All Ransomware Records
Top Countries
All Ransomware Attacks in All period
Posts
| Target | Discovered | Country | Source | Business Category | Intel Link |
|---|---|---|---|---|---|
| www.vectorinf.c... View Details _ | lockbit2 | Other | |||
|
www.vectorinf.c... appears to refer to a U.S.-based web property in the Other sector; the available search results do not provide enough verified public detail to describe its specific offerings with confidence. In threat-intelligence indexing, such entities are typically cataloged by their web presence and sector when a fuller company profile is not publicly established. The listing was recorded as a ransomware victim associated with lockbit2. |
|||||
| cargoexperts.eu View Details _ | lockbit2 | Transportation / Travel / Logistics | |||
|
Cargo Experts Ltd operates in freight forwarding, logistics, and warehousing, offering supply chain solutions through offices in Cyprus, Greece, and Romania. Its website describes the company as a provider of freight forwarding and logistics services, with contact details in Strovolos, Nicosia, and additional locations in Athens and Constanța. The company appears in the transportation and travel logistics segment and serves international shipping and distribution needs. It was listed as a ransomware victim associated with lockbit2. |
|||||
| kaisoten.co.jp View Details _ | Japan | lockbit2 | Other | ||
|
Goto Kaisoten Ltd. is a comprehensive logistics operator headquartered in Kobe, Japan, specializing in port transportation services, customs brokerage, and freight forwarding. Founded in 1877, the company offers end-to-end support for transport, storage, and international multimodal logistics across ocean, air, and inland routes. Its business activities include warehousing, coastal shipping, worker dispatch services, and sales of marine containers and timber. The company operates a network of domestic and international locations, including offices in Taiwan and Hong Kong, to facilitate global intermodal transportation. Goto Kaisoten Ltd. was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| CAPECODRTA - HACKED AND DATA LEAKED View Details _ | lv | Other | |||
|
CAPECODRTA - HACKED AND DATA LEAKED appears to refer to the Cape Cod Regional Transit Authority, a public transit agency serving Cape Cod with regional bus and related rider information services in Massachusetts, United States. Public posts and coverage indicate it experienced ransomware-related disruption to website publishing and transit operations materials. The entity is categorized in the Other sector and is associated with a ransomware victim listing. It was listed as a ransomware victim associated with lv. |
|||||
| Palermo View Details _ | vicesociety | Other | |||
|
Palermo is the capital of Sicily and a city in southern Italy known for its historic port, urban commerce, tourism, and service industries. It also serves as a regional center for agriculture and other local economic activity. In broader location-based indexing, Palermo is used as a geographic entity rather than a company profile. It was listed as a ransomware victim associated with vicesociety. |
|||||
| virtus- View Details _ | lockbit2 | Other | |||
|
virtus- is an entity in the Other sector, and available sources do not provide a reliable public profile for its location or offerings. In threat-intelligence records, the name appears as a victim entry rather than as a full corporate description, so only limited factual context can be confirmed from public data. It is therefore best described conservatively as an otherwise unspecified organization in the Other sector. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Goodman Campbell Brain & Spine View Details _ | United States | hive | Other | ||
|
Goodman Campbell Brain & Spine is a US health care provider based in Indiana, with locations in Carmel, Greenwood, Indianapolis and other communities. It offers neurosurgical, spine and neurological care, including adult neurosurgery outpatient clinics, pain management and related specialty services. The organization describes itself as a leader in brain and spine care and a center for neurosurgery training and clinical research. It was listed as a ransomware victim associated with Hive. |
|||||
| English Construction Company View Details _ | United States | blackbasta | Construction / Real Estate | ||
|
English Construction Company, Inc. is a fourth-generation family-owned construction firm based in Lynchburg, Virginia, serving governmental, institutional, industrial, and infrastructure clients throughout the Mid-Atlantic. Founded in 1909, it provides general contracting and related construction services across projects such as roads, bridges, water and wastewater facilities, power plants, factories, and historic renovations. The company’s public contact listing places it at 615 Church Street in Lynchburg, VA. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Losberger De Boer View Details _ | blackbasta | Other | |||
|
Losberger De Boer is a Netherlands-based company that provides temporary and permanent space solutions, including tents, halls, modular buildings, and other structures for events and business use. The group operates internationally and lists offices in the Netherlands and Germany, with offerings spanning commercial, public, military, and event applications. In threat-intelligence listings, Losberger De Boer appears as a ransomware victim associated with blackbasta. |
|||||
| Alliance Steel View Details _ | conti | Manufacturing / Engineering | |||
|
Alliance Steel is a steel service center headquartered in Gary, Indiana, serving manufacturing and engineering customers from Northwest Indiana. The company supplies flat-rolled steel sheet and coil processing, including slitting, blanking, stretcher leveling, cold reduction, and laser-cut parts. Public company listings also show operations in Atlanta and Memphis. It was listed as a ransomware victim associated with Conti. |
|||||
| equis.com View Details _ | lockbit2 | Other | |||
|
Equis Development Pte. Ltd. is a Singapore-based infrastructure and energy development company with offices across Asia-Pacific, including Australia, Japan, South Korea and Singapore. The company focuses on the development, construction, ownership and operation of energy assets, including renewable and hybrid systems, and has also described bioenergy and broader infrastructure investment activity. Its site and related company materials indicate work across the project lifecycle from development through operation. It was listed as a ransomware victim associated with lockbit2. |
|||||
| gpml View Details _ | lockbit2 | Other | |||
|
GPML Group is a small construction company based in Wilmington, Kent, England, with 11-50 employees and a focus on construction services. Its public company profile identifies it as operating in the construction sector and using the GPMLGroup.co.uk website. In threat-intelligence indexes, GPML is referenced as a ransomware victim tied to the LockBit2 ecosystem. |
|||||
| https://www.equ... View Details _ | lockbit2 | Other | |||
|
equ is a personalized nutrition app from Australia that helps users plan meals and manage weight, strength, and body composition through guided dietary tools. Its service emphasizes sustainable nutrition support and macro-friendly recipes for everyday use. The company is associated with the Other sector and operates as a consumer health and wellness platform. It was listed as a ransomware victim associated with lockbit2. |
|||||
| VTVCAB View Details _ | everest | Other | |||
|
VTVCAB appears to be an organization in the Other sector, but the available sources do not provide enough reliable public detail to confirm its location or business offerings. In threat-intelligence listings, such entities are typically identified by name and sector when public corporate information is limited. Everest is a ransomware group active since at least 2020 and known for double-extortion activity across multiple industries and regions. VTVCAB was listed as a ransomware victim associated with everest. |
|||||
| mandiant.com View Details _ | lockbit2 | Other | |||
|
Mandiant is a leading cybersecurity company headquartered in Mountain View, California, offering incident response, threat intelligence services, and cyber risk management to enterprises and governments worldwide. As part of Google Cloud, Mandiant delivers frontline expert support for incident response and continuous monitoring through its managed services, empowering security teams to stay ahead of cyber threats. The company is recognized globally by enterprises, governments, and law enforcement agencies as the market leader in threat intelligence and expertise. Mandiant was listed as a ransomware victim associated with LockBit2. |
|||||
| kan View Details _ | lockbit2 | Other | |||
|
kan is a company in the Other sector; publicly available business details on its specific offerings and location are limited in the provided sources. Threat-intelligence listings use the name to index a ransomware-victim record tied to broader LockBit activity, a ransomware-as-a-service ecosystem active since 2021. LockBit 2.0 is the second major iteration of the group’s ransomware platform and has been associated with widespread extortion campaigns against organizations across many industries. kan was listed as a ransomware victim associated with lockbit2. |
|||||
| sesver.gob.mx View Details _ | Mexico | lockbit2 | Other | ||
|
sesver.gob.mx is the official health system of the state of Veracruz, Mexico, operating under the Secretaría de Salud de Veracruz. Located in Xalapa, Veracruz, it manages public health services, including vaccination programs and hospital infrastructure across 839 primary care units and 58 hospitals. The system has invested over 49 million pesos to ensure vaccine access for all municipalities, reaching more than 13 million doses. sesver.gob.mx was listed as a ransomware victim associated with the LockBit2 threat actor in a cyberattack targeting Mexico's health sector. |
|||||
| patralogistik.c... View Details _ | lockbit2 | Other | |||
|
PT Patra Logistik is an Indonesian logistics company in the energy supply chain, based in Jakarta Selatan, Jakarta. Its website describes the business as operating in upstream and downstream oil and gas logistics, with a focus on logistics services and related support services. Public profiles also describe it as supporting sustainable energy distribution across Indonesia. The entity was listed as a ransomware victim associated with lockbit2. |
|||||
| linmark.com View Details _ | lockbit2 | Other | |||
|
Linmark is a Hong Kong-based supply chain and sourcing company headquartered in Kowloon Bay, with operations centered on apparel and related product development, sourcing, merchandising, logistics, and quality control. The company describes itself as a supply chain partner that supports design, product development, sourcing, and execution across an international network. Its business profile also identifies it as a manufacturing-oriented firm serving global markets from Hong Kong. It was listed as a ransomware victim associated with LockBit2. |
|||||
| hyatts.com View Details _ | lockbit2 | Other | |||
|
hyatts.com belongs to Hyatt Hotels Corporation, a global hospitality company headquartered in Chicago, Illinois, with operations in the United States and internationally. Hyatt develops, manages, franchises, and operates hotels and resorts across multiple brands and market segments. Founded in 1957 near Los Angeles International Airport, the company is known for its hospitality and lodging services. It was listed as a ransomware victim associated with lockbit2. |
|||||
| IBRCN.COM View Details _ | lockbit2 | Other | |||
|
IBRCN.COM is a United States-based organization in the Other sector, though its public-facing business description is not readily established from available sources. As a domain-based listing, it may represent a company, service, or institutional site rather than a clearly classified industry operator. The threat-intelligence record associates IBRCN.COM with a ransomware victim listing tied to lockbit2. |
|||||
| kansashighwaypa... View Details _ | lockbit2 | Other | |||
|
kansashighwaypa... is an Other-sector organization in the United States, identified in a ransomware victim listing rather than a detailed company profile. Public search results do not provide enough verified context to describe its offerings, so the entity is best treated as a named organization associated with a threat-intelligence record. The listing places it in the ransomware-victim category monitored by the index. It was listed as a ransomware victim associated with lockbit2. |
|||||
| bestattung-walz... View Details _ | lockbit2 | Other | |||
|
bestattung-walz... appears to be a funeral-services business in Germany, likely operating as a local bestattung or bestattungsinstitut that supports families with burial arrangements, funeral planning, and related care. Public web results for similar businesses show this sector typically offers personal consultation, 24-hour availability, and assistance with arrangements in the surrounding region. The listing is categorized in the Other sector, and it was listed as a ransomware victim associated with lockbit2. |
|||||
| vainieritraspor... View Details _ | lockbit2 | Other | |||
|
vainieritraspor... is an Other-sector entity whose public-facing business details are not clearly established in the available records. No reliable web results identify a confirmed country, core offering, or operating profile, so it should be treated as an unidentified organization for cataloging purposes. In threat-intelligence indexing, it appears as a ransomware victim entry tied to the LockBit2 actor set. The listing places vainieritraspor... in the Other sector and associates it neutrally with lockbit2. |
|||||
| rosagroup View Details _ | lockbit2 | Services | |||
|
Rosa Group is a Services-sector business based in Italy. The company says it focuses on exclusive tourism, emphasizing service, hospitality, attention to detail, and empathy. It also states that it began in construction before diversifying into premium tourism. In this index, rosagroup is listed as a ransomware victim associated with lockbit2. |
|||||
| SilTerra - HACKED AND 1 TB DATA LEAKED WITH SOURCES AND NDA View Details _ | lv | Other | |||
|
SilTerra Malaysia Sdn. Bhd. is a semiconductor and electronic component manufacturer headquartered in Kulim, Kedah, Malaysia. The company operates within the Kulim Hi-Tech Park, a leading high-technology industrial zone in northern Malaysia. It provides wafer fabrication and related semiconductor offerings to clients in Taiwan and Malaysia. SilTerra was listed as a ransomware victim associated with lv following a security incident involving leaked data and NDA breach. |
|||||
| wik-group.com View Details _ | lockbit2 | Services | |||
|
wik-group.com is the digital presence of WIK Group, a Hong Kong-headquartered company in the services sector specializing in the design, production, and distribution of electrical household appliances. The firm operates globally, serving leading brands with offerings including kitchen appliances, water systems, beverage systems, and coffee equipment. WIK Group functions as a contract designer and manufacturer for industry-leading global brands, with facilities in Hong Kong, China, and Indonesia. The company was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| specpharm.co.za View Details _ | South Africa | lockbit2 | Other | ||
|
Specpharm.co.za belongs to Specpharm, a South African pharmaceutical company based in Gauteng, South Africa. The company describes itself as black-owned and empowered, with activities in the registration, sales, and marketing of high-quality medicines, and its manufacturing arm operates in pharmaceuticals. Public directory listings also describe Specpharm as focused on the development, manufacturing, and distribution of specialised medicines. The entity was listed as a ransomware victim associated with lockbit2. |
|||||
| ora.com View Details _ | lockbit2 | Other | |||
|
ora.com is associated with ORA Group, which is headquartered in Alme', Lombardy, Italy, and presents itself as a company focused on training management, occupational medicine, safety consulting, and safety and environmental services. Public business listings also describe Ora as a customer intelligence platform for tracking, monitoring, and analyzing a company and its competitors online. The available records indicate an other-sector organization with an Italian business presence. It was listed as a ransomware victim associated with lockbit2. |
|||||
| colonail.com View Details _ | lockbit2 | Other | |||
|
Colonail.com is the website of the City of Colona, a local government in Colona, Illinois, in the United States. The city provides municipal services and public information, with office hours listed Monday through Friday from 8:00 a.m. to 4:30 p.m. Colonail.com was listed as a ransomware victim associated with lockbit2. |
|||||
| familyclinicbri... View Details _ | lockbit2 | Healthcare / Pharma | |||
|
familyclinicbri... appears to refer to a family medicine or primary care clinic in the Healthcare / Pharma sector, serving patients with routine and preventive medical care. Publicly available clinic listings show Brio Primary Care in Greenville and Simpsonville, South Carolina, offering preventive care and chronic-condition management across multiple locations. The entity is a healthcare provider rather than a manufacturer or distributor, and its public-facing services center on outpatient primary care. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Northeastern Technical College View Details _ | suncrypt | Education | |||
|
Northeastern Technical College is a public two-year community college in Cheraw, South Carolina, serving Chesterfield, Marlboro, and Dillon counties. It operates branch campuses in Bennettsville, Dillon, and Pageland and provides college transfer, occupational, technical, and continuing-education programs. The college’s mission is to prepare the local workforce through education and training. It was listed as a ransomware victim associated with suncrypt. |
|||||
| Sierra Packaging Leaked View Details _ | ragnarlocker | Other | |||
|
Sierra Packaging Leaked is a threat-intelligence listing for a packaging company in the Other sector, reportedly operating in the United States and offering packaging-related products or services. Publicly available search results do not provide a reliable company profile for this exact name, so the description is limited to the entity label and sector. The entry is used to index a ransomware-related incident for monitoring and analysis. It was listed as a ransomware victim associated with ragnarlocker. |
|||||
| sport View Details _ | lockbit2 | Other | |||
|
sport is listed in the Other sector and appears as an organization or entity name rather than a clearly identified public company. Available catalog data does not provide a verified location or a detailed public profile for this entity, so its business offerings cannot be stated beyond the listing itself. In threat-intelligence indexes, such entries are used to tag victims by sector and attribution when public disclosure is limited or unavailable. It was listed as a ransomware victim associated with lockbit2. |
|||||
| St Paul View Details _ | vicesociety | Other | |||
|
St Paul most commonly refers to Saint Paul, the capital of Minnesota and the county seat of Ramsey County in the United States. The city serves as a public-sector hub and houses municipal departments that support residents through services such as public safety, parks, and emergency response. In threat-intelligence catalogs, the name may also appear as an entity label when listing incident references. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Acorn Recruitment View Details _ | vicesociety | Other | |||
|
Acorn Recruitment Limited, now branded as Acorn by Synergie, is a UK staffing and recruitment agency based in Newport, Wales. It provides specialist permanent, contract and temporary recruitment solutions across the UK, serving employers and jobseekers through multiple branches and divisions. The business operates in the recruitment sector and is registered as an active private limited company in Newport. It was listed as a ransomware victim associated with vicesociety. |
|||||
| The De Montfort School View Details _ | vicesociety | Education | |||
|
The De Montfort School is a co-educational secondary school and sixth form in Evesham, Worcestershire, England. It serves students in the Education sector and provides secondary and post-16 schooling. The school has also been profiled as an education employer in Evesham, United Kingdom. It was listed as a ransomware victim associated with vicesociety. |
|||||
| closetheloopeu.... View Details _ | lockbit2 | Other | |||
|
closetheloopeu.... appears to be Close The Loop EU, a Belgian company based in Malle that presents itself as part of the Close The Loop recycling group. Its website lists a Delften 23, Unit 13 address in 2390 Malle and describes recycling-related activity under the group’s circular-economy brand. Public company profiles also place the broader Close The Loop group in Melbourne, Australia, with operations across Australia, the Americas, and EMEA. It was listed as a ransomware victim associated with lockbit2. |
|||||
| jewelry.or View Details _ | lockbit2 | Other | |||
|
jewelry.or appears to be a jewelry-related entity, and jewelry generally covers decorative items such as rings, necklaces, earrings, bracelets, and similar personal adornments. In industry terms, jewelry retail commonly includes the sale of new jewelry, watches, and related repair or customization services. The listing places jewelry.or in the Other sector. It was listed as a ransomware victim associated with lockbit2. |
|||||
| compagniedep View Details _ | lockbit2 | Other | |||
|
compagniedep is a French entity operating in the manufacturing sector, with its primary activities centered on production and related industrial offerings. The company is based in France and provides goods typical of the manufacturing industry, though specific product details are not publicly documented. While operational specifics remain limited, compagniedep is recognized as part of the broader French manufacturing landscape. The company was listed as a ransomware victim associated with lockbit2, marking its inclusion in this threat-intelligence index. |
|||||
| hilltopconstruc View Details _ | lockbit2 | Other | |||
|
Hilltop Construction is a U.S. construction firm that provides residential and commercial building services, including design-build work, for projects in Upstate New York. The company describes over 40 years of experience focused on craftsmanship, communication, and durable construction, and it also lists a Freehold, New Jersey headquarters and an Upstate New York operating presence. As a business in the Other sector, it fits a broad construction-services profile rather than a specialized vertical. It was listed as a ransomware victim associated with lockbit2. |
|||||
| cepima View Details _ | lockbit2 | Other | |||
|
Cepima is a research group in the Department of Chemical Engineering at the Universitat Politècnica de Catalunya in Spain. It focuses on computer modelling and optimisation of chemical processes, including the development of artificial-intelligence-based support techniques and software. In a threat-intelligence context, it belongs to the broader category of organizations outside a traditional commercial sector. Cepima was listed as a ransomware victim associated with lockbit2. |
|||||
| XYTECH - HACKED AND 650 GB DATA LEAKED View Details _ | lv | IT | |||
|
XYTECH is a U.S.-based software company focused on media operations for broadcast and production workflows. It provides a media operations platform for managing people, resources, assets, scheduling, workflow, and related business processes in the media and entertainment sector. Its offerings include media resource management and operational automation for organizations handling content and transmission. The listing identifies XYTECH as a ransomware victim associated with lv. |
|||||
| CICIS.COM- HACKED AND INFORMATION MORE THEN 120,000 CUSTOMERS LEAKED View Details _ | lv | Other | |||
|
Cicis Pizza is a U.S.-based restaurant chain headquartered in Coppell, Texas, known for its pizza buffet, carryout, delivery, wings, salads, pasta, sides, and desserts. The brand operates locations across the United States and promotes an all-you-can-eat buffet and value-oriented menu for dine-in and to-go orders. The listing refers to CICIS.COM- HACKED AND INFORMATION MORE THEN 120,000 CUSTOMERS LEAKED as a ransomware victim. It is associated with lv. |
|||||
| bradfo View Details _ | lockbit2 | Other | |||
|
Bradford Company is a fifth-generation, family-owned U.S. manufacturer of packaging products and material handling systems. It produces industrial chipboard partitions, custom-engineered reusable and returnable protective packaging, and serves industries such as automotive, appliance, electronics, and consumer products. The company is headquartered in Holland, Michigan, and operates additional North American locations. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Jonathan Adler Leaks View Details _ | ragnarlocker | Other | |||
|
Jonathan Adler Leaks is a ransomware victim listing tied to the name Jonathan Adler and categorized in the Other sector. Available intelligence does not identify a public-facing business profile, products, or a confirmed operational location for this entry. The listing is used in ransomware tracking catalogs to record claimed victims and related threat activity. It was listed as a ransomware victim associated with ragnarlocker. |
|||||
| Groupe J.F. Nadeau Inc View Details _ | blackbasta | Services | |||
|
Groupe J.F. Nadeau Inc is a Québec-based company in the services sector, with listings placing it in Sainte-Mélanie and Thetford Mines, Canada. Public company descriptions say it specializes in general transport and live poultry transport, with long-standing operations serving local industries. Directory records also associate the firm with excavation, demolition, earthworks, snow removal, and crushing and screening services. It was listed as a ransomware victim associated with blackbasta. |
|||||
| JBS TEXTILE GROUP View Details _ | blackbasta | Services | |||
|
JBS TEXTILE GROUP A/S is a Denmark-based textile company headquartered in Herning, Central Jutland. It is known as Scandinavia’s largest supplier of underwear and says it offers a broad range of clothing through multiple own brands. Company profiles also describe it as operating in apparel and textile distribution and manufacturing. The entity was listed as a ransomware victim associated with blackbasta. |
|||||
| CAVENDERS View Details _ | blackbasta | Other | |||
|
Cavender's is a Texas-based retailer focused on Western wear and fashion, serving customers through stores and online sales in the United States. It has operated for more than 60 years and is known for boots, apparel, and accessories inspired by Western lifestyle and culture. Public store openings show locations across Texas and other U.S. states. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Westwood View Details _ | United States | lorenz | Other | ||
|
Westwood Country Club is a private country club located in Westwood, Missouri, within central St. Louis County, offering golf, dining, and recreational facilities exclusively for members and their guests. The club, headquartered at 11801 Conway Road in Saint Louis, MO, pursues excellence in providing world-class social and exclusive recreational experiences for its members, families, and guests. It operates as a private club that respects traditional values centered on friendship, camaraderie, and appreciation of the game. Westwood Country Club was listed as a ransomware victim associated with the threat actor Lorenz. |
|||||
| CMC Electronics View Details _ | Canada | alphv | Other | ||
|
CMC Electronics is a Canadian avionics manufacturer headquartered in Montreal, Quebec, with additional operations in Ottawa, Ontario, and Sugar Grove, Illinois. It designs and manufactures advanced commercial and military avionics, including cockpit systems integration, display solutions, and custom, open-architecture aerospace systems. The company serves civil and defense aviation customers and emphasizes engineering, manufacturing, and support across North America. It was listed as a ransomware victim associated with alphv. |
|||||
| G&P Projects And Systems S.A. View Details _ | Brazil | hive | Communication / Marketing | ||
|
G&P Projects And Systems S.A. is a Brazilian enterprise operating for nearly three decades in the information technology sector, with locations in São Paulo and Rio de Janeiro. The company specializes in delivering end-to-end solutions for developers, contractors, and project teams seeking reliable sourcing and streamlined procurement support. It operates within the communication and marketing industry, providing technology-driven services to clients across Brazil. G&P Projects And Systems S.A. was listed as a ransomware victim associated with the hive threat actor. |
|||||
| Caracol TV View Details _ | Colombia | hive | Other | ||
|
Caracol Televisión is a Colombian media and entertainment company and one of the country’s two private national TV networks. Based in Bogotá, it broadcasts popular programming across entertainment, series, realities, telenovelas, documentaries, and live television. The channel is widely known for its national reach and Spanish-language content distribution. It was listed as a ransomware victim associated with hive. |
|||||
| intertabak.com View Details _ | lockbit2 | Other | |||
|
Intertabak AG operates in the tobacco retail and import sector in Switzerland, with locations in Basel, Zurich, Lugano, St. Gallen, Nyon, Zug, Samnaun Dorf, Mendrisio, and Geneva. It presents itself as the exclusive direct importer of Cuban cigars and Cuban cigarillos in Switzerland and Liechtenstein, and its site also promotes La Casa del Habano franchise shops. The company serves consumers through a network of specialist cigar stores and related retail services. It was listed as a ransomware victim associated with lockbit2. |
|||||
| inla View Details _ | lockbit2 | Other | |||
|
inla is identified in available records as a life sciences organization based in Los Angeles County, California, a region that supports companies in this industry cluster. Life sciences firms typically operate in research, development, and related services for health and biomedical applications. Publicly indexed threat-intelligence material associates inla with the other sector category used in this listing. It was listed as a ransomware victim associated with lockbit2. |
|||||
| tcpharmachem.co... View Details _ | lockbit2 | Healthcare / Pharma | |||
|
T.C. Pharma-Chem Co., Ltd. is a Thailand-based distributor of pharmaceutical and healthcare products, operating from Bangkok and presenting itself as a long-running supplier in the sector. Company information describes its business as serving healthcare and pharmaceutical distribution needs in Thailand. In threat-intelligence listings, tcpharmachem.co... is cataloged as a ransomware victim associated with LockBit2. |
|||||
| gpmlife.com View Details _ | lockbit2 | Other | |||
|
GPM Life Insurance Company is a San Antonio, Texas-based life insurer serving individuals and families, federal employees, and active-duty military members. Its offerings include life insurance products and Medicare Supplement coverage, with customer and agent support handled through its Texas headquarters. The company describes itself as a long-standing provider of insurance solutions and related financial protection products. It was listed as a ransomware victim associated with lockbit2. |
|||||
| foxconnbc.com View Details _ | lockbit2 | Other | |||
|
Foxconn BC, operating at foxconnbc.com, is an electronics and original equipment manufacturer based in Tijuana, Baja California, Mexico. The company describes itself as providing advanced manufacturing services for electronic products and OEM customers, and business listings identify it as a contract manufacturer serving industries such as consumer electronics and medical devices. Public business sources place it in the Other sector because its site focuses on manufacturing services rather than a single end-market. It was listed as a ransomware victim associated with lockbit2. |
|||||
| koenigstahl.pl View Details _ | Poland | lockbit2 | Other | ||
|
KönigStahl is a Polish company based in Warszawa, Poland, with additional operations in Poznań and Solec Kujawski. It specializes in the distribution of steel tubes, hollow sections, and drawn steel, and also sells window, door, and facade systems, including Jansen steel systems. The company presents itself as a long-established steel trader serving the Polish market. It was listed as a ransomware victim associated with lockbit2. |
|||||
| pauly.de View Details _ | Germany | lockbit2 | Other | ||
|
Pauly operates in Germany as an office products retailer and distributor, serving business and other customers through its pauly.de web presence and related commercial activities. Company listings place it in the retail and software testing categories, with headquarters in Limburg an der Lahn, Hesse. In threat-intelligence indexes, it is treated as an “Other” sector entity because its public profile is not tied to a single specialized industry. It was listed as a ransomware victim associated with lockbit2. |
|||||
| hospitalsanjose... View Details _ | lockbit2 | Healthcare / Pharma | |||
|
hospitalsanjose appears to refer to a San Jose, California healthcare provider operating hospital and specialty care services through local medical facilities. Public location listings show San Jose Medical Center at 250 Hospital Pkwy in San Jose, with emergency services available 24 hours a day, alongside additional nearby outpatient and support locations. The organization serves patients in the San Jose area across general hospital and care-center offerings. It was listed as a ransomware victim associated with lockbit2. |
|||||
| BLAIR inc. View Details _ | blackbasta | Services | |||
|
BLAIR Inc. is a woman-owned, full-service exhibit house in Springfield, Virginia, serving clients from planning and design through fabrication, shipping, and full installation services. Its offerings also include exhibit development and management, positioning the company in the Services sector. Public business listings place its office at 7001 Loisdale Road in Springfield, VA. It was listed as a ransomware victim associated with blackbasta. |
|||||
| An Technology Company - Paid View Details _ | cheers | IT | |||
|
An Technology Company - Paid is an IT-sector company in Australia, operating in information technology and related services. Publicly available search results do not provide a reliable official company profile, so its location and offerings beyond that sector-level identification are not confirmed. In threat-intelligence indexing, it appears as a named entity used to track ransomware-related exposure and attribution context. It was listed as a ransomware victim associated with cheers. |
|||||
| An Financial Company - Paid View Details _ | cheers | Finance / Legal / Insurance | |||
|
An Financial Company - Paid is a financial-services organization in the Finance, Legal, and Insurance space, a sector that includes providers of lending, insurance, and related risk-management services. In the United States, premium finance companies are a regulated class of financial businesses that help customers fund insurance premiums, and financial-services firms often also support legal and insurance operations. The listing appears in a threat-intelligence context rather than as a public corporate profile. It was listed as a ransomware victim associated with cheers. |
|||||
| An Belgium Hospital - Unpay View Details _ | cheers | Healthcare / Pharma | |||
|
