additional Florida locations in Tampa, Dade City, and Orlando. The firm was listed as a ransomware victim associated with blackbasta. |
|||||
| Atcore View Details _ | blackbasta | Other | |||
|
Atcore is a United Kingdom-based travel technology company that provides reservation, booking, e-commerce, and related software services for the leisure travel industry. It is headquartered in Slough, Berkshire, and its offerings are described as specialist products and services for travel operators and agencies. The company is positioned in the broader software sector, with a focus on travel infrastructure and service delivery. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Dingbro Ltd View Details _ | blackbasta | Services | |||
|
Dingbro Ltd is a family-owned Aberdeen-based UK company in the services sector, operating as a trade-only distributor of automotive components and related supplies. It serves the motor trade, truck and plant operators, offshore industry, oil service companies, marine engineers, and shipping customers across Scotland and nearby regions. Founded in 1973, Dingbro is described as Scotland’s largest independent motor factoring group. It was listed as a ransomware victim associated with blackbasta. |
|||||
| A.R. Thomson Group View Details _ | blackbasta | Services | |||
|
A.R. Thomson Group Inc. is a leading Canadian supplier of mechanical seals, gaskets, and instrumentation valves and fittings, operating 11 branches across the country. The company designs and manufactures industrial metallic and non-metallic gaskets, pump packing, and fluid containment products for diverse industries including oil and gas. Based in Surrey, British Columbia, it serves clients with high-quality sealing solutions and seal repair services backed by over 30 years of experience. A.R. Thomson Group was listed as a ransomware victim associated with the threat actor blackbasta. |
|||||
| Cleveland Brothers View Details _ | blackbasta | Other | |||
|
Cleveland Brothers Equipment Co. is a Pennsylvania-based industrial machinery company headquartered in Murrysville, with branch locations across Pennsylvania, West Virginia, and Maryland. Founded in 1948, it serves construction, mining, forestry, and agricultural customers with Cat equipment sales, rentals, parts, service, and related support. Its regional network includes sales and service operations for equipment users across the Keystone and Panhandle states. It was listed as a ransomware victim associated with blackbasta. |
|||||
| AIRCOMECHANICAL View Details _ | blackbasta | Energy | |||
|
AIRCOMECHANICAL is a mechanical contractor serving commercial and industrial customers in the energy-adjacent building services space. Public company listings describe Airco Mechanical, Inc. as a Sacramento, California firm focused on HVAC, plumbing, piping, and building control systems, while Airco Mechanical Services in Florida provides commercial HVAC and plumbing services. In Northern California, the company says it delivers cost-effective, energy-efficient mechanical systems for commercial and industrial facilities. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Panolam Surface Systems View Details _ | blackbasta | Communication / Marketing | |||
|
Panolam Surface Systems is a Shelton, Connecticut-based manufacturer and supplier of integrated surface solutions for building and interior applications. The company says it has provided surface products for more than 70 years, including high-pressure laminates, thermally fused laminates, fiberglass reinforced laminates, and related specialty offerings. Its product line serves commercial and other building-materials use cases, and company profiles place it in the wholesale building materials and building products sector. It was listed as a ransomware victim associated with blackbasta. |
|||||
| SEACAST View Details _ | blackbasta | Manufacturing / Engineering | |||
|
SeaCast is a manufacturing company based in Marysville, Washington, in the United States. It specializes in high-precision investment castings and machined parts, serving aerospace, military, industrial, medical, transportation, and related sectors. The company also describes itself as an AS9100-certified manufacturer with deep experience in manufacturing engineering and investment-casting production. It was listed as a ransomware victim associated with blackbasta. |
|||||
| nworksllc View Details _ | blackbasta | Services | |||
|
nworksllc is a Services-sector business in the United States; available public records do not clearly identify a single official company profile, offering, or headquarters for this exact name. In threat-intelligence listings, it appears as an indexed business entity rather than as a publicly documented brand with confirmed operational details. Its presence is noted in a ransomware-victim context associated with blackbasta. It was listed as a ransomware victim associated with blackbasta. |
|||||
| ChemiFlex View Details _ | quantum | Other | |||
|
ChemiFlex is an industrial machinery manufacturer based in Lombard, Illinois, in the United States. The company says it designs, engineers, and manufactures polyurethane and silicone timing belts, serving sectors including medical, electronics, automotive, machinery, food and beverage, and pharmaceutical. Company profiles also describe it as a long-running supplier of custom and precision timing-belt solutions. ChemiFlex was listed as a ransomware victim associated with quantum. |
|||||
| Radical Sportscars View Details _ | quantum | Other | |||
|
Radical Sportscars, formerly Radical Sportscars, is a British racing and high-performance sports car manufacturer founded in 1997 by racing driver Mick Hyde and automotive engineer Phil Abbott in Cambridgeshire, England, now headquartered in Peterborough. The company produces purpose-built racing cars, delivering over 3,000 units since inception and manufacturing around 230 cars annually, ranking as the second largest volume producer of purpose-built racing cars globally, just behind Porsche. Radical offers single-marque race series, track day experiences, and road and race cars designed for high-speed performance on the track. The company was listed as a ransomware victim associated with the threat actor quantum. |
|||||
| Orotex View Details _ | quantum | Other | |||
|
Orotex is a mechanical and industrial engineering company based in Farmington Hills, Michigan, with operations tied to automotive manufacturing. Its website describes it as a global plastic injection manufacturer producing noise and anti-vibration control components for Tier-1 automotive customers. Public company profiles also link Orotex to parent-company operations in Japan and to a U.S. presence in Michigan. It was listed as a ransomware victim associated with quantum. |
|||||
| Acquarius Trust Group View Details _ | quantum | Services | |||
|
Acquarius Trust Group is a private client and corporate services firm based in Gibraltar. It provides trustee, company management, fiduciary, accounting, tax, payroll, and pension scheme administration services to private and corporate clients. The company is licensed and regulated by Gibraltar’s Financial Services Commission. It operates from Icom House on Irish Town in Gibraltar. It was listed as a ransomware victim associated with quantum. |
|||||
| Pilenpak View Details _ | quantum | Other | |||
|
Pilenpak is an Other-sector company in the country, and available public sources do not provide enough reliable detail here to confirm its exact offerings or operating profile. In threat-intelligence catalogs, it is identified by name as a corporate entity rather than a consumer brand, so the listing is best read as an organizational reference. Public reporting on Quantum describes a ransomware operation active in the early 2020s and associated with fast intrusion-to-encryption campaigns. Pilenpak was listed as a ransomware victim associated with quantum. |
|||||
| AHT Wisconsin Windows View Details _ | quantum | Energy | |||
|
AHT Wisconsin Windows is a family-owned home improvement company based in Wisconsin that specializes in high-efficiency replacement windows and doors engineered for the state's extreme climate. The company serves residents across Clintonville, Appleton, Madison, and Green Bay, offering triple-pane, solid-core composite windows designed to resist warping, cracking, and energy loss. Its core offerings focus on energy-efficient solutions that help homeowners lower utility costs while maintaining comfort in harsh weather conditions. AHT Wisconsin Windows was listed as a ransomware victim associated with the threat actor quantum. |
|||||
| ??????? View Details _ | play | Other | |||
|
??????? is an organization in the Other sector with publicly available details not provided in the available sources. Play, also known as PlayCrypt, is a ransomware group that targets organizations worldwide through credential-based intrusions, data theft, and file encryption. It has affected victims across multiple industries and regions, including North America, South America, and Europe. ??????? was listed as a ransomware victim associated with Play. |
|||||
| Hilldrup View Details _ | play | Other | |||
|
Hilldrup is a family-owned American moving, storage, relocation, logistics, and workplace solutions company founded in 1903. It is headquartered in Stafford, Virginia, and operates multiple branch locations across the Mid-Atlantic and Southeast, serving residential, corporate, government, military, and employee mobility clients. The company describes itself as a long-established provider of moving and storage services with logistics support. It was listed as a ransomware victim associated with play. |
|||||
| New Partners View Details _ | vicesociety | Other | |||
|
New Partners Inc. is a New York City nonprofit organization in the Other sector, and Candid identifies it as a 501(c)(3) public charity. It is based in New York, New York. Public profile details confirm the entity name and location, but do not describe a commercial product line or service portfolio beyond its charitable status. In threat-intelligence records, New Partners was listed as a ransomware victim associated with vicesociety. |
|||||
| ???? View Details _ | play | Other | |||
|
???? is an entity in the Other sector, and its specific public profile is not available from the provided sources. The listing indicates it operates in the country associated with the record, but no additional verified details about its offerings or business line are available here. Play is a ransomware group that targets organizations across many sectors with double-extortion attacks, stealing data and encrypting systems to pressure victims. ???? was listed as a ransomware victim associated with play. |
|||||
| Albina Asphalt View Details _ | lorenz | Other | |||
|
Albina Asphalt is a construction-sector company based in Vancouver, Washington, with operations tied to Oregon and West Coast markets. It manufactures and distributes asphalt-related products, including road and paving materials, serving contractors and infrastructure customers. Company contact information lists its headquarters in Vancouver and identifies plant locations supporting its asphalt supply business. Albina Asphalt was listed as a ransomware victim associated with lorenz. |
|||||
| test View Details _ | monti | Other | |||
|
test is a company in the Other sector, but no reliable public source in the provided results identifies its location, offerings, or business profile with enough certainty to describe them accurately. Available reporting on Monti shows the group targeting organizations across legal, financial services, healthcare, and government sectors, with victims appearing on its leak site since 2022. Monti is a ransomware collective first identified in June 2022 after Conti's shutdown, and its activity has included Linux and VMware ESXi-focused variants. test was listed as a ransomware victim associated with monti. |
|||||
| Skoda Praha View Details _ | play | Communication / Marketing | |||
|
