Ransomware Group intelligence
0apt
InactiveTrack 0apt with 190 published victims and 1 known leak locations in a single intelligence view.
Overview
0apt is tracked by Dark Eye as a ransomware group with 190 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | oaptxiyisljt2kv3we2we34kuudmqda7f2geffoylzpeo7ourhtz4dad.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (190)
Search, filter and paginate the victim timeline for 0apt.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | HCA Healthcare UK (Private Division) id26205 View details | United Kingdom | Healthcare / Pharma | — | |
|
HCA Healthcare UK is a private healthcare provider in the United Kingdom, operating hospitals, outpatient facilities, and medical centres. Its services span consultation through treatment, and public listings describe offerings across areas such as oncology, fertility, surgery, orthopaedics, gastroenterology, primary care, and diagnostic or supportive services. The organization is registered in England and Wales as HCA International Limited and serves patients through private-sector teams across the UK. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Vestas Wind Systems (Denmark) id26204 View details | Denmark | Energy | — | |
|
Vestas Wind Systems A/S is a Danish energy company headquartered in Denmark and focused on wind power technology. It designs, manufactures, installs, sells, and services wind turbines and related renewable energy solutions. The company is widely known for supporting utility-scale wind projects and turbine operations across international markets. In threat-intelligence catalogs, Vestas Wind Systems (Denmark) is listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Edwards Lifesciences (USA) id26203 View details | United States | Healthcare / Pharma | — | |
|
Edwards Lifesciences is a US-based medical technology company headquartered in Irvine, California, and is known for structural heart innovation and patient-focused cardiovascular solutions. The company develops and supplies technologies used in heart disease treatment and critical care monitoring, serving the healthcare and pharma ecosystem. Its global operations reflect a broad commercial and manufacturing footprint across multiple regions. In threat-intelligence catalogs, Edwards Lifesciences (USA) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Keysight Technologies (USA) id26202 View details | United States | IT | — | |
|
Keysight Technologies, Inc. is a U.S.-based technology company headquartered in Santa Rosa, California, and operates in the IT and electronics measurement space. It provides electronic design and test solutions that support simulation, prototype validation, manufacturing test, and secure operation across communications, networking, and electronics industries. The company serves enterprises, service providers, and governments with tools and software used to accelerate product development and deployment. Keysight Technologies (USA) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Hologic, Inc. (USA) id26201 View details | United States | Healthcare / Pharma | — | |
|
Hologic, Inc. is a U.S.-based medical technology company headquartered in Marlborough, Massachusetts. It develops and supplies diagnostic products, medical imaging systems, and surgical products, with a strong focus on women’s health and healthcare solutions. Its portfolio includes technologies used in breast health, gynecologic care, diagnostics, and bone density assessment. In threat-intelligence records, Hologic, Inc. was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Galderma Pharma (Switzerland) id26200 View details | Switzerland | Healthcare / Pharma | — | |
|
Galderma Pharma is a Swiss healthcare and pharmaceutical company based in Zug, Switzerland, and operates in dermatology-focused skin care and treatment markets. It offers a science-based portfolio of clinically proven products and is described as a leading independent global dermatology company. In cataloging and threat-intelligence contexts, the company is associated with Switzerland's healthcare and pharma sector. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Sysmex Corporation (Japan) id26199 View details | Japan | Services | — | |
|
Sysmex Corporation is a Japan-based company headquartered in Kobe, Hyogo, and operates in the healthcare diagnostics sector. It develops, manufactures, sells, and exports/imports diagnostic instruments, reagents, and related software, with a global footprint in more than 190 countries. The company’s portfolio includes in vitro diagnostics and service support for clinical laboratories and healthcare organizations. Sysmex Corporation, Japan, was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Align Technology (USA) id26198 View details | United States | IT | — | |
|