An Belgium Hospital - Unpay appears as a Belgium-based healthcare and pharma entity in a hospital context, indicating activity centered on patient care and related medical services in Belgium. Public reporting on Belgian hospitals in ransomware incidents describes operational disruption, including cancelled surgeries and staff payment issues, underscoring the sector’s exposure to cyber risk. The listing reflects a healthcare organization rather than a cyber actor, and its name suggests an unpaid account or billing-related label used in threat-intelligence indexing. It was listed as a ransomware victim associated with cheers. |
|||||
| An International Maritime Company - Unpay View Details _ | cheers | Services | |||
|
An International Maritime Company - Unpay is a Services-sector maritime business associated with maritime operations and seaborne commerce in Panama. International maritime companies typically provide shipping, vessel, crew, logistics, or related support services to keep trade moving across ports and routes. The name suggests a company operating in the maritime services space rather than a manufacturer or retailer. It was listed as a ransomware victim associated with cheers. |
|||||
| Travira Air View Details _ | Indonesia | hive | Other | ||
|
Travira Air is an Indonesian air charter service operator headquartered in Jakarta. Public company profiles also describe it as providing maintenance services in the aviation sector and serving specialized commercial clients from its Jakarta base. The company is associated with charter operations rather than scheduled passenger airline service. It was listed as a ransomware victim associated with hive. |
|||||
| XEIAD View Details _ | United Kingdom | hive | Other | ||
|
XEIAD appears to be a United Kingdom-based organization in the broad “Other” sector, indicating a business or entity outside standard industry classifications. Publicly available details about its specific offerings are limited, so a neutral profile should avoid assuming products or services beyond its identified sector and country. Hive is a ransomware operation known for double extortion, which has targeted organizations across multiple sectors. XEIAD was listed as a ransomware victim associated with Hive. |
|||||
| undefined View Details _ | blackbasta | Other | |||
|
undefined is listed here as an entity in the Other sector, but no reliable public details in the provided sources identify its location, offerings, or corporate profile. Black Basta is a ransomware-as-a-service group known for double-extortion operations, using encryption plus data-theft threats against organizations across many industries. Public reporting shows it has targeted a broad mix of sectors worldwide, including business services, manufacturing, finance, healthcare, and infrastructure. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Florida Department of Veterans' Affairs View Details _ | United States | quantum | Public Sector | ||
|
floridavets.org is the official website of the Florida Department of Veterans’ Affairs, a US public-sector agency based in Largo, Florida. It serves as a central entry point for Florida veterans seeking benefits, claims help, employment support, and other state and federal services. The site also provides contact details for service officers, crisis support, and veterans’ preference guidance. It was listed as a ransomware victim associated with quantum. |
|||||
| kerrylog View Details _ | lockbit2 | Other | |||
|
kerrylog is an organization in the Other sector; public search results do not provide a verified company profile, so its exact location and offerings are not clearly documented. In a threat-intelligence context, it is best described only at that general level unless a first-party source identifies the business more specifically. LockBit 2.0 is a ransomware-as-a-service operation used to extort victims through data theft and encryption. kerrylog was listed as a ransomware victim associated with lockbit2. |
|||||
| skinnertran View Details _ | lockbit2 | Other | |||
|
Skinnertran, formally known as Skinner Transportation, Inc., is a trucking company headquartered in Austin, Texas, specializing in the transport of hot asphalt and emulsions for highway construction projects in central Texas. Founded in 1992, the firm provides high-quality, accident-free transportation services primarily for clients working with asphalt and related materials. The company operates with a workforce of 41 to 49 employees and maintains its base at 850 Ed Bluestein Blvd., Austin, TX, United States. Skinnertran was listed as a ransomware victim associated with the threat actor Lockbit2, with no official confirmation of stolen data types or breach specifics disclosed by the company itself. |
|||||
| ils.theinnovate... View Details _ | lockbit2 | Other | |||
|
ils.theinnovate... appears to be a U.S.-based organization associated with the broader Innovate branding, but public search results do not clearly identify a specific sector, location, or services for this exact entity. Because the name is incomplete, its operational profile cannot be verified from available sources without risking misidentification. In threat-intelligence catalogs, such records are often used to index entities tied to intrusion claims or extortion campaigns for analyst review. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Lamborghini, Ferrari, Fiat Group, VAG, Brembo And data from other automobile concerns View Details _ | everest | Telecommunications | |||
|
Lamborghini, Ferrari, Fiat Group, VAG and Brembo are names tied to major automotive manufacturers and suppliers in Italy and Europe, spanning luxury cars, mass-market vehicles, components and braking systems. Ferrari and Lamborghini are Italian performance-car brands, Fiat Group is an Italian automotive group, VAG refers to Volkswagen Group, and Brembo is a specialist manufacturer of braking systems used across the automotive industry. The listing also references data from other automobile concerns, indicating a broader automotive-targeted context rather than a single company profile. It was listed as a ransomware victim associated with Everest. |
|||||
| Mebulbs View Details _ | lorenz | Other | |||
|
MEbulbs, formerly Maintenance Engineering Ltd, is a premium industrial lighting company headquartered in Fargo, North Dakota, United States. The firm designs, develops, and markets its own lighting products, including light bulbs, LED bulbs, fixtures, and retrofits for offices, stores, schools, and factories. It serves commercial, industrial, and retail sectors with comprehensive lighting solutions for diverse applications. MEbulbs was listed as a ransomware victim associated with the threat actor lorenz. |
|||||
| edm-stone.com View Details _ | lockbit2 | Other | |||
|
edm-stone.com is associated with EDM USA, a construction-sector business that offers natural stone and marble procurement, fabrication, and installation services for interior projects. Public business listings describe the company as focused on stone and marble work, including design-oriented supply and installation for clients in the United States. The domain and related profiles point to a U.S.-based operation serving commercial and residential stone projects. It was listed as a ransomware victim associated with lockbit2. |
|||||
| SOUCY View Details _ | Canada | hive | Other | ||
|
SOUCY is a Canadian industrial group based in Drummondville, Québec, that designs and manufactures track systems and high-performance components and accessories for off-road vehicles. Its broader operations also include parts and castings for sectors such as power sports, agriculture, defense, and industrial applications. Public company listings describe Soucy as an integrated manufacturing and distribution group with multiple Québec locations. It was listed as a ransomware victim associated with hive. |
|||||
| Guardian Fueling Technologies View Details _ | United States | hive | IT | ||
|
Guardian Fueling Technologies is a privately held US company based in Jacksonville, Florida, serving fuel system owners and operators across the Southeast. It provides petroleum equipment distribution, fueling system construction, installation, maintenance, and related service support. Public company materials describe it as a provider of world-class fueling solutions and technology with multiple branch locations across several states. It was listed as a ransomware victim associated with Hive. |
|||||
| ChemStation International View Details _ | United States | hive | Services | ||
|
ChemStation International, Inc. is a US-based company headquartered in Dayton, Ohio that produces industrial cleaning and process chemicals. The company's products serve diverse industries including concrete form release, flexographic printing, floor cleaning, food and beverage, forest products, odor control, parts cleaning, and transportation. ChemStation offers custom-formulated, environmentally friendly cleaning solutions delivered via a unique refillable container system. The company was listed as a ransomware victim associated with the hive threat actor. |
|||||
| GUARDFUEL View Details _ | hive | Energy | |||
|
GUARDFUEL is a US-based Energy sector company that designs, constructs, services, and distributes equipment for petroleum storage, pumping, and dispensing systems, as well as EV chargers and associated products. The company provides factory-authorized service, sales, and installation of major equipment lines for retail and commercial-industrial fuel system applications across Florida, North Carolina, and Georgia. GUARDFUEL was listed as a ransomware victim associated with the threat actor hive. |
|||||
| NUAIRE View Details _ | United Kingdom | hive | Other | ||
|
NUAIRE LIMITED is a British company registered in Leeds, England, specializing in the manufacture of non-domestic cooling and ventilation equipment. Founded in 1966 and headquartered in Bridgend, Wales, the firm produces fans for both commercial and residential applications. For over 50 years, Nuaire has provided clean air solutions through ventilation systems for residential, commercial, and industrial buildings. The company was listed as a ransomware victim associated with the threat actor hive. |
|||||
| IGHQ View Details _ | hive | Other | |||
|
IGHQ is a U.S.-based real estate company headquartered in San Diego, California, with a Boston presence and a portfolio focused on life-science and innovation districts. Its website says it develops properties in major U.S. research hubs and in the United Kingdom, serving tenants in science and technology-driven markets. Public business directories also classify IGHQ as a real estate firm. It was listed as a ransomware victim associated with hive. |
|||||
| Huge iCloud Nudes Leak View Details _ | darkleakmarket | IT | |||
|
Huge iCloud Nudes Leak refers to a collection of nude photographs of celebrities that were exposed after hackers gained unauthorized access to their iCloud accounts through targeted phishing attacks. The incident occurred in the IT sector, primarily affecting users in the United States, with offerings centered on the public dissemination of stolen intimate images from cloud storage. Apple confirmed that certain celebrity accounts were compromised via a highly targeted assault on usernames, passwords, and security questions, though no breach of Apple’s own systems was found. This listing was categorized as a ransomware victim associated with the darkleakmarket group, which operates as a dark web data resale marketplace active since at least 2019. |
|||||
| Yachiyo Of America View Details _ | Japan | hive | Other | ||
|
Yachiyo Of America is a Tier 1 automotive supplier specializing in plastic fuel tanks and sunroofs, operating its North American headquarters and R&D center in Columbus, Ohio. The company, founded in 1997 as a consolidated subsidiary of Motherson Yachiyo Automotive Systems, is committed to innovation and quality in manufacturing automotive components. It serves the global automotive industry with products including fuel tanks, sunroofs, and rollshades, maintaining production facilities in Marion, Ohio. Yachiyo Of America was listed as a ransomware victim associated with the threat actor hive. |
|||||
| AGCO View Details _ | blackbasta | Other | |||
|
AGCO Corporation is a U.S.-based agricultural equipment company headquartered in Duluth, Georgia, that designs, manufactures, and distributes machinery and precision-agriculture solutions for farmers worldwide. Its portfolio includes tractors, harvesting equipment, and related brands that support modern farming operations. The company operates globally and serves the agricultural sector as an equipment and technology supplier. It was listed as a ransomware victim associated with blackbasta. |
|||||
| LCRD View Details _ | conti | Other | |||
|
LCRD is NASA’s Laser Communications Relay Demonstration, a space communications mission managed by Goddard Space Flight Center in the United States. It tests optical relay links that move data between spacecraft and Earth using laser communications, with ground stations in California and Hawaii. The program supports NASA and external partners by evaluating high-speed, bidirectional laser communications for future missions. It was listed as a ransomware victim associated with Conti. |
|||||
| The Contact Company View Details _ | conti | Services | |||
|
The Contact Company is a small-sized contact center solutions provider located in Birkenhead, Merseyside, United Kingdom, specializing in outsourced customer support services. As a European BPO, the firm offers exceptional services in the customer service industry, managing inbound and outbound helplines for retail, eCommerce, and financial clients. The company helps businesses maintain customer satisfaction by staffing helplines on demand, ensuring fast and personalized service across multiple channels. It was listed as a ransomware victim associated with the threat actor conti. |
|||||
| pointsbet.com View Details _ | lockbit2 | Other | |||
|
PointsBet is an Australian-founded online sports wagering operator and iGaming provider that offers sports and racing betting products and services. It is headquartered in Melbourne, Victoria, Australia, and operates as an ASX-listed company in the horse and sports betting sector. The brand serves customers through its digital betting platform and related wagering services. It was listed as a ransomware victim associated with LockBit2. |
|||||
| TRANSCONTRACT View Details _ | kelvinsecurity | Other | |||
|
TRANSCONTRACT is a ship-management company founded in 1994, focused on employing seamen and other crew members on foreign vessels. It operates in the maritime services sector and is associated with London, United Kingdom, through its UK-registered ship-management business. Public company records also show a dissolved UK entity using the TRANSCONTRACT name, underscoring that the name has been used in shipping-related operations. The entity was listed as a ransomware victim associated with kelvinsecurity. |
|||||
| Mansfield Energy View Details _ | kelvinsecurity | Energy | |||
|
Mansfield Energy is a family-owned energy company headquartered in Gainesville, Georgia, serving customers across North America. Founded in 1957, it provides fuel supply, logistics, and energy procurement solutions, including diesel, natural gas, and related energy management services. The company says it operates in every U.S. state and all 10 Canadian provinces. It was listed as a ransomware victim associated with kelvinsecurity. |
|||||
| Central Restaurant Products View Details _ | conti | Hospitality / Food & Beverage / Tourism | |||
|
Central Restaurant Products is a leading wholesale distributor of commercial kitchen equipment and supplies, headquartered in Indianapolis, Indiana, serving the foodservice industry in the United States and internationally. The company offers over 10,000 items including refrigeration solutions, cooking equipment, restaurant furniture, food preparation tools, and dishwashing sanitation systems. Founded in 1981, it supplies a wide range of commercial kitchen equipment and smallwares to more than 250,000 customers across the Hospitality, Food & Beverage, and Tourism sectors. Central Restaurant Products was listed as a ransomware victim associated with the threat actor conti. |
|||||
| Schaumburg Park District View Details _ | conti | Other | |||
|
Schaumburg Park District is a parks and recreation agency serving Schaumburg, Illinois, in the Chicago metropolitan area. It provides community leisure opportunities through programs, facilities, parks, and open spaces, and it maintains more than 60 parks across the area. The district operates as a local public-sector service organization focused on recreation, events, and outdoor amenities. It was listed as a ransomware victim associated with conti. |
|||||
| vitalprev.com.b... View Details _ | lockbit2 | Communication / Marketing | |||
|
VitalPrev is a Brazilian company based in São Paulo, with a contact address in Vila Mariana, that presents itself as a provider in occupational medicine and preventive health. Its website says it has operated in workplace health and safety for more than 19 years, offering occupational medicine management, preventive health services, and SST training. Public business directories also classify the company in human health services. The entity was listed as a ransomware victim associated with lockbit2. |
|||||
| https://www.vit... View Details _ | lockbit2 | Other | |||
|
VIT is an Australian education provider based in Melbourne, with additional campuses in Geelong and Adelaide. It offers higher-education and vocational pathways, including bachelor’s, master’s, MBA, vocational, and ELICOS programs, and provides in-person and remote support for prospective students. Public contact details and campus addresses are listed on its website. VIT was listed as a ransomware victim associated with lockbit2. |
|||||
| pet-link.com View Details _ | lockbit2 | Other | |||
|
PetLink operates in the **pet identification and reunification** sector, offering microchip registration, lost-pet recovery tools, and GPS tracking products for dogs and cats. Its website also supports veterinarians, shelters, and other animal professionals in registering and managing pet records. Based in the United States, PetLink presents itself as a long-running service focused on helping owners and pets reconnect. The domain was listed as a ransomware victim associated with **lockbit2**. |
|||||
| kuwaitflourmill... View Details _ | lockbit2 | Other | |||
|
Kuwait Flour Mills and Bakeries Company is a leading food industry pioneer in the State of Kuwait, operating across nine facilities throughout the country. The company specializes in food industries, including flour milling and bakery production, with bakeries located in Al Shaab, Kifan, Khaitan, Jahraa, Yarmouk, Shuwaikh, Rumaytheya, and Ahmadi. It serves as a cornerstone of Kuwait's food security infrastructure, supporting national milling and grain storage operations at its Al Shuwaikh port site. The company was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| erdwaerme-gruen... View Details _ | lockbit2 | Other | |||
|
Erdwärme Grünwald GmbH is a German geothermal-energy company based in Grünwald, Bavaria, with offices at Rathausstraße 3, 82031 Grünwald. It develops and operates deep geothermal projects that use underground heat to supply energy, including heating and power generation. Public project information identifies its Grünwald geothermal plant as an established local energy asset. The company was listed as a ransomware victim associated with lockbit2. |
|||||
| architectenbure... View Details _ | lockbit2 | Other | |||
|
architectenbure... is an architecture business in the Netherlands, part of the broader architecture sector that plans and designs buildings and related spaces. Architecture firms typically develop concepts, drawings, and project documentation for clients across commercial, residential, and public projects. The available listing identifies architectenbure... in an “Other” sector classification. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Allports Group View Details _ | blackbasta | Services | |||
|
Allports Group is a UK-based services company focused on logistics and commercial vehicle support. Its website lists sea freight, air freight, customs clearance, road transport, warehousing, and courier services, while company profiles also describe van, truck, and trailer products and services for operators across the United Kingdom. Established in 1959, it serves commercial vehicle customers with purchase, leasing, rental, and aftersales support. It was listed as a ransomware victim associated with blackbasta. |
|||||
| RateGain View Details _ | India | hive | Other | ||
|
RateGain Travel Technologies Limited is an India-based software-as-a-service company focused on the travel and hospitality industry, with its primary office in Noida, Uttar Pradesh. It offers AI-powered products for rate intelligence, revenue optimization, channel distribution, and guest engagement across hotels and other travel providers. The company is also described as serving more than 13,000 customers globally. It was listed as a ransomware victim associated with hive. |
|||||
| RateGain View Details _ | conti | Other | |||
|
RateGain Travel Technologies Limited is an India-based software-as-a-service company focused on travel and hospitality technology. It provides AI-powered tools for rate intelligence, revenue optimization, channel distribution, and guest experience management for travel businesses. The company is headquartered in Noida, Uttar Pradesh, and serves customers across the travel ecosystem, including hotels, airlines, and online travel agents. It was listed as a ransomware victim associated with Conti. |
|||||
| www.intertabak.... View Details _ | lockbit2 | Other | |||
|
Intertabak AG is a Swiss tobacco company based in Pratteln, Basel-Landschaft, with operations focused on Habanos cigars and mini cubanos in Switzerland. The company also operates specialist retail channels, including La Casa del Habano locations in Swiss cities such as Basel, Zürich, Lugano, St. Gallen, Zug, Samnaun, Nyon, Mendrisio and Geneva. Public company profiles describe Intertabak AG as a tobacco manufacturing and retail business with a small corporate workforce. It was listed as a ransomware victim associated with lockbit2. |
|||||
| virtus-advocate... View Details _ | lockbit2 | Finance / Legal / Insurance | |||
|
Virtus Advocate... is a United States-based business in the finance, legal and insurance space, offering insurance, risk management, and related advisory services. Public business materials describe Virtus as an insurance brokerage and consulting firm serving clients with professional guidance across legal and compliance-sensitive matters. It operates in a regulated services environment where confidentiality, liability, and client trust are central. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Carinthia, Austria View Details _ | Austria | alphv | Other | ||
|
Carinthia is Austria’s southernmost federal state, known for its mix of industry, technology, forestry, agriculture, and tourism. It promotes investment and business activity through regional support services and a broad economic network. The region also markets itself as a destination for alpine scenery, lakes, and year-round visitor offerings. It was listed as a ransomware victim associated with alphv. |
|||||
| Germany Corporation "VMT-GmbH" Leaked View Details _ | ragnarlocker | Services | |||
|
VMT GmbH is a German services company based in Bruchsal, Baden-Wuerttemberg, that provides smart systems for navigation, monitoring, quality control, and data management in tunnelling and industrial measurement. Its offerings include surveying services, guidance and control systems, and industrial 3D measurement solutions for tunnel construction and related applications. The company has described itself as a long-standing supplier to the tunnelling industry and operates from Stegwiesenstraße 24 in Germany. It was listed as a ransomware victim associated with Ragnar Locker. |
|||||
| Active Communications International View Details _ | quantum | Communication / Marketing | |||
|
Active Communications International (ACI) is a conference planning and production company in the communication and marketing sector, based in Chicago, Illinois, with offices reported in London, Pune and other locations. ACI has operated since 1999 and is described as producing and running business conferences across industries such as healthcare, energy, maritime, and LNG. Its services focus on event organization, forum facilitation, and industry networking. It was listed as a ransomware victim associated with quantum. |
|||||
| Transsion Holdings View Details _ | China | quantum | Other | ||
|
Transsion.com is a Chinese multinational telecommunications manufacturing company headquartered in Shenzhen, CN, specializing in mobile phone production and mobile Internet services. The firm offers high-quality multi-brand smart devices, including smartphones and feature phones under the TECNO, itel, and Infinix brands, while also providing after-sales services via Carlcare. Founded in 2006, Transsion Holdings has become a leading player in mobile industries across global emerging markets, notably Africa, where it surpassed Samsung in smartphone sales by 2017. Transsion.com was neutrally listed as a ransomware victim associated with the Quantum threat actor. |
|||||
| Eurocept View Details _ | quantum | Other | |||
|
Eurocept operates within the Other sector, with its primary location and offerings not publicly detailed in available sources. The entity's specific services and operational scope remain generally described due to limited public information. Despite this, Eurocept was neutrally listed as a ransomware victim associated with the Quantum threat actor. This listing highlights the entity's exposure to cyber threats without confirming specific breach details or stolen data types. The association with Quantum underscores the broader risk landscape facing organizations in the Other sector. |
|||||
| Imenco AS View Details _ | conti | Other | |||
|
Imenco AS is a Norway-based industrial group headquartered in Aksdal, Rogaland, and it operates across offshore oil and gas, offshore renewables, aquaculture, marine and naval, and industrial markets. The company was established in 1979 and describes itself as providing industrial products, engineering services, and related technologies for global industries. Its business profile centers on engineering and manufacturing support for complex offshore and marine operations. Imenco AS was listed as a ransomware victim associated with conti. |
|||||
| Concepts in Millwork View Details _ | conti | Other | |||
|
Concepts in Millwork is a privately held millwork company based in Colorado Springs, Colorado. It specializes in custom architectural millwork and fixtures for commercial and institutional projects, including retail, medical, education, sports, hotels, and airports. Public company profiles and its website describe it as a family-owned business serving tailored design and fabrication needs. It was listed as a ransomware victim associated with Conti. |
|||||
| Eurofred View Details _ | conti | Other | |||
|
Eurofred is a Spain-based company headquartered in Barcelona that distributes air conditioning, industrial heating, commercial refrigeration, catering equipment, spare parts, and related services. Founded in 1966, it serves residential, commercial, and industrial markets across Spain and other European operations. Public company information also describes Eurofred as a leader in air conditioning and climate-control distribution. It was listed as a ransomware victim associated with conti. |
|||||
| Agile Sourcing Partners View Details _ | conti | Other | |||
|
Agile Sourcing Partners is a California-based supply chain services company serving the utilities sector nationwide. Its offerings include procurement, workforce, project management, and outsourced supply chain support for gas and electric utilities, supply partners, and utility contractors. The company has operated since 2006 and lists multiple U.S. locations, including Anaheim and Corona, California. It was listed as a ransomware victim associated with conti. |
|||||
| Alimentos y Frutos S.A. View Details _ | conti | Other | |||
|
Alimentos y Frutos S.A., also known as Alifrut, is a Chilean company based in Santiago, with its main office in Quilicura. It operates in the production of frozen fruits, juices, and vegetables, serving the agroindustrial food sector. Company and trade listings also place it at Camino Lo Echevers 250 and identify it as part of Empresas Minuto Verde. It was listed as a ransomware victim associated with conti. |
|||||
| Worksoft View Details _ | conti | Other | |||
|
Worksoft is an enterprise test automation company founded in 1998, headquartered in Addison, Texas, United States. It provides a codeless platform that enables teams to automate testing, data provisioning, and corrections without technical expertise. The company’s primary offering, Worksoft Certify, is an automated software testing solution designed for scalability and efficiency in enterprise environments. Worksoft helps businesses optimize processes by ensuring they drive success rather than merely run. The company was listed as a ransomware victim associated with the Conti threat actor. |
|||||
| Omicron Consulting S.r.L View Details _ | conti | Services | |||
|
Omicron Consulting S.r.L is a Romanian business and management consulting company based in Bucharest, operating in the Services sector and offering professional consulting activities. Business directories classify it under business and other management consultancy services, reflecting an advisory role rather than a product manufacturing profile. In threat-intelligence catalogs, it appears as a ransomware victim entry connected to the conti actor. The listing is neutral and does not by itself confirm the scope or impact of any incident. |
|||||
| Pianca View Details _ | conti | Other | |||
|
Pianca is an Italian furniture manufacturer based in Gaiarine, Treviso, with a headquarters at Via dei Cappellari 20 in Veneto. Founded in 1954, it produces home furnishings and related interior solutions and sells through retail networks in Italy and abroad. Company materials describe it as a Made in Italy brand with production facilities in Italy and export markets. It was listed as a ransomware victim associated with conti. |
|||||
| Allcat Claims Service View Details _ | conti | Services | |||
|
Allcat Claims Service is a U.S. services company based in Boerne and San Antonio, Texas, that provides insurance claims handling and adjusting support. Its offerings include initial claims calls, estimating, closing, check issuance, electronic reporting, tracking, and other end-to-end claims services for insurance carriers and policyholders. Company materials also describe it as a total-solution provider for insurance claims and related field and desk services. It was listed as a ransomware victim associated with Conti. |
|||||
| berschneider.de View Details _ | Germany | lockbit2 | Other | ||
|
Berschneider GmbH is a German meat-specialties producer based in Valluhn, Mecklenburg-Vorpommern, Germany. Founded in 1966 in Hamburg, the company relocated to Valluhn in 1994 and describes its business as Fleischspezialitäten Produktion. Public company profiles also describe it as an animal-processing firm offering smoked and canned meats, sausages, and poultry. It was listed as a ransomware victim associated with lockbit2. |
|||||
| etrp View Details _ | lockbit2 | Other | |||
|
etrp is an entity in the Other sector, but the available public record does not provide a verified business description, location, or product list. In threat-intelligence catalogs, it is therefore identified conservatively by its name and sector rather than by unconfirmed operational details. The listing connects etrp to the LockBit2 ransomware ecosystem as a victim entry. It was listed as a ransomware victim associated with lockbit2. |
|||||
| reitzner View Details _ | lockbit2 | Other | |||
|
Reitzner is a U.S.-based business in the “Other” sector; available public records do not clearly identify a single company profile or offering for this name. As a result, its location and services cannot be stated confidently from the supplied sources, and any fuller description would require direct first-party or corporate records. In threat-intelligence catalogs, Reitzner is referenced as an organization of interest rather than as a published incident narrative. It was listed as a ransomware victim associated with LockBit2. |
|||||
| HEMERIA View Details _ | France | snatch | Energy | ||
|
HEMERIA is a French industrial company based in Toulouse, France, and it operates in the defense and space sectors, supplying technology-intensive equipment and systems. Its work includes integrated sub-assemblies, satellite platforms, composite panels, electrical harnesses, thermal protections, and related space hardware. Public materials also describe HEMERIA as a provider of secure equipment for demanding aerospace and defense applications. It was listed as a ransomware victim associated with snatch. |
|||||
| Elkuch Group View Details _ | blackbasta | Services | |||
|
Elkuch Group is a Liechtenstein-based holding company specializing in environmental services and high-quality steel products for construction. The group delivers waste management solutions for airports, hospitals, hotels, and food production facilities, alongside demanding steel doors and frames for public spaces. With manufacturing sites in Liechtenstein, Switzerland, and Germany, Elkuch employs approximately 400 people focused on metall processing and construction. Elkuch Group was listed as a ransomware victim associated with the threat actor blackbasta. |
|||||
| seatarrabida.pt View Details _ | Portugal | lockbit2 | Other | ||
|
seatarrabida.pt is a Portuguese website associated with the Arrábida area, a region in Setúbal known for its natural park, coastline, tourism, and outdoor activities. The name suggests a local, place-linked service or business presence in Portugal rather than a large industrial or public-sector organization. In a threat-intelligence index, it is cataloged under the Other sector for Portugal. It was listed as a ransomware victim associated with lockbit2. |
|||||
| focusadventure.. View Details _ | lockbit2 | Other | |||
|
FOCUS Adventure is a Singapore-based corporate team-building and adventure-learning company that offers experiential programs designed to build collaboration, leadership, and team spirit. Its headquarters are in Singapore, and its services are positioned for organizations seeking outdoor and adventure-based learning experiences. Public company profiles describe it as a premier provider in the region with facilities in Singapore and other locations. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Grupo Pavisa View Details _ | blackbyte | Other | |||
|
Grupo Pavisa is a privately held glass product manufacturer based in Naucalpan, Mexico, with a history dating to 1952. It produces artisanal glass containers and other glass and crystal products for industrial and commercial customers. Company profiles describe it as part of the glass product manufacturing sector and note its headquarters in Mexico. The company was listed as a ransomware victim associated with blackbyte. |
|||||
| Contraloría General de la República View Details _ | blackbyte | Other | |||
|
Contraloría General de la República Bolivariana de Venezuela is the country’s public audit and fiscal-control authority, based in Caracas on Avenida Andrés Bello. It provides citizen and declarant support, contact channels, and administrative services related to state oversight and accountability. In official Colombian and Venezuelan government references, similar contralorías are described as the highest fiscal-control bodies charged with supervising public resources and enforcing control procedures. The entity was listed as a ransomware victim associated with blackbyte. |
|||||
| bsm.upf.ed View Details _ | lockbit2 | Other | |||
|