Skoda Praha is a Czech company operating in the communication and marketing sector, with business activity centered in Prague, Czech Republic. Its work appears to focus on marketing communications, brand promotion, and related digital or campaign services for clients and partners. Public references indicate a Prague-based presence and an emphasis on communication and marketing offerings. It was listed as a ransomware victim associated with play. |
|||||
| MME Group View Details _ | play | Services | |||
|
MME Group is a services-sector contract manufacturer based in St. Paul, Minnesota. It provides full-service production support, including engineering, tooling, molding, assembly, and supply-chain management for regulated and consumer markets. Public company profiles also describe it as an injection molder and box-build manufacturer serving medical, government, and consumer products customers. It was listed as a ransomware victim associated with Play. |
|||||
| Highwater Ethanol View Details _ | play | Other | |||
|
Highwater Ethanol, LLC is a fuel ethanol production facility located in Lamberton, Minnesota, operating within the energy sector as part of the oil and gas refining industry. The company produces and sells fuel ethanol along with co-products from the ethanol manufacturing process, utilizing third-party professional marketers for distribution. It is a 70 million gallon ethanol facility situated one mile west of Lamberton along US Highway 14. Highwater Ethanol was formed in May 2006 and reached actual production three years after its establishment. The company was listed as a ransomware victim associated with the play threat actor. |
|||||
| Wrota Mazowsza View Details _ | play | Other | |||
|
Wrota Mazowsza is the Mazovia region’s public spatial-information and e-services portal, operated from Warsaw by the regional geodesy and digitalization administration. It helps residents, businesses, offices, and investors access maps, land, buildings, roads, rail data, and other electronic public services. The portal is part of a wider regional GIS environment serving local government users across Mazovia. It was listed as a ransomware victim associated with play. |
|||||
| UJV Rez View Details _ | play | Other | |||
|
UJV Rez, a.s. is a Czech company based in Řež, near Prague, that provides engineering, research, and technical services for the energy, industry, and health sectors. It is known for applied research and development, with a long-standing focus on nuclear technology and support for power-plant safety and reliability. The company describes itself as one of the Czech Republic’s leading technology centers. It was listed as a ransomware victim associated with play. |
|||||
| ????????? ???? ????? View Details _ | play | Other | |||
|
????????? ???? ????? cannot be reliably identified from the available search results, which show only placeholder characters and no verifiable company profile. Based on the listing context, it is categorized in the Other sector, but no confirmed location, offerings, or public corporate details are available here. The entity was listed as a ransomware victim associated with play. |
|||||
| Feu Vert View Details _ | vicesociety | Other | |||
|
Feu Vert is a French automotive retail and service company founded in Lyon in 1972, known for car maintenance, repairs, and a wide range of auto products. It operates a network of more than 450 maintenance and repair centres across France, Spain, and Portugal, with headquarters in Boves, Hauts-de-France. The group serves motorists through workshops and retail offerings tied to vehicle upkeep and accessories. Feu Vert was listed as a ransomware victim associated with vicesociety. |
|||||
| g4s.com View Details _ | lockbit3 | Other | |||
|
g4s.com belongs to G4S, a British multinational private security company headquartered in London, England. The company provides integrated security services, including guarding, monitoring, and response solutions, and operates in more than 100 countries and territories. Its business spans physical security and related outsourced services for commercial and public-sector clients. The site was listed as a ransomware victim associated with LockBit3. |
|||||
| amundson.co.nz View Details _ | New Zealand | lockbit3 | Other | ||
|
Amundson & Amundson is a New Zealand business communications company that provides professional answering services for clients in New Zealand and abroad. Its offerings include telephone, email, internet-based, and 24/7 message-handling support for businesses. The company describes a team of 40 trained telephone operators and positions its services around call answering and overflow support. It was listed as a ransomware victim associated with LockBit3. |
|||||
| myersontooth.com View Details _ | lockbit3 | Other | |||
|
myersontooth.com is the website of Myerson, a Chicago-based dental manufacturing company founded in 1917. It makes dental materials, denture teeth, and related equipment for removable prosthetics and digital dentistry. The company describes itself as a global manufacturer serving dental professionals and operating from its headquarters in Chicago, Illinois, with additional international locations. In threat-intelligence catalogs, myersontooth.com is listed as a ransomware victim associated with lockbit3. |
|||||
| PANOLAM View Details _ | blackbasta | Other | |||
|
PANOLAM Surface Systems is a Shelton, Connecticut-based manufacturer of integrated surface solutions in the wholesale building materials sector. The company offers decorative and specialty laminate products, including high-pressure laminates, thermally fused laminates, and fiberglass reinforced laminates, through North American manufacturing and distribution operations. Its portfolio includes Panolam, Nevamar, and Pionite brands used in commercial and architectural applications. PANOLAM was listed as a ransomware victim associated with blackbasta. |
|||||
| CIBTvisas View Details _ | play | Other | |||
|
CIBTvisas is a travel and immigration services provider that expedites passports and visas for business and leisure travelers. It describes itself as a leading global provider of visa and immigration solutions, with operations across the Americas, Europe, the Middle East and Africa, and Asia Pacific. The company is headquartered in McLean, Virginia, United States. It was listed as a ransomware victim associated with play. |
|||||
| INTERSPORT France View Details _ | hive | Other | |||
|
INTERSPORT France is a French sporting goods retailer based in Longjumeau, near Paris, and part of the wider INTERSPORT network. It distributes sports apparel, footwear, equipment, and related leisure products through a national retail and logistics footprint in France. Founded in 1924, the company serves consumers and sports clubs across the country. It was listed as a ransomware victim associated with hive. |
|||||
| Advanced Micro Devices, Inc View Details _ | ransomhouse | Services | |||
|
Advanced Micro Devices, Inc. (AMD) is a U.S.-based semiconductor company headquartered in Santa Clara, California. It designs and sells microprocessors, graphics processors, chipsets, and related computing products for data center, client, gaming, and embedded markets. The company serves global customers across enterprise, consumer, and cloud computing environments. Advanced Micro Devices, Inc. was listed as a ransomware victim associated with ransomhouse. |
|||||
| Fairfax - Crum & Forster View Details _ | ransomhouse | Other | |||
|
Fairfax - Crum & Forster is part of Fairfax Financial Holdings Limited, a holding company focused on property and casualty insurance, reinsurance, and investment management. Crum & Forster is headquartered in Morristown, New Jersey, and operates as a national property, casualty, and accident & health insurer offering specialty insurance products. It is an established U.S. insurance brand within the Fairfax group. It was listed as a ransomware victim associated with ransomhouse. |
|||||
| Ipca Laboratories View Details _ | ransomhouse | Other | |||
|
Ipca Laboratories is an Indian pharmaceutical company based in Mumbai, Maharashtra, with operations in pharmaceuticals and active pharmaceutical ingredients. It develops and manufactures branded and generic medicines, bulk drugs, and formulations for domestic and export markets, supported by multiple manufacturing sites. Public company materials also note its own API manufacturing and a focus on generic formulations and emerging markets. It was listed as a ransomware victim associated with ransomhouse. |
|||||
| Carmen Copper Corporation View Details _ | ransomhouse | Services | |||
|
Carmen Copper Corporation is a Philippine mining company in the services sector, based in Toledo City, Cebu, and a significant subsidiary of Atlas Consolidated Mining and Development Corporation. It operates the Toledo copper mine and is engaged in metallic mining, mineral exploration, and development. Public company references also describe its community and sustainability programs tied to local operations in Cebu. It was listed as a ransomware victim associated with ransomhouse. |
|||||
| ROFA INDUSTRIAL AUTOMATION View Details _ | ransomhouse | Manufacturing / Engineering | |||
|
ROFA INDUSTRIAL AUTOMATION AG is a Germany-based industrial automation company headquartered in Kolbermoor, Bavaria, and it develops and realizes turnkey production plants and material-handling solutions for customers worldwide. Its profile and business listings describe it as a manufacturer and automation machinery provider with research, development, and service capabilities. The ROFA Group also operates international sites, including in China and the United States, to support its industrial systems business. It was listed as a ransomware victim associated with ransomhouse. |
|||||
| ADATA Technology View Details _ | ransomhouse | IT | |||
|
ADATA Technology Co., Ltd. is a Taiwanese fabless hardware manufacturer founded in May 2001, specializing in the design and distribution of high-performance memory and storage solutions. The company is the world's second-largest DRAM module provider and offers products including DRAM modules, USB flash drives, SSDs, HDDs, and DDR5 memory. Based in New Taipei City, ADATA serves global markets with branded SSD modules and external storage devices, ranking among the top 25 Best Taiwan Global Brands. ADATA Technology was neutrally listed as a ransomware victim associated with the threat actor ransomhouse. |
|||||
| Severn Glocon Group View Details _ | ransomhouse | Services | |||
|
Severn Glocon Group is a UK-based industrial valve manufacturer in the services sector, focused on severe-service and engineered flow-control solutions. It designs and supplies control valves, chokes, butterfly valves, and related products for energy-industry applications, including refining, LNG, power, and subsea use. The company has operations in Gloucester, England, and serves industrial clients through valve engineering, manufacturing, and support services. It was listed as a ransomware victim associated with ransomhouse. |
|||||
| SMB Solutions View Details _ | ransomhouse | Services | |||
|
SMB Solutions Cloud Services is a family-owned business based in Australia that has operated for over 15 years, providing expert cloud solutions tailored for small and medium businesses. The company specializes in hosting SAP Business One Cloud solutions in constantly monitored, off-site locations, offering scalable and secure technology services to optimize client operations. As a key player in the Services sector, SMB Solutions delivers integrated voice and data communication solutions designed for businesses of all sizes. The organization was neutrally listed as a ransomware victim associated with the threat actor ransomhouse. |
|||||
| BRYCON Construction View Details _ | ransomhouse | Construction / Real Estate | |||
|