bsm.upf.ed refers to UPF Barcelona School of Management, the management school of Pompeu Fabra University in Barcelona, Spain. It offers internationally accredited master’s degrees and postgraduate courses in business and management, with a focus on academic rigor, research, and knowledge transfer. The school is part of a public university recognized for excellence in teaching and research, and it presents itself as a global business school serving professional and industry-oriented education needs. It was listed as a ransomware victim associated with lockbit2. |
|||||
| salumificiovene... View Details _ | lockbit2 | Other | |||
|
Salumificio Benese S.r.l. is an Italian food producer based in Bene Vagienna, Piedmont, where it makes cured meats and related specialty meats. The company says it has operated since 1973 and focuses on selecting quality raw materials for its products. In threat-intelligence listings, the entity name appears as salumificiovene... with sector tagged as Other. It was listed as a ransomware victim associated with lockbit2. |
|||||
| de View Details _ | lockbit2 | Other | |||
|
de is an entity in the Other sector and, based on its name alone, no reliable public information in the search results identifies its location, offerings, or corporate profile. In threat-intelligence catalogs, such sparse entries are often used when the available record names a target but does not provide enough context to describe it more specifically. LockBit 2.0 was a ransomware-as-a-service operation that used double-extortion tactics and was widely active in ransomware leak-site reporting. de was listed as a ransomware victim associated with lockbit2. |
|||||
| SPORTPLAZA View Details _ | hive | Other | |||
|
SPORTPLAZA is a Netherlands-based business entity; public company records identify Sportplaza Moerdijk B.V. as a holding company founded in 2005. The name also appears in commercial directories for a sports and fitness business, but the available records do not clearly establish a more detailed operating profile. In threat-intelligence indexes, SPORTPLAZA is listed as a ransomware victim associated with Hive. |
|||||
| firbarcarolo.it View Details _ | Italy | lockbit2 | Hospitality / Food & Beverage / Tourism | ||
|
firbarcarolo.it is an Italy-based site associated with the hospitality, food and beverage, and tourism sector, reflecting a business focused on guest services and visitor-oriented offerings. Its name suggests a branded local presence in the Italian market, where such businesses typically serve travelers, diners, and leisure customers. In threat-intelligence catalogs, it is listed as a ransomware victim associated with lockbit2. |
|||||
| The Catholic Foundation View Details _ | vicesociety | NGOs / Associations | |||
|
The Catholic Foundation is a separate 501(c)(3) organization established to serve the Catholic community in northeastern Wisconsin, specifically Green Bay, WI. It functions as a philanthropic entity that connects donors with nonprofits, manages funds, and facilitates long-term, sustainable support for parishes. The organization offers centralized fundraising resources and focuses on planned giving and endowment building to strengthen the church. It was neutrally listed as a ransomware victim associated with the threat actor vicesociety. |
|||||
| morrisonexpress... View Details _ | lockbit2 | Communication / Marketing | |||
|
Morrison Express is a global freight forwarding and logistics company founded in 1972 and headquartered in Taipei, Taiwan, with U.S. operations in El Segundo, California, and a European hub in Luxembourg. It provides supply-chain and transport services for hi-tech, automotive, consumer, healthcare, chemical, industrial, and energy clients, with particular strength in semiconductor and high-tech logistics. Public company materials describe it as a leading logistics provider with a worldwide network. It was listed as a ransomware victim associated with lockbit2. |
|||||
| bata View Details _ | lockbit2 | Other | |||
|
Bata is a multinational footwear company headquartered in Lausanne, Switzerland, known for manufacturing and retailing shoes, apparel, and related fashion accessories. Its business spans company-owned stores, franchised outlets, and e-commerce operations across international markets. Public company profiles describe Bata as one of the world’s leading footwear brands with a global retail footprint. It was listed as a ransomware victim associated with lockbit2. |
|||||
| EIITNET View Details _ | United States | hive | Other | ||
|
EIITNET appears to be a U.S. organization classified in the Other sector, but the available source set does not identify its public offerings or operational profile. In this index context, the name is used to label an affected entity rather than to describe a confirmed compromise. Hive is a ransomware-as-a-service operation known for double-extortion tactics and widespread victimization. EIITNET was listed as a ransomware victim associated with hive. |
|||||
| CARTEGRAPH View Details _ | United States | hive | Other | ||
|
CARTEGRAPH is a US-based software company in the Other sector, headquartered in Dubuque, Iowa. It builds software for local governments and similar organizations to manage physical assets, work orders, infrastructure, and facility planning. Its products are used to support stewardship of buildings and critical infrastructure, helping teams map, track, and maintain assets more efficiently. CARTEGRAPH was listed as a ransomware victim associated with hive. |
|||||
| skinnertrans.ne... View Details _ | lockbit2 | Other | |||
|
Skinner Transportation Inc. is a transportation and logistics company based in Austin, Texas. It hauls hot asphalt, liquid asphalt, emulsions, and related materials for customers in Texas and nearby states. Public company listings also show terminal and job postings tied to Austin and Clifton, Texas. It operates in the broader transportation sector and supports freight movement for construction and road-surfacing materials. It was listed as a ransomware victim associated with lockbit2. |
|||||
| gymund.dk View Details _ | Denmark | lockbit2 | Other | ||
|
gymund.dk is a Danish education-sector domain used by gymnasium networks and services, including student login, printing, and Office 365 access for school users in Denmark. Public school guidance pages show the domain tied to institutional IT services and account formats ending in @gymund.dk. In a threat-intelligence context, it is cataloged as an entity in the "Other" sector rather than a commercial brand. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Magtek View Details _ | lorenz | Other | |||
|
MagTek is a Seal Beach, California-based manufacturer of electronic systems for secure card issuance, reading, transmission, and authentication. Its products include payment hardware, EMV card readers, PIN pads, check scanners, and related transaction-security services. The company serves organizations that need secure payment and identity workflows across financial and retail environments. It was listed as a ransomware victim associated with Lorenz. |
|||||
| Tri-Ko View Details _ | United States | hive | Other | ||
|
Tri-Ko is a United States company in the Other sector, and public business information for the name is limited in the available sources. Its exact offerings are not clearly identified in the search results, so this entry describes it conservatively as a US-based business outside a more specific industry classification. The threat-intelligence listing associates Tri-Ko with Hive, a ransomware group active since 2021. Tri-Ko was listed as a ransomware victim associated with hive. |
|||||
| groupe-trouille... View Details _ | lockbit2 | Services | |||
|
groupe-trouille... appears in the Services sector in France, a broad category that covers organizations delivering business, professional, or operational support. Public web results do not provide enough verified detail to identify its exact offerings or city, so a conservative description is appropriate. In threat-intelligence catalogs, it is indexed as a victim entry rather than as a confirmed breach case. It was listed as a ransomware victim associated with lockbit2. |
|||||
| gdctax.com.au View Details _ | Australia | lockbit2 | Other | ||
|
gdctax.com.au is the website for GDC Chartered Accountants, an accounting firm in New South Wales, Australia, serving clients with tax and financial support. Public business profiles describe services including tax compliance, tax planning, auditing, business services, accounting software, and SMSF advice. The firm presents itself as focused on personal service for a range of clients across industries. It was listed as a ransomware victim associated with lockbit2. |
|||||
| fed-gmbh.de View Details _ | Germany | lockbit2 | Other | ||
|
fed-gmbh.de refers to Fördersysteme Engineering GmbH (FED), a mid-sized company based in Darmstadt, Germany. The company operates in machinery engineering and automation, with a workforce of about 15 employees and a focus on conveying systems engineering. Its website presents it as a specialist provider of industrial engineering solutions. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Contractors Pipe and Supply Corporation View Details _ | blackbasta | Construction / Real Estate | |||
|
Contractors Pipe and Supply Corporation is a family-owned wholesale plumbing and heating distributor based in Farmington Hills, Michigan. It serves professional trades across southeastern Michigan with plumbing products and services such as pipes, fixtures, water heaters, and related supplies. The company has operated since 1964 and supports contractors, mechanical trades, and other construction-related customers. It was listed as a ransomware victim associated with blackbasta. |
|||||
| http://wsretail... View Details _ | lockbit2 | Other | |||
|
http://wsretail... is listed in threat-intelligence records as a company in the Other sector, with publicly available details about its exact operations not clearly disclosed. Based on its name alone, it appears to be a retail-related business, but no authoritative public source in the provided results confirms its location, products, or services. LockBit 2.0 is a ransomware strain and associated victim listings are used to track entities named by the group. In this index, http://wsretail... was listed as a ransomware victim associated with lockbit2. |
|||||
| Atlanta Perinatal Associates View Details _ | vicesociety | Other | |||
|
Atlanta Perinatal Associates is a Georgia medical group in Atlanta that provides maternal-fetal medicine and physician assistant care, with locations serving patients across the metro area. The practice is based in Atlanta and appears to focus on prenatal and high-risk pregnancy services. It operates as a healthcare provider under the other sector classification. Atlanta Perinatal Associates was listed as a ransomware victim associated with vicesociety. |
|||||
| Carmel College View Details _ | vicesociety | Education | |||
|
Carmel College is a PreK through Grade 12 educational institution located in rural Caroline County, Virginia, offering exceptional education and opportunities for all students. The campus rests on 145 acres in a rural setting approximately halfway between Richmond and Fredericksburg. Carmel College was listed as a ransomware victim associated with the threat actor vicesociety. |
|||||
| Higher School of the Public View Details _ | vicesociety | Education | |||
|
Higher School of the Public is an educational institution operating within the Education sector, providing public schooling and academic offerings to students in its community. Based on its name and sector, it likely delivers K-12 education or similar public school programs, serving students and families in its local area. The institution aligns with public education providers that focus on equipping students with essential skills for academic and personal development. Higher School of the Public was listed as a ransomware victim associated with the threat actor vicesociety. |
|||||
| Important announcement View Details _ | lv | Other | |||
|
Important announcement is an entity in the Other sector, with publicly available details indicating it operates in lv. Available source material does not provide enough verified information to describe its offerings more specifically, so the listing should be treated as a generic organizational profile. In threat-intelligence coverage, it appears as an indexed victim entry rather than a confirmed incident narrative. It was listed as a ransomware victim associated with lv. |
|||||
| clublinks.com.a... View Details _ | lockbit2 | Other | |||
|
Clublinks is an Australian company based in Victoria that provides leisure, sports and fitness, residential, aquatic, and facilities management services. Public profiles describe it as a privately owned operator serving golf, leisure, and community settings across Australia. Its business spans service delivery for venues and residential environments rather than a single consumer product. The company was listed as a ransomware victim associated with LockBit2. |
|||||
| Mercyhurst.edu View Details _ | United States | lockbit2 | Other | ||
|
Mercyhurst University is a private Catholic liberal arts university in Erie, Pennsylvania, serving more than 2,000 traditional undergraduates on a residential campus. It offers 50+ undergraduate majors, 10+ graduate programs, and other academic services, including study abroad, career development, and student life programs. The university also supports campus engagement through athletics, leadership, and experiential learning. Mercyhurst.edu was listed as a ransomware victim associated with lockbit2. |
|||||
| https://clublin... View Details _ | lockbit2 | Other | |||
|
Clublin operates within the Other sector, providing general offerings from its base in the United Kingdom. The entity functions as a service provider with broad operational scope, though specific industry details are not publicly defined. Clublin maintains a neutral presence in its market, delivering standard services to its clientele. The organization was listed as a ransomware victim associated with LockBit2, reflecting its involvement in a recent cyberattack incident. |
|||||
| Xplay Data Leak View Details _ | darkleakmarket | Other | |||
|
Xplay Data Leak is an other-sector entity in the United States that appears in ransomware-victim indexes under the name “Xplay Data Leak.” Public indexing does not identify its offerings, but the record is treated as a threat-intelligence listing rather than a confirmed breach report. Ransomware.live recorded the item as discovered on 2022-05-18. It was listed as a ransomware victim associated with darkleakmarket. |
|||||
| suntecktts.com View Details _ | lockbit2 | Other | |||
|
SUNTECKtTS is a full-service transportation logistics provider headquartered in Jacksonville, Florida, operating through a network of sales and independent business owner agents across the United States. The company delivers multimodal transportation solutions serving diverse markets including food, oil, automotive, electronics, textiles, lumber, and paper-printing products. As a MODE Global company, SUNTECKtTS offers instant rate quotes and 24-hour customer service access through 50 strategically located centers. The organization was listed as a ransomware victim associated with the LockBit2 threat actor, reflecting emerging cyber risks in the transportation logistics sector. |
|||||
| modetransportat... View Details _ | lockbit2 | Transportation / Travel / Logistics | |||
|
MODE Transportation is a North American transportation and logistics company that provides freight management and shipping services across truckload, less-than-truckload, intermodal, parcel, air, ocean, and supply-chain operations. Its public company profile says it serves domestic and international freight customers through a broad carrier network and end-to-end transportation solutions. Based on the available indexing, the entity appears under the Transportation, Travel and Logistics sector and is associated with the LockBit2 ransomware ecosystem. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Tex-Isle Supply View Details _ | United States | quantum | Manufacturing / Engineering | ||
|
Tex-Isle Supply is a Houston, Texas-based manufacturing and engineering company serving the energy and industrial supply chain in the United States. Public company profiles describe it as a distributor of energy tubulars with value-added manufacturing and processing capabilities, and Tex-Isle also offers pipe coating, heat treatment, inspection, threading, and related technical support. Its website says the company serves applications including structural steel tubing for roads, bridges, and pressurized water and gas systems. Tex-Isle Supply was listed as a ransomware victim associated with quantum. |
|||||
| vivalia.be View Details _ | Belgium | lockbit2 | Other | ||
|
Vivalia is a Belgian healthcare organization based in Luxembourg Province, operating a regional network that includes six hospital sites, nursing homes, a polyclinic, and a psychiatric care home. Company profiles also describe it as a provider of other clinical services, with headquarters in Bastogne, Belgium. In threat-intelligence indexing, vivalia.be was listed as a ransomware victim associated with lockbit2. |
|||||
| FOR BlackCat and LockBit advert View Details _ | conti | Other | |||
|
FOR BlackCat and LockBit advert is a threat-intelligence index entry for a victim in the Other sector; the name suggests a public-facing advert or notice tied to BlackCat and LockBit activity. As a ransomware-victim listing, it identifies an organization associated with the Conti ecosystem rather than describing a product, service, or geographic operation. LockBit is a ransomware-as-a-service operation used by affiliates to encrypt victim systems and extort payment, and Conti is a prominent ransomware group active since 2020. The entry was listed as a ransomware victim associated with conti. |
|||||
| 2easy.com.br View Details _ | Brazil | lockbit2 | Other | ||
|
2easy.com.br is a Brazilian business services company based in São Paulo, Brazil, focused on human resources, payroll BPO, SaaS, and related support services. Its public materials describe offerings for workforce administration, payroll processing, and connected HR tools for client organizations. The company operates from São Paulo and serves business customers across multiple segments. It was listed as a ransomware victim associated with lockbit2. |
|||||
| khs-wp.de View Details _ | Germany | lockbit2 | Other | ||
|
khs-wp.de is KHS Kempis Kleinlosen, a professional insurance services firm based in Cologne, Germany, that covers professional activities across Germany, EU member states, Turkey, and former Soviet Union territories. The company operates from Wilhelm-von-Capitaine-Straße 20 in D-50858 Cologne, providing insurance coverage for professional activities in multiple jurisdictions. It maintains a positive team culture with flat hierarchies and equal opportunities, reflecting a unique Cologne charm in its workplace environment. The firm was listed as a ransomware victim associated with LockBit2, with the data breach discovered on May 18, 2022. |
|||||
| upskwt View Details _ | cuba | Other | |||
|
upskwt is an organization in the broad Other sector, which typically covers businesses outside standard industry categories such as manufacturing, finance, or healthcare. Publicly available information does not clearly identify its products, services, or location beyond its appearance in ransomware-victim tracking. In threat-intelligence catalogs, such entries are used to document entities named on leak sites or incident lists without asserting the full scope of an event. It was listed as a ransomware victim associated with cuba. |
|||||
| Hirsch Watch Straps & Accessories View Details _ | Austria | quantum | IT | ||
|
Hirsch Watch Straps & Accessories is a premium watch strap and accessory manufacturer based in Klagenfurt, Austria, specializing in artisanal leather craftsmanship and technical innovation for the global watch industry. Founded in 1765, the company develops and produces high-quality watch straps with unmatched detail, offering a wide range of exclusive bracelets and accessories for men and women. As a multinational brand with over 800 employees worldwide, it serves the IT sector through its luxury watchband production and distribution operations. The entity was listed as a ransomware victim associated with the threat actor quantum. |
|||||
| InnPower View Details _ | quantum | Energy | |||
|
InnPower Corporation is an electricity distribution utility based in Innisfil, Ontario, Canada, serving the Town of Innisfil and South Barrie. It provides safe, reliable, and competitively priced power to homes, businesses, and industries across its service territory. The company maintains and improves local electrical infrastructure and customer service for a growing community. It was listed as a ransomware victim associated with quantum. |
|||||
| jaykal View Details _ | lockbit2 | Other | |||
|
Jaykal LED Solutions is a U.S.-based company founded in 2008 and headquartered in Georgetown, Delaware. It develops commercial, industrial, and institutional LED lighting products, including indoor, outdoor, hazard, and emergency lighting solutions. Public company materials also describe it as offering energy-efficient lighting for new construction and retrofit projects. In threat-intelligence listings, Jaykal was named as a ransomware victim associated with LockBit2. |
|||||
| Brunk Industries Inc. View Details _ | lorenz | Services | |||
|
Brunk Industries Inc. is a Lake Geneva, Wisconsin-based services-sector manufacturer that provides precision metal stamping, contract assembly, and contract manufacturing for micro-precision components and class-critical devices. Founded in 1960, it operates as a full-service source for complex metal-forming work and serves industries including medical, defense, and other precision applications. Public company materials describe it as a leader in the metal-forming industry with a focus on high-tolerance production and scalable manufacturing solutions. It was listed as a ransomware victim associated with lorenz. |
|||||
| AmCham Shanghai View Details _ | lorenz | Other | |||
|
AmCham Shanghai, the American Chamber of Commerce in Shanghai, is a nonprofit business organization founded in 1915 and known as the “Voice of American Business” in China. It operates from Shanghai and serves member companies with business advocacy, networking, events, and membership services. The organization describes itself as a dynamic business service group focused on member success and growth. It was listed as a ransomware victim associated with lorenz. |
|||||
| Piggly Wiggly Alabama Distributing Company View Details _ | United States | blackbasta | Services | ||
|
pwadc.net is the website of Piggly Wiggly Alabama Distributing Company, a Bessemer, Alabama-based cooperative serving independent grocery retailers across the US. The company provides grocery distribution and retail support services, including bakery, deli, meat and produce supply, advertising, warehouse and transportation support, retail accounting, pricing management, food shows, and store engineering. Public company profiles describe it as part of the retail and grocery distribution sector. It was listed as a ransomware victim associated with blackbasta. |
|||||
| sherpamarketing... View Details _ | lockbit2 | Communication / Marketing | |||
|
Sherpa Marketing is a communication and marketing agency founded by Carlos Cordoba, offering communications and consulting services for public agencies and private organizations. Its website says the firm provides integrated marketing support, including outreach and campaign services, and has served clients such as the California Department of Insurance. The company’s presence reflects a services-focused business in the communication and marketing sector. It was listed as a ransomware victim associated with lockbit2. |
|||||
| cassagne.com.ar View Details _ | Argentina | lockbit2 | Other | ||
|
Cassagne Abogados is a law firm based in Buenos Aires, Argentina, at Talcahuano 833, and its website identifies it as a specialist practice in administrative, economic, and regulatory law. The firm says it provides integrated legal solutions and publishes updates and publications for clients and the public. In threat-intelligence records, cassagne.com.ar was listed as a ransomware victim associated with lockbit2. |
|||||
| fronteousa View Details _ | cuba | Other | |||
|
Fronteousa is the U.S.-based legal services arm associated with FRONTEO, a company that provides AI and data-analysis solutions for legal and investigative work. Its legal site operates as a business-facing platform for those offerings and related services. In May 2022, public reporting linked the site to a Cuba ransomware intrusion claim involving the firm. It was listed as a ransomware victim associated with cuba. |
|||||
| teka.com.mx View Details _ | Mexico | lockbit2 | Other | ||
|
Teka Mexico is a leading manufacturer of home appliances based in Mexico, specializing in cooktops, ovens, sinks, and faucets for residential kitchens. The company offers a comprehensive catalog of modern, easy-to-clean appliances including induction, gas, and hybrid cooktops designed for contemporary homes. Teka provides official customer support and technical service across Mexico, with product manuals included upon purchase. The company was listed as a ransomware victim associated with the Lockbit2 threat actor. |
|||||
| talaadthaii.com View Details _ | lockbit2 | Other | |||
|
talaadthaii.com appears to be the web presence for Talaad Thai, a Thailand-based business associated with the Talaad Thai name and the Pathum Thani area. Available business listings describe Talaad Thai as a market or commercial operator in the retail and wholesale space, serving buyers and sellers through its platform and related services. The site is cataloged in the Other sector, indicating a non-specific business classification in threat-intelligence indexing. It was listed as a ransomware victim associated with lockbit2. |
|||||
| saludparatodos.... View Details _ | lockbit2 | Other | |||
|
saludparatodos.... appears to refer to a healthcare-related entity; available search results are insufficient to confirm its exact legal name, but the name suggests a health-services provider or clinic. In the broader Zaragoza healthcare context, public sources show a network of primary-care and hospital services in Aragón, including sector-based centers and contact points in Zaragoza. As a catalog listing, the entry should be read as a neutral threat-intelligence record rather than a confirmed breach report. It was listed as a ransomware victim associated with lockbit2. |
|||||
| rexontec.com.tw View Details _ | Taiwan, Province of China | lockbit2 | Other | ||
|
rexontec.com.tw is the website of Rexon Technology Co., Ltd., a Taiwanese manufacturer based in Taichung City, Taiwan. The company says it has operated since 1990 and focuses on two-way radios and related wireless device production. Its site also describes PCBA, cable assembly, and wire harness services for manufacturing customers. In threat-intelligence catalogs, rexontec.com.tw was listed as a ransomware victim associated with lockbit2. |
|||||
| http://2easy.co... View Details _ | lockbit2 | Other | |||
|
2easy is a dark web marketplace in the Other sector that Searchlight Cyber describes as specializing in the sale of “logs,” or records harvested by information-stealing malware. KELA likewise characterizes 2easy as a marketplace for stolen credentials and other data obtained from infostealer infections. Public reporting places the operation on the dark web rather than in a conventional business location. It was listed as a ransomware victim associated with lockbit2. |
|||||
| grupocabal.cl View Details _ | Chile | lockbit2 | Other | ||
|
GrupoCabal.cl is a Chilean company based in Colina that specializes in transport services and the distribution of premium buses, representing brands like Irizar and Volvo. The company operates in the transportation sector, offering buses, taxibuses, tires, and related services for secure and comfortable passenger transport. It serves as a representative of prestigious bus manufacturers, with its headquarters linked to Ormaiztegui in Spain, while maintaining operations in Chile. GrupoCabal.cl was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| STU View Details _ | lockbit2 | Other | |||
|
STU is an entity in the Other sector, but the available search results do not provide a reliable public profile describing its exact location, products, or services. Because of that, its business activity should be treated as unspecified from the evidence provided. In threat-intelligence catalogs, STU is recorded for monitoring and attribution purposes rather than as a description of operational details. STU was listed as a ransomware victim associated with lockbit2. |
|||||
| hinakaorg.com View Details _ | lockbit2 | Other | |||
|
HINAKA Fluid Power Co., Ltd., operating at hinakaorg.com, is an industrial manufacturer based in Kaohsiung, Taiwan. Founded in 1988, it provides OEM and ODM hydraulic systems, pneumatic systems, oil-air boosting technology, and pneumatic cylinders for industrial use. Its website also highlights product information, company news, and contact resources for customers and partners. It was listed as a ransomware victim associated with lockbit2. |
|||||
| arcelormittal.h... View Details _ | lockbit2 | Other | |||
|
ArcelorMittal is a global steel and mining company headquartered in Luxembourg City, with industrial operations in more than 60 countries and customers worldwide. Its business includes steel production and related industrial products for construction, manufacturing, and infrastructure. The arcelormittal.h... listing appears in a threat-intelligence context for the Other sector. It was listed as a ransomware victim associated with lockbit2. |
|||||
| mercyhurst.edu View Details _ | United States | lockbit2 | Other | ||
|
Mercyhurst University is a private Catholic liberal arts university in Erie, Pennsylvania, in the United States. It serves more than 2,600 students and offers 50+ undergraduate majors, 10+ graduate programs, and 31 athletic teams. The university also provides academic support, study abroad options, and campus life services for traditional and visiting students. It was listed as a ransomware victim associated with lockbit2. |
|||||
| boltburdon.co.u... View Details _ | lockbit2 | Other | |||
|
Bolt Burdon is a London, England law firm providing solicitor services to individuals and businesses from its head office in Islington. The firm operates in the legal sector and serves clients through a broad range of professional legal services. Its website is boltburdon.co.uk, and its registered office is Providence House, Providence Place, London, N1 0NT. It was listed as a ransomware victim associated with lockbit2. |
|||||
| redgwick. View Details _ | lockbit2 | Other | |||
|
redgwick is an entity in the Other sector; available public search results do not provide a reliable official profile for its location or offerings, so those details are not stated here. LockBit 2.0 is a ransomware-as-a-service platform used by affiliates to target organizations and extort victims through file encryption and leak-site pressure. In threat-intelligence indexes, redgwick is cataloged as a victim entry associated with the LockBit2 cluster. It was listed as a ransomware victim associated with lockbit2. |
|||||
| hoffsu View Details _ | lockbit2 | Other | |||
|
hoffsu is an entity in the Other sector, but the available sources do not provide reliable public details about its location or offerings. Based on the name alone, it cannot be accurately identified as a specific company, product, or organization without risking invention. In threat-intelligence catalogs, such entries are used to index organizations named in ransomware leak lists or victim disclosures. It was listed as a ransomware victim associated with lockbit2. |
|||||
| optoma.com View Details _ | lockbit2 | Other | |||
|
Optoma.com belongs to Optoma Technology, a Taiwanese visual display company headquartered in Fremont, California, with regional operations across Europe, North America, Asia-Pacific, and China. The company markets and sells projectors, interactive flat panels, large-format LED displays, image processing equipment, and related services for education, corporate, home, entertainment, and large-venue use. Its corporate site presents Optoma as a global provider of visual solutions and support services. It was listed as a ransomware victim associated with LockBit2. |
|||||
| For Costa Rica and US terrorists (Biden and his administration) View Details _ | conti | Other | |||
|
For Costa Rica and US terrorists (Biden and his administration) appears to refer to the Costa Rican government, a public-sector target in Costa Rica that provides national administrative and civic services through multiple ministries and agencies. Reporting on the 2022 incident says Conti disrupted government systems and prompted U.S. cybersecurity support for recovery and resilience efforts. Costa Rica’s response focused on restoring critical government operations and strengthening defensive infrastructure across ministries and agencies. It was listed as a ransomware victim associated with Conti. |
|||||
| boltburdonkemp.... View Details _ | lockbit2 | Other | |||
|
boltburdonkemp.... operates within the Other sector, offering services or products that are not classified under standard industry categories, with its primary location in the United States. The entity provides offerings that remain distinct from typical commercial sectors, reflecting a specialized or niche operational focus. It was listed as a ransomware victim associated with the Lockbit2 threat actor, indicating its involvement in a significant cyber incident. This listing underscores the entity's exposure to advanced ransomware tactics employed by Lockbit2. The neutral disclosure confirms its status without detailing specific breach metrics or stolen data types. |
|||||
| www.optoma.com View Details _ | lockbit2 | Other | |||
|
www.optoma.com is the corporate website of Optoma, a global provider of display and projection technology serving business, education, and home users. Its offerings include projectors, LED displays, interactive flat panel displays, screens, and related visual solutions. The company is headquartered in Fremont, California, with an international footprint in Europe and other markets. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Channel Navigator business intelligence IT View Details _ | kelvinsecurity | Services | |||
|
Channel Navigator business intelligence IT is a Services-sector business intelligence provider based in the United States, focused on IT and telecom sales and marketing use cases. Public product descriptions characterize Channel Navigator as a dynamic platform that helps professionals identify and connect with North American business contacts. In catalog and intelligence contexts, the company is referenced by its business intelligence branding and IT-oriented market focus. It was listed as a ransomware victim associated with kelvinsecurity. |
|||||
| sgservicesud.it View Details _ | Italy | lockbit2 | Services | ||
|
sgservicesud.it belongs to S.G. Service Sud Srl, a services company based in Modugno, Puglia, Italy. The company sells and rents earthmoving, construction, and lifting machinery, and also provides support services such as maintenance, spare parts, and technical assistance. Public company listings describe it as active for more than 40 years in machinery for construction and earthmoving, serving builders and related businesses. It was listed as a ransomware victim associated with lockbit2. |
|||||
| riken-nosan.com View Details _ | lockbit2 | Other | |||
|
riken-nosan.com belongs to 理研農産化工株式会社, a Japan-based manufacturer headquartered in Fukuoka and Saga, with offices and factories in Japan. The company produces edible oil and flour products for household and industrial use, and also handles related fertilizers and feed. Its website also highlights business and consumer product lines, including oil and wheat products. It was listed as a ransomware victim associated with lockbit2. |