BRYCON Construction is headquartered in Rio Rancho, New Mexico, and operates across Arizona, New Mexico, Nevada, and other states in the United States. The company delivers specialized, self-perform construction services for complex facilities and technical environments, including phased tenant improvements and cleanroom construction. With in-house teams and a roster of seasoned subcontractors, BRYCON serves as a one-stop contracting source for owners in the Construction and Real Estate sector. The firm was listed as a ransomware victim associated with the threat actor ransomhouse. |
|||||
| prinovaglobal.com View Details _ | lockbit3 | Communication / Marketing | |||
|
Prinovaglobal.com serves as the digital platform for Prinova, a leading global supplier of ingredients and premix manufacturing solutions for the food, beverage, and nutrition industries. The company operates headquarters in London, United Kingdom, and Itasca, Illinois, USA, delivering aromas, essential oils, nutrient premixes, and market-ready blends. Prinova provides customized services to transform client visions into market-ready products with expert concept-to-launch support. The organization was listed as a ransomware victim associated with Lockbit3. |
|||||
| littleswitzerland.com View Details _ | lockbit3 | Other | |||
|
Little Switzerland is a luxury jewelry and watch retailer serving the Caribbean, with stores and branded boutiques in locations including St. Thomas, Puerto Rico, Aruba, Nassau, St. John, Tortola, and the Dominican Republic. The company offers fine jewelry, luxury timepieces, duty-free shopping, and online ordering with in-store pickup at select locations. Its website also highlights financing options and a Rolex showroom in San Juan. The company was listed as a ransomware victim associated with lockbit3. |
|||||
| Glutz View Details _ | vicesociety | Other | |||
|
Glutz is a Swiss company in the other sector, based in Solothurn, and best known for security and access solutions such as locks, fittings, door hardware, and related building components. Its products are used in commercial and institutional environments where controlled access and durable construction hardware are required. In threat-intelligence records, Glutz appears as a ransomware victim associated with vicesociety. |
|||||
| Bonn Nutrients Pvt View Details _ | bianlian | Other | |||
|
Bonn Nutrients Pvt. Ltd. is a Ludhiana, Punjab-based food and beverage company within the Bonn Group of Industries, known for bakery and biscuit manufacturing. Company listings place it at Jhabewal on Chandigarh Road in Ludhiana, where it operates as part of a larger regional food business. The firm is associated with Bonn’s broader consumer foods portfolio and industrial operations in Punjab. It was listed as a ransomware victim associated with BianLian. |
|||||
| Golden Coin Bake Shop and Restaurant View Details _ | bianlian | Retail / E-commerce | |||
|
Golden Coin Bake Shop and Restaurant operates within the Retail and E-commerce sector, specializing in baked goods, delicatessen, and food offerings for online and local customers. Based in the United States, the establishment provides a range of baked products and food items through both physical storefronts and virtual shelves for e-commerce buyers. The business has grown alongside the booming online retailing of food and delicatessen, leveraging digital channels to extend its product selection. Golden Coin Bake Shop and Restaurant was listed as a ransomware victim associated with bianlian. |
|||||
| Ability Commerce View Details _ | bianlian | Retail / E-commerce | |||
|
Ability Commerce is a privately held company headquartered in Delray Beach, Florida, United States, specializing in direct commerce retail platforms and software solutions. The firm offers an Order Management System called Ability OMS that helps mid-sized retailers manage orders, inventory, fulfillment, and customer data across ecommerce channels, marketplaces, and call centers. Its integrated suite combines order management, point-of-sale, web store capabilities, and digital marketing services to support growing multi-channel retail businesses. Ability Commerce was listed as a ransomware victim associated with the threat actor bianlian. |
|||||
| CROWN TECHNOLOGY Ltd View Details _ | bianlian | IT | |||
|
CROWN TECHNOLOGY Ltd is a United Kingdom-registered company in the IT sector, with a registered office in Potters Bar, Hertfordshire. Companies House lists its nature of business under SIC 7222, indicating computer consultancy activities. Publicly available records do not provide a fuller product or services profile in the search results. The company was listed as a ransomware victim associated with bianlian. |
|||||
| IM Group View Details _ | bianlian | Services | |||
|
IM Group Services is the UK's largest family-owned shopping management company, headquartered in Manchester, England. The firm manages a growing portfolio of shopping centres and works with retailers on both local and national levels. It operates within the services sector, providing property management and retail support across the country. The company was listed as a ransomware victim associated with the threat actor bianlian. |
|||||
| *u**** View Details _ | bianlian | Other | |||
|
u**** operates in the Other sector with no specific geographic location or defined offerings publicly documented. The entity lacks verifiable details on its business scope, industry focus, or operational footprint. It was listed as a ransomware victim associated with the BianLian threat actor, known for targeting diverse industries globally. BianLian, a GoLang-based ransomware group active since 2022, employs double-extortion and data theft tactics. u****'s inclusion reflects the group's broad victim selection without sector discrimination. |
|||||
| ****** ******* School View Details _ | bianlian | Education | |||
|
****** ******* School is a K-12 educational institution operating within the Education sector in the United States, providing instruction and training to students across elementary, middle, and high school levels. The school delivers foundational learning, early childhood education, and skill-based curricula aligned with national educational standards, serving students and families in its local community. As part of the public elementary and secondary education industry, it functions as a cornerstone of the formal education structure, ensuring students receive the education they need and deserve. The institution was listed as a ransomware victim associated with the threat actor Bianlian. |
|||||
| AV Solutions View Details _ | bianlian | Services | |||
|
AV Solutions is a services-sector company in the United States that provides audiovisual support for meetings and events, including conference-room technology, design services, engineering support, and related service work. Public business listings place its Baton Rouge, Louisiana office at 2631 Bernwood Drive, and describe its focus as helping customers run reliable AV environments and live collaboration spaces. The company’s offerings center on practical AV integration and support rather than a product catalog. It was listed as a ransomware victim associated with BianLian. |
|||||
| *** Technologies View Details _ | bianlian | IT | |||
|
*** Technologies is an IT-sector company in the United States that provides technology-related services and support. Public threat-intelligence reporting links BianLian to attacks on organizations in the IT sector, alongside other business services targets. BianLian is widely tracked as a ransomware and data-extortion group active since 2022 and known for targeting organizations across North America and beyond. *** Technologies was listed as a ransomware victim associated with BianLian. |
|||||
| **i* **s**** View Details _ | bianlian | Other | |||
|
i* s* operates within the Other sector, with no specific geographic location or defined public offerings disclosed in available records. The entity functions as a general organization without sector-specific details on its primary activities or service portfolio. Despite limited public information, i* s* was identified as a victim in a ransomware attack linked to the Bianlian threat actor. Bianlian is a GoLang-based ransomware group known for double extortion, targeting industries including healthcare, manufacturing, and legal services primarily in North America. i* s* was listed as a ransomware victim associated with Bianlian. |
|||||
| **a***** H****** ******r**** View Details _ | bianlian | Other | |||
|
a***** H****** ******r**** is an Other-sector organization based in the United States, but no reliable public source in the search results identifies its specific offerings or line of business. Public threat-intelligence coverage on BianLian describes it as a ransomware and data-extortion group active since 2022, known for targeting a range of sectors and often using leak-site pressure. In threat-intelligence indexing, this entry identifies a***** H****** ******r**** as a ransomware victim associated with BianLian. |
|||||
| B****** *b* View Details _ | bianlian | Other | |||
|
B****** *b* is an entity in the Other sector, operating in its home country and offering services or operations associated with that line of business. Publicly available details are limited, so this listing reflects the organization as identified in threat-intelligence records rather than a detailed corporate profile. BianLian is a ransomware and extortion group known for targeting organizations across multiple industries and regions. B****** *b* was listed as a ransomware victim associated with bianlian. |
|||||
| Austria Presse Agentur View Details _ | play | Communication / Marketing | |||
|
Austria Presse Agentur is Austria's national news agency and the country's leading information provider, located in Vienna. It serves media organizations, political institutions, and companies by delivering news, information, and IT services. As a key player in the Communication and Marketing sector, it offers high-quality content and technological solutions for editorial and media operations. The agency is jointly owned by Austrian daily newspapers and ORF, reinforcing its role as an integrated information company. Austria Presse Agentur was neutrally listed as a ransomware victim associated with the play threat actor. |
|||||
| sentenia.net View Details _ | lockbit3 | Other | |||
|
Sentenia Systems is a premier technology solutions provider based in Wakefield, Massachusetts, with over 30 years of experience in the industry. The company specializes in customized VoIP, carrier services, structured cabling, network deployment, and wireless solutions for healthcare and small to medium businesses. As New England's leading provider of business communication systems, Sentenia offers reliable, best-in-class services tailored to specific client needs. The organization was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| handrhealthcare.com View Details _ | lockbit3 | Healthcare / Pharma | |||
|
H&R Healthcare is a New Jersey-based medical equipment supplier serving acute, post-acute, skilled nursing, assisted living, senior living, hospice, and home-care providers. It offers specialty equipment solutions and support surfaces, negative pressure wound therapy, bed frames, bariatric equipment, and related service support. The company says it provides 24/7/365 customer care and tailored solutions to improve patient care. It was listed as a ransomware victim associated with LockBit3. |
|||||
| brunoy.fr View Details _ | France | lockbit3 | Other | ||
|
brunoy.fr is the official website of the commune of Brunoy, a municipality in Essonne in the Île-de-France region, southeast of Paris. The site supports local government services and public information for residents, including municipal news, administrative resources, and community-facing content. As a public-sector domain, it represents the city’s official online presence and service channel. It was listed as a ransomware victim associated with lockbit3. |
|||||
| abilways.com View Details _ | lockbit3 | Other | |||
|