|||||
| mosaiceins.com View Details _ | lockbit2 | Other | |||
|
Mosaic Eins is a Thailand-based building materials company that focuses on professional lighting solutions and related services. Its website lists offices in Bangkok and Phuket and notes nationwide distribution from warehouses in both cities. The company presents itself as an established local supplier with project references across hospitality, commercial, residential, and food-and-beverage settings. It was listed as a ransomware victim associated with LockBit2. |
|||||
| bradfordmarine.... View Details _ | lockbit2 | Other | |||
|
Bradford Marine is a marine services company based in Fort Lauderdale, Florida, with a presence in Freeport, Grand Bahama. It operates as a full-service superyacht repair facility and marina, offering yacht sales, dockage, refit, and repair services. Public company listings also describe it as family-owned and serving the yachting market since 1966. It was listed as a ransomware victim associated with LockBit2. |
|||||
| purapharm.com View Details _ | lockbit2 | Other | |||
|
PuraPharm Corporation Limited is a Hong Kong-based healthcare company focused on the research, production, marketing, and sale of concentrated Chinese medicine granules. Its business includes Chinese medicine products and related healthcare offerings, with operations and market reach in Hong Kong and international markets. Public company profiles describe it as part of the healthcare and drug-manufacturing sector, with a strong emphasis on botanicals and Chinese medicine. It was listed as a ransomware victim associated with lockbit2. |
|||||
| alliancesand.co... View Details _ | lockbit2 | Other | |||
|
Alliance Sand & Aggregates, LLC is an Alabama-based supplier of sand and aggregate products for construction, landscaping, and asphalt work. Its website lists a main office in Decatur, Alabama, and a plant office in Phil Campbell, Alabama, with contact details for customer quotes and project bids. The company describes itself as serving projects that need materials such as masonry sand, concrete sand, and gravel products. It was listed as a ransomware victim associated with lockbit2. |
|||||
| agapemeanslove.... View Details _ | lockbit2 | Other | |||
|
agapemeanslove.... is an entity operating in the sector Other, with no specific location or offerings publicly documented beyond its name. The entity functions within an undefined operational scope, as no verified details about its services or geographic presence are available from public sources. It was listed as a ransomware victim associated with Lockbit2, a cybercriminal group known for deploying ransomware-as-a-service attacks. The listing indicates that agapemeanslove.... was targeted by Lockbit2's malicious software, which encrypts files and demands ransom for decryption keys. No official first-party disclosure or breach notification date from agapemeanslove.... has been confirmed. |
|||||
| zine-eskola.eus View Details _ | lockbit2 | Other | |||
|
zine-eskola.eus belongs to Elías Querejeta Zine Eskola (EQZE), a film school and research centre based in Tabakalera, Donostia / San Sebastián, Spain. It operates within the cultural and professional ecosystem of the Tabakalera centre and publishes academic and film-related content, including its ZINE research series. The institution focuses on film education, research, and related projects for filmmakers and the wider cinema community. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Cjk Group, Inc. View Details _ | conti | Services | |||
|
CJK Group, Inc. is a privately held U.S. services company based in Brainerd, Minnesota, with businesses in printing, publishing services, and technology/information solutions. Its operations include digital and offset printing, fulfillment, distribution, and supply-chain support for books, magazines, catalogs, journals, and commercial print. Industry profiles describe it as one of the country’s larger printing and publishing services organizations. It was listed as a ransomware victim associated with conti. |
|||||
| Ludwig Freytag Group View Details _ | revil | Services | |||
|
Ludwig Freytag Group is a German services-sector company based in Oldenburg, Lower Saxony. It operates as an innovative, versatile construction technology and service group with offerings spanning civil engineering, building construction, deep-water construction, hydraulic engineering, foundations, and bridge works. Company profiles also place it in architectural and related engineering services. It was listed as a ransomware victim associated with revil. |
|||||
| xydias.gr View Details _ | Greece | blackbyte | Other | ||
|
xydias.gr is the website of Costas Xydias S.A., a pharmaceutical distributor based in Athens, Greece, operating from Solomou Street. The company supplies medicines, parapharmaceuticals, and cosmetics to pharmacies and pharmaceutical wholesalers across Greece, and also offers online ordering for pharmacists. Its business profile places it in the broader “Other” sector for cataloging purposes. It was listed as a ransomware victim associated with BlackByte. |
|||||
| usu.org.au View Details _ | Australia | blackbyte | Other | ||
|
usu.org.au is the official site of the United Services Union, an Australian union based in Sydney, New South Wales. The union provides industrial support, member benefits, and assistance for workers, and its site includes a member portal, contact details, and joining information. It also publishes union news and service updates for members across covered industries. The domain was listed as a ransomware victim associated with BlackByte. |
|||||
| ats-insubria.it View Details _ | Italy | blackbyte | Other | ||
|
ats-insubria.it is the institutional website of ATS Insubria, the Agenzia di Tutela della Salute dell’Insubria, a public health authority in Italy. It serves the Varese and Como area and provides institutional information, territorial offices, training, open data, news, and reserved-access services. Its site also lists contact details and administrative resources for users and stakeholders. It was listed as a ransomware victim associated with blackbyte. |
|||||
| saskarc.com View Details _ | lockbit2 | Other | |||
|
Saskarc Inc. is a commercial and residential construction company based in Oxbow, Saskatchewan, specializing in structural steel fabrication, modular metal solutions, and support of excavation for infrastructure projects. The firm operates with over 30 years of experience delivering structural steel projects for industrial and large-scale infrastructure clients. Saskarc provides bracing, shoring, and anchoring solutions through its affiliated entity infraMOD, serving major infrastructure initiatives across North America. The company was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| Simonson-Lumber decided to be Leaked View Details _ | ragnarlocker | Other | |||
|
Simonson Lumber is a Minnesota-based lumber and building materials company serving residential and commercial customers through multiple locations in central and southern Minnesota. Its St. Cloud operations include retail and distribution sites, and its corporate office is also in St. Cloud, with no sales or inventory at that office. The company offers lumber, building materials, and related supply services through its yard and distribution network. It was listed as a ransomware victim associated with ragnarlocker. |
|||||
| Trans Technology Pte Ltd. View Details _ | vicesociety | IT | |||
|
Trans Technology Pte Ltd is a Singapore-based company in the IT and electronics solutions space, operating from Henderson Industrial Park in Singapore. Sources describe it as an SMT solutions provider and a market leader in sales, distribution, service, and technical training for electronic manufacturing equipment. Its profile also notes activity in industrial machinery and equipment distribution. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Caldes de Montbui View Details _ | vicesociety | Other | |||
|
Caldes de Montbui is a municipality in the Vallès Oriental comarca of Catalonia, Spain, located approximately 35 km north of Barcelona with a population of 18,567 inhabitants. It is renowned as one of the most important thermal destinations in Catalonia, known for its hot springs and wellness offerings, earning the nickname "the town that boils". The local economy includes 1,619 registered enterprises, with a dominant sector in the primary industry and urban development activities. Caldes de Montbui was listed as a ransomware victim associated with the threat actor Vicesociety. |
|||||
| Salud Total View Details _ | vicesociety | Other | |||
|
Salud Total is a Colombia-based health services brand associated in public directories with Bogotá, where it appears to operate from multiple local addresses. Sources describe it as a health provider in the broader services sector, with offerings tied to medical or wellness support rather than a single industrial vertical. Public listings also place the organization in Bogotá, Colombia, supporting its identification as a local entity. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Black Bros. Co. View Details _ | blackbasta | Other | |||
|
Black Bros. Co. is a sixth-generation, family-owned U.S. manufacturing company based in Mendota, Illinois, with a Southeast Division in High Point, North Carolina. Founded in 1882, it designs and manufactures roll-coating, laminating, gluing, and finishing equipment for industrial customers. Its products include individual machines and complete systems used in global manufacturing markets. Black Bros. Co. was listed as a ransomware victim associated with blackbasta. |
|||||
| topaces.us View Details _ | United States | lockbit2 | Other | ||
|
Top Aces is a defence contractor headquartered in Montreal, Quebec, that provides advanced adversary air and joint terminal attack controller technology and training to leading armed forces globally. The company serves the Canadian Armed Forces, Bundeswehr, United States Air Force, and other NATO allies with contracted airborne training services. As a privately owned entity, Top Aces transforms the aerospace industry through proprietary adversary air technology and live-fly training programs. The organization was listed as a ransomware victim associated with the threat actor lockbit2. |
|||||
| sportco.com View Details _ | lockbit2 | Other | |||
|
Sportco.com is the online storefront for Sportco & Outdoor Emporium, a Washington-based sporting goods retailer serving outdoor customers from Fife and Seattle. The company offers fishing, camping, hiking, watersports, hunting, and related gear, along with retail support and customer service for online and in-store shoppers. Public site information also identifies its Fife, Washington security contact details and retail locations. It was listed as a ransomware victim associated with lockbit2. |
|||||
| silverbayseafoo... View Details _ | lockbit2 | Other | |||
|
silverbayseafoo... appears in threat-intelligence records as an Other-sector entity in the United States. The listing itself does not identify a public-facing product, service, or organization profile, so a cautious catalog description is limited to the name and sector classification. In this index, it is recorded as a ransomware victim associated with LockBit2. |
|||||
| hansh View Details _ | lockbit2 | Other | |||
|
hansh is an entity operating within the Other sector, with no specific geographic location or defined commercial offerings publicly documented in available sources. As the entity is not widely recognized in standard business registries or industry reports, its precise operational scope remains generally described by its sector classification alone. Despite this lack of specific detail, hansh has been formally included in threat intelligence records as a victim of ransomware activity. The listing identifies hansh as a ransomware victim associated with the LockBit2 threat actor, marking it as part of the broader campaign of cyberattacks attributed to this group. This entry serves as a neutral record within the threat intelligence index, confirming the association without asserting confirmed breach specifics or stolen data types. |
|||||
| Cavender View Details _ | blackbasta | Other | |||
|
Cavender’s is a retail company headquartered in Tyler, Texas, in the United States. It specializes in western wear, including cowboy boots, apparel, and related workwear, and operates stores across multiple states. Founded in 1965, the company is known for its Western-focused merchandise and family-owned retail heritage. In threat-intelligence reporting, Cavender’s was listed as a ransomware victim associated with blackbasta. |
|||||
| Fachgroßhandel View Details _ | blackbasta | Other | |||
|
Fachgroßhandel is a German term for specialist wholesale businesses that supply trade, craft, and industrial customers with goods and related services. In Germany, this sector spans many product areas, including technical supplies, hygiene, medical aids, and other distribution-focused offerings. As a business category, it operates within the broader trade and logistics landscape and serves professional buyers rather than end consumers. The entity was listed as a ransomware victim associated with blackbasta. |
|||||
| Flexible Circuit Technologies View Details _ | blackbasta | IT | |||
|
Flexible Circuit Technologies (FCT) is a U.S.-based manufacturer in Minnesota that serves the IT and electronics supply chain. It designs and produces flexible circuits, rigid flex, flexible heaters, membrane switches, plastic moldings, and related advanced interconnect and assembly solutions. The company operates from Minneapolis and supports customers in multiple markets with custom manufacturing capabilities. It was listed as a ransomware victim associated with blackbasta. |
|||||
| ioi View Details _ | stormous | Other | |||
|
IOI is a Malaysia-based conglomerate headquartered in Putrajaya. It operates in the palm oil sector through plantations, refineries, specialty fats and oleochemicals, and related resource-based manufacturing. Public company profiles also describe property development and renewables among its business interests. In threat-intelligence records, IOI was listed as a ransomware victim associated with Stormous. |
|||||
| shimamura.gr.jp View Details _ | Japan | lockbit2 | Other | ||
|
shimamura.gr.jp is the official website of SHIMAMURA Co., Ltd., a Japan-based retail company headquartered in Saitama, Japan. The company sells general clothing and fashion-related products, including apparel and related household goods, through its group business. Its corporate site also presents company profile, governance, sustainability, and business information. In threat-intelligence listings, shimamura.gr.jp was named as a ransomware victim associated with lockbit2. |
|||||
| safarni.com View Details _ | lockbit2 | Other | |||
|
Safarni.com operates an online travel-booking service in the airlines and aviation sector, offering flight and hotel reservations through its website and mobile apps. The company presents itself as a travel platform for booking trips and managing related travel services, and publicly lists contact channels in Egypt and the Gulf. Available directory data identifies Safarni as a privately held business with 11–50 employees in Cairo, Egypt. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Saskatchewan Liquor and Gaming Authority View Details _ | ransomhouse | Public Sector | |||
|
Saskatchewan Liquor and Gaming Authority (SLGA) is a Saskatchewan public sector Crown corporation based in Regina, Canada. It is responsible for the distribution, control and regulation of beverage alcohol in the province. SLGA also oversees gaming activities, including electronic gaming, charitable gaming and horse racing, and registers provincial gaming employees and suppliers. It was listed as a ransomware victim associated with ransomhouse. |
|||||
| Jefferson Credit Union View Details _ | ransomhouse | Finance / Legal / Insurance | |||
|
Jefferson Credit Union is a not-for-profit financial institution based in Hoover, Alabama, serving members across Jefferson County and surrounding areas. It offers savings, checking accounts, financial wellness programs, and mobile banking services, functioning similarly to traditional banks. Members can access branches in Hoover, Birmingham, Hueytown, and Fultondale, with ATM access through the Presto! network. The organization operates as a member-owned credit union, requiring an initial deposit of $5 for lifetime membership. Jefferson Credit Union was listed as a ransomware victim associated with the threat actor ransomhouse. |
|||||
| Dellner Couplers AB View Details _ | ransomhouse | Other | |||
|
Dellner Couplers AB is a Sweden-based manufacturer of train connection systems for the rail sector, headquartered in Falun, Sweden. The company designs, manufactures, and services couplers, gangways, dampers, and related train systems for rail manufacturers and operators worldwide. Its offerings support safety-critical passenger rail applications and global maintenance needs. It was listed as a ransomware victim associated with ransomhouse. |
|||||
| AHS Aviation Handling Services GmbH View Details _ | ransomhouse | Transportation / Travel / Logistics | |||
|
AHS Aviation Handling Services GmbH is a leading independent provider of comprehensive aviation ground handling services across Germany, operating at 14 major airports including Frankfurt, Munich, and Hamburg. The company offers passenger handling such as check-in and gate services, baggage handling, ramp services including aircraft loading and pushback, flight operations, and station management. Its headquarters are located in Hamburg, with representative operational addresses at key airports nationwide. AHS Aviation Handling Services GmbH was neutrally listed as a ransomware victim associated with the threat actor ransomhouse. |
|||||
| realestateconsu... View Details _ | lockbit2 | Construction / Real Estate | |||
|
realestateconsu... is a Construction / Real Estate company in the United States, operating in a sector that includes property development, construction services, and related real-estate activities. Public records in the available search results do not provide a fuller corporate profile, so its exact offerings cannot be stated with confidence. In threat-intelligence indexes, it is identified by its company name and industry context rather than by a detailed service catalog. It was listed as a ransomware victim associated with lockbit2. |
|||||
| nipmo.dst.gov.z... View Details _ | lockbit2 | Other | |||
|
The National Intellectual Property Management Office (NIPMO) is a South African government entity under the Department of Science, Technology and Innovation, headquartered in Pretoria. It empowers small businesses and innovators by facilitating intellectual property protection, commercialization, and advocacy for publicly financed research. NIPMO delivers workshops, training sessions, and policy guidance to strengthen IP management across the nation’s science and technology sector. The organization was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| mpusd. View Details _ | lockbit2 | Other | |||
|
mpusd. operates within the Other sector, with no specific geographic location or defined offerings publicly documented. The entity lacks detailed information regarding its core business activities, market presence, or service portfolio. Despite this ambiguity, mpusd. has been identified as a victim of ransomware activity linked to the Lockbit2 threat actor. This listing reflects its inclusion in threat-intelligence records as an affected organization under the Lockbit2 campaign. The association underscores the broader risk environment impacting entities across unspecified sectors. |
|||||
| fnoutlet.com View Details _ | lockbit2 | Retail / E-commerce | |||
|
fnoutlet.com is the website of FN Factory Outlet Public Co., Ltd., a Thai retail and e-commerce company that operates factory outlets across Thailand. Its business focuses on discounted apparel, bedding, household goods, accessories, and gifts through both branches and online channels. The company presents itself as a factory-outlet operator selling apparel and non-apparel merchandise to consumers in Thailand. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Next Leak On Hold View Details _ | kelvinsecurity | Other | |||
|
Next Leak On Hold is an organization listed in the Other sector, with no public location or service details visible in the available record. The name suggests a standalone entity or site entry rather than a widely documented business profile, so its offerings cannot be confirmed from the evidence provided. In threat-intelligence indexes, such entries typically denote a target named by a leak-site operator rather than a verified breach summary. It was listed as a ransomware victim associated with kelvinsecurity. |
|||||
| PTC Industries View Details _ | kelvinsecurity | Other | |||
|
PTC Industries Limited is an Indian manufacturing company founded in 1963 and headquartered in Lucknow, Uttar Pradesh, specializing in precision metal components for critical and supercritical applications. The company serves industries including aerospace, defense, oil and gas, LNG processing, marine, energy, and petrochemical sectors through advanced manufacturing, castings, and precision CNC machining. It produces high-quality components and sub-systems for critical applications, including titanium and superalloy facilities for defense projects like BrahMos. PTC Industries Limited was listed as a ransomware victim associated with kelvinsecurity. |
|||||
| Rollecate Group View Details _ | blackbasta | Services | |||
|
Rollecate Group is the leading façade construction company in the Netherlands, specializing in custom solutions for aluminium, steel, uPVC, and composite façade systems and components. Founded in Staphorst in 1954, the company operates divisions for aluminium, plastic, steel, composite, glass, maintenance, and export, serving both interior and exterior applications. The organization provides high-quality façade construction and window frames, leveraging 65 years of industry experience to deliver demanding custom projects. Rollecate Group was listed as a ransomware victim associated with the BlackBasta threat actor. |
|||||
| Sole Technology View Details _ | United States | blackbasta | IT | ||
|
Sole Technology, Inc. is a U.S.-based company headquartered in Lake Forest, California. It designs, produces, and distributes action-sports footwear and apparel, including skate shoes and related gear. Public company profiles describe it as a global brand with operations and distribution in multiple countries. In threat-intelligence records, soletechnology.com was listed as a ransomware victim associated with blackbasta. |
|||||
| liceu.barcelon View Details _ | lockbit2 | Hospitality / Food & Beverage / Tourism | |||
|
liceu.barcelon appears to be a Barcelona-based property or venue in the tourism and hospitality space, tied to the city’s cultural and visitor economy. Barcelona’s Liceu is centered on La Rambla and is associated with the Gran Teatre del Liceu, a historic opera house that stages opera, concerts, and guided visits. The entity is cataloged in a Hospitality / Food & Beverage / Tourism context and is relevant to travel, leisure, and guest-facing services. It was listed as a ransomware victim associated with lockbit2. |
|||||
| delcourt.fr View Details _ | France | lockbit2 | Other | ||
|
delcourt.fr is the website of Groupe Delcourt, a French publishing company based in Paris. The group is known for comics, graphic novels, and youth literature, and operates from France with offices in Paris and Toulon. It is part of the broader publishing sector and serves readers and retailers through its catalogue and imprints. The site was listed as a ransomware victim associated with lockbit2. |
|||||
| Tosoh Corporation View Details _ | lorenz | Services | |||
|
Tosoh Corporation is a Tokyo, Japan-based chemical and specialty materials company that serves industrial and manufacturing customers worldwide. It produces basic chemicals, plastic resins, and other materials used across modern industry, with operations in Japan and overseas. The company is part of a broader group of chemical and specialty products businesses. It was listed as a ransomware victim associated with lorenz. |
|||||
| willsent View Details _ | mindware | Other | |||
|
willsent is a company in the broad Other sector; publicly available threat-intelligence listings do not provide a verified business description, location, or product line. In this index entry, the name appears as a ransomware victim record rather than an operational profile. The associated threat actor is Mindware, a ransomware group tracked for targeting organizations across multiple sectors. The listing identifies willsent as a ransomware victim associated with Mindware. |
|||||
| welplaat View Details _ | mindware | Other | |||
|
Welplaat is an organization in the Netherlands classified in the Other sector. Public threat-intelligence listings identify it as a victim name associated with a ransomware exposure event. No verified public source in the provided results describes its products, services, or operating footprint in detail. The listing was recorded under the Mindware ransomware group and should be read as a threat-intelligence reference, not a confirmed breach disclosure. |
|||||
| toshfarms View Details _ | mindware | Agriculture / Food | |||
|
Tosh Farms is an agriculture and food business based in Henry, Tennessee, with operations in pig production across Tennessee and Kentucky. Its website says the company raises pigs on more than 18,000 acres and identifies Tosh Farms as the largest pork producer in Tennessee. Public business listings place its headquarters at 1586 Atlantic Avenue, Henry, Tennessee. It was listed as a ransomware victim associated with mindware. |
|||||
| thebureau View Details _ | mindware | Other | |||
|
thebureau is a Miami-based cannabis packaging company that designs and manufactures specialty packaging and vape hardware. Its offerings include customizable jars, tubes, bags, boxes, and all-in-one vapes for cannabis brands. Public listings describe it as a full-service product development, sourcing, design, and production business in the packaging sector. It was listed as a ransomware victim associated with mindware. |
|||||
| smd View Details _ | mindware | Other | |||
|
SMD is an Other-sector organization; public records in the available search results do not identify a more specific industry, location, or offering. In threat-intelligence indexing, it is best described by its company name and sector only, without adding unverified operational details. Mindware is a ransomware group first reported in 2022 and associated with double-extortion activity against organizations across multiple industries. SMD was listed as a ransomware victim associated with Mindware. |
|||||
| simpsonplastering View Details _ | mindware | Other | |||
|
Simpson Plastering, LLC is an Alabama-based subcontractor headquartered in Birmingham, with a second office in Belmont, North Carolina. The company provides stucco, EIFS, plastering, panel installation, and custom wall finish services for owners, construction companies, and general contractors. Public business listings place its core operations in Birmingham and note service coverage across the Southeast. It was listed as a ransomware victim associated with mindware. |
|||||
| nottco View Details _ | mindware | Other | |||
|
Nott Company is a U.S.-based industrial distributor and engineering supplier headquartered in Arden Hills, Minnesota, with multiple Midwest locations. It provides fluid power products and systems, industrial power transmission products and systems, custom rubber fabricated products, and material handling equipment. Company materials also describe hydraulic system design and OEM integration services. It was listed as a ransomware victim associated with mindware. |
|||||
| micropakkn View Details _ | mindware | Agriculture / Food | |||
|
micropakkn is an entity operating within the Agriculture and Food sector, providing services relevant to grain, livestock, or crop production in the United States. While specific location details and full offerings are not publicly documented, the entity functions as part of the broader agricultural services landscape supporting food supply chains. The organization was listed as a ransomware victim associated with the Mindware threat actor, which claimed the incident on May 5, 2022. No official confirmation of data theft or breach specifics is available from primary sources, and the entity has not issued a formal public disclosure regarding the incident. This listing serves as a neutral record of the claimed association between micropakkn and the Mindware ransomware group. |
|||||
| mediuscorp View Details _ | mindware | Services | |||
|
Mediuscorp is a Morgan Hill, California-based services company in the printing sector, operating from 15850 Concord Circle. It describes itself as an experienced provider of print production and related services, with offerings that include printing, finishing, packaging, kitting and assembly, fulfillment, and logo merchandise. The company also promotes customer communication through its sales and customer service teams and lists a local contact number and email on its site. It was listed as a ransomware victim associated with mindware. |
|||||
| diager View Details _ | mindware | Other | |||
|
Diager is a French manufacturing company based in Poligny, in the Jura department of Bourgogne-Franche-Comté, France. It describes itself as a leading maker of professional tools, including drilling products, and says it manufactures nearly one million tools per year. Public company profiles also place Diager in the manufacturing sector and identify its headquarters in Poligny. Diager was listed as a ransomware victim associated with Mindware. |
|||||
| callinc View Details _ | mindware | Services | |||
|
Callinc is a U.S. services company that appears to operate in cold calling, call center, or outbound sales support based on available business listings and service descriptions. In this sector, firms typically help clients with phone outreach, lead generation, and customer contact workflows. Publicly available information about its exact offerings and location is limited. It was listed as a ransomware victim associated with Mindware. |
|||||
| allwell View Details _ | mindware | Other | |||
|
Allwell is a U.S. Medicare Advantage product offered through local health insurers under the Wellcare by Allwell brand. It operates in multiple states and provides Medicare Part C coverage, with some plans including prescription drug, dental, vision, hearing, and other supplemental benefits. Public plan information also shows member and provider support channels and a mailing address in Van Nuys, California. The company was listed as a ransomware victim associated with Mindware. |
|||||
| acorentacar View Details _ | mindware | Other | |||
|
Aco Rent a Car is a car rental company that operates in the United States, with locations and airport service in Miami, Fort Lauderdale, Orlando, and other markets. Its website promotes low-cost rentals, shuttle-supported airport pickups, and a range of vehicle options for travelers. Public listings also place its headquarters in Florida, reflecting a regional rental operation with multiple pickup points. It was listed as a ransomware victim associated with mindware. |
|||||
| jewelry. View Details _ | lockbit2 | Other | |||
|
Jewelry consists of decorative items worn for personal adornment such as rings, necklaces, earrings, and bracelets. The global jewelry market was valued at approximately USD 286 billion in 2025 and is projected to grow steadily through 2034, with the U.S. dominating North America and India leading Asia Pacific. The industry offers diverse products including diamond, gold, and gemstone jewelry, supported by services like engraving and repair, and increasingly embraces digital design, 3D printing, and virtual try-ons for personalized experiences. Jewelry stores operate under NAICS code 44831 in the U.S., with over 73,000 businesses generating about $60 billion in revenue. This entity was listed as a ransomware victim associated with LockBit2. |
|||||
| ELTA Hellenic Post View Details _ | vicesociety | Other | |||
|
ELTA Hellenic Post is Greece’s national postal service, headquartered in Athens, and it provides domestic and international postal, logistics, philately, financial, and bancassurance services. It also operates a nationwide retail network serving customers across Greece. In threat-intelligence indexing, it is identified as a ransomware victim entry. The listing is associated with vicesociety. |
|||||
| Haynes Manuals View Details _ | vicesociety | Other | |||
|
Haynes Manuals is a publishing company best known for owner’s workshop and repair manuals for cars, motorcycles, and related machinery. It operates from Sparkford, Somerset, United Kingdom, and serves readers with print and digital DIY repair guides through its Haynes brand. The company’s offerings are aimed at vehicle maintenance, servicing, and customization, making it a recognized name in technical publishing. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Zito Media View Details _ | blackbasta | Communication / Marketing | |||
|
Zito Media is a telecommunications company headquartered in Coudersport, Pennsylvania, in the United States. It provides cable television, high-speed internet, digital voice, WiFi, mobile, and business services in select markets, with offerings that vary by location. The company serves residential and commercial customers and supports small business communications needs. In threat-intelligence indexing, Zito Media was listed as a ransomware victim associated with blackbasta. |
|||||
| Faw-Volkswagen Automobile Co., Ltd. View Details _ | China | hive | Telecommunications | ||
|
FAW-Volkswagen Automobile Co., Ltd. is a large passenger automobile manufacturer based in Changchun, Jilin, China. It is a joint venture of FAW Group and Volkswagen Group and produces Audi and Volkswagen-branded passenger cars for the Chinese market. The company operates multiple assembly plants in China and is part of Volkswagen Group China’s local manufacturing network. It was listed as a ransomware victim associated with hive. |
|||||
| Tosoh Bioscience View Details _ | lorenz | Other | |||
|
Tosoh Bioscience, Inc. is a U.S.-based subsidiary of Tosoh Corporation, headquartered in Tokyo, Japan, with operations in Grove City, Ohio. It markets clinical diagnostics systems and reagents, including immunoassay and HPLC A1C platforms, and serves laboratories in the bioscience and diagnostics sector. Tosoh Corporation also describes the wider group as a diversified chemical and specialty materials company. Tosoh Bioscience was listed as a ransomware victim associated with lorenz. |
|||||
| rogz.com View Details _ | lockbit2 | Other | |||
|
Rogz is a South African pet brand based in Cape Town, Western Cape, that designs, manufactures, and distributes pet accessories and gear for dogs and cats. Its product range emphasizes safety, quality, function, and comfort, and the company says it sells into more than 90 countries. Rogz also describes a retail category management system used to support merchandising in stores. The entity was listed as a ransomware victim associated with lockbit2. |
|||||
| nizing.com.tw View Details _ | Taiwan, Province of China | lockbit2 | Other | ||
|
Nizing Electric Wire & Cable Co., Ltd. is a Taiwan-based manufacturer headquartered in New Taipei City, Taiwan, serving industrial and commercial cable markets. Its website presents products and applications such as heavy-duty cable, military-spec signal control cable, and other wire-and-cable solutions for sectors including semiconductor, robotic, and steel industry use. The company operates from Sanchong District in New Taipei City and markets its offerings through a multilingual corporate site. It was listed as a ransomware victim associated with lockbit2. |
|||||