Abilways is a digital training company headquartered in Paris, France, that helps tech professionals learn and share their digital skills. The company provides vocational training services to professionals and individuals across multiple sectors including healthcare, logistics, IT, and finance. With approximately 300 active collaborators in France and other countries, Abilways operates as a leader in the education sector in France, offering both initial and continuous training programs. The company was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| https://allseasonmovers.com View Details _ | royal | Other | |||
|
All Season Movers, Inc. operates as a moving and storage company in Kearny, New Jersey, serving the Tri-State area. Its services include residential and commercial relocations, local, long-distance, and international moving, storage, and FF&E installation support. The company’s website presents it as a professional mover for customers seeking relocation and storage solutions. It was listed as a ransomware victim associated with Royal. |
|||||
| http://www.pgtinnovations.com View Details _ | royal | Other | |||
|
PGT Innovations was a Florida-based company in the wholesale building materials sector, known for manufacturing high-performance windows and doors for residential and commercial projects. Its headquarters were in North Venice, Florida, and company materials describe a U.S. footprint with production and office operations supporting its product lines. After acquiring PGT Innovations in 2024, MITER Brands continued to reference the business as part of its portfolio. It was listed as a ransomware victim associated with Royal. |
|||||
| http://www.yoursummit.com View Details _ | royal | Other | |||
|
yoursummit.com is the website of Summit Financial Group, a Dallas-based national full-service benefits firm with a presence in Tulsa. It offers risk management, employee benefits, insurance, and retirement plan solutions for companies and C-suite executives across industries. Its site also includes market commentary, webinars, and company resources. The domain was listed as a ransomware victim associated with royal. |
|||||
| thorntontomasetti.com View Details _ | lockbit3 | Other | |||
|
Thornton Tomasetti is an American science and engineering consulting firm headquartered in New York City, with offices across North America and global project reach. Its website presents structural design, investigation and analysis, and specialized engineering services for buildings, events, and complex projects. The company describes itself as serving clients worldwide with technical consulting across a broad range of sectors. ThorntonTomasetti.com was listed as a ransomware victim associated with LockBit3. |
|||||
| st-group.com View Details _ | lockbit3 | Services | |||
|
st-group.com is the website of Scandinavian Tobacco Group A/S, a Denmark-based company headquartered in Gentofte. The company describes itself as a world leader in cigars and traditional pipe tobacco, with international brands and regional brands across its portfolio. It operates globally and employs close to 9,000 people across offices and factories worldwide. The site serves corporate, investor, careers, contact, and product information for the group. It was listed as a ransomware victim associated with lockbit3. |
|||||
| smithsinterconnect.com View Details _ | lockbit3 | Other | |||
|
Smiths Interconnect is a UK-based company that provides high-reliability connectivity products and solutions. Its offerings include electronic components, subsystems, and connectivity technologies for aerospace and defense, medical, industrial, space, and test markets. The company operates internationally with offices and facilities in the United Kingdom, the United States, Canada, Singapore, China, Mexico, and Tunisia. It was listed as a ransomware victim associated with LockBit3. |
|||||
| menziesaviation.com View Details _ | lockbit3 | Transportation / Travel / Logistics | |||
|
Menzies Aviation is a global aviation services company headquartered in Edinburgh, Scotland, United Kingdom, providing aircraft ground handling, air cargo, and fuel solutions worldwide. The firm operates in 65 countries across six continents, delivering critical ground, air cargo, fuel, and executive services to the global aviation industry. As a subsidiary of John Menzies Ltd., it became the world's largest aviation services company in 2022 after being acquired by Agility. Menzies Aviation was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| hildinganders.com View Details _ | lockbit3 | Other | |||
|
Hilding Anders is a Swedish sleep and bedding company headquartered in Malmö, Sweden. It develops and sells beds, mattresses, and related sleep products for consumer and commercial markets. The group presents itself as a global bedding and mattress company with brands and private-label offerings. It was listed as a ransomware victim associated with LockBit3. |
|||||
| ckfinc.com View Details _ | lockbit3 | Services | |||
|
CKF Inc. is a Canadian-owned manufacturer headquartered in Hantsport, Nova Scotia, with additional facilities in Ontario and British Columbia. Founded in 1933, the company specializes in sustainable food service products, including moulded pulp, foam, and rPET items for retail consumers, food service operators, and the packaging industry. CKF Inc. offers tailored packaging solutions such as disposable plates, bowls, and meat trays, committed to quality and sustainability. The company was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| adamjeeinsurance.com View Details _ | lockbit3 | Finance / Legal / Insurance | |||
|
AdamjeeInsurance.com is the digital platform of Adamjee Insurance Company, one of the largest general insurance providers in Pakistan, headquartered in Lahore and Karachi. The company offers Motor Insurance, Health Insurance, Travel Insurance, and other non-life insurance products to individuals and businesses across the country. As a key player in Pakistan’s Finance and Insurance sector, it serves as a trusted partner for risk protection and financial security. The entity was neutrally listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| adamjeeinsurance.com View Details _ | Pakistan | lockbit3 | Finance / Legal / Insurance | ||
|
Adamjee Insurance is one of the leading general insurance companies in Pakistan, offering Motor Insurance, Health Insurance, and Travel Insurance and offers customised solutions to meet the protection needs of individual and corporate customers. |
|||||
| 8x8.com View Details _ | lockbit3 | Other | |||
|
8x8.com is the website of 8x8, Inc., an American cloud communications company headquartered in Campbell, California. It provides unified communications and customer experience software, including voice, video, chat, and contact center tools for businesses. The company serves customers through a global cloud platform and operates internationally across multiple regions. It was listed as a ransomware victim associated with LockBit3. |
|||||
| nissin.com.br Disclose the compressed package password View Details _ | dataleak | Communication / Marketing | |||
|
nissin.com.br is the Brazilian website of Nissin, a food company that presents products, recipes, and contact channels for consumers and business inquiries. Its public pages show brand and customer-service information in Brazil, with instant noodles featured among its offerings. The site operates in Brazil and supports communication and marketing activities through product promotion and public contact points. It was listed as a ransomware victim associated with dataleak. |
|||||
| rkw-group.com Disclose the compressed package password View Details _ | dataleak | Communication / Marketing | |||
|
RKW Group operates from Mannheim, Germany, and describes itself as one of the world’s leading manufacturers of polyolefin-based film solutions with 17 sites across Europe, Asia, and North America. Its portfolio includes films for packaging, hygiene, medical, and other industrial uses, supporting customers in communication and marketing-adjacent packaging and materials supply chains. The listing references the domain rkw-group.com and the compressed package password notice associated with the entry. It was listed as a ransomware victim associated with dataleak. |
|||||
| ni*usa.com View Details _ | dataleak | Other | |||
|
ni*usa.com operates within the Other sector in the United States, providing specialized offerings aligned with its industry focus. The entity is recognized for its role in delivering services relevant to its operational scope. It was listed as a ransomware victim associated with the dataleak threat actor, marking its inclusion in threat-intelligence records. This designation reflects its exposure to cyber incidents linked to dataleak activities. The listing serves as a neutral acknowledgment of its status within the threat-intelligence index. |
|||||
| wiesauplast.de View Details _ | Germany | dataleak | Other | ||
|
wiesauplast.de refers to SCHERDEL Wiesauplast Deutschland GmbH & Co. KG, a plastics engineering and manufacturing company based in Wiesau, Bavaria, Germany. It develops and produces molds for plastic injection molding and offers high-tech plastic systems and assembly technology. Company materials also describe it as focused on sustainable, innovative plastics solutions for industrial applications. The entity was listed as a ransomware victim associated with dataleak. |
|||||
| grantweber.com View Details _ | dataleak | Other | |||
|
Grant & Weber operates as a U.S.-based revenue solutions and receivables management company, serving business partners since 1977. The company says it provides receivables management, debt collection, and revenue cycle services, with a focus on healthcare, credit union, and related financial services. Public-facing materials also describe it as a nationwide business with a California headquarters and operations tied to account management and collections. It was listed as a ransomware victim associated with dataleak. |
|||||
| The Beacon Insurance Company Limited View Details _ | dataleak | Finance / Legal / Insurance | |||
|
The Beacon Insurance Company Limited is a Trinidad and Tobago insurance provider headquartered in Port of Spain. It underwrites general insurance lines, including motor, property, marine, accident, casualty, bonds and engineering, serving both private and commercial clients. Company profiles also describe it as one of the country’s larger insurers, with roots dating to 1972 and a later rebranding in 1996. It was listed as a ransomware victim associated with dataleak. |
|||||
| Maple Leaf Foods View Details _ | blackbasta | Agriculture / Food | |||
|
Maple Leaf Foods is a Canadian food company headquartered in Mississauga, Ontario, with operations in Canada, the U.S. and Asia. It produces consumer protein products, including fresh, prepared and plant-based foods, and describes itself as a leading provider of protein products. The company emphasizes sustainable, high-quality food production and serves retail and foodservice markets. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Landaumedia View Details _ | cuba | Communication / Marketing | |||
|
Landaumedia is a leading German company in the Communication and Marketing sector, headquartered in Berlin, that provides media monitoring, press review services, and media analysis solutions. The firm offers a comprehensive PR software platform that measures and visualizes PR success for small businesses and large corporations alike. With over 230 employees, Landaumedia has been a key player in media analysis since its establishment in 1997. The company was listed as a ransomware victim associated with the Cuba threat actor. |
|||||
| Generator-power View Details _ | cuba | Energy | |||
|
Generator-power is an Energy-sector entity in the United States associated with generator or power-related operations, based on its name and the industry context provided. Energy companies typically support electricity generation, backup power, or related infrastructure services, which places them in a high-value operational sector. In threat-intelligence indexing, Generator-power appears as a ransomware victim entry. It was listed as a ransomware victim associated with cuba. |