| aref.government... View Details _ | lockbit2 | Public Sector | |||
|
aref.government... appears to be a United States Public Sector government entity, likely tied to a public-service or administrative function based on its domain-style name. Public sector organizations provide civic, regulatory, and operational services to residents and businesses, and they are frequent ransomware targets. Threat-intelligence reporting shows government agencies are among the sectors most affected by ransomware activity. It was listed as a ransomware victim associated with lockbit2. |
|||||
| EYP View Details _ | conti | Other | |||
|
EYP is a U.S.-based professional services firm known for architecture and engineering work, with headquarters in Albany, New York, and offices in cities including Boston and Washington, DC. Its services focus on design and project delivery across built-environment and infrastructure work. Public company profiles describe it as operating in the other sector rather than a single regulated industry. EYP was listed as a ransomware victim associated with Conti. |
|||||
| Asia Pacific University View Details _ | vicesociety | Education | |||
|
Asia Pacific University of Technology & Innovation (APU) is a private university in Kuala Lumpur, Malaysia, located at Technology Park Malaysia in Bukit Jalil. It offers a range of undergraduate and postgraduate programmes with a strong focus on technology and innovation, alongside education-related study areas. The institution serves the education sector and operates as a higher-education provider in Malaysia. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Unicity International View Details _ | revil | Public Sector | |||
|
Unicity International is a wellness and fitness services company headquartered in Provo, Utah, that designs and develops innovative nutritional products for healthy living. The organization operates globally with locations in the United States, Japan, Canada, Thailand, and Switzerland, serving Members and Customers worldwide. It provides nutritional offerings that make healthy living doable in an on-the-go world, supported by a large workforce of over 2,360 employees. Unicity International was listed as a ransomware victim associated with the threat actor revil. |
|||||
| Municipality of Posadas View Details _ | kelvinsecurity | Public Sector | |||
|
The Municipality of Posadas is the capital city of Misiones Province in northeastern Argentina, functioning as a key administrative and public service center for the region. It oversees essential government operations, cultural initiatives, and economic activities including wood and iron manufacturing, while serving a population exceeding 324,000 residents. As a central hub in the Public Sector, the municipality provides critical services to local citizens and coordinates regional development efforts. The Municipality of Posadas was neutrally listed as a ransomware victim associated with the threat actor kelvinsecurity. |
|||||
| bfclcoin View Details _ | kelvinsecurity | Other | |||
|
bfclcoin is an entity operating in the sector Other, with no specific geographic location or defined offerings publicly documented. As a general category based on its name, it lacks verified operational details regarding products, services, or market presence. The entity was listed as a ransomware victim associated with the kelvinsecurity threat actor, as discovered by ransomware tracking sources. This listing indicates bfclcoin was targeted by kelvinsecurity's ransomware operations, though no breach specifics are confirmed. The association remains part of the broader threat-intelligence index tracking kelvinsecurity's victim timeline. |
|||||
| Instance IT Solutions India View Details _ | kelvinsecurity | Services | |||
|
Instance IT Solutions India is a leading IT solutions company headquartered in Surat, Gujarat, specializing in secure custom software solutions for business automation globally. The firm offers end-to-end services including web development, mobile apps, ERP, digital marketing, and enterprise solutions for diverse industries such as finance, healthcare, and manufacturing. With expertise across 70+ industries and over 750 projects delivered, it serves small businesses and micro-enterprises primarily in India. Instance IT Solutions India was neutrally listed as a ransomware victim associated with kelvinsecurity. |
|||||
| fivestar View Details _ | lockbit2 | Other | |||
|
fivestar is reported in search results as Five-Star Business Finance Ltd., an Indian non-banking financial company in the financials sector. It provides secured loans to small business owners, self-employed individuals, micro-entrepreneurs, and related small mortgage financing services across South India. The company is also described as operating as a specialized financial services provider focused on underserved borrowers. In threat-intelligence listings, fivestar was named as a ransomware victim associated with lockbit2. |
|||||
| Jameco Electronics View Details _ | blackbasta | Other | |||
|
Jameco Electronics is an electronic components distributor based in Belmont, California, in the United States. Founded in 1974, it supplies parts and components to businesses, educational institutions, and hobbyists. The company describes itself as an authorized distributor with more than 50 years in business. It was listed as a ransomware victim associated with blackbasta. |
|||||
| PRGX Global Inc. View Details _ | blackbasta | Communication / Marketing | |||
|
PRGX Global Inc. is an Atlanta, Georgia-based company that provides recovery audit and spend analytics services to organizations in more than 30 countries. Its offerings help large enterprises identify savings, recover lost profit, and improve source-to-pay performance through technology-enabled analytics. PRGX operates as a global services provider serving complex corporate clients across multiple regions. It was listed as a ransomware victim associated with blackbasta. |
|||||
| The Scholz Group View Details _ | blackbasta | Services | |||
|
The Scholz Group is a leading European scrap recycler and one of the largest recycling companies for ferrous and non-ferrous metal worldwide, operating more than 180 sites globally. Based in Germany with regional presence in Poland, Austria, the Balkans, and the Czech Republic, the group focuses on the recovery and processing of scrap metals and other materials. It describes itself as a key company in raw materials recycling in Germany and Europe, specializing in steel and metal scrap. The Scholz Group was listed as a ransomware victim associated with the threat actor blackbasta. |
|||||
| erediriva.it View Details _ | Italy | lockbit2 | Other | ||
|
Erediriva.it represents Eredi Riva geom. Mario S.r.l., a construction company based in Galbiate, Italy, within the civil and industrial building sector. The firm specializes in constructing residential and industrial buildings while directly managing the sale and rental of its real estate operations. Operating for over 30 years in the Lecco area, the company guarantees quality and attention to detail in its construction projects. Erediriva.it was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| cwaengineers.co... View Details _ | lockbit2 | Other | |||
|
CWA Engineers Inc. is a Vancouver, British Columbia-based multidisciplinary engineering and project management company. It provides professional services for industrial projects, including mining and minerals, ports, bulk material handling, and related processing systems. The company is known for EPCM-style support and project-specific solutions across complex material-handling environments. In threat-intelligence records, CWA Engineers was listed as a ransomware victim associated with LockBit2. |
|||||
| agenilsen.no View Details _ | Norway | lockbit2 | Other | ||
|
Åge Nilsen is a plumbing company based in Tromsø, Norway, with its office at Ringvegen 9 and a public website at agenilsen.no. The company describes itself as Nord-Norges ledende rørleggerbedrift, indicating a leading regional role in plumbing services. Public corporate coverage also identifies it as a construction-related business with work in large projects. The listing identifies agenilsen.no as a ransomware victim associated with lockbit2. |
|||||
| Limited May Access Sale View Details _ | everest | Other | |||
|
Limited May Access Sale appears in the ransomware listing for Everest, a group known for posting victim names and threatening data leaks if demands are not met. Publicly available intelligence does not identify its industry beyond the label “Other,” and no verified location or commercial offerings are provided in the available sources. The entry is best understood as an incident listing tied to Everest’s extortion activity, not as a detailed company profile. It was listed as a ransomware victim associated with everest. |
|||||
| FRANSABANK View Details _ | blackbyte | Finance / Legal / Insurance | |||
|
FRANSABANK S.A.L. is a leading Lebanese financial group established in 1921, offering commercial, retail, corporate, and investment banking services to individuals and SME clients in Lebanon. The bank provides trade finance, project finance, and private banking solutions, supporting small and medium-sized enterprises through diverse financial offerings. Headquartered in Beirut, FRANSABANK ranks among the top four leading financial groups in Lebanon and serves a majority of Lebanese individuals and private clients. The entity was neutrally listed as a ransomware victim associated with the threat actor blackbyte. |
|||||
| M+R SPEDAG GROUP View Details _ | blackbyte | Services | |||
|
M+R SPEDAG GROUP is a family-owned transport and logistics company headquartered in Muttenz, Switzerland, serving clients through freight forwarding, overland services, project logistics, customs clearance, and related logistics solutions. Its service profile includes container transport and combined road-rail transport, with a focus on tailored logistics for industry sectors such as fashion, lifestyle, and consumer goods. The company operates in the Services sector and maintains its headquarters in Muttenz, Basel-Landschaft. It was listed as a ransomware victim associated with blackbyte. |
|||||
| SOGEGROSS SPA View Details _ | blackbyte | Other | |||
|
SOGEGROSS SPA is an Italian wholesale company based in Genoa, Liguria, specializing in non-specialized distribution of food, beverages, and tobacco products. The company supplies frozen food, fresh fruits, vegetables, beverages, baked products, and meat products to retailers and businesses across Italy. Operating since 1925, it serves over 1,000 employees through its cash-and-carry and retail brands including Basko and Doro Supermercati. SOGEGROSS SPA was listed as a ransomware victim associated with the blackbyte threat actor. |
|||||
| vestas View Details _ | lockbit2 | Other | |||
|
Vestas is a Denmark-based energy company headquartered in Aarhus. It designs, manufactures, installs, and services wind turbines and related renewable energy solutions for customers worldwide. The company operates across global markets and maintains offices and production sites in multiple countries, including the United States. It was listed as a ransomware victim associated with lockbit2. |
|||||
| CPQD - BANCO CENTRAL OF BRASIL BLOCKHAIN. 1.8TB DATA LEAKED WITH ALL SOURCES. View Details _ | lv | Finance / Legal / Insurance | |||
|
CPQD, the Centro de Pesquisa e Desenvolvimento em Telecomunicações, is a Brazilian research and development center focused on telecommunications and blockchain solutions for sectors including Finance, Legal, and Insurance. It develops blockchain technologies, though none of its sensitive blockchain solutions are currently in use by Banco Central do Brasil. The organization clarified that alleged leaked repositories were internal test data without personal or sensitive information. Despite ransomware group LV claiming a 1.8TB data leak involving blockchain servers, CPQD stated no personal data was leaked and no client solution was compromised. CPQD was listed as a ransomware victim associated with the LV threat actor. |
|||||
| State Bar of Georgia View Details _ | United States | bitlocker | Hospitality / Food & Beverage / Tourism | ||
|
State Bar of Georgia is a nonprofit legal organization based in Atlanta, Georgia, that serves the state’s lawyers and supports the public interest in the administration of justice. Its work includes bar membership functions, professional standards, and services for members across Georgia. Public listings place it in Atlanta with additional Georgia locations, reflecting its statewide role. It was listed as a ransomware victim associated with bitlocker. |
|||||
| ethiopianai View Details _ | lockbit2 | Other | |||
|
ethiopianai is an Ethiopia-based entity associated with the Other sector, a broad category used for organizations that do not fit standard industry labels. Public search results do not provide enough reliable detail to describe its specific offerings or operating model with confidence. In threat-intelligence indexing, it appears as a named victim entity rather than a verified breach source. It was listed as a ransomware victim associated with lockbit2. |
|||||
| card View Details _ | lockbit2 | Other | |||
|
card is identified in the Other sector, with no reliable public detail in the provided sources confirming a specific industry, location, or offering set. As a result, the entity can only be described conservatively as a named organization associated with an unspecified business profile. The available threat-intelligence context places it among victims referenced in connection with LockBit 2.0, a ransomware-as-a-service operation active across many sectors. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Collegiate sports medicine View Details _ | everest | Healthcare / Pharma | |||
|
Collegiate sports medicine is a specialized healthcare sector in the United States that delivers injury prevention, diagnosis, and treatment services to collegiate athletes through certified athletic trainers and sports medicine physicians. It offers comprehensive care including non-operative treatments, physical therapy programs, concussion management, and rehabilitation to support recovery and long-term health for student-athletes. This field operates within academic institutions and affiliated clinics, integrating orthopedics, sports cardiology, and employee health services to ensure athlete safety and performance. Collegiate sports medicine was listed as a ransomware victim associated with the threat actor everest. |
|||||
| zdgllc.com View Details _ | lockbit2 | Services | |||
|
ZDG LLC is a privately held construction management company headquartered in New York City, serving the New York Metro Area. It provides full-service preconstruction, construction, and post-construction support for complex projects across sectors such as residential, healthcare, hospitality, institutional, mixed-use, and services. The company’s published services include conceptual estimates, budgeting, site investigation, as-built condition reviews, constructibility reviews, and abatement program coordination. It was listed as a ransomware victim associated with lockbit2. |
|||||
| smtuc.pt View Details _ | Portugal | lockbit2 | Other | ||
|
SMTUC, or Serviços Municipalizados de Transportes Urbanos de Coimbra, is a municipal public transport operator in Coimbra, Portugal, responsible for managing the city's bus and trolleybus networks. The organization provides essential urban transportation services, including route planning, stop positioning, and fare integration for residents and visitors. It operates as a structure under the Coimbra City Council, ensuring the public service of urban transport across the region. SMTUC was listed as a ransomware victim associated with the threat actor Lockbit2. |
|||||
| orthopaedie-app... View Details _ | lockbit2 | Other | |||
|
orthopaedie-app... appears to be an orthopaedic care brand or application tied to the health services sector, but the public record in this query does not identify a precise legal entity or location. Orthopaedic practices and related apps typically support patient access to specialist care, urgent visits, and scheduling tools, reflecting a clinical services offering. Because the entity name is truncated, the safest description is a generic health-sector listing rather than a more specific corporate profile. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Regina Public Schools View Details _ | Canada | alphv | Education | ||
|
Regina Public Schools is the public school division for Regina, Saskatchewan, Canada, serving the city’s Anglophone secular K-12 education system. It is one of Saskatchewan’s largest school divisions and offers elementary and high school programs, along with services such as newcomers support, night school, and outdoor environmental education. The district is headquartered in Regina and serves approximately 25,000 to 26,000 students. It was listed as a ransomware victim associated with alphv. |
|||||
| sagefruit.com View Details _ | lockbit2 | Other | |||
|
Sage Fruit is a Yakima, Washington-based produce company that sells and markets fresh apples, pears, and cherries. It operates in the food and beverage services sector and has described itself as a grower, packer, and shipper serving customers in produce distribution. Public business listings place its headquarters in Yakima, reflecting its role in the U.S. fruit supply chain. It was listed as a ransomware victim associated with lockbit2. |
|||||
| p View Details _ | lockbit2 | Other | |||
|
p is listed in the Other sector in the United States, but the available record does not provide a verified corporate profile, location beyond country, or stated offerings. In threat-intelligence catalogs, such entries are typically used to index organizations or entities named in ransomware leak-site reporting when public business details are limited. The listing places p in a LockBit 2-related victim set, reflecting a ransomware exposure record rather than a confirmed operational summary. It was listed as a ransomware victim associated with lockbit2. |
|||||
| hispanoamerican... View Details _ | lockbit2 | Telecommunications | |||
|
hispanoamerican... is listed as a telecommunications entity, a sector that provides network connectivity, communications services, and related technology offerings to businesses and consumers. Publicly available search results do not clearly identify its exact corporate name, headquarters, or product portfolio, so this description stays limited to the sector shown in the listing. Telecommunications companies typically support voice, data, and digital infrastructure across regional markets. It was listed as a ransomware victim associated with lockbit2. |
|||||
| 7generations.or... View Details _ | lockbit2 | Other | |||
|
Seven Generations Education Institute (SGEI) is an Indigenous-led educational organization in Ontario, Canada, serving learners through high school, post-secondary, and employment training programs. It also offers customizable training, Ontario-approved micro-credentials, and employment resources from its main campus in Kenora and related community settings. SGEI says it is governed by the First Nations communities surrounding its main campus and has operated for four decades. The entity 7generations.org was listed as a ransomware victim associated with lockbit2. |
|||||
| w View Details _ | lockbit2 | Other | |||
|
w is listed as an entity in the Other sector, but the available source material does not provide enough verified detail to identify its location, offerings, or business profile with confidence. LockBit 2.0 is a ransomware-as-a-service operation that has affected organizations across multiple industries and countries, according to threat-intelligence reporting. In catalog context, w should be treated as a minimally described victim record rather than a fully profiled company. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Valley Rentals View Details _ | Netherlands | quantum | Construction / Real Estate | ||
|
Valley Rentals is a Netherlands-based real estate business focused on renting out apartments in well-regarded districts of The Hague. Its offering centers on residential rental brokerage and arranging rental agreements for available properties. The company operates in the construction and real estate sector, where rental marketing and tenant placement are core services. It was listed as a ransomware victim associated with quantum. |
|||||
| Hufcor View Details _ | United States | quantum | Other | ||
|
Hufcor is a U.S.-based company headquartered in Janesville, Wisconsin, that manufactures and distributes operable partitions, movable walls, room dividers, and airwalls. It presents itself as a global industry leader in flexible space-management solutions and related professional services. Its products are used to divide and reconfigure interior spaces for commercial and institutional settings. Hufcor was listed as a ransomware victim associated with Quantum. |
|||||
| Grosvenor Engineering Group View Details _ | Australia | quantum | Manufacturing / Engineering | ||
|
Grosvenor Engineering Group is an Australian-owned building services company based in Moorebank, New South Wales, with operations across Australia and New Zealand. It provides HVAC, fire services, electrical systems and advisory services for existing and new buildings, supporting technical asset management for commercial properties. Founded in 1994, it serves property portfolios and building owners with maintenance, design and refurbishment work. It was listed as a ransomware victim associated with quantum. |
|||||
| Drive Products View Details _ | Canada | quantum | Communication / Marketing | ||
|
Drive Products is a Canada-based company in the communication and marketing-related commercial vehicle and truck equipment sector, headquartered in Mississauga, Ontario, with locations across Canada. It describes itself as a leading supplier of truck-mounted equipment and a one-stop shop for work trucks, offering products, services, system integration, upfitting, fabrication, and manufacturing. The company says it has more than 40 years of experience and supports a nationwide branch and partner network. It was listed as a ransomware victim associated with quantum. |
|||||
| Petro Serve View Details _ | Qatar | quantum | Agriculture / Food | ||
|
Petro Serve is a Qatar-based company in the Agriculture / Food sector, operating from QA. Public company profiles do not provide detailed product lines, so the business can only be described at a sector level without adding unsupported specifics. In threat-intelligence indexing, it is identified by name, country, and industry to help analysts distinguish it from similarly named firms. It was listed as a ransomware victim associated with quantum. |
|||||
| Henry View Details _ | United States | quantum | Construction / Real Estate | ||
|
Henry is a US company in the construction and real estate sector, known for supplying building and roofing materials and related products. Public reporting describes Henry Company as a California-based construction supply business serving commercial and residential markets. Its operations sit within a sector that is frequently targeted by ransomware actors because of its project, procurement, and customer data flows. It was listed as a ransomware victim associated with quantum. |
|||||
| brid View Details _ | lockbit2 | Other | |||
|
brid is listed in the Other sector, but no reliable public profile in the available sources identifies its exact location, core offerings, or business model. In threat-intelligence cataloging, such entries are typically recorded under the company name when public-facing corporate details are limited or not yet verified. LockBit 2.0 is a ransomware-as-a-service variant associated with double-extortion tactics and broad victim targeting across industries. It was listed as a ransomware victim associated with lockbit2. |
|||||
| remar. View Details _ | lockbit2 | Other | |||
|
Remar is an Ecuador-based logistics company, also identified as ULOG Ecuador, operating in the transportation and logistics sector. Public incident reporting describes it as a firm serving shipping and logistics needs in Ecuador. In threat-intelligence records, it appears under the name remar.com.ec and is associated with the other sector classification. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Jasper County Sheriff's Office View Details _ | onyx | Public Sector | |||
|
Jasper County Sheriff's Office is a public-sector law enforcement agency serving Jasper County, South Carolina, from Ridgeland. It provides patrol, criminal investigations, records access, emergency response, dispatch, and other sheriff’s office services for county residents. The office also handles incident reporting, warrants, and community-facing public safety support. In this ransomware victim listing, it was associated with onyx. |
|||||
| Monterey Mechanical Co. View Details _ | United States | hive | Other | ||
|
Monterey Mechanical Co. is a California-based industrial contractor and metal fabricator headquartered in Oakland, with operations centered in the San Francisco Bay Area. The company describes its work in complex water and wastewater projects, industrial facilities, metals fabrication and installation, HVAC, and odor control. Industry directories also list contractor specialties that include general engineering and related industrial services. The company was listed as a ransomware victim associated with Hive. |
|||||
| watermarkbeachr View Details _ | lockbit2 | Other | |||
|
watermarkbeachr is an entity operating in the Other sector, with no specific geographic location or defined offerings publicly documented. As its name and sector suggest minimal public data, it is generally described by its classification rather than detailed operational specifics. The entity was listed as a ransomware victim associated with lockbit2, reflecting its inclusion in threat-intelligence records regarding this cybercriminal group. This listing type categorizes watermarkbeachr within the broader context of lockbit2's ransomware victim portfolio. No confirmed breach details, stolen data types, or record counts are available for this entity. |
|||||
| Mercadocar Mercantil Ltda. View Details _ | vicesociety | Services | |||
|
Mercadocar Mercantil Ltda. is a Brazilian services company focused on automotive retail. Public company profiles describe Mercadocar as an auto parts and accessories business serving both consumers and businesses, with operations in Brazil. It is associated with the broader automotive services and retail market. The company was listed as a ransomware victim associated with vicesociety. |
|||||
| Suhl. City in Germany View Details _ | vicesociety | Public Sector | |||
|
Suhl is a city in Thuringia, central Germany, on the Lauter River in the Thuringian Forest, and it is known for a long industrial and civic history. Today, it functions as a municipal public-sector center, with local government and community services serving residents in and around the city. Public records and city-related listings also show municipal procurement and service activity in Suhl. It was listed as a ransomware victim associated with vicesociety. |
|||||
| MOTIVE-ENERGY - HACKED AND 1.5 TB DATA LEAKED View Details _ | lv | Energy | |||
|
Motive Energy is a leading supplier in the energy sector, operating across the United States with a focus on solar, energy storage, and EV charging solutions. For over fifty years, the company has delivered customized, innovative energy management systems to meet diverse business needs. It provides best-in-class products for the material handling industry, including batteries, chargers, and watering systems. Motive Energy was listed as a ransomware victim associated with the threat actor lv. |
|||||
| bri View Details _ | lockbit2 | Other | |||
|
bri refers to Bank Rakyat Indonesia, a major financial institution operating in the Other sector within Indonesia, providing banking and digital financial services to individuals and corporations. The entity is known for its extensive network of branches and digital platforms that support regular banking operations without disruption. It was listed as a ransomware victim associated with LockBit2, a ransomware-as-a-service group that emerged in 2021 and has claimed to target thousands of companies globally. While LockBit2 affiliates employ double extortion techniques including data encryption and exfiltration, bri has confirmed its systems remain unaffected by similar ransomware threats. The listing serves as a reference point for threat-intelligence analysts monitoring ransomware victim patterns in the Indonesian financial sector. |
|||||
| Associazione Bancaria Italiana View Details _ | vicesociety | Finance / Legal / Insurance | |||
|
Associazione Bancaria Italiana (ABI) is a voluntary, non-profit trade association for the Italian banking sector, based in Rome with additional offices in Milan, Brussels, and Frankfurt. It represents and supports banks and financial operators through studies, information, technical assistance, training, and sector events. ABI also publishes analysis and guidance on issues affecting the banking and finance industry. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Domingues and Pinho Contadores View Details _ | vicesociety | Other | |||
|
Domingues e Pinho Contadores is a Brazilian accounting and business-management firm based in Rio de Janeiro, with offices in São Paulo and Macaé. It provides accounting outsourcing and related services for national and international clients, including fiscal, payroll, financial, and tax consulting. Public company profiles also describe it as a reference in accounting outsourcing and business management in Brazil. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Building Plastics, Inc. View Details _ | vicesociety | Manufacturing / Engineering | |||
|
Building Plastics, Inc. is a U.S. wholesale decorative surfacing and building materials company based in Memphis, Tennessee, with operations in Mississippi. It distributes flooring, laminate, hardwood, tile, carpet, countertops, and other decorative surfacing products to dealers, contractors, and commercial clients. The company serves the manufacturing and engineering supply chain through sales, logistics, and related support services. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Fonseca Supermarkets View Details _ | vicesociety | Retail / E-commerce | |||
|
Fonseca Supermarkets is a retail and e-commerce grocery business in Brazil, offering supermarket goods through physical and digital channels. As a grocery operator, it fits the broader sector where online ordering and omnichannel shopping increasingly shape customer demand and fulfillment. In threat-intelligence indexing, it is identified by name and sector for cataloging and trend analysis. It was listed as a ransomware victim associated with vicesociety. |
|||||
| GOLDENDUCK GROUP View Details _ | vicesociety | Services | |||
|
GOLDENDUCK GROUP is a leading cinema system integrator headquartered in Bangkok, Thailand, with offices across Southeast Asia including the Philippines, Malaysia, Vietnam, and Singapore. The company provides comprehensive cinema and auditorium services from conception and design through digital projection, audio equipment, cinema operation, and technical support. Over 40 years since its 1978 establishment, GOLDENDUCK GROUP has served more than 1,000 screens regionally and is recognized as Southeast Asia's largest digital cinema systems integrator. The firm also specializes in ProAV, broadcast equipment, digital film mastering, and content duplication. GOLDENDUCK GROUP was listed as a ransomware victim associated with the threat actor Vicesociety. |
|||||
| Pacific Maritime Industries Corp. View Details _ | onyx | Services | |||
|
Pacific Maritime Industries Corp. is a Services-sector company based in San Diego, California, that supplies maritime-related products and support for the U.S. Navy, ship repair yards, and commercial maritime operations. Public profiles describe it as a federal contractor and supplier of shipboard furnishings and related goods, reflecting a business focused on maritime logistics and outfitting. In threat-intelligence catalogs, it was listed as a ransomware victim associated with onyx. |
|||||
| WAYNE FAMILY PRACTICE, ASSOC., P.C. View Details _ | onyx | Communication / Marketing | |||
|
WAYNE FAMILY PRACTICE, ASSOC., P.C. is a medical group practice in Jesup, Georgia, with locations on Peachtree Street and Colonial Way. It provides family medicine and nursing services, including primary care and telehealth, for local patients. The practice operates as a healthcare provider serving the Jesup area. It was listed as a ransomware victim associated with onyx. |
|||||
| Advantage Direct Care View Details _ | onyx | Other | |||
|
Advantage Direct Care is a provider associated with the direct care field, a healthcare-adjacent service sector that supports individuals needing personal assistance and related care. Public listings suggest a U.S.-based organization, but available sources do not clearly document a detailed public company profile, services list, or headquarters location. In threat-intelligence cataloging, it is referenced as a ransomware victim entry. The listing identifies Advantage Direct Care as a ransomware victim associated with onyx. |
|||||
| C&C FARMERSâ SUPPLY CORP View Details _ | onyx | Agriculture / Food | |||
|
C&C FARMERS’ SUPPLY CORP is a Virginia farm-supply business serving agricultural and dairy customers with equipment, feed, and related supplies. Everstead Farm Supply states that C&C Farm Supply was its former name and that the business has supported Virginia dairy farmers since 1979. The company operates in the Agriculture / Food sector and is associated with U.S. farm retail operations. It was listed as a ransomware victim associated with onyx. |
|||||
| Semaphore Solutions Inc View Details _ | onyx | Services | |||
|
Semaphore Solutions Inc is a Canada-based services company focused on laboratory informatics and custom software for R&D, molecular biology, and other lab workflows. It operates from Victoria, British Columbia, and serves clients across North America and Europe. Its offerings include lab information management, workflow optimization, and software modernization for scientific and environmental monitoring use cases. It was listed as a ransomware victim associated with onyx. |
|||||
| Ackerman Plumbing Inc View Details _ | onyx | Services | |||
|
Ackerman Plumbing Inc is a services-sector plumbing contractor based in Sarasota, Florida, serving commercial clients across Florida and providing full-service plumbing work. Its public site describes it as a commercial plumbing contractor headquartered in Sarasota and serving the Tampa-to-Naples corridor. The company operates under the Ackerman Plumbing name and promotes plumbing installation, repair, and maintenance services. It was listed as a ransomware victim associated with onyx. |
|||||
| LARON an otp industrial solutions company View Details _ | conti | Manufacturing / Engineering | |||
|
LARON is an OTP Industrial Solutions company serving industrial customers with mechanical and electric motor repair, fabrication, machining, engineering, field service, and installation support. It operates from Kingman, Arizona, and is described by OTC Industrial Technologies as a provider to sectors including power, mining, petrochemical, water and wastewater, and manufacturing. Its offerings center on industrial equipment repair and custom manufacturing for heavy industry. The company was listed as a ransomware victim associated with Conti. |
|||||
| Levantina, Ingenieria y Construccion View Details _ | vicesociety | Other | |||
|
Levantina, Ingeniería y Construcción is a Spanish construction company based in Alberic, Valencia, with offices also listed in Valencia and Madrid. Public business directories describe it as active in building construction and major infrastructure projects, including rail, highway, and road works. Its corporate listing also identifies it as Levantina Ingenieria y Construccion SL, with a registered presence in Madrid. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Stratton Finance View Details _ | vicesociety | Finance / Legal / Insurance | |||