|||||
| Boss-inc View Details _ | cuba | Services | |||
|
Boss-inc is a services company based in Lake Mary, Florida, in the United States. Public company profiles describe BOSS, Inc. as Business Operations Services & Support, providing outsourcing and technology resources that help organizations automate manual tasks and support day-to-day operations. Its services are described as business operations support, including process automation and related back-office functions for clients. In threat-intelligence listings, Boss-inc was identified as a ransomware victim associated with cuba. |
|||||
| Holler-Classic View Details _ | lorenz | Other | |||
|
Holler-Classic is an entity operating in the Other sector, with no specific geographic location or defined offerings publicly documented. The entity lacks a known public profile, making its sector classification broad and non-specific. It was listed as a ransomware victim associated with the Lorenz threat actor, which has targeted multiple small and medium businesses. Lorenz is a double-extortion ransomware group active since at least February 2021, primarily targeting organizations in the United States with outliers in China and Mexico. Holler-Classic remains a documented victim in the Lorenz ransomware campaign, as confirmed by threat-intelligence sources. |
|||||
| Patton View Details _ | cuba | Other | |||
|
Patton is an entity operating in the Other sector, with no specific location or defined offerings publicly documented. As its sector is categorized as Other, its precise business activities and geographic presence remain unclear. Despite this ambiguity, Patton was listed as a ransomware victim associated with the Cuba threat actor. The incident highlights the targeting of entities across diverse sectors by sophisticated cyber groups. No further specifics about the breach or stolen data are confirmed. |
|||||
| Plascar Participacoes Industriais View Details _ | vicesociety | Other | |||
|
Plascar Participacoes Industriais S.A. is a Brazilian company headquartered in Jundiaí, São Paulo. It operates in the automotive sector, manufacturing and selling interior and exterior finishing parts for motor vehicles. Its product range includes bumpers, instrument panels, trim parts, diffusers and related components, and it also produces some non-automotive items. The company was listed as a ransomware victim associated with vicesociety. |
|||||
| colonialgeneral.com View Details _ | lockbit3 | Other | |||
|
Colonial General Insurance Agency, Inc. is a family-owned insurance firm based in the United States, established in 1995, that offers top-quality insurance products and solutions to independent agents. The company specializes in workers compensation and other insurance risks, providing tailored coverage for small businesses across the nation. Colonial General operates as a family-owned business with office hours from 8:00 AM to 4:30 PM MST, excluding US holidays and weekends. The agency was listed as a ransomware victim associated with the LockBit3 threat actor, marking its inclusion in threat-intelligence records. |
|||||
| https://www.rmclaw.net/ View Details _ | royal | Other | |||
|
rmclaw.net is the website of Righeimer Martin & Cinquino, P.C., a Chicago, Illinois law firm in the Other sector. The firm presents civil litigation services, with emphasis on eminent domain, probate administration, real estate, banking law, and estate planning. Its contact page lists the office at 230 West Monroe Street, Suite 2500, Chicago, IL 60606, with a firm telephone line and email contact. It was listed as a ransomware victim associated with royal. |
|||||
| ??? View Details _ | play | Other | |||
|
??? is an organization in the Other sector whose public profile, offerings, and location are not clearly identified in the available sources. Play is a ransomware group known for encrypting victims’ files and using double extortion, with attacks spanning multiple sectors and regions. In threat-intelligence indexing, ??? is recorded as a victim associated with Play, a designation that reflects the listing context rather than a verified public disclosure. |
|||||
| https://www.cates.com View Details _ | royal | Other | |||
|
Cates Control Solutions is an industrial automation company based in Plano, Texas, with additional operations in Webster, Texas. It provides engineering and fabrication services, including system integration, panel fabrication, and control products for manufacturers. The company also highlights experience supporting industrial and oil and gas operations. Cates.com was listed as a ransomware victim associated with Royal. |
|||||
| kusd.edu View Details _ | United States | revil | Other | ||
|
kusd.edu is the official website of Kenosha Unified School District in Kenosha, Wisconsin, a public school district serving the City of Kenosha and nearby communities, including Pleasant Prairie and Somers. The district provides K-12 education, registration services, school information, departments, and student support resources. Its site also directs families to online enrollment, boundary school lookup, and district contact details. It was listed as a ransomware victim associated with REvil. |
|||||
| Sunknowledge Services Inc View Details _ | revil | Services | |||
|
Sunknowledge Services Inc is a Services company that provides business and knowledge process outsourcing for the U.S. healthcare sector, with revenue cycle management, practice management, and related support services. It describes itself as an American-owned and operated provider headquartered in New York City, with an office in Kolkata, India. Its offerings include pre-billing, mid-billing, and post-billing support, along with prior authorization, accounts receivable, denial management, and virtual assistance. It was listed as a ransomware victim associated with revil. |
|||||
| Verity cloud View Details _ | play | IT | |||
|
Verity Cloud is an India-based IT services company that provides business consulting, technology, engineering, and outsourcing support to help clients innovate and transform. Its offerings include managed services and tailored cloud and IT support. Public company information lists its head office in Hyderabad, India. In threat-intelligence indexes, Verity Cloud is listed as a ransomware victim associated with Play. |
|||||
| ??????????? View Details _ | play | Other | |||
|
The entity name was not available in the source data, so it can only be described as an Other-sector organization. Public search results did not provide a verified location, offerings, or corporate profile for the affected company. Play, also known as PlayCrypt, is a ransomware group that targets organizations across multiple sectors with data theft and file encryption. The listing identified the company as a ransomware victim associated with play. |
|||||
| ???? ????? View Details _ | play | Other | |||
|
???? ????? is an Other-sector organization based in the country, operating in a non-specified line of business. Public threat-intelligence sources identify Play, also known as Playcrypt, as a ransomware group active since 2022 that targets organizations across North America, South America, and Europe. Play is known for double-extortion attacks that combine encryption with data theft and ransom demands. ???? ????? was listed as a ransomware victim associated with play. |
|||||
| bankseta.org.za View Details _ | South Africa | lockbit3 | Finance / Legal / Insurance | ||
|
bankseta.org.za is the website of the Banking Sector Education and Training Authority (BANKSETA), a South African organization based in Centurion that supports skills development and transformation in the broader banking and micro-finance sector. Its site publishes funding calls, stakeholder guidance, and program information for universities, training partners, SMEs, youth, and adult education. BANKSETA also provides contact channels for regional offices and anti-fraud reporting. It was listed as a ransomware victim associated with lockbit3. |
|||||
| https://tubularsteel.ca View Details _ | royal | Other | |||
|
Tubularsteel.ca is the website of Tubular Steel Inc., a Canadian manufacturer of precision welded steel tubing for North American customers. The company says it serves multiple industries, including automotive, fitness, and furniture, and manufactures tubes in Toronto, Canada, and Centerville, Tennessee. Its contact page lists Toronto-area office details and a Canadian phone number. It was listed as a ransomware victim associated with royal. |
|||||
| IKEA MoroccoIKEA Kuwait View Details _ | Morocco | vicesociety | Retail / E-commerce | ||
|
IKEA Morocco and IKEA Kuwait operate as independent retail franchises under the global IKEA brand, offering a wide range of ready-to-assemble furniture, home accessories, and household goods to consumers in their respective regions. These entities are managed by a Kuwait-based franchisee, distinct from other international IKEA operations, and provide comprehensive home furnishing solutions through physical showrooms and e-commerce platforms. The organizations were officially listed as ransomware victims associated with the threat actor group known as Vice Society. |
|||||
| IKEA Morocco IKEA Kuwait View Details _ | vicesociety | Retail / E-commerce | |||
|
We believe that no matter what we do in life, we should always try to be the absolute best at it. At IKEA we focus on being the best at ordinary everyday things. Because to us, the ordinary everyday contains the best of life. We want to be Extraordinary at the ordinary for you. |
|||||
| STGi View Details _ | snatch | Other | |||
|
STGi, also known as STG International, is a United States-based firm specializing in healthcare services, training services, and grants management for federal customers. The company operates nationwide, managing over 22 healthcare and residential facilities while delivering clinical operations, behavioral healthcare, and homeless services. STGi thrives in challenging environments and remote locations, providing facility management, case management, and early education programs across the United States. The firm was listed as a ransomware victim associated with the snatch threat actor. |
|||||
| VANOSS Public School View Details _ | bianlian | Education | |||
|
Vanoss Public Schools is a public school district in Ada, Oklahoma, in Pontotoc County, about ten miles west of Ada. It serves students across grades PK-12 and operates schools and district services for the local community. The district describes its mission as helping young minds think, learn, grow, and become productive citizens. It was listed as a ransomware victim associated with bianlian. |
|||||
| Power Plant Services LLC View Details _ | bianlian | Energy | |||
|
Power Plant Services LLC is a U.S. energy-industry company based in Melrose Park, Illinois. It describes itself as a full-service, turnkey provider for the power generation industry and a non-OEM parts manufacturer, with services supporting repairs, outages, and operational continuity. The company has also presented itself as an advanced machine shop serving power-generation customers and related industrial users. Power Plant Services LLC was listed as a ransomware victim associated with bianlian. |
|||||
| Samrin Services Pvt Ltd View Details _ | bianlian | Services | |||
|
Samrin Services Pvt Ltd is a services company based in Mumbai, Maharashtra, India. Public business listings describe it as a provider of purchase management, quality control, shipping and documentation, and related support services for EXIM and international brands. Company profile sources also place its office in Andheri, Mumbai, and describe a broader business-support offering. It was listed as a ransomware victim associated with bianlian. |
|||||
| Altec Engineering LLC View Details _ | bianlian | Manufacturing / Engineering | |||
|