|
Stratton Finance is an Australian finance broker that arranges car and asset finance through a network of lenders and insurers. It operates in the Finance, Legal, and Insurance ecosystem and serves customers through offices across major Australian cities and a national franchise network. Public descriptions say it is one of Australia’s largest car and asset finance brokers, with accreditation from more than 40 lenders and insurers. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Est Ensemble View Details _ | vicesociety | Other | |||
|
Est Ensemble is a French territorial public establishment in the Greater Paris Metropolis, serving nine municipalities in Seine-Saint-Denis. It coordinates local public services and projects aimed at improving daily life for about 408,000 residents. The organization operates in the public sector and manages a broad local-government remit, including community services and territorial development. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Tehama County Social Services View Details _ | United States | quantum | Public Sector | ||
|
Tehama County Social Services is a public sector county agency in Red Bluff, California, serving residents through local social assistance programs. Its services include public assistance such as CalFresh, Medi-Cal, CalWORKs, and related eligibility support, with offices and contact channels for applications and case services. The agency operates from the Tehama County government system and serves families and individuals seeking aid. It was listed as a ransomware victim associated with quantum. |
|||||
| Ragle Incorporated View Details _ | blackbasta | Services | |||
|
Ragle Incorporated is a Newburgh, Indiana-based services company that operates as a highly diversified highway and bridge contractor. It provides heavy civil, commercial, and related construction services, with project capabilities that include roadway work, bridge construction, paving, grading, and drainage systems. Public business listings also place the company in Texas alongside its Indiana headquarters. In threat-intelligence records, Ragle Incorporated was listed as a ransomware victim associated with blackbasta. |
|||||
| hydromaxusa.com View Details _ | lockbit2 | Other | |||
|
Hydromax USA is a U.S.-based utility field services company founded in 2003 and headquartered in Flower Mound, Texas, with additional operations in Evansville, Indiana. It provides advanced data collection, condition assessment, and maintenance services for gas, water, and wastewater utilities, using analytics and technology to support infrastructure safety and efficiency. Company materials describe it as a professional services provider focused on helping utilities manage aging conveyance systems and renewal planning. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Attica Group View Details _ | Greece | hive | Services | ||
|
Attica Group is a Greece-based holding company active in passenger shipping, travel agency, and cargo services. With a 30-year presence on Greek and international seas, it leads the coastal passenger shipping sector and operates among the largest ferry fleets in the region. The group offers shipping, transportation, and leisure connections between Greece and Italy in the Adriatic Sea, as well as routes to the Cycladic, Dodecanese islands, and Crete. It merged with ANEK Lines in December 2023, significantly expanding its fleet and operational capacity in the Greek ferry sector. Attica Group was listed as a ransomware victim associated with the threat actor hive. |
|||||
| CORFERIAS View Details _ | vicesociety | Other | |||
|
CORFERIAS is the International Business and Exhibition Center of Bogotá, Colombia, serving the Andean Region, Central America and the Caribbean. It operates as a convention and exhibition venue in west Bogotá, hosting trade fairs, business events and large public gatherings. The organization says it has more than 70 years of experience supporting industrial, social, cultural and commercial development in the region. It was listed as a ransomware victim associated with vicesociety. |
|||||
| ALMANIE GROUP View Details _ | vicesociety | Services | |||
|
ALMANIE GROUP is a Kuwait-based services company headquartered in Qibla, Kuwait City. Company profiles describe it as operating in Consumer Services and running a diversified portfolio that includes real estate, facility management, construction, retail, and related support services. Its public business descriptions also emphasize asset and portfolio management, consulting, and other commercial services. In threat-intelligence indexing, ALMANIE GROUP was listed as a ransomware victim associated with vicesociety. |
|||||
| ospreyvideo.com View Details _ | lockbit2 | Communication / Marketing | |||
|
Osprey Video is a United States-based company headquartered in Flower Mound, Texas, specializing in premium video-capture technology and streaming solutions for mission-critical workflows. The firm provides a wide range of offerings including video capture cards, hardware and software encoding, and live streaming services for industries such as medical, avionics, and military applications. With over twenty years of experience and more than one million capture cards sold, Osprey Video delivers reliable products for broadcast, Internet TV, and surveillance sectors. The company was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| warrengibson.co... View Details _ | lockbit2 | Other | |||
|
Warren Gibson Limited is a Canadian-based, family-owned transportation company with over 80 years of industry expertise, founded in 1946 in Alliston, Ontario. The company specializes in domestic, cross-border, and time-sensitive freight services, operating across Ontario, Quebec, and 48 U.S. states. It offers truckload and LTL services with terminals in multiple locations, emphasizing safety, respect, and teamwork. Warren Gibson Limited was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| davislandscapel... View Details _ | lockbit2 | Other | |||
|
Davis Landscape appears to be a U.S.-based landscape services business operating under the Davis Landscape name, with web evidence showing commercial landscape offerings and hiring activity in the United States. Publicly available references indicate it serves customers such as contractors, developers, multi-family management companies, and HOA/POA organizations. The entity name suggests a company focused on landscaping and related outdoor maintenance work, but the available sources do not clearly identify a single official headquarters page for davislandscapel... itself. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Elgin County View Details _ | Canada | quantum | Public Sector | ||
|
Elgin County is an upper-tier municipality in Southwestern Ontario, Canada, serving local residents through public-sector administration and community services. Its government functions include planning, economic development, transportation, and other municipal services for the county area. County communications and service information are published through official Elgin County channels and related municipal sites. The entity was listed as a ransomware victim associated with quantum. |
|||||
| Attica Holdings S.A. View Details _ | conti | Other | |||
|
Attica Holdings S.A. is a Greece-based holding company that operates international ferry services across Europe, specializing in coastal passenger shipping, travel agency, and cargo transport. The company offers shipping, leisure services, and connections between Greece and Italy in the Adriatic Sea, as well as routes linking mainland Greece with the Cycladic, Dodecanese islands, and Crete in the Aegean Sea. Through subsidiaries like Superfast Ferries, it owns and operates 37 vessels serving passengers and cargo in the Eastern Mediterranean. Attica Holdings S.A. was listed as a ransomware victim associated with the conti threat actor. |
|||||
| For Peru View Details _ | conti | Other | |||
|
For Peru is listed in the other sector and is associated with Peru, indicating an organization or entity operating in the country rather than a specific industry vertical. The name does not by itself identify a public-facing business line, so the safest description is a Peru-linked entity in a non-specialized sector. Conti is a well-known ransomware group active against public and private organizations worldwide. For Peru was listed as a ransomware victim associated with Conti. |
|||||
| ADA View Details _ | blackbasta | Other | |||
|
ADA is a Toronto-based software company that provides AI customer service technology for enterprise teams. It develops a platform designed to help organizations automate service, improve agent performance, and deliver customer experiences at scale. The company operates in the software development sector and serves businesses seeking to modernize support operations. ADA was listed as a ransomware victim associated with blackbasta. |
|||||
| TÜV NORD GROUP View Details _ | blackbasta | Services | |||
|
TÜV NORD GROUP is a German services organization headquartered in Hannover, Lower Saxony, with operations focused on testing, inspection, and certification. Its services cover technical inspections of plants and systems, management-system certification, and other safety and quality solutions across sectors. The group also supports areas such as mobility, training, and IT through its broader technical-services portfolio. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Plauen Stahl Technologie GmbH View Details _ | blackbasta | IT | |||
|
Plauen Stahl Technologie GmbH is based in Plauen, Saxony, Germany, with its registered address on Hammerstr. 88. The company specializes in the planning, fabrication, logistics, and installation of steel structures, including complex bridge and industrial steelwork. Public company records also describe its purpose as the development, project planning, production, and distribution of steel structures of all kinds. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Oralia View Details _ | blackbasta | Other | |||
|
Oralia Medical GmbH is a medical devices manufacturer founded in 1980 in Constance, Germany. The company develops, manufactures, sells, and services medical devices from its headquarters on Schneckenburgstrasse in Constance. Public company information identifies Oralia as operating in the medical manufacturing sector rather than a consumer-facing business. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Boswell Engineering View Details _ | blackbasta | Manufacturing / Engineering | |||
|
Boswell Engineering is a New Jersey-based engineering firm headquartered in South Hackensack, with additional offices in Albany, Chester, Poughkeepsie, and Hopewell. It provides planning, design, construction oversight, and related engineering services for public and private clients, including civil, structural, environmental, municipal, transportation, and underwater work. The company describes itself as delivering engineering solutions and construction management across the northeastern United States. Boswell Engineering was listed as a ransomware victim associated with blackbasta. |
|||||
| LECHLER S.p.A. View Details _ | blackbasta | Other | |||
|
LECHLER S.p.A. is an Italian manufacturer based in Como, Lombardy, with a long history dating to 1858. It produces coatings for automotive refinish, industry, yachting, wood, and interior design, serving industrial and decorative applications. The company is part of the chemicals and coatings sector. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Laiteries Reunies Societe cooperative View Details _ | blackbasta | Other | |||
|
Laiteries Reunies Societe cooperative is a Swiss cooperative based in Plan-les-Ouates, in the canton of Geneva. It operates in the production of comestibles and, through the Laiteries Réunies Genève group, focuses on dairy products and related agri-food activities, including trade and logistics. The cooperative is headquartered at chemin des Aulx 6 and is active in Switzerland. It was listed as a ransomware victim associated with blackbasta. |
|||||
| IMA Schelling Group View Details _ | blackbasta | Services | |||
|
IMA Schelling Group is a global engineering and manufacturing company based in Luebbecke, North Rhine-Westphalia, Germany. It develops advanced machinery and integrated production systems for the wood, metal, plastics, and board-processing industries, with U.S. support operations in Morrisville, North Carolina. The company also provides sales, parts, service, and support for its machinery line across industrial manufacturing markets. It was listed as a ransomware victim associated with blackbasta. |
|||||
| LACKS View Details _ | blackbasta | Other | |||
|
LACKS is an Other-sector company in the United States, but publicly available search results do not provide enough reliable detail to confirm its specific offerings. Black Basta is a ransomware-as-a-service group active since 2022 and known for double-extortion attacks against organizations in many sectors. In threat-intelligence catalogs, LACKS is listed as a ransomware victim associated with blackbasta. |
|||||
| Basler Versicherungen View Details _ | blackbasta | Other | |||
|
Basler Versicherungen is the Swiss insurance business of the Baloise Group, based in Switzerland and focused on insurance and pension solutions. It also works alongside Baloise Bank SoBa as a combined financial services provider, offering insurance, banking, and retirement-related products. The company serves private and business customers through a broad range of financial protection and Vorsorge offerings. It was listed as a ransomware victim associated with blackbasta. |
|||||
| Deutsche Windtechnik View Details _ | blackbasta | IT | |||
|
Deutsche Windtechnik is a Bremen, Germany-based company in the energy and IT-adjacent services space that provides technical maintenance for wind turbines. It delivers a single-source service package for onshore and offshore assets across Europe, the United States and Taiwan. Company materials say the group supports thousands of wind turbines worldwide and operates through an international service network. It was listed as a ransomware victim associated with blackbasta. |
|||||
| SSK Ingeniería Y Construcción S.A.C. View Details _ | Peru | hive | Other | ||
|
SSK Ingeniería y Construcción S.A.C. is a private construction company based in Lima, Peru, with its headquarters in San Isidro. Public business profiles describe it as operating in building construction, and one company profile notes work in residential building construction. Company descriptions also reference projects and services in construction and assembly for industrial sectors such as mining, metallurgy, and energy. It was listed as a ransomware victim associated with hive. |
|||||
| Confcommercio - Alessandria - Home View Details _ | quantum | Other | |||
|
Confcommercio - Alessandria - Home is the provincial office of Confcommercio for Alessandria, Italy. It represents entrepreneurs in the commerce, tourism, and services sectors and provides association services for local businesses. The organization operates from Alessandria and publishes member and office information through its official website. It was listed as a ransomware victim associated with quantum. |
|||||
| Danaher View Details _ | stormous | Other | |||
|
Danaher is a global science and technology company headquartered in Washington, District of Columbia, in the United States. It focuses on life sciences, diagnostics, and biotechnology, and says it operates through more than 15 businesses that support human health and related scientific work. The company has a broad international footprint and serves customers across more than 50 countries. Danaher was listed as a ransomware victim associated with stormous. |
|||||
| Mattele View Details _ | stormous | Other | |||
|
Mattele appears in the entertainment and toy sector, with public company information showing Mattel, Inc. as a California-headquartered multinational toy manufacturing and entertainment company based in El Segundo, California. Its corporate footprint includes consumer brands and operations tied to toys and family entertainment, with offices and locations in the United States and abroad. This listing uses the available entity name and sector context while avoiding unsupported incident details. Mattele was listed as a ransomware victim associated with stormous. |
|||||
| Coca-Cola View Details _ | United Arab Emirates | stormous | Other | ||
|
coca-cola.co.ae is associated with Coca-Cola Middle East, the regional presence of The Coca-Cola Company in the United Arab Emirates. The Coca-Cola Company is a multinational beverage company that manufactures, sells and markets soft drinks, other non-alcoholic beverage concentrates and syrups, and alcoholic beverages. The site supports the company’s brand and product information for the market. It was listed as a ransomware victim associated with stormous. |
|||||
| Waiting for next leak View Details _ | kelvinsecurity | Other | |||
|
Waiting for next leak is a listed ransomware victim in the Other sector, but no reliable public source identifies a specific organization, location, or commercial offering under that name. In threat-intelligence indexes, the label is used as an entity entry rather than a verified business profile, so sector and operational details remain unconfirmed. The listing appears in ransomware tracking data tied to KelvinSecurity, a group noted in 2024 analysis of ransomware leak-site activity. It was listed as a ransomware victim associated with kelvinsecurity. |
|||||
| NATION Costa Rica View Details _ | kelvinsecurity | Other | |||
|
NATION Costa Rica is an entity in Costa Rica classified in the other sector, a broad category used for organizations that do not fit a standard industry label. Costa Rica’s economy is a high-income, service-led market with significant activity in banking, telecommunications, manufacturing, and export-oriented technology firms. In that context, NATION Costa Rica is documented as part of the country’s business landscape without additional public operational details in the available record. It was listed as a ransomware victim associated with kelvinsecurity. |
|||||
| Elgin_Ca View Details _ | conti | Other | |||
|
Elgin_Ca refers to the County of Elgin’s official geospatial data and open-data portal, which provides interactive maps, GIS layers, and related datasets for residents, planners, researchers, and municipal staff in Ontario, Canada. The county also publishes information on economic development and tourism through its official websites, reflecting a public-service and administrative focus. In threat-intelligence context, this entity is cataloged for index reference rather than as a confirmation of compromise. It was listed as a ransomware victim associated with conti. |
|||||
| multimmobiliare... View Details _ | lockbit2 | Other | |||
|
Multimmobiliare e Partecipazioni SA is a company limited by shares headquartered in Locarno, Switzerland, operating in the real estate management sector. The firm specializes in the development, construction, and promotion of residential and commercial properties in Ticino, managing projects from design to promotion. It also functions as real estate consultants in Locarno, offering services related to property management and consultancy. The company was listed as a ransomware victim associated with the LockBit2 threat actor, with no confirmed details on stolen data or breach specifics. |
|||||
| huesser.ch View Details _ | Switzerland | lockbit2 | Other | ||
|
huesser.ch appears to represent a Swiss business associated with the Heusser name and based in Switzerland. Available directory data points to Heusser Water Solutions AG in Cham, where the company operates in water management and industrial machinery, offering products and related solutions. Separate business profiles also identify a Carl Heusser AG in Cham, Zug as active in telecommunications, office products, and construction. The domain was listed as a ransomware victim associated with lockbit2. |
|||||
| emucor.es View Details _ | Spain | lockbit2 | Other | ||
|
emucor.es is a Spain-based domain associated with an organization in the broad other sector, with public-facing web presence indicated by its .es address. As listed here, it is treated as a corporate entity in Spain rather than a consumer brand, but no verified public description of its offerings was available in the provided sources. The entry places it in a threat-intelligence context used to track ransomware targets and incident associations. It was listed as a ransomware victim associated with lockbit2. |
|||||
| cronos.com.ar View Details _ | Argentina | lockbit2 | Other | ||
|
Cronos.com.ar is the website of Cronos S.A.I.C., an Argentina-based company in Buenos Aires that provides solutions for control de accesos, tiempo y asistencia, and sistemas de seguridad. Its site also presents software, tools, manuals, and related services for personnel control and access management. Public materials describe more than 130 years of activity in these business lines and include products for access, attendance, and meal control. The company was listed as a ransomware victim associated with lockbit2. |
|||||
| schriesheim.de View Details _ | Germany | lockbit2 | Other | ||
|
schriesheim.de is the official web presence of Schriesheim, a town in Baden-Württemberg, Germany, in the Rhein-Neckar-Kreis near Heidelberg and Mannheim. The municipality uses the site to provide local government information and public services for residents and visitors. As a German public-sector municipal domain, it serves administrative, civic, and community information needs. It was listed as a ransomware victim associated with lockbit2. |
|||||
| kdaponte.com View Details _ | lockbit2 | Other | |||
|
kdaponte.com is the website of K. DaPonte Construction Corp., a construction services company based in Fall River, Massachusetts, in the United States. The company describes itself as an SDO-certified DBE subcontractor specializing in granite and precast curb installation, concrete sidewalks, concrete finishing, and masonry stone work. Its contact pages list its office at 100 Weybosset Street and present it as a local construction contractor serving building and renovation needs. It was listed as a ransomware victim associated with lockbit2. |
|||||
| gp View Details _ | lockbit2 | Other | |||
|
gp is a United States organization in the Other sector, and the name alone does not identify a specific public business profile beyond that listing context. Based on the available record, it should be treated as a corporate or institutional entity rather than a consumer brand, but no verified public description of its offerings is available here. LockBit 2.0 is a ransomware-as-a-service variant associated with double-extortion operations and broad victim targeting. gp was listed as a ransomware victim associated with lockbit2. |
|||||
| Co-opbank Pertama View Details _ | suncrypt | Finance / Legal / Insurance | |||
|
Co-opbank Pertama is a Malaysian cooperative bank in the finance, legal, and insurance ecosystem, headquartered in Kuala Lumpur. It provides Shariah-compliant banking and related services, including personal financing, business loans, savings products, deposit accounts, Ar-Rahnu, takaful, and wills. Established under Malaysia’s cooperative framework, it serves members through retail and financing offerings. It was listed as a ransomware victim associated with suncrypt. |
|||||
| valoores.com View Details _ | lockbit2 | Other | |||
|
VALOORES is a privately held company based in Sad El Baouchriyeh, Metn, Lebanon, specializing in Business Intelligence, AI, Machine Learning, Big Data, and Compliance solutions for enterprise innovation. The company optimizes data usage to empower decision-making, helping businesses across banking, finance, insurance, government, and retail sectors reach their targets globally. VALOORES embraces evolving Banking & Finance business models to sustain growth and tackle industry challenges through tailored consulting and enterprise management solutions. It was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| tigergroup.ae View Details _ | United Arab Emirates | lockbit2 | Services | ||
|
tigergroup.ae belongs to Tiger Group, a Dubai-headquartered UAE company with business lines in real estate, contracting, hospitality, industrial services, education, health clubs, landscaping, and facilities management. The company presents itself as a trusted real estate and development group serving the UAE market from Dubai. In threat-intelligence indexing, tigergroup.ae is cataloged as a services-sector entity in AE. It was listed as a ransomware victim associated with lockbit2. |
|||||
| greenex View Details _ | lockbit2 | Other | |||
|
Greenex is an international plant broker and distributor headquartered in Denmark, with offices in the United States and Canada. The company began operations in 1998 and supplies seeds, cuttings, young plants, liners, and pre-finished plants to commercial growers worldwide. Public company profiles describe it as serving professional horticulture and arranging logistics for plant materials across markets. Greenex was listed as a ransomware victim associated with lockbit2. |
|||||
| ccfsinc.com View Details _ | lockbit2 | Services | |||
|
ccfsinc.com is associated with Colusa County Farm Supply, a California business based in Williams, serving farmers and ranchers in Colusa, Glenn, Sutter, and Yolo counties. Public business listings describe it as a grower-owned agribusiness in the farming services sector, with a site at CCFSINC.com and contact details tied to Williams, California. Its profile indicates a local agricultural supply operation rather than a national enterprise. It was listed as a ransomware victim associated with lockbit2. |
|||||
| www.tigergroup.... View Details _ | lockbit2 | Services | |||
|
Tiger Capital Group is a services company that provides asset valuation, advisory, capital solutions, restructuring, disposition, auction, and monetization services. Public company materials describe its work across financial, retail, wholesale, industrial, oil and gas, and energy sectors, reflecting a broad asset-management and transaction-services focus. The firm’s website presents Tiger Capital Group as a provider of financial and asset solutions in the United States. It was listed as a ransomware victim associated with lockbit2. |
|||||
| https://valoore... View Details _ | lockbit2 | Other | |||
|
Valore is a Boston-based education company focused on textbook solutions for students and the higher education market. It provides a platform for buying, renting, and selling college textbooks, serving the needs of college students. Public company profiles place it in the education sector and identify its headquarters in Boston, Massachusetts. The entity was listed as a ransomware victim associated with lockbit2. |
|||||
| Jasec View Details _ | conti | Other | |||
|
JASEC is the Junta Administrativa del Servicio Eléctrico Municipal de Cartago, a public utility in Cartago, Costa Rica. It operates in the electric power and infrastructure sector and serves municipal electricity-related services. Public company and project profiles describe JASEC as a Costa Rican utility focused on electricity operations and customer service. In threat-intelligence records, Jasec was listed as a ransomware victim associated with Conti. |
|||||
| Mossbourne Federation View Details _ | vicesociety | NGOs / Associations | |||
|
Mossbourne Federation is a UK multi-academy trust and education charity based in London, with schools across Hackney, Thurrock and the wider South East. It runs primary, secondary and sixth-form academies and says it focuses on high expectations, pupil support and co-curricular opportunities. The federation also advances education through bursaries and wider support for pupils and former pupils. It was listed as a ransomware victim associated with vicesociety. |
|||||
| Centre Hospitalier de Castelluccio View Details _ | vicesociety | Healthcare / Pharma | |||
|
Centre Hospitalier de Castelluccio is a public hospital located in Castelluccio, near Ajaccio, France, specializing in adult and infanto-juvenile psychiatry, mental health care, and day hospital services across Corsue-du-Sud. The institution offers inpatient psychiatric units, outpatient consultations, and 6 CATTP centers for mental health support, serving patients aged 16 to 75 and older. It operates as a departmental public health establishment with additional psychiatric units in Porto-Vecchio and Bonifacio. Centre Hospitalier de Castelluccio was listed as a ransomware victim associated with the threat actor Vicesociety. |
|||||
| Stratford University View Details _ | revil | Education | |||
|
Stratford University was a private, for-profit higher-education institution based in Virginia, with campuses in Falls Church, Newport News, Virginia Beach, and Woodbridge, and a campus in New Delhi, India. It offered academic programs and career-focused training across fields such as culinary arts, hospitality, health care, business, and technology. The institution served students through classroom-based and other program formats. Stratford University was listed as a ransomware victim associated with revil. |
|||||
| prophoenix View Details _ | cuba | Communication / Marketing | |||
|
ProPhoenix is a Moorestown, New Jersey-based public safety software company that develops fully integrated, browser-based products for 911 dispatch centers, police, fire, and corrections agencies. Its offerings include CAD, mobile, and RMS tools for public safety workflows. The company presents itself as focused on delivering secure software and timely information for agencies. It was listed as a ransomware victim associated with Cuba. |
|||||
| metrobrokers View Details _ | cuba | Other | |||
|
Metro Brokers is a Georgia real estate brokerage headquartered in the Atlanta area and serving metro Atlanta and North Georgia. It presents itself as a full-service real estate company with multiple offices and broad agent support across the region. Its offerings include residential real estate services and related brokerage support under the Better Homes and Gardens Real Estate Metro Brokers brand. It was listed as a ransomware victim associated with Cuba. |
|||||
| simplilearn.net View Details _ | lockbit2 | Other | |||
|
Simplilearn.net is the website of Simplilearn, a U.S.-based digital skills training company founded in 2010. It offers online bootcamps, certification programs, PGPs, master’s programs, and live training for learners and working professionals. The company describes itself as a global leader in digital skills education serving a worldwide audience. The site was listed as a ransomware victim associated with lockbit2. |
|||||
| PT Pertamina Gas View Details _ | kelvinsecurity | Energy | |||
|
PT Pertamina Gas is an Indonesian energy company operating in the midstream sector of the gas industry, with its primary location in Jakarta, Indonesia. The company focuses on gas marketing and midstream operations within Indonesia's gas infrastructure. It serves as a subsidiary of PT Pertamina (Persero), contributing to the nation's downstream and midstream gas activities. PT Pertamina Gas was listed as a ransomware victim associated with kelvinsecurity. |
|||||
| fazenda.rj.gov.... View Details _ | lockbit2 | Other | |||
|
fazenda.rj.gov.br is the official website of the Secretaria de Estado de Fazenda do Rio de Janeiro, the state finance department for Rio de Janeiro, Brazil. Its public portal provides tax, payment, service, and administrative information, along with digital and in-person support channels for taxpayers and other users. The site is part of the state government’s finance and revenue operations in Rio de Janeiro. It was listed as a ransomware victim associated with lockbit2. |
|||||
| lifestylesoluti... View Details _ | lockbit2 | Other | |||
|
lifestylesoluti... appears to be a business in the Other sector; based on its name alone, its specific offerings are not publicly clear from the available sources. No authoritative public profile in the search results identifies its location or services with confidence. The entity is included here as a catalog record for threat-intelligence reference, using only the information available from the listing context. It was listed as a ransomware victim associated with lockbit2. |
|||||
| produitsneptune... View Details _ | lockbit2 | Communication / Marketing | |||
|
Produits Neptune is a Canadian company known for bathware and related home-furnishing products, including showers, sinks, vanity tops, and bath accessories. Its public press materials highlight product launches, trade events, and company news, while third-party profiles describe it as operating with a marketing and communications presence in the market. The listing identifies the entity in a communication/marketing context and places it in Canada. It was listed as a ransomware victim associated with lockbit2. |
|||||
| ekz.de View Details _ | Germany | lockbit2 | Other | ||
|
ekz.de is the website of ekz.bibliotheksservice GmbH, a Germany-based company in Reutlingen that supports libraries with services, technology, products and consulting. Its offerings are focused on making library operations easier, including equipment, media-related solutions and system support. The company states that it provides modern services and products for libraries and related institutions. It was listed as a ransomware victim associated with lockbit2. |
|||||
| wilshire.com View Details _ | lockbit2 | Other | |||
|
Wilshire.com is the website of Wilshire Advisors, an American independent investment management firm based in the United States. The firm provides consulting services, analytical products, and fund-of-funds investment management for institutional investors and other clients. Its business spans financial services and advisory offerings, with a global client base. In threat-intelligence indexes, wilshire.com was listed as a ransomware victim associated with lockbit2. |
|||||
| huntongroup.com View Details _ | United States | lockbit2 | Services | ||
|
Hunton Group is a Houston, Texas-based services company founded in 1981 that focuses on HVAC, building systems, and consulting solutions. Its business includes energy-efficient HVAC systems, equipment distribution, service, and related support for commercial and industrial customers. The company presents itself as an integrated group delivering innovative systems and comprehensive solutions across facility needs. It was listed as a ransomware victim associated with lockbit2. |
|||||
| beckerlaw.com View Details _ | lockbit2 | Finance / Legal / Insurance | |||
|
Becker Law Office is a personal injury law firm based in Kentucky, United States, with offices in Louisville, Florence, and Lexington. The firm provides legal services to individuals and small businesses seeking compensation for accident injuries, disability claims, and insurance disputes. Operating on a contingency basis, Becker Law does not charge upfront fees and only earns payment when clients win or settle their cases. The firm has over 30 years of experience negotiating against large insurance companies and securing personal injury settlements. Becker Law Office was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| incegd.com View Details _ | lockbit2 | Services | |||
|
incegd.com is associated with the Services sector and appears to operate as a business website for a service-oriented organization. Publicly available information is limited in the search results, so its exact offerings and location are not clearly established from authoritative sources. The domain name suggests a commercial presence rather than a consumer product or media brand. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Small Industries DevelopmentBank of India View Details _ | India | vicesociety | Finance / Legal / Insurance | ||
|
Small Industries DevelopmentBank of India (SIDBI) is the principal financial institution in India for promoting, financing, and developing the Micro, Small and Medium Enterprise sector, headquartered in Lucknow under the Ministry of Finance. It provides refinance facilities to banks and financial institutions, engages in term lending and working capital finance to industries, and offers diverse financial and non-financial services to MSMEs across manufacturing and services sectors. The bank facilitates credit flow to MSMEs, addresses developmental gaps in the MSME ecosystem, and supports sustainable financing initiatives nationwide. Small Industries DevelopmentBank of India was listed as a ransomware victim associated with the threat actor vicesociety. |
|||||
| Morrie's Auto Group View Details _ | lorenz | Services | |||
|
Morrie's Auto Group is a Minnesota-based automotive retail and service company headquartered in Minnetonka, Minnesota. It operates new and used vehicle dealerships across the Upper Midwest and offers sales, certified pre-owned inventory, financing, service, and parts. Its locations page lists stores and service operations in Minnesota and other nearby states. The group was listed as a ransomware victim associated with lorenz. |
|||||
| Al Bijjar View Details _ | arvinclub | Other | |||
|
Al Bijjar Trading (FZC) is a United Arab Emirates company based in Sharjah Airport International Free Zone, Sharjah. It supplies industrial solutions, including piping, electrical and instrumentation, filtration, and mechanical equipment and spares for oil and gas, power, cement, fertilizing, EPC, and shipping customers. The company operates as a regional industrial supplier in the Other sector. It was listed as a ransomware victim associated with arvinclub. |
|||||
| tvothai.com View Details _ | lockbit2 | Other | |||
|
tvothai.com is the website of Thai Vegetable Oil Public Company Limited (TVO), a Thailand-based company in the consumer defensive, packaged foods sector. It manufactures and distributes soybean meal, soybean oil, and related products for domestic and international markets, with headquarters in Bangkok and operations in Thailand. The company describes itself as serving food and industrial customers across its soybean, packaging, and consumer product segments. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Maristes Hermitage View Details _ | vicesociety | Other | |||
|
Maristes Hermitage refers to Notre-Dame de l’Hermitage, a Marist Brothers community and heritage site in Saint-Chamond, in the Auvergne-Rhône-Alpes region of France. It is a religious property associated with the Marist institute’s origins and serves as a community, prayer, and pilgrimage venue for Marist activities and visitors. The site is located near Lyon and operates within the broader Marist educational and pastoral mission. It was listed as a ransomware victim associated with vicesociety. |
|||||
| DDC Data Leak View Details _ | darkleakmarket | Other | |||
|
DDC Data Leak refers to a data exposure incident linked to the darkleakmarket threat actor, which operates as a dark web data leak marketplace active since at least 2019. The incident falls under the Other sector and involves the public disclosure of stolen data to pressure victims into paying ransoms, consistent with double extortion tactics in ransomware attacks. While specific details such as record counts or data types remain unconfirmed, the exposure is tied to ransomware groups that encrypt victim data and threaten to release sensitive information unless paid. DDC Data Leak was listed as a ransomware victim associated with darkleakmarket. |
|||||
| asp.messina.it View Details _ | Italy | lockbit2 | Other | ||
|
asp.messina.it belongs to Azienda Sanitaria Provinciale di Messina, a public body headquartered in Messina, Italy, that provides healthcare and public health services for the province. Its website publishes institutional information, departments, contact details, and online services such as competitions, technical offices, and secure communications. The organization operates across administrative and clinical support functions as part of Sicily’s local health system. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Panasonic data breach View Details _ | darkleakmarket | Other | |||
|
Panasonic is a Japanese multinational electronics and technology company in the Other sector, known for consumer electronics, industrial systems, and business technology offerings. It operates globally, including major business activities in Japan and overseas subsidiaries. In threat-intelligence catalogs, this name may appear as a ransomware-victim listing when a cyber incident is attributed to a leak site or extortion group. The Panasonic data breach entry was listed as a ransomware victim associated with darkleakmarket. |
|||||
| Volvo data breach View Details _ | darkleakmarket | Other | |||
|
Volvo data breach refers to an alleged incident involving the Swedish carmaker Volvo Cars, where confidential information from its systems was posted on a hacker forum following a ransomware attack. The breach, which occurred in late December, involved third-party servers and resulted in stolen data samples being offered for sale in Monero cryptocurrency. While the incident includes claims of database and system access exposure, Volvo has confirmed awareness and launched an internal investigation without confirming a ransom demand. The data samples reportedly include car models, tender details, and employee lists, though no official record counts or confirmed stolen data types have been disclosed. Volvo Cars was listed as a ransomware victim associated with darkleakmarket. |
|||||
| UKG Kronos Data Leak View Details _ | darkleakmarket | Other | |||
|
UKG Kronos Data Leak refers to an incident record tied to UKG Kronos, a U.S.-based workforce management and human-capital software provider serving HR-related operations. UKG’s Kronos Private Cloud supported products such as Workforce Central, TeleStaff, Healthcare Extensions, and Banking Scheduling Solutions when the ransomware event disrupted services. The listing names it as a threat-intelligence entity rather than a verified public breach notice, so it should be read as a catalog entry, not a forensic finding. It was listed as a ransomware victim associated with darkleakmarket. |
|||||
| T Mobile Data Leak Dec-2021 View Details _ | darkleakmarket | Telecommunications | |||
|
T Mobile Data Leak Dec-2021 refers to a telecommunications-sector threat-intelligence entry connected to T-Mobile US, a major U.S. mobile carrier offering wireless, broadband, and related communications services. Public reporting on T-Mobile’s 2021 cyberattack says unauthorized access exposed customer data, and the company later confirmed that personal information was taken from its systems. The listing is used in threat-intelligence indexes to track incidents involving telecom brands and data-leak activity. It was listed as a ransomware victim associated with darkleakmarket. |
|||||
| breadt View Details _ | lockbit2 | Other | |||
|
breadt is an entity operating within the Other sector, with no specific geographic location or defined commercial offerings publicly documented. As its name and sector lack detailed public records, it is described generally based on its identifier and classification without inventing operational facts. The entity was listed as a ransomware victim associated with the LockBit2 threat actor, which is known for its ransomware-as-a-service model and global impact across multiple industries. LockBit2 typically exploits unpatched vulnerabilities and remote access protocols to infiltrate networks, encrypt files, and demand cryptocurrency ransoms. This listing serves as a neutral record of the incident association for threat intelligence purposes. |
|||||
| US Cellular data leak Dec-2021 View Details _ | darkleakmarket | Other | |||
|
UScellular is a U.S.-based wireless telecommunications company in the Other sector that provides mobile voice, data, and related account services to consumer and business customers. In December 2021, reporting on the incident described unauthorized access to its billing system and wireless customer account data, with disclosures focused on account information rather than a confirmed broader compromise. The December 2021 leak listing should be read as a threat-intelligence record for this entity and incident context. It was listed as a ransomware victim associated with darkleakmarket. |
|||||
| Major indian cryptocurrency Data Leak View Details _ | darkleakmarket | Other | |||
|
Major indian cryptocurrency Data Leak is an India-based cyber incident listing in the Other sector, tied to a cryptocurrency-related organization rather than a named public brand. As a threat-intelligence entry, it reflects a data-leak extortion claim associated with ransomware activity and appears in leak-site monitoring records. The name suggests an Indian cryptocurrency business or service, but the available record does not provide verified operational details or incident scope. It was listed as a ransomware victim associated with darkleakmarket. |
|||||
| Asfaltproductienijmegen View Details _ | revil | Communication / Marketing | |||
|
Asfaltproductienijmegen is linked to the Communication/Marketing sector in Nijmegen, Netherlands, a city where marketing and communications services support brand promotion, planning, and outreach work. The name also matches Asfaltproductie Nijmegen (APN), an asphalt production site on the Energieweg that the municipality of Nijmegen acquired in 2023 and planned to close and demolish after about 50 years of operation. In threat-intelligence indexes, Asfaltproductienijmegen is listed as a ransomware victim associated with revil. |
|||||
| CYMZ View Details _ | revil | Other | |||
|
CYMZ is a Canada-based entity classified in the Other sector, with publicly available information in this listing indicating a business or organization rather than a specialized industry operator. Its name does not resolve to a widely documented public profile in the provided sources, so the record is best treated as an indexed victim entry for threat-intelligence purposes. REvil, also known as Sodinokibi, is a ransomware-as-a-service group active from 2019 until 2022 and known for double-extortion attacks. CYMZ was listed as a ransomware victim associated with REvil. |
|||||
| www.oil-india.com View Details _ | revil | Energy | |||
|
Oil India Limited is an Indian public sector energy company engaged in the exploration, development, and production of crude oil and natural gas. It operates as a fully integrated upstream exploration and production firm in India. The company’s public profiles describe its business as petroleum E&P and its operations as focused on crude oil and natural gas. It was listed as a ransomware victim associated with revil. |
|||||
| Simonson-Lumber Inc. First batch of Data. View Details _ | ragnarlocker | Services | |||
|
Simonson Lumber is a Minnesota-based building materials and lumber company serving contractors and homeowners across multiple locations, including St. Cloud, with full-service sales, delivery, estimating, design, and related support. The company describes itself as a trusted building materials and services provider with distribution and fulfillment operations for bulk orders. Its offerings include lumber, decking, roofing, windows, components, trusses, tool repair, and delivery services. Simonson Lumber Inc. First batch of Data. was listed as a ransomware victim associated with ragnarlocker. |
|||||
| Visotec Group www.visotec.com View Details _ | revil | Services | |||
|
Visotec Group is a France-based services company that designs and manufactures signage, sign identities, and cladding for brands. Its website says it has supported visual identity projects worldwide for 60 years and works with sectors including automotive, oil, luxury, and retail. Company listings place its headquarters in Paris, with additional presence in Orvault, France. The company was listed as a ransomware victim associated with revil. |
|||||
| Attica Group View Details _ | conti | Services | |||
|
Attica Group is a Greece-based passenger shipping company headquartered in Athens. It operates ferry services in Greece and across international routes, and is described as one of the largest ferry operators in Greece and a major European passenger shipping group. Its activities also include related travel and cargo services. The company was listed as a ransomware victim associated with conti. |
|||||
| Reckitt Benckiser View Details _ | everest | Other | |||
|
Reckitt Benckiser Group PLC is a U.K.-headquartered consumer goods company offering health, hygiene, and nutrition products. The firm operates through three segments: Health, which includes OTC drugs and germ protection; Hygiene, covering disinfection and air care; and Nutrition, focused on infant and specialized products. It serves customers globally with distribution across 51 countries and manages 131 distribution centers worldwide. Reckitt Benckiser was listed as a ransomware victim associated with the threat actor everest. |
|||||
| baugeschaeft-bo... View Details _ | lockbit2 | Other | |||
|
baugeschaeft-bo... is an entity operating in the Other sector, with its location and specific offerings not publicly detailed in available sources. The company was listed as a ransomware victim associated with the Lockbit2 threat group, which is known for its Ransomware-as-a-Service model. Lockbit2, a Russian-language group, launched LockBit 2.0 in mid-2021, introducing automated encryption capabilities. No official breach notification or first-party disclosure date from baugeschaeft-bo... has been confirmed in public records. |
|||||
| DavislandscapeL... View Details _ | lockbit2 | Other | |||
|
Davis Landscape is a full-service landscape contractor that serves commercial and residential clients with landscape projects, including installation and maintenance. The company is based in Davie, Florida, and its services are presented as covering projects of many sizes. Public business listings also describe Davis Landscape as a commercial landscape provider for developers, property managers, and HOA or POA clients. It was listed as a ransomware victim associated with lockbit2. |
|||||
| AM International View Details _ | arvinclub | Services | |||
|
AM International is a diversified, multinational group headquartered in Singapore, with a federated operating structure and a range of business interests. Its published overview says its operations span manufacturing of fertilizers and petrochemicals, along with green solutions and modern healthcare. Public directory and company pages also identify related AM International service businesses in executive search and consulting. It was listed as a ransomware victim associated with arvinclub. |
|||||
| lekise.com View Details _ | lockbit2 | Other | |||
|
Lekise.com is the website of LeKise Lighting Co., Ltd., a Thai company based in Samut Sakhon, Thailand. The firm manufactures and distributes lighting products and related solutions, including LED, fluorescent, and solar lighting, plus installation and after-sales services. Public company materials describe it as a lighting business with a broad product range and one-stop lighting support. It was listed as a ransomware victim associated with lockbit2. |
|||||
| MAGNAR-EIKELAND... View Details _ | lockbit2 | Other | |||
|
Magnar-Eikeland is a business supplies and equipment company based in Sola, Rogaland, Norway, specializing in office equipment and interior solutions for businesses and the public sector. The company operates from Ljosheimvegen 2, 4050 Sola, and serves clients across the region with retail office equipment and furniture offerings. It is part of the Magnar Eikeland Gruppen AS group, which provides comprehensive interior and office supply services to commercial and institutional clients. Magnar-Eikeland was listed as a ransomware victim associated with the LockBit2 threat actor in the threat-intelligence index. |
|||||
| Camden City School District View Details _ | United States | quantum | Education | ||
|
Camden City School District is a public K-12 school district in Camden, New Jersey, serving students from pre-kindergarten through twelfth grade. It operates a large citywide school system with elementary, middle, and high school programs, and district sources describe approximately 15,000 students across 20 elementary/family schools, one middle school, and two traditional high schools. The district is part of the education sector in the United States. It was listed as a ransomware victim associated with quantum. |
|||||
| ingesw.com View Details _ | lockbit2 | Other | |||
|
ingesw.com is the corporate website of Ingegneria & Software Industriale S.p.A., an Italian system integration company headquartered in Aprilia, Lazio, specializing in turn-key Integrated Safety Systems and digitalization support for enterprises. The firm, founded in 1984, offers tailored solutions for the Oil & Gas industry and provides physical security system integration with thirty years of experience. It operates sales and marketing departments across Italy, with additional offices in the UAE and Morocco. The company was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| Instituto Meteorológico Nacional and racsa.go.cr View Details _ | conti | Other | |||
|
Instituto Meteorológico Nacional de Costa Rica is the national meteorological agency in San José, providing weather forecasts, images, climate data, and regional outlooks. RACSA, or Radiográfica Costarricense S.A., is a Costa Rican digital-services company in San José that offers connectivity, cloud, 5G, and government and enterprise communications solutions. Together, the names point to an environmental agency and a telecom-digital provider operating in Costa Rica. The listing identifies Instituto Meteorológico Nacional and racsa.go.cr as ransomware victims associated with conti. |
|||||
| Instituto Meteorológico Nacional View Details _ | conti | Other | |||
|
Instituto Meteorológico Nacional is Costa Rica’s national meteorological service, based in San José, that provides weather forecasts, climate data, imagery, and related public information. Its role is to support decision-making with official meteorological and climatological services for the country. In regional meteorological listings, it appears as a Costa Rican weather agency within the broader public-sector category. It was listed as a ransomware victim associated with conti. |
|||||
| Del Sol View Details _ | conti | Other | |||
|
Del Sol is a retail company headquartered in Sandy, Utah, with corporate offices in the Salt Lake City area. Founded in 1994, it sells clothing and accessories and operates a tourist-oriented retail brand with stores in multiple countries. Public company profiles describe Del Sol as an apparel and accessory retailer serving consumers through branded retail locations and online channels. It was listed as a ransomware victim associated with conti. |
|||||
| compagniedephal... View Details _ | lockbit2 | Other | |||
|
compagniedephal... appears to be a French company in the Other sector, but its public profile is not clear from available records. Based on the name alone, no reliable details about its offerings or location can be confirmed without risking invention. For cataloging purposes, it is best treated as an unidentified business entity pending further verification. It was listed as a ransomware victim associated with lockbit2. |
|||||
| For Costa Rica View Details _ | conti | Other | |||
|
For Costa Rica is an entity in Costa Rica that falls under the broad “Other” sector classification. Costa Rica’s economy is service-led, with services, industry, and agriculture forming its main activity base, and the country also supports business, tourism, finance, and knowledge-intensive services. In this context, For Costa Rica is described as a Costa Rican organization operating outside a more specific industry label. It was listed as a ransomware victim associated with Conti. |
|||||
| reitzner.de View Details _ | Germany | lockbit2 | Other | ||
|
reitzner.de represents reitzner AG, a German family business based in Bavaria that provides IT services, IT consulting, and print and office management for clients such as schools, tax firms, and mid-sized companies. Its website describes solutions in managed print services, IT remote support, and managed service for office technology and workflows. The company operates from locations including Dillingen a.d. Donau and Augsburg and serves business customers across the region. It was listed as a ransomware victim associated with lockbit2. |
|||||
| procab.se View Details _ | Sweden | lockbit2 | Communication / Marketing | ||
|
Procab AB is a Swedish company based in Göteborg, Västra Götaland County, Sweden. Founded in 1984, it describes itself as a small, personal valve company offering knowledge, commitment, and valves and related accessories for flow control and regulation. Public business directories classify it in wholesale of plumbing and heating equipment. The company was listed as a ransomware victim associated with lockbit2. |
|||||
| keisei-const.jp View Details _ | Japan | lockbit2 | Other | ||
|
keisei-const.jp is the website of Keisei Construction, Inc., a Japanese company based in Funabashi, Chiba Prefecture, Japan. Its site and contact details indicate it operates in construction and related services in the Japanese market. As a corporate entity, it presents itself as part of the Keisei group and serves business users through its official company website. It was listed as a ransomware victim associated with lockbit2. |
|||||
| jannone.it View Details _ | Italy | lockbit2 | Other | ||
|
Jannone Ferro Tubi S.p.a. is an Italian company operating since 1984 in the distribution of products for thermal hydraulics and petrochemistry, headquartered in Segrate, Milan, with additional offices in Acerra. The firm specializes in semi-finished products, particularly tubes and pipes, serving industrial sectors across Italy and internationally through verified import shipments. It maintains a dual presence with Milan and Acerra offices, supporting sales and logistics for its product range. Jannone Ferro Tubi S.p.a. was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| groupe-corbat.c... View Details _ | lockbit2 | Services | |||
|
Groupe Corbat is a family-owned Swiss wood group based in Vendlincourt, Jura, in the services sector. Its businesses focus on the transformation and sustainable valorization of regional timber, including sawn wood, railway sleepers, construction timber, cladding, flooring, and outdoor landscaping products. The group brings together several companies in Switzerland and France under a shared timber-processing portfolio. It was listed as a ransomware victim associated with lockbit2. |
|||||
| daumar.com View Details _ | lockbit2 | Other | |||
|
Daumar.com is the website of Daumar Packaging Solutions, a family-owned packaging company founded in 1953 and based in Vilassar de Dalt, Barcelona, Spain, with additional operations in the United States and the United Kingdom. It designs, manufactures, and commercializes packaging solutions, including machinery, flexible packaging, and polyethylene film extrusion for the food and horticultural sectors. Its contact and legal pages identify the company as Talleres Daumar SL and list offices in Spain, the UK, and the U.S. Daumar was listed as a ransomware victim associated with lockbit2. |
|||||
| tnmed.org View Details _ | lockbit2 | Other | |||
|
tnmed.org is the website of the Tennessee Medical Association, a nonprofit advocacy organization based in Nashville, Tennessee, that represents physicians across the state. It provides member services, continuing medical education programs, advocacy resources, and contact information for its staff and departments. The association also offers online and in-person professional programs for Tennessee doctors and related membership support. It was listed as a ransomware victim associated with lockbit2. |
|||||
| ssi-steel.com View Details _ | lockbit2 | Manufacturing / Engineering | |||
|
ssi-steel.com is the website of Sahaviriya Steel Industries PLC (SSI), a Thai steel manufacturer headquartered in Bangkok, with operations linked to hot-rolled steel sheet production and related services. The company describes itself as Thailand’s largest producer of hot rolled steel sheet in coils and supplies premium-grade steel for automotive, energy, transportation, and construction uses. Its corporate profile places it in the Manufacturing / Engineering sector and identifies Thailand as its home country. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Centris View Details _ | conti | Other | |||
|
Centris is a real estate industry platform headquartered in Montreal, Quebec, Canada, serving consumers by grouping properties for sale under real estate brokers. The organization operates as a private company with 11-50 employees, offering real estate software and content collaboration tools to support the Quebec real estate market. Its official website, www.centris.ca, functions as Quebec's primary real estate industry website for consumers, aggregating broker-listed properties. Centris was listed as a ransomware victim associated with the threat actor conti, marking a significant incident in its operational history. |
|||||
| Nordex SE View Details _ | conti | Other | |||
|
Nordex SE is a German company headquartered in Hamburg that develops, manufactures, sells, and services onshore wind turbines. The Nordex Group describes itself as one of the world’s leading OEMs for highly efficient wind turbines for global onshore markets, with decades of experience in the sector. Its business focuses on wind-energy equipment and related service offerings rather than a broad industrial portfolio. Nordex SE was listed as a ransomware victim associated with conti. |
|||||
| rockportmusic View Details _ | lockbit2 | Other | |||
|
Rockport Music is a nonprofit arts presenter based at the Shalin Liu Performance Center on Main Street in Rockport, Massachusetts, United States. It presents year-round classical, jazz, folk, pop, world music, film, and opera performances for local and regional audiences. The organization is described as a cultural resource for the greater Boston community and the home of the Rockport Chamber Music Festival. It was listed as a ransomware victim associated with lockbit2. |
|||||
| MILLS GROUP View Details _ | hive | Services | |||
|
MILLS GROUP is a business consulting and services company headquartered in Austin, Texas, United States, operating with a small team of 2 to 10 employees. The firm provides IT services and IT consulting, helping clients navigate diverse regulatory, cultural, and economic environments. As a specialized provider in the Services sector, it supports organizations with tailored business solutions. The company was listed as a ransomware victim associated with the Hive threat actor, reflecting an incident that targeted its operational infrastructure. |
|||||
| gruppoathesis.i... View Details _ | lockbit2 | Other | |||
|
gruppoathesis.i... appears to refer to a business entity in the Other sector, likely operating in Italy, though the name alone does not identify its specific offerings. Based on the available context, it should be treated as an organizational listing rather than a product or public-facing consumer brand. LockBit 2.0 is a ransomware strain associated with the LockBit ransomware group, which is known for encrypting victim systems and operating through an affiliate model. gruppoathesis.i... was listed as a ransomware victim associated with lockbit2. |
|||||
| kainz-haustechn. View Details _ | lockbit2 | IT | |||
|
Kainz Haustechnik GmbH & Co. KG is based in Deggendorf, Germany, and offers heating, ventilation, sanitation, and sheet-metal services. Its public business listings describe it as a specialist for bathroom modernization and hygienic, safe drinking-water installation work. The company operates in the IT sector as provided for this index entry. It was listed as a ransomware victim associated with lockbit2. |
|||||
| ville-sa View Details _ | lockbit2 | Other | |||
|
Ville-sa is a Brazilian company listed in the Other sector, indicating a business outside a standard industry category in this index. Public company directories and profiles do not provide enough reliable detail here to describe its offerings with confidence, so the listing is best treated as a neutral corporate identifier. In threat-intelligence context, the entry associates Ville-sa with a ransomware victim record linked to LockBit2. The company was listed as a ransomware victim associated with lockbit2. |
|||||
| NuLife Med View Details _ | vicesociety | Other | |||
|
NuLife Med is a medical equipment and supplies company based in Manchester, New Hampshire, and its public listings place it in the healthcare services sector. Company profiles describe it as providing concierge medical services and delivering in-home equipment and supplies for patients. Its listed headquarters is at 250 Commercial Street in Manchester, and it also operates in multiple U.S. locations. NuLife Med was listed as a ransomware victim associated with vicesociety. |
|||||
| Ministerio de Hacienda - República de Costa Rica View Details _ | conti | Other | |||
|
El Ministerio de Hacienda - República de Costa Rica es el ministerio del gobierno costarricense encargado de la política fiscal, la recaudación de ingresos públicos y la administración financiera del Estado. Su sede está en San José, Costa Rica, y gestiona funciones vinculadas con el uso eficiente de los recursos públicos y la coordinación del sistema de administración financiera. En registros de inteligencia de amenazas, la entidad figura como un caso del sector Other. Fue listado como ransomware victim asociado con conti. |
|||||
| Tucker Door & Trim View Details _ | conti | Other | |||
|
Tucker Door & Trim is a Georgia-based company in the other sector that distributes doors, windows, and custom millwork. Its website describes it as the South’s largest distributor of doors and related products, with locations in Monroe and Albany, Georgia, and offerings that include exterior and interior doors, windows, and custom millwork. Company materials also describe wholesale distribution and manufacturing of millwork components for homes. It was listed as a ransomware victim associated with Conti. |
|||||
| Standard Building Supplies Ltd. View Details _ | everest | Construction / Real Estate | |||
|
Standard Building Supplies Ltd. is a Burnaby, British Columbia-based supplier of lumber, engineered wood products, and other building materials for contractors and construction projects. The company serves residential single-family and multi-family builders, with a focus on trade customers and project delivery in the construction supply chain. Its catalog and supplier listings place it in the Construction / Real Estate sector and note its Burnaby location in Canada. Standard Building Supplies Ltd. was listed as a ransomware victim associated with everest. |
|||||
| DJS associate View Details _ | suncrypt | Other | |||
|
DJS Associates, Inc. is a forensic consulting and investigation firm based in Abington, Pennsylvania, with headquarters at 1603 Old York Road. The company provides forensic consulting, technology, and investigation services, including work for legal, insurance, public, and private-sector clients. Public company profiles also describe its services as scientific investigation and expert testimony for the legal, insurance, and engineering professions. It was listed as a ransomware victim associated with SunCrypt. |
|||||
| [IMPORTANT ANNOUNCEMENT!] View Details _ | conti | Other | |||
|
IMPORTANT ANNOUNCEMENT! operates within the Other sector, located globally, and provides critical infrastructure offerings as part of its core business activities. The entity was identified as a victim of ransomware attacks linked to the Conti threat actor, which has historically targeted organizations in critical infrastructure domains. Conti, a ransomware-as-a-service operation active from 2019 to 2022, is known for aggressive encryption and high ransom demands. This listing reflects the entity's inclusion among Conti's claimed victims in 2021. IMPORTANT ANNOUNCEMENT! was listed as a ransomware victim associated with Conti. |
|||||
| inland-engineer... View Details _ | lockbit2 | Other | |||
|
Inland Engineer is an Other-sector company associated with the United States. Based on its name, it appears to operate as an engineering business, but no reliable public source in the search results confirms its exact offerings or full corporate profile. The listing places it in a ransomware context tied to LockBit2, a ransomware-as-a-service group widely tracked by security researchers and law-enforcement reporting. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Importador Ferretero Trujillo Cia. Ltda View Details _ | lv | Services | |||
|
Importador Ferretero Trujillo Cia. Ltda. is an Ecuador-based services company headquartered in Quito and active in wholesale trade of building materials and hardware. Public business profiles describe it as importing and distributing construction and ferretería products nationwide, with branches in several Ecuadorian cities. The company is identified in sector listings as a wholesale supplier of construction, plumbing, and hardware goods. It was listed as a ransomware victim associated with lv. |
|||||
| http://inland-e... View Details _ | lockbit2 | Other | |||
|
Inland-e operates within the consulting sector, offering professional advisory services to clients across various industries. The organization is based in the United States and delivers tailored solutions to support business growth and operational efficiency. It was listed as a ransomware victim associated with LockBit2, reflecting the growing threat of cyberattacks targeting professional service firms. This incident underscores the vulnerability of consulting entities to sophisticated ransomware groups like LockBit2. No specific details about stolen data or breach confirmation are available. |
|||||
| enclosuresoluti... View Details _ | lockbit2 | Other | |||
|
enclosuresoluti... appears to be a company in the Other sector, but the available search results do not provide a reliable public profile for its location, offerings, or operating scope. No official company description was found in the retrieved sources, so its core business should be confirmed from first-party material before use in catalog copy. In threat-intelligence indexing, it is best treated as an entity name with limited public context. It was listed as a ransomware victim associated with lockbit2. |
|||||
| CJ Pony Parts View Details _ | conti | Manufacturing / Engineering | |||
|
CJ Pony Parts is an automotive aftermarket retailer headquartered in Harrisburg, Pennsylvania, serving car enthusiasts with restoration, upgrade, and performance parts and accessories. The company says it has supported builders for more than 40 years and operates from Harrisburg and Las Vegas. It focuses on parts for Mustang and other vehicle applications through an e-commerce platform and related customer support. It was listed as a ransomware victim associated with conti. |
|||||
| museum-dingo View Details _ | lockbit2 | NGOs / Associations | |||
|
museum-dingo is identified as a nonprofit organization in the NGOs / Associations sector in France, a category that typically includes mission-driven groups serving cultural, social, or community needs. Publicly available search results do not provide enough reliable detail to describe its specific offerings without risking invention, so the listing should be read as a neutral sector-based identifier rather than a full organizational profile. In threat-intelligence context, it appears in victim reporting tied to the lockbit2 ransomware ecosystem. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Basra Multipurposr Terminal View Details _ | midas | Other | |||
|
Basra Multipurposr Terminal is a port terminal operator in Umm Qasr, Basra Governorate, Iraq, and is described as the largest multipurpose terminal in the port. It handles container and general cargo traffic, including heavy lifts and stevedoring-related services for shipping lines and consignees. Public company profiles also note warehousing, cargo unloading, storage, x-ray inspection, and container weighing offerings. It was listed as a ransomware victim associated with midas. |