Altec Engineering LLC is a U.S.-based manufacturing and engineering company associated with the Altec group, headquartered in Birmingham, Alabama. Altec provides products and services for the electric utility, tree care, telecommunications, and lights-and-signs markets, and offers engineering work in product development, applications, manufacturing, and hydraulic systems nationwide. The company’s profile reflects a manufacturing and engineering business with broad industrial and utility-sector offerings. It was listed as a ransomware victim associated with bianlian. |
|||||
| Block Buildings LLC View Details _ | bianlian | Construction / Real Estate | |||
|
Block Buildings LLC is a U.S. company in the construction and real estate sector, with business profiles describing services in construction management, general contracting, and building-related real estate activities. Public listings place the company in Houston, Texas, and note an additional Louisiana location, indicating a regional operating footprint. Company materials also describe work across multifamily and commercial projects. It was listed as a ransomware victim associated with bianlian. |
|||||
| Badger Truck Refrigeration, Inc View Details _ | bianlian | Services | |||
|
Badger Truck Refrigeration, Inc is a Wisconsin-based company in the Services sector that designs and supports custom heating, air conditioning, cab filtration, fire suppression, and idle-reduction technologies for trucks and vehicles. Located in Eau Claire, WI, the firm provides OE-grade mobile HVAC engineered for severe-duty applications, including custom cab A/C, heat, filtration, and fire suppression for off-highway and specialty builds. The company pioneered heating and cooling setups for early logging equipment and specialty machinery, serving fleets across the Midwest with truck refrigeration parts and mobile HVAC systems. Badger Truck Refrigeration, Inc was listed as a ransomware victim associated with the threat actor bianlian. |
|||||
| GLEN DIMPLEX GROUP UNITS WERE HACKED (DEFOND, DEFONDTECH AND OTHER). MORE THAN 1TB DATA WA View Details _ | lv | IT | |||
|
Glen Dimplex Group is a leading international manufacturer of electric heating and domestic appliances headquartered in Dublin, Ireland. Founded in 1973, the privately held firm operates across 20 countries and specializes in low carbon electric heating, ventilation, cooling, and renewable energy solutions. The company serves business-to-business clients including dealers, wholesalers, engineers, and architects, while also offering consumer products. Its units, including Defond and DefondTech, were hacked, resulting in over 1TB of data being affected. The group was listed as a ransomware victim associated with the threat actor lv. |
|||||
| PVFCCo View Details _ | play | Other | |||
|
PVFCCo, or Petrovietnam Fertilizer and Chemicals Corporation, is a leading Vietnamese producer and trader of fertilizers and chemicals for agriculture and the oil and gas industry. Headquartered in Ho Chi Minh City, its core operations include production at the Phu My Fertilizer Plant in Ba Ria-Vung Tau Province, serving markets across Vietnam and Southeast Asia. The company employs nearly 1,500 staff and is recognized as a top enterprise in the fertilizer and petrochemical sector. PVFCCo was listed as a ransomware victim associated with the threat actor play. |
|||||
| Leadtek View Details _ | play | Other | |||
|
Leadtek Research Inc. is a Taiwan-based computer and smart-medical manufacturer founded in 1986. It develops and sells graphics cards, AI workstations and servers, visualization tools, and other NVIDIA-related computing solutions from its New Taipei City headquarters. The company also presents itself as a long-term NVIDIA partner with products for professional graphics and 3D collaboration. Leadtek was listed as a ransomware victim associated with play. |
|||||
| Alcomet View Details _ | play | Other | |||
|
Alcomet AD is a Bulgaria-based aluminium manufacturing company headquartered in Shumen, operating a fully integrated production facility covering downstream cycles from billet and coil casting. The company produces a wide range of aluminium products including sheets and serves key industries across European and US markets. Alcomet AD operates as a subsidiary of Alumetal AD and specializes in aluminium re-melting, refining, and rolled products manufacturing. The company was listed as a ransomware victim associated with the play threat actor. |
|||||
| Ministry of Transport and Public Works View Details _ | play | Public Sector | |||
|
The Ministry of Transport and Public Works is a **public sector** government ministry in **Cambodia** responsible for transport and public works administration. It oversees infrastructure and related services across transport modes, including roads, rail, marine, and aviation, as part of the state’s public works function. Public works agencies manage the physical assets, policies, and services that support essential public infrastructure. The ministry was listed as a ransomware victim associated with **play**. |
|||||
| Itsgroup View Details _ | play | Services | |||
|
Itsgroup is a Services-sector company based in the United States, operating in business IT and consulting. Public business listings describe it as providing IT support, cloud services, and related professional services for organizations. Its offerings are presented as helping clients with digital operations, infrastructure, and productivity needs. It was listed as a ransomware victim associated with play. |
|||||
| Conseil departemental - Alpes-Maritimes View Details _ | play | Other | |||
|
Conseil departemental - Alpes-Maritimes is the deliberative assembly of the French department of Alpes-Maritimes, a decentralized territorial collectivity headquartered in Nice. It manages key decentralized competencies including social action, child protection, RSA benefits, road maintenance, school construction, and local economic development. As the departmental parliament, it defines local public policies and represents citizens while implementing national policies adapted to its territory. The entity was listed as a ransomware victim associated with the play threat actor. |
|||||
| Origin Property Company Limited View Details _ | play | Construction / Real Estate | |||
|
Origin Property Company Limited is a Thailand-based property development company established in 2009. It focuses on residential real estate, especially condominiums, and says its projects are designed for convenient travel near Skytrain routes and expressways. Public profiles also describe it as active in land, houses, and related real-estate services. It was listed as a ransomware victim associated with play. |
|||||
| https://www.friedmanlawoffices.com View Details _ | royal | Other | |||
|
FriedmanLawOffices.com is the official website of the Law Offices of Heywood G. Friedman, a premier California legal firm specializing in workers' compensation claims defense, business litigation, insurance law, employment and labor law, and general liability defense. The firm provides services statewide across California, with offices located in Los Angeles County, Orange County, the Bay Area, the State Capital, and the Central Valley. Heywood Friedman and his staff deliver strategic legal expertise to clients in sectors including healthcare, construction, and transportation. The firm also serves vulnerable beneficiaries such as children, at-risk teens, and seniors in multiple California valleys. FriedmanLawOffices.com was listed as a ransomware victim associated with the Royal threat actor. |
|||||
| Guilford College View Details _ | hive | Education | |||
|
Guilford College is a private not-for-profit higher education institution located in Greensboro, North Carolina, offering bachelor's degrees including an Education Studies major with teacher licensure and non-licensure tracks. The college emphasizes practical field study and close student-faculty relationships through its Education Studies Department. It serves approximately 1,160 undergraduate students and provides a city-atmosphere campus experience in Greensboro. Guilford College was listed as a ransomware victim associated with the threat actor hive. |
|||||
| Essent company - Leaked View Details _ | ragnarlocker | Services | |||
|
Essent Group Ltd. is a U.S.-based services company focused on residential mortgage finance. Through its subsidiaries, it provides private mortgage insurance, reinsurance, and title insurance and settlement services to mortgage lenders and homebuyers. The company serves the U.S. housing finance market and helps support low-down-payment lending. Essent company - Leaked was listed as a ransomware victim associated with Ragnar Locker. |
|||||
| ITM View Details _ | blackbasta | Other | |||
|
ITM Isotope Technologies Munich SE is a radiopharmaceutical theranostics company based in Germany with a U.S. headquarters in Princeton, New Jersey. The firm develops and markets therapeutic and diagnostic radioisotopes while advancing its targeted radiopharmaceutical pipeline for potential market registration. ITM strengthened its U.S. presence by opening a new headquarters at 5 Vaughn Drive, Suite 390, to accelerate sales and marketing efforts. ITM was listed as a ransomware victim associated with the BlackBasta threat actor. |
|||||
| Myton School View Details _ | bianlian | Education | |||
|
Myton School is a larger-than-average, co-educational secondary school for ages 11–18 in Warwick, Warwickshire, England, set between Warwick and Leamington Spa. It operates on Myton Road in Warwick and provides mainstream secondary education, with support services for pupils with special educational needs. Public listings describe it as part of the education sector and as a school campus serving the local community. It was listed as a ransomware victim associated with bianlian. |
|||||
| Modular Mining View Details _ | bianlian | Other | |||
|
Modular Mining is a Tucson, Arizona-based mining technology company that develops software and systems for fleet management, operations planning, maintenance, and safety in the mining industry. Founded in 1979, it brought the DISPATCH system to market and later became part of Komatsu’s mining technology portfolio. Its offerings support mining operators with integrated, vendor-agnostic tools for productivity and operational control. Modular Mining was listed as a ransomware victim associated with bianlian. |
|||||
| Centura College View Details _ | bianlian | Education | |||
|
Centura College is a private, for-profit education institution in Virginia Beach, Virginia, with additional campuses in the state. It offers career-focused programs through technical and healthcare trade training, including health science and skilled trades. The school was founded in 1969 and serves students seeking undergraduate and graduate-level education. It was listed as a ransomware victim associated with BianLian. |
|||||
| Versah View Details _ | bianlian | Other | |||
|
Versah is a medical equipment manufacturer based in Jackson, Michigan, best known for its dental implant preparation products and osseodensification drills. Founded in 2014 by Dr. Salah Huwais, the company markets Densah burs and related kits for dental osteotomy procedures. Versah operates in the medical equipment sector and serves dental implant workflows in the United States and abroad. It was listed as a ransomware victim associated with bianlian. |
|||||
| Gazelle International Ltd View Details _ | bianlian | Services | |||
|
Gazelle International Ltd is a UK services company based in Godalming, Surrey, with a registered office in Woolsack Way. It was formed in 1992 and offers a complete range of transport solutions across the UK and the rest of the world. Company records show it remains active and operate from its Surrey address. In threat-intelligence listings, Gazelle International Ltd was listed as a ransomware victim associated with bianlian. |
|||||
| Boon Tool Co View Details _ | bianlian | Other | |||
|