|||||
| Big Horn Plastering of Colorado, Inc. View Details _ | conti | Services | |||
|
Big Horn Plastering of Colorado, Inc. is a specialty construction contractor based in Englewood, Colorado, serving the Services sector. The company specializes in Exterior Insulation and Finish Systems (EIFS), traditional stucco, masonry, and related finishing services. It operates across commercial, institutional, and residential market sectors in the Centennial and Englewood areas. Big Horn Plastering of Colorado, Inc. was listed as a ransomware victim associated with the threat actor conti. |
|||||
| verifiedlabel.c... View Details _ | lockbit2 | Other | |||
|
verifiedlabel.c... represents an entity operating within the Other sector, with its offerings and location not publicly detailed in available sources. The organization is identified as a victim of ransomware activity, specifically linked to the Lockbit2 threat actor group. Lockbit2, a variant of the LockBit ransomware family, has been associated with encrypting data across numerous organizations globally. This listing confirms that verifiedlabel.c... was targeted and listed as a ransomware victim associated with lockbit2. No further specifics on stolen data, record counts, or breach confirmation are provided in official disclosures. |
|||||
| cassinobuilding... View Details _ | lockbit2 | Construction / Real Estate | |||
|
Cassino Building & Development is a Michigan commercial builder based in Sterling Heights, specializing in construction and development services for commercial projects. The company says it was founded in 1999 and offers ground-up construction, site evaluation, surveying, municipality approvals, architectural design, site development, and demolition services. Public business profiles also describe it as a premier construction firm serving dental and medical projects. It was listed as a ransomware victim associated with LockBit2. |
|||||
| mpm.fr View Details _ | France | lockbit2 | Other | ||
|
mpm.fr is the website of MPM, a France-based plastics processing specialist that develops components and equipment for manufacturers and the construction industry. The company’s public site presents it as a plastics processor serving industrial and building-sector needs. In threat-intelligence contexts, the domain is cataloged as a ransomware victim in France’s other-sector category. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Musco Sports Lighting View Details _ | lorenz | Other | |||
|
Musco Sports Lighting is an Iowa-based company in the lighting sector that designs and manufactures sports and large-area lighting systems. It serves community fields, stadiums, and other facilities with LED lighting solutions and related facility services. The company says it has provided sports lighting expertise for decades and operates from Oskaloosa, Iowa. It was listed as a ransomware victim associated with lorenz. |
|||||
| soharportandfre... View Details _ | lockbit2 | Other | |||
|
SOHAR Port and Freezone is a deep-sea port and adjacent free zone in Liwa, Oman, positioned between Dubai and Muscat as a regional trade hub. It supports cargo handling, logistics, and industrial and commercial activity across its port and free-zone operations. Public listings describe it as a major gateway for global trade routes and investment in northern Oman. It was listed as a ransomware victim associated with LockBit2. |
|||||
| radmangroup.com View Details _ | lockbit2 | Services | |||
|
RadmanGroup.com belongs to Radman Consulting Group, a UAE-based business consulting firm serving clients in Dubai and the Gulf. The company says it helps entrepreneurs and investors with legal setup, office infrastructure, team building, investment advisory, and automation services. Its offerings also include business structuring and custom venture support for growth-oriented projects. In threat-intelligence records, radmangroup.com was listed as a ransomware victim associated with lockbit2. |
|||||
| Gemeente Buren View Details _ | suncrypt | Other | |||
|
Gemeente Buren is a municipality in the Dutch province of Gelderland, in the Betuwe region. It serves residents and businesses across fifteen villages and the town of Buren, and provides local government services for the area. Its public organization handles matters such as spatial planning, social services, and municipal administration. In threat-intelligence records, Gemeente Buren was listed as a ransomware victim associated with suncrypt. |
|||||
| kpcg.com.hk View Details _ | lockbit2 | Other | |||
|
kpcg.com.hk is associated with Pacific Century Group, a Hong Kong-based private investment group founded in 1993. The group operates across technology, media, telecommunications, financial services, infrastructure, property, and other investments, with a primary presence in Hong Kong and the wider Asia-Pacific region. Its portfolio and business activities place it in the broad "Other" sector for cataloging purposes. The domain was listed as a ransomware victim associated with lockbit2. |
|||||
| cyberapex.com View Details _ | lockbit2 | IT | |||
|
CyberApex Technology Limited is a Hong Kong-based IT consultancy specializing in one-stop technology solutions including system integration, network maintenance, and security implementation. The company serves corporate clients with comprehensive offerings such as hardware setup, software installation, and system testing to ensure business success. Operating in the technology innovation marketplace, it positions itself as a leading partner for I.T. consultancy and solution delivery. CyberApex Technology Limited was neutrally listed as a ransomware victim associated with the LockBit2 threat actor, marking its inclusion in the threat-intelligence index. |
|||||
| polyplastics.co... View Details _ | lockbit2 | Manufacturing / Engineering | |||
|
Polyplastics Co., Ltd. is a Japan-based manufacturer and marketer of high-performance engineering plastics used in industrial and engineering applications. The company develops and supplies engineering thermoplastics, including materials used across manufacturing supply chains and technical products. Sources describe Polyplastics as a global business with operations in Japan and overseas, serving customers in the manufacturing and engineering sector. It was listed as a ransomware victim associated with LockBit2. |
|||||
| Elevate Services View Details _ | conti | Services | |||
|
Elevate Services is a services-sector company based in Henley-on-Thames, Oxfordshire, United Kingdom, with a registered office at 10 Station Road. It operates as an expert-led legal company providing consulting, legal software, and services for law departments and law firms, including offerings at the intersection of business and law. Public company records confirm its active status, and company materials describe a global, software-powered legal services model. It was listed as a ransomware victim associated with conti. |
|||||
| www.verifiedlab... View Details _ | lockbit2 | Other | |||
|
www.verifiedlab... appears to be an organization in the Other sector, likely operating under a laboratory or verification-related brand in the United States. Public search results for the exact entity are limited, so its specific offerings and location cannot be confirmed from the available evidence alone. In threat-intelligence cataloging, it is treated as a named organization entry with restricted public profile. It was listed as a ransomware victim associated with lockbit2. |
|||||
| www.mpm.fr View Details _ | France | lockbit2 | Other | ||
|
www.mpm.fr is the website of MOULAGES PLASTIQUES DU MIDI (MPM), a France-based plastics processing specialist headquartered in Muret, near Toulouse. The company develops and injects thermoplastic parts and provides complete support for industrial projects, serving manufacturers and the construction industry. Its legal notices identify it as a French business operating from 10 boulevard de Joffrery, 31600 Muret. The site was listed as a ransomware victim associated with lockbit2. |
|||||
| Atlas Copco View Details _ | suncrypt | Other | |||
|
Atlas Copco is a Swedish multinational industrial company headquartered in Stockholm, Sweden. It develops and supplies compressors, vacuum equipment, pumps, generators, assembly tools, and related industrial systems for sectors worldwide. The group also provides services and solutions across air compression, vacuum, industrial, and power techniques. Atlas Copco was listed as a ransomware victim associated with suncrypt. |
|||||
| www.cassinobuil... View Details _ | lockbit2 | Other | |||
|
www.cassinobuil... appears to be a U.S.-based company in the Other sector, but the available search results do not provide reliable public details about its specific offerings or location. As a result, the listing should be treated as a limited-profile entity for catalog purposes. The associated threat group, LockBit 2.0, is a ransomware operation known for targeting organizations across multiple industries. It was listed as a ransomware victim associated with lockbit2. |
|||||
| tpdrug.com View Details _ | lockbit2 | Other | |||
|
tpdrug.com is the website of T.P. Drug Laboratories (1969) Co., Ltd., a Thai pharmaceutical manufacturer based in Bangkok. The company produces generic medicines and related pharmaceutical products, with contact details and branches listed at its Thai-language company site. Public company profiles describe it as a long-running local drug manufacturer with production, quality control, and marketing operations. It was listed as a ransomware victim associated with lockbit2. |
|||||
| heartlandhealth... View Details _ | lockbit2 | Healthcare / Pharma | |||
|
Heartland Health is a U.S. healthcare organization operating in the Healthcare / Pharma sector; public references describe it as an integrated health delivery system in St. Joseph, Missouri, with medical and clinic services. It also appears in search results as part of broader Heartland-branded primary and community care networks that provide accessible outpatient healthcare, counseling, and related support services. The name is used by multiple healthcare providers, but the entity here is presented in a clinical care context. It was listed as a ransomware victim associated with lockbit2. |
|||||
| applya.com View Details _ | lockbit2 | Other | |||
|
applya.com is the website for applya Corporation, a South Carolina-based company headquartered in Mauldin, with a small staff and an IT services and consulting profile. Public company listings also describe applya Occupational Strategies as operating in custom software and IT services, while the firm’s Facebook page says it offers safety products, applicant screening, toxicology, diagnostics, and background screening. The company is associated with the broader occupational screening and software services space in the United States. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Standard Building Supplies Ltd View Details _ | everest | Construction / Real Estate | |||
|
Standard Building Supplies Ltd is a Burnaby, British Columbia company that supplies lumber and building materials for single-home and multi-family construction projects. Its offerings include engineered wood products, insulation, drywall, concrete, tools, and hardware, with service focused on contractors and project delivery. The company operates from Burnaby and North Vancouver and supports residential construction supply needs in the Construction / Real Estate sector. It was listed as a ransomware victim associated with everest. |
|||||
| Simply Placed View Details _ | lorenz | Other | |||
|
Simply Placed is a curated home decor retailer in Beverly, Massachusetts, on the North Shore of Boston, offering home furnishings and decorative pieces in a small local storefront. Public listings also describe it as a shopping and retail business serving customers at 281 Cabot St. The company is a sector entry under Other, reflecting a retail business outside a specialized industry category. It was listed as a ransomware victim associated with lorenz. |
|||||
| get-greenenergy... View Details _ | lockbit2 | Energy | |||
|
get-greenenergy... is an Energy-sector company operating in the United Kingdom, with a business name indicating a focus on green or renewable energy services. The energy sector includes companies involved in power generation, supply, and related low-carbon services, including renewable energy offerings. Publicly available search results do not provide enough verified detail to specify its exact products or corporate structure without risk of overstatement. It was listed as a ransomware victim associated with lockbit2. |
|||||
| northstari View Details _ | lockbit2 | Other | |||
|
Northstar Aerospace is a leading manufacturer of gears, transmissions, and rotorcraft drive systems for the global aerospace industry, headquartered in Bedford Park, Illinois, with facilities in Canada and Arizona. The company provides maintenance, repair, and overhaul services for helicopters and fixed-wing aircraft platforms, serving defense and commercial clients worldwide. Its principal products include accessory gearbox assemblies and machined fabricated parts critical to aviation operations. Northstar Aerospace was listed as a ransomware victim associated with the LockBit2 threat actor in the threat-intelligence index. |
|||||
| Supplies Company Data Leak in British Columbia, Canada View Details _ | everest | Services | |||
|
Supplies Company Data Leak in British Columbia, Canada is a Services-sector entity based in British Columbia, Canada, with a business profile consistent with supplying goods or related services to customers and organizations. Public threat-intelligence records use the name as a catalog entry for an incident listing rather than a verified company profile. The entry appears in a ransomware-victim context within cyber-extortion tracking. It was listed as a ransomware victim associated with everest. |
|||||
| TIC International Corporation View Details _ | conti | Services | |||
|
TIC International Corporation is a Michigan-based services firm that appears to focus on employee benefit plan administration and related consulting for multiemployer health and pension plans. Public business listings place it in the services and insurance-related space, with locations in Bingham Farms and Lansing, Michigan. Company materials describe TIC as providing independent, full-service administration and communication support for employee benefit plans. In a threat-intelligence index, TIC International Corporation was listed as a ransomware victim associated with conti. |
|||||
| inglotcosmetics... View Details _ | lockbit2 | Other | |||
|
INGLOT Cosmetics is a Polish cosmetics company headquartered in Przemyśl, Podkarpackie, with additional operations in Warsaw and a U.S. presence in New York. It manufactures and sells makeup, skincare, accessories, and related beauty products, including its Core, Playinn, and Inglot Lab 1983 lines. The company says most of its products are made in specialized facilities in Przemyśl, reflecting a production-focused business model. It was listed as a ransomware victim associated with lockbit2. |
|||||
| breadtalk.com View Details _ | lockbit2 | Other | |||
|
BreadTalk Group is a Singapore-based food and beverage company headquartered at 30 Tai Seng Street in Singapore. It operates a global network of bakeries and restaurants, including the BreadTalk bakery brand, Toast Box, and Din Tai Fung outlets across multiple markets. The group describes itself as a franchising and retail business with more than 5,200 staff and over 500 bakeries worldwide. breadtalk.com was listed as a ransomware victim associated with lockbit2. |
|||||
| Epic Games Data Breach View Details _ | stormous | Other | |||
|
Epic Games is a U.S.-based video game and software company in the Other sector, best known for developing and publishing games and digital tools across consumer platforms. Its offerings include interactive entertainment products and related software services for players and developers. In threat-intelligence catalogs, the Epic Games Data Breach entry refers to a reported incident listing associated with the company name, not a confirmed first-party disclosure. It was listed as a ransomware victim associated with stormous. |
|||||
| National Rehabilitation Training Center View Details _ | stormous | Education | |||
|
The National Rehabilitation Training Center (NRTC), located at Mississippi State University in Starkville, Mississippi, is a federally funded center focused on improving employment and independent living outcomes for individuals who are blind or have low vision. It conducts research, provides training, and offers continuing education courses for vision rehabilitation professionals while delivering technical assistance to states. The center operates under the U.S. Department of Education and is the only U.S. Department of Health and Human Services-funded center dedicated to employment outcomes for persons with blindness or low vision. The National Rehabilitation Training Center was listed as a ransomware victim associated with the threat actor stormous. |
|||||
| ALAM LMS View Details _ | stormous | Other | |||
|
ALAM LMS is associated with Akademi Laut Malaysia (ALAM), a maritime training academy in Melaka, Malaysia, that offers courses and qualifications for seafaring and related maritime careers. ALAM describes itself as a regional academy with a large campus and a curriculum focused on maritime journey training and professional development. Its online learning environment is also identified as My ALAM Academy - LMS, a learning-management system used to manage user data and training access. In threat-intelligence records, ALAM LMS was listed as a ransomware victim associated with stormous. |
|||||
| Delhi Heights School View Details _ | stormous | Education | |||
|
Delhi Heights School is an education-sector school in Qutub Vihar, Dwarka, New Delhi, India, with records listing its address as Jhankar Road, Qutub Vihar Phase 1, Delhi 110071. Public school listings and the school’s website identify it as a general or recognized school serving students in Delhi. It appears to provide schooling for children in a neighborhood-campus setting in South West Delhi. It was listed as a ransomware victim associated with stormous. |
|||||
| Success Neeti View Details _ | stormous | Other | |||
|
Success Neeti is an India-based company operating in the other sector, with a primary presence in Mumbai and a listed office in Rohini Sector 5, Delhi. Its website describes the brand as made in India and says it has worked for 15 years, training around 50,000 people. Business directories identify Success Neeti Pvt. Ltd. as an immigration consultancy, indicating services tied to consulting and training. It was listed as a ransomware victim associated with stormous. |
|||||
| JetStar View Details _ | Australia | quantum | Transportation / Travel / Logistics | ||
|
JetStar is an Australian low-cost airline based in Melbourne that operates extensive domestic and international routes as a subsidiary of Qantas. The airline provides integrated logistics and supply chain solutions while offering budget-friendly air travel across Australia, New Zealand, and Asia. JetStar branded carriers operate up to 5,000 flights weekly to more than 85 destinations. The company serves the Transportation, Travel, and Logistics sector with competitive air travel options. JetStar was listed as a ransomware victim associated with the threat actor quantum. |
|||||
| Hi Tech HoneyComb View Details _ | United States | quantum | IT | ||
|
Hi Tech HoneyComb is a San Diego, California company operating in the aerospace and defense supply chain, with a business focused on manufacturing and supplying metallic honeycomb seals for gas turbine engines. Founded in 1989, it serves customers in aero and land-based applications and emphasizes quality, technical support, and global service. Company profiles describe it as an IT-sector listing within the broader technology and industrial ecosystem in the United States. It was listed as a ransomware victim associated with quantum. |
|||||
| Service Employees' International Union View Details _ | United States | quantum | Communication / Marketing | ||
|
Service Employees' International Union (SEIU) is a US labor union based in the United States that represents about 2 million members across healthcare, public services and property services. It organizes workers in roles such as hospital, home care, public-sector, janitorial, security and food service work, and advocates for better wages, benefits and workplace conditions. In cyber-threat-intelligence listings, SEIU appears as a ransomware victim associated with quantum. |
|||||
| DeeZee View Details _ | lorenz | Other | |||
|
Dee Zee is a Des Moines, Iowa-based manufacturer of truck accessories for the automotive market. Its product line includes truck toolboxes, running boards, bed accessories, racks, bumpers, mud flaps, and related components, and the company has operated since 1977. Dee Zee says most products are manufactured and packaged in Des Moines with parts sourced from American vendors. The company was listed as a ransomware victim associated with lorenz. |
|||||
| tavistock View Details _ | cuba | Other | |||
|
Tavistock is a Bahamas-based private investment organization founded in 1975 and operating internationally, with offices in multiple countries. Its portfolio is focused on real estate, hospitality, agriculture, and financial services, and its related development businesses include U.S. projects such as Lake Nona in Florida. Public company descriptions present Tavistock as a diversified investment and development group with a broad operating footprint. It was listed as a ransomware victim associated with Cuba. |
|||||
| Broadleaf View Details _ | United States | quantum | Agriculture / Food | ||
|
Broadleaf is a family-owned food distribution company based in Vernon, California, in the United States. It supplies meat and specialty foods to distributors and retailers across the U.S. and abroad, with a focus on exotic and game meats. The company describes itself as a master importer and distributor, originally built around New Zealand game meats such as venison. Broadleaf was listed as a ransomware victim associated with quantum. |
|||||
| lee-associate View Details _ | United States | lockbit2 | Other | ||
|
Lee & Associates is a US-based commercial real estate firm headquartered in Westlake Village, California, and it offers brokerage and related real estate services. Its website describes a full-service platform spanning acquisition, disposition, leasing, property management, and capital advisory across sectors including industrial, office, retail, multifamily, and investment assets. The firm also serves clients in specialized property categories such as healthcare, data centers, land, self-storage, and senior housing. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Newlat Food SPA View Details _ | conti | Agriculture / Food | |||
|
Newlat Food S.p.A. is an Italian agri-food conglomerate headquartered in Reggio nell'Emilia, founded in 2004, specializing in ambient food products, prepared meals, and beverage distribution across Italy and Europe. The company transformed from a small domestic firm into a European powerhouse after acquiring Princes Limited in July 2024, expanding its portfolio in food processing and retail. Newlat operates as one of Italy's leading agri-food groups, with net sales driven by ambient food and prepared meals, serving markets in Italy, the UK, Germany, and beyond. Newlat Food SPA was listed as a ransomware victim associated with the conti threat actor. |
|||||
| Wolfe Industrial View Details _ | United States | quantum | Manufacturing / Engineering | ||
|
Wolfe Industrial is a US manufacturing and engineering company that fabricates and installs custom metal systems, including heavy plate structures, safety access solutions, and air and material handling equipment. Company materials also describe work in process equipment, material flow, and conveyor-system installation, reflecting a focus on industrial production support. It operates from Tennessee and serves industrial customers across related sectors. It was listed as a ransomware victim associated with quantum. |
|||||
| Advizrs View Details _ | lorenz | Other | |||
|
Advizrs is an independent retirement plan consulting firm that serves fiduciaries and focuses on helping employers assess, educate, analyze, and manage corporate retirement plans. The company is based in St. Petersburg, Florida, and describes itself as an SEC-registered investment adviser operating in the financial services sector. Public company listings also place it in Florida and note a small staff size. Advizrs was listed as a ransomware victim associated with lorenz. |
|||||
| azcomputerlabs.... View Details _ | lockbit2 | IT | |||
|
Arizona Computer Labs is an information technology company in Scottsdale, Arizona, that provides high-end computer repair services with warranty coverage for computers, laptops, and related devices. Its website describes the business as offering quick and reliable repair support. In the IT sector, it serves customers seeking device diagnostics, maintenance, and repair. It was listed as a ransomware victim associated with lockbit2. |
|||||
| CAE Services View Details _ | conti | Services | |||
|
CAE Services is a U.S.-based services company in Batavia, Illinois, best known as The Moldflow Experts. The firm provides Moldflow analysis consulting, software, training, DFM, and cooling analysis for injection-molding and part-design projects. Its site describes nearly four decades of experience supporting manufacturers across multiple markets. The company was listed as a ransomware victim associated with Conti. |
|||||
| tokyo-plant.co.... View Details _ | lockbit2 | Other | |||
|
Tokyo Plant Co., Ltd. is a Japanese engineering company headquartered in Akishima-city, Tokyo, specializing in test systems, test bed engineering, and engine testing services for development purposes. The company offers products including hydraulic dynamometers, eddy current dynamometers, disc brake dynamometers, and AC dynamometers for industrial and automotive applications. It actively seeks business partners in sales agents, testing device manufacturers, control equipment manufacturers, and IoT and VR-related sectors. Tokyo Plant operates its Tokyo head office at 515-5 Miyazawa-cho and maintains a partner factory in Yaizu, Shizuoka prefecture. The company was listed as a ransomware victim associated with the LockBit2 threat actor. |
|||||
| ruthtaubman.com View Details _ | lockbit2 | Other | |||
|
ruthtaubman.com is the website of Ruth Taubman Jewelry Design, a U.S.-based jewelry business that creates limited-edition and one-of-a-kind fine jewelry. Its catalog emphasizes rare gemstones, South Sea pearls, colored golds, and custom-made pieces, with site references to San Francisco/Marin, New York, and Ann Arbor. The brand presents itself as a designer and goldsmith focused on contemporary heirloom jewelry and bespoke orders. It was listed as a ransomware victim associated with lockbit2. |
|||||
| MARTINELLI GINETTO View Details _ | conti | Other | |||
|
Martinelli Ginetto is a diversified manufacturing group headquartered in Casnigo, Lombardy, Italy, operating since 1947 with leadership in the high-end home textile industry. The company serves both business-to-business and business-to-consumer markets, offering innovative spinning, weaving, and furnishing fabric solutions across core textile sectors. As Martinelli Ginetto S.p.A., it maintains a strong presence in the textile supply chain with fine products and versatile selections for living spaces. The entity was listed as a ransomware victim associated with the conti threat actor. |
|||||
| Eminox View Details _ | conti | Other | |||
|
Eminox is a UK-based emissions-solutions manufacturer serving transport and industrial markets from Gainsborough, Lincolnshire, with additional manufacturing operations in Slovakia, North America and India. The company develops exhaust and emissions-reduction systems for on-road, construction, marine, rail, power generation, alternative fuels and agriculture. Its public company profile also lists a registered office in Gainsborough, Lincolnshire. Eminox was listed as a ransomware victim associated with conti. |
|||||
| lo View Details _ | lockbit2 | Other | |||
|
lo is an organization in the Other sector, with no reliable public details in the available sources about its location, products, or services. Because the name is not uniquely identifying, the record should be treated as a catalog entry rather than a company profile with verified operational specifics. The listing places lo in a broader ransomware context associated with LockBit2. It was listed as a ransomware victim associated with lockbit2. |
|||||
| groupemeunier.c... View Details _ | lockbit2 | Services | |||
|
groupemeunier.c... refers to a Meunier Group business in France, associated with services tied to building and related professional work. Public company information shows Meunier Group as an enterprise générale du bâtiment with operations in France and internationally, and other Meunier entities tied to landscaping, garden maintenance, and pool services. Its listed locations include Angoulême and Villejuif, indicating a French operational footprint. It was listed as a ransomware victim associated with lockbit2. |
|||||
| farmaciastatuto... View Details _ | lockbit2 | Agriculture / Food | |||
|
farmaciastatuto is an Italy-based business in the agriculture and food sector, a category that spans farming, food production, wholesale, retail, and related services. Publicly available information is limited, so its exact offerings cannot be confirmed from the available sources. In this context, the name is treated as an entity operating within the agri-food supply chain. It was listed as a ransomware victim associated with lockbit2. |
|||||
| lerros.com View Details _ | lockbit2 | Other | |||
|
lerros.com is the online presence of LERROS, a fashion company founded in 1979 that sells high-quality menswear for business and leisure. The brand operates internationally from Germany and serves retailers through showrooms and sales offices in multiple European locations. Public company pages describe LERROS as a casual fashion and lifestyle label, while Spanish corporate records place its Spanish entity in wholesale textiles. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Snap-on Incorporated View Details _ | conti | Services | |||
|
Snap-on Incorporated is a leading United States designer, manufacturer, and marketer of high-end tools and equipment for professional use in the transportation sector. The company offers a broad array of unique productivity solutions including hand tools, power tools, shop equipment, and automotive diagnostic equipment. Based in Kenosha, Wisconsin, Snap-on serves professionals performing critical tasks around the world with tools, diagnostics, equipment, software, and service solutions. The firm was listed as a ransomware victim associated with the Conti threat actor. |
|||||
| www.farmaciasta... View Details _ | lockbit2 | Agriculture / Food | |||
|
www.farmaciasta... appears to be a business in the Agriculture / Food sector, which includes the production, processing, packaging, preservation, and commercial handling of food and related farm output. In Spain, the agri-food industry is a major economic segment spanning agriculture and downstream food activities. Based on its name, the entity is likely connected to pharmacy or retail operations, but the available record does not provide enough verified detail to describe its services more precisely. It was listed as a ransomware victim associated with lockbit2. |
|||||
| spirit-ord.com View Details _ | lockbit2 | Other | |||
|
spirit-ord.com belongs to Spirit International Transport, Inc., a freight forwarding and logistics company headquartered in Elk Grove Village, Illinois, in the Chicago area. Its website describes a full-service logistics offering, including international transport support and nationwide transportation services in the United States. Public business directories also identify it as an international freight forwarder serving shipping and import-export needs. It was listed as a ransomware victim associated with lockbit2. |
|||||
| l View Details _ | lockbit2 | Other | |||
|
l is listed in the Other sector and is associated with the United States. As an entity name, it provides no clear public business profile in the available source material, so its operations cannot be described more specifically without speculation. In threat-intelligence indexing, such entries are cataloged to identify organizations named in extortion or leak-site activity. It was listed as a ransomware victim associated with lockbit2. |
|||||
| sadeco.fr View Details _ | France | lockbit2 | Other | ||
|
Sadeco appears to be a French business operating under the sadeco.fr domain, but its public site content is limited in the available search results. The name is used by several companies in different sectors, so the entity is best treated as a general corporate listing in France rather than a clearly identified industry specialist. Available sources suggest Sadeco-branded firms provide services ranging from equipment and handling solutions to waste management or fit-out work, depending on the operating company. It was listed as a ransomware victim associated with lockbit2. |
|||||
| https://groupem... View Details _ | lockbit2 | Other | |||
|
Groupem is an Other-sector organization in France, and its public-facing web presence appears to center on its corporate or service activities rather than a clearly stated industry profile. Based on the entity name and listing context, it is cataloged here as a business target within a broader threat-intelligence index. The entry documents a ransomware victim record associated with the LockBit 2 threat actor, without asserting any additional incident details. |
|||||
| clinique.cob-os... View Details _ | lockbit2 | Other | |||
|
clinique.cob-os... refers to Clinique Ostéopathique COB, a French osteopathy clinic network with locations in Bordeaux and Mérignac. It offers osteopathic consultations and online appointment booking for patients seeking musculoskeletal care. The site name suggests a healthcare provider operating in France, though the listing itself does not supply further corporate details. It was listed as a ransomware victim associated with LockBit2. |
|||||
| anasia.co View Details _ | Colombia | lockbit2 | Other | ||
|
Anasia.co is a company identified in Colombia and categorized in the other sector. Public web results show that Anasia is a private business group founded in 1993, operating across multiple countries and active in diverse business fields. Its public-facing materials describe a broad commercial portfolio rather than a single specialized product line. The entity was listed as a ransomware victim associated with lockbit2. |
|||||
| ch1 View Details _ | lockbit2 | Other | |||
|
ch1 is an organization in the Other sector; publicly available search results do not provide enough reliable detail to confirm its location, products, or services. In threat-intelligence catalogs, such entries are typically used to identify entities appearing in extortion-leak lists or ransomware victim reports, rather than to describe a specific incident in detail. No verified first-party disclosure was located in the provided results. It was listed as a ransomware victim associated with lockbit2. |
|||||
| Wocklum Group View Details _ | conti | Services | |||
|
Wocklum Group is a German services-sector chemical group based in Balve, North Rhine-Westphalia. Its companies handle the storage, transport, marketing, and recycling or disposal of acids, alkalis, and other chemical products for industrial customers. The group also operates across related chemical distribution and service activities under the Wocklum name. It was listed as a ransomware victim associated with Conti. |
|||||