Bon Tool Co is a U.S.-based manufacturer and supplier of professional hand tools and equipment for the trowel trades and general construction. Its product line includes tools for masonry, drywall, plaster, flooring, and related construction work, and its headquarters is in Gibsonia, Pennsylvania. The company also operates distribution and manufacturing sites in the United States. Bon Tool Co was listed as a ransomware victim associated with bianlian. |
|||||
| Rentz Management View Details _ | bianlian | Services | |||
|
Rentz Management is a full-service community association management company based in Covington, Kentucky, serving the Greater Cincinnati area. Its services include general administration, owner accounting, collections, and association management for community associations. The company also provides payment and customer-service support for client associations. It was listed as a ransomware victim associated with bianlian. |
|||||
| Harry Rosen View Details _ | bianlian | Other | |||
|
Harry Rosen is a Canadian luxury retail chain headquartered in Toronto, founded in 1954 and known for premium men’s apparel, footwear, and accessories. The company operates as a leading menswear retailer with a focus on designer clothing and tailored service. Its catalog includes high-end clothing for work, formalwear, and casual wear, along with complementary fashion accessories. It was listed as a ransomware victim associated with bianlian. |
|||||
| https://www.labusinessjournal.com View Details _ | royal | Other | |||
|
Los Angeles Business Journal is an award-winning B2B media company based in Los Angeles, California, that has served the city’s business community for more than 40 years. It publishes business news, industry coverage, lists, special editions, and events for sectors including real estate, health care, tech, finance, and manufacturing. Its website also promotes staff, archives, and local business resources. The site was listed as a ransomware victim associated with royal. |
|||||
| Cincinnati State View Details _ | vicesociety | Public Sector | |||
|
Cincinnati State Technical and Community College is a public-sector institution in Cincinnati, Ohio, that offers accessible higher education through associate’s degrees, bachelor’s degrees, technical certificates, and transfer pathways. It provides more than 170 degree and certificate programs across four locations, including workforce-focused and public safety education. The college also serves a large student body and maintains community and employer partnerships through its academic divisions. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Pmc-group View Details _ | cuba | Services | |||
|
Pmc-group is a Services-sector organization in the United States, and its public-facing business details indicate it operates in professional or commercial services. The name alone does not confirm a specific product line, so this listing describes the entity at a high level without adding unverified incident claims. In threat-intelligence catalogs, such victims are recorded to map ransomware activity across industries and regions. It was listed as a ransomware victim associated with Cuba. |
|||||
| Astra Daihatsu Motor (ID) View Details _ | Indonesia | daixin | Manufacturing / Engineering | ||
|
Astra Daihatsu Motor (ID) is Indonesia's largest car manufacturer by production output and installed capacity, operating in the Automobile Manufacturing industry within West Java and Jakarta. The company serves as the sole distributor and retailer of Daihatsu vehicles in Indonesia, offering a diverse range of family vehicles including the New Terios, All New Xenia, and New Rocky. It has been incorporated since 1978 and remains the second best-selling car brand behind Toyota in the country. Astra Daihatsu Motor (ID) was listed as a ransomware victim associated with the daixin threat actor. |
|||||
| Astra Daihatsu Motor View Details _ | Indonesia | daixin | Manufacturing / Engineering | ||
|
PT Astra Daihatsu Motor is an automobile manufacturing company based in Jakarta, Indonesia. It is a joint venture company between Daihatsu, Astra International and Toyota Tsusho. It is the largest car manufacturer in Indonesia by production output and installed capacity, and has been second best-selling car brand behind |
|||||
| Norman Public Schools View Details _ | hive | Education | |||
|
Norman Public Schools is a public school district in Norman, Oklahoma, serving students in grades PK-12 across 26 schools and academies. It is the eighth-largest district in Oklahoma and operates near the University of Oklahoma, providing academic programs and educational services for the community. The district’s administrative center is at 131 S. Flood Ave. in Norman. It was listed as a ransomware victim associated with Hive. |
|||||
| Aeronautics company Canada / UTC Aerospace Systems, Bombardier aerospace, NASA partners View Details _ | everest | Hospitality / Food & Beverage / Tourism | |||
|
Aeronautics company Canada / UTC Aerospace Systems, Bombardier aerospace, NASA partners refers to a Canadian aerospace organization tied to Bombardier, which develops and supports aircraft programs and related aerospace services. Bombardier is based in Montreal and is known for aircraft manufacturing and aerospace research partnerships, including work with industry and academic partners. The entity name also reflects collaboration with UTC Aerospace Systems and NASA-related aerospace partnerships. It was listed as a ransomware victim associated with everest. |
|||||
| lapiamontesa View Details _ | Argentina | blackbyte | Communication / Marketing | ||
|
lapiamontesa.com belongs to Piamontesa, an Argentine organization with an online presence that includes contact, catalog, distribution, and job pages. Its site indicates a business context centered on communications and marketing activities, with offerings organized around public-facing information and customer engagement. The entity is listed in Argentina, and its sector is identified as Communication / Marketing. It was listed as a ransomware victim associated with blackbyte. |
|||||
| Leak Announcement - IT company ITonCLOUD View Details _ | ragnarlocker | IT | |||
|
ITonCLOUD is an Australian IT and cloud services company based in Castle Hill, New South Wales, that helps businesses simplify and automate their IT systems through cloud desktops and hosted environments. Its offerings include access to email, files and business applications in the cloud, along with security-focused support for remote work. Public descriptions also note that it serves organizations seeking to reduce reliance on on-premise servers and hardware. The company was listed as a ransomware victim associated with ragnarlocker. |
|||||
| ssp-worldwide.com View Details _ | lockbit3 | Other | |||
|
SSP Worldwide is a technology company that provides software for the insurance industry, serving brokers, insurers, MGAs, underwriting agents and financial advisers. It is headquartered in Halifax, West Yorkshire, United Kingdom, and operates internationally across multiple markets. The company says its platforms support localized insurance processing, including country-specific tax, language and regulatory needs. It was listed as a ransomware victim associated with lockbit3. |
|||||
| ryokikogyo.co.jp View Details _ | Japan | lockbit3 | Other | ||
|
Ryoki Kogyo Co., Ltd. operates in Japan and is associated with mechanical systems and environmental equipment work, including air-conditioning, plumbing, heating, and related installation services. Public company profiles also describe the business as focusing on creating comfortable living and working environments through refrigeration and building-systems services. The domain ryokikogyo.co.jp corresponds to the company’s corporate presence in Japan. It was listed as a ransomware victim associated with LockBit3. |
|||||
| Aeronautics company Canada / UTC Aerospace Systems, Bombardier aerospace partners View Details _ | everest | Hospitality / Food & Beverage / Tourism | |||
|
Aeronautics company Canada / UTC Aerospace Systems, Bombardier aerospace partners refers to aerospace-linked organizations in Canada connected to aircraft manufacturing and supplier activity. Bombardier is a Montreal-based aerospace company headquartered in Dorval, Quebec, known for designing, building, and maintaining business aircraft such as the Global and Challenger lines. UTC Aerospace Systems, now part of Collins Aerospace, supplies aerospace systems and components used across commercial and business aviation. The listing states it was a ransomware victim associated with everest. |
|||||
| www.artisticstairs.com View Details _ | onyx | Other | |||
|
Artistic Stairs and Railings is an Edmonton, Alberta-based construction company that manufactures and installs custom staircases, railings, and specialty mouldings. Its website describes the firm as a staircase and railing manufacturer and installer serving residential, renovation, and commercial building projects. The company presents itself as Alberta's custom stair leader with a focus on bespoke craftsmanship and production. It was listed as a ransomware victim associated with onyx. |
|||||
| www.wayan.com.mx View Details _ | Mexico | onyx | Other | ||
|
Wayan Natural Wear is a Mexico-based retail brand that presents itself as a fashion and lifestyle store with an online shop at wayan.com.mx. Its public channels describe a warm, ethnic, natural concept centered on women’s apparel, accessories, and resort-style pieces. Available listings also place the business in Quintana Roo, Mexico, reflecting a presence in the country’s tourism and retail market. The entity was listed as a ransomware victim associated with onyx. |
|||||
| www.candcfarmsupply.com View Details _ | onyx | Agriculture / Food | |||
|
C&C Farm Supply operates in the Agriculture / Food sector and serves dairy farmers from Harrisonburg, Virginia. Public business listings and the company’s former website identify it as a local farm supply business with the same location and phone number now used by Everstead Farm Supply. It has been described as serving dairy farms across the Shenandoah Valley and nearby areas. It was listed as a ransomware victim associated with onyx. |
|||||
| www.ackermanplumbinginc.com View Details _ | onyx | Services | |||
|
Ackerman Plumbing Inc is a trusted commercial plumbing services provider located in Sarasota, Florida, specializing in new builds, renovations, and emergency repairs. The company offers a wide range of services including routine maintenance, complex commercial projects, and medical gas systems. As a licensed and union-affiliated firm, it serves Johnson County and surrounding areas with professional plumbing solutions. Ackerman Plumbing Inc was neutrally listed as a ransomware victim associated with the Onyx threat actor. |
|||||
| www.semaphorehq.com View Details _ | onyx | Other | |||
|
Semaphore HQ is a family of companies based in Irvine, California, with a website at semaphorehq.com. Its public materials describe offerings that include accounting, tax preparation, payroll, insurance, business management, and brand or licensing services, with support for small and medium businesses and creators. The company presents itself as a concierge-style service provider for clients seeking financial and business support. It was listed as a ransomware victim associated with onyx. |
|||||
| www.baltholding.eu View Details _ | onyx | Other | |||
|
www.baltholding.eu appears to be a Dutch business operating in the broader logistics and warehousing space, which is commonly centered on storage, handling, and distribution services in Europe. Publicly available trade and company-index data associate the name Baltholding with import-export activity, but detailed corporate information on offerings is limited in the sources provided. The entity is classified in the Other sector for this listing, reflecting an unspecified business profile rather than a clearly defined industry vertical. It was listed as a ransomware victim associated with onyx. |
|||||
| www.pacmaritime.com View Details _ | onyx | Other | |||
|
Pacific Maritime Industries Corp., associated with www.pacmaritime.com, is a San Diego, California–based manufacturer serving maritime and industrial customers. Public business listings describe the company as producing and installing shipboard interiors, modular furniture, and related wood and interior products for vessels and naval use. Its footprint is centered in Southern California, with an address listed in San Diego and another directory entry in Chula Vista, California. It was listed as a ransomware victim associated with onyx. |
|||||
| www.waynefamilypractice.com View Details _ | onyx | Communication / Marketing | |||
|
Wayne Family Practice is a family medicine practice in Jesup, Georgia, in the United States, with a published address at 330 Peachtree Street and a local contact number. Its public listing identifies it as a family medicine practice serving patients through primary care services. The practice also uses a patient portal email address, indicating online patient communication and account access. It was listed as a ransomware victim associated with onyx. |
|||||
| www.advantagedirectcare.com View Details _ | onyx | Other | |||
|
www.advantagedirectcare.com appears to represent Advantage Direct Care, a healthcare practice in the United States that offers direct primary care services. Direct care practices typically provide members with primary care access outside the traditional insurance-driven model, emphasizing routine visits and ongoing patient relationships. The site name and service model place it in the broader Other sector rather than a specialized industry category. It was listed as a ransomware victim associated with onyx. |
|||||
| www.cucafresca.com.br View Details _ | Brazil | onyx | Other | ||
|
www.cucafresca.com.br is the website of Cuca Fresca Informática, a Brazilian software company that provides integrated systems for accounting, tax, payroll, and timekeeping. Its platform serves accounting firms and businesses across Brazil, with products and support channels for commercial and technical customers. The company also offers solutions for ponto eletrônico, jornadas, and conformidade trabalhista. It was listed as a ransomware victim associated with onyx. |
|||||
| www.arisaseguros.com View Details _ | onyx | Other | |||
|
ARISA, Corredores de Seguros, S.A. operates as an insurance brokerage and risk-advisory firm in Guatemala, serving corporate and personal clients across Central America. Its website describes offerings in medical, life, business, property, auto, and bond insurance, with headquarters in Guatemala City. The company says it has provided insurance advisory services since 1976 and maintains regional coverage in multiple Central American countries. It was listed as a ransomware victim associated with onyx. |
|||||
| www.jaspercountysheriffoffice.com View Details _ | onyx | Public Sector | |||
|
www.jaspercountysheriffoffice.com is the official website of the Jasper County Sheriff’s Office in Jasper, Texas, a public sector law-enforcement agency serving the county from 101 Burch Street in Jasper. The office provides local sheriff services and public information, including records, personnel contacts, commissary deposit details, inmate phone deposit information, and other helpful links. As a county sheriff’s office, it supports law-enforcement administration, records handling, and related public services for residents and visitors in Jasper County. It was listed as a ransomware victim associated with onyx. |
|||||
| www.minex.gob.gt View Details _ | onyx | Other | |||
|
www.minex.gob.gt is the official website of Guatemala’s Ministry of Foreign Affairs, a government body based in Guatemala City that manages embassies, consulates, appointments, and consular services. It also provides online services such as apostille and legalisation requests for Guatemalan and overseas users. In threat-intelligence catalogs, it appears under the broader other sector. The site was listed as a ransomware victim associated with onyx. |
|||||
| www.projectredirectdc.org View Details _ | onyx | Communication / Marketing | |||
|
Project ReDirect, Inc. (Project ReDirect DC) is a nonprofit organization based in Washington, D.C., with operations also listed in Las Vegas, Nevada and New York. Its website says it provides person-centered, transformative programs and services that support individuals facing life challenges and enhance quality of life in their communities. The organization’s public materials describe a communications and marketing-focused mission around outreach, newsletters, and program information. It was listed as a ransomware victim associated with onyx. |
|||||
| McGRATH View Details _ | snatch | Other | |||
|
McGrath RentCorp is a business-to-business rental company headquartered in Livermore, California, with a national footprint in the United States and international activity. It rents and sells relocatable modular buildings, electronic test equipment, and liquid and solid containment tanks and boxes through four segments: Mobile Modular, TRS-RenTelco, Adler Tanks, and Enviroplex. The company serves customers across industrial, commercial, and infrastructure use cases and operates as a diversified rental-services provider. It was listed as a ransomware victim associated with snatch. |
|||||
| SAIPRESS View Details _ | snatch | Communication / Marketing | |||
|
SAIPRESS is a communication and marketing company in Cyprus, operating in the broader public relations, branding, and promotional services space. Firms in this sector typically support clients with messaging, campaign planning, content, and media-facing communications. In threat-intelligence records, SAIPRESS is indexed under the communication and marketing sector for cataloging and analysis. It was listed as a ransomware victim associated with snatch. |
|||||
| westmount.org View Details _ | lockbit3 | Other | |||
|
westmount.org is the official website of the City of Westmount, a municipality on the Island of Montreal in southwestern Quebec, Canada. It provides civic information and access to local services, including recreational facilities and resident forms. The city serves a residential community and manages public-facing municipal offerings through its online portal. It was listed as a ransomware victim associated with lockbit3. |
|||||
| https://mcandrewslaw.com View Details _ | royal | Other | |||
|
mcandrewslaw.com is the website for McAndrew & Associates, P.C., a Michigan law firm serving clients from offices in Grand Rapids and East Lansing. The firm provides legal services across areas that include litigation, business matters, employment issues, estate planning, and family law. As a professional-services organization in the legal sector, its online presence supports client information and firm communications. The site was listed as a ransomware victim associated with Royal. |
|||||
| AirAsia Group (MY, ID, TH) View Details _ | Malaysia | daixin | Transportation / Travel / Logistics | ||
|
AirAsia Group, now Capital A, is a Malaysian multinational holding company operating in Malaysia, Indonesia, and Thailand with a portfolio of synergistic travel and lifestyle businesses. It includes AirAsia, the largest low-cost airline in Malaysia by fleet size, offering scheduled domestic and international flights to over 166 destinations across 25 countries. The group provides enterprise travel solutions through its corporate booking platform with multi-user functionality for business clients. AirAsia Group was listed as a ransomware victim associated with the threat actor daixin. |
|||||
| AirAsia Group View Details _ | Malaysia | daixin | Transportation / Travel / Logistics | ||
|
AirAsia is a Malaysian multinational low-cost airline headquartered near Kuala Lumpur, Malaysia. It is the largest airline in Malaysia by fleet size and destinations. AirAsia operates scheduled domestic and international flights to more than 165 destinations. |
|||||
| norseman.ca View Details _ | Canada | lockbit3 | Other | ||
|
Norseman.ca is the website of Norseman Inc, a long-established Canadian manufacturer based in Edmonton, Alberta, that provides shelter solutions for industries including construction, oil and gas, and manufacturing. Since the 1960s, the company has delivered industrial fabric, foam, and film protective solutions to diverse customers across North America. Norseman Inc operates from 14545 - 115 Avenue, Edmonton, AB, and is recognized as a leading supplier of shelter products in Canada. The company was listed as a ransomware victim associated with the LockBit3 threat actor. |
|||||
| UNITEDAUTO.MX HAVE BEEN HACKED DUE TO MULTIPLE NETWORK VULNERABILITIES. MORE THAN 2TB OF P View Details _ | lv | Telecommunications | |||
|
UNITEDAUTO.MX is a Mexico-based company identified in source material as United Auto, with a presence in Nuevo León and multiple branches in Mexican cities. Public company profiles describe it as a mobility and motor-vehicle business offering integrated auto solutions. The listing alleges the site was hacked through multiple network vulnerabilities and references more than 2TB of data, but that claim is not independently verified here. It was listed as a ransomware victim associated with lv. |
|||||
| https://www.vafb.com View Details _ | royal | Other | |||
|
vafb.com is the website for Virginia Farm Bureau, a Richmond, Virginia-based mutual insurance organization serving Virginians through auto, home, property, farm, and related coverage. Its site also points users to local agents, office locations, and member savings across the state. The company presents itself as part of a family of companies with insurance and service offerings for Virginia customers. It was listed as a ransomware victim associated with royal. |
|||||
| https://naulty.com View Details _ | royal | Other | |||
|
Naulty, Scaricamazza & McDevitt, LLC is a client-focused regional defense litigation law firm headquartered in Philadelphia, Pennsylvania. It serves clients across Pennsylvania, New Jersey, and Delaware and also lists an office in Marlton, New Jersey. The firm focuses on defense litigation and insurance-related legal services. It was listed as a ransomware victim associated with royal. |
|||||
| Institute of Science and Technology Austria View Details _ | vicesociety | IT | |||
|
Institute of Science and Technology Austria (ISTA) is a PhD-granting research institution in Lower Austria, near Vienna, focused on cutting-edge research in the physical, mathematical, computer, and life sciences. It is located in Klosterneuburg, on the outskirts of Vienna, and serves as an international institute for advanced research and graduate education. In threat-intelligence listings, it was recorded as a ransomware victim associated with vicesociety. |
|||||
| Kessing Rechtsanwälte und Fachanwälte in PartGmbB View Details _ | blackbasta | Other | |||
|
Kessing Rechtsanwälte und Fachanwälte in PartGmbB is a German law and notary practice based in Saterland-Ramsloh, Lower Saxony. The firm presents a team of attorneys with multiple legal specialisms and offers legal and notarial services from its Hauptstraße 517 office. It serves private and business clients with counsel across varied areas of law. The company was listed as a ransomware victim associated with blackbasta. |
|||||
| https://www.m2selectronics.com View Details _ | royal | Other | |||
|
M2S Electronics is an electronics and HVAC company headquartered in Quebec City, Quebec, Canada, specializing in heating, ventilation, air conditioning systems, thermostats, and electromechanical integration. The firm has over 15 years of experience serving clients in the railway sector across North America with more than 20 ambitious projects completed. It offers electronic design, assembly, PCBA, and box-build integration services for electromechanical and electronic systems. M2S Electronics was listed as a ransomware victim associated with the Royal threat actor. |
|||||