Align Technology is a U.S.-based medical device company headquartered in Tempe, Arizona, with operations and locations in the United States and abroad. It designs, manufactures, and markets orthodontic, restorative, and aesthetic dentistry products, including the Invisalign clear aligner system and iTero intraoral scanners. The company serves dental and orthodontic care markets through technology-driven treatment and scanning solutions. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Snap-on Incorporated (USA) id26197 View details | United States | Finance / Legal / Insurance | — | |
|
Snap-on Incorporated is a U.S.-based manufacturer and marketer headquartered in Kenosha, Wisconsin, known for tools, equipment, diagnostics, repair information, and systems solutions for professional users. Its offerings include hand and power tools, shop equipment, automotive diagnostics, and related productivity solutions used across vehicle repair and other technical industries. The company operates as a global industrial and professional services supplier rather than a financial institution, despite the listing sector label. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Varian Medical Systems (USA) id26196 View details | United States | Healthcare / Pharma | — | |
|
Varian Medical Systems is a U.S.-based healthcare technology company headquartered in Palo Alto, California, that designs, manufactures, sells, and services medical equipment and software. Its portfolio includes cancer treatment systems and oncology software used for radiotherapy, radiosurgery, proton therapy, brachytherapy, and related clinical workflows. The company serves healthcare customers globally and is part of the cancer care and medical devices ecosystem. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Bruker BioSpin (Germany) id26195 View details | Germany | Healthcare / Pharma | — | |
|
Bruker BioSpin GmbH is a German company located in Ettlingen, Baden-Württemberg, that develops, manufactures, and markets instruments based on magnetic resonance technology. The firm specializes in nuclear magnetic resonance (NMR), electron paramagnetic resonance (EPR), and preclinical imaging tools for molecular and materials research. It serves the healthcare and pharmaceutical sectors by enabling breakthrough discoveries and advanced analysis through its high-value life science solutions. Bruker BioSpin is part of Bruker Corporation, an American parent company headquartered in Billerica, Massachusetts. The company was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Teledyne Technologies (USA) id26194 View details | United States | IT | — | |
|
Teledyne Technologies is a U.S.-based technology company headquartered in Thousand Oaks, California, with operations spanning electronic components, instruments, communications products, and related systems. Its offerings include data acquisition and communications equipment, monitoring and control instruments, and subsystems for wireless and satellite communications. The company also provides systems engineering and information technology services for defense, industrial, and space applications. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Terumo Corporation (Japan) id26193 View details | Japan | Communication / Marketing | — | |
|
Terumo Corporation is a Tokyo, Japan-based medical technology company founded in 1921 that manufactures and sells medical products and equipment. Its business spans healthcare areas including cardiovascular systems, medical care solutions, and blood and cell technologies, with operations in Japan and other global markets. The company’s portfolio includes devices and solutions used in cardiac surgery, hospital care, and blood processing. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Xylem Inc. (USA) id26192 View details | United States | Construction / Real Estate | — | |
|
Xylem Inc. is a U.S.-based water technology company headquartered in Washington, DC, that designs, manufactures, and services solutions for public utility, industrial, commercial, agricultural, and residential water applications. It serves customers in more than 150 countries and focuses on the delivery, treatment, testing, analysis, and reuse of water and wastewater systems. The company’s portfolio includes pumps, filtration, disinfection, and other infrastructure products used across the water cycle. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | BioMérieux (France) id26191 View details | France | Other | — | |
|
BioMérieux is a French company headquartered in Marcy-l’Étoile, near Lyon, that develops, manufactures, and markets in vitro diagnostics. Its portfolio supports the detection of infectious diseases, microbiology testing, and contamination analysis for healthcare and industrial settings. Founded in 1963, the company describes itself as a world leader in in vitro diagnostics and operates internationally through a broad network of sites and subsidiaries. The listing identifies BioMérieux (France) as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Ingersoll Rand (USA) id26190 View details | United States | Manufacturing / Engineering | — | |
|
Ingersoll Rand (USA) is an American multinational company headquartered in Davidson, North Carolina, that operates in the Industrial Machinery Manufacturing sector. The company provides industrial products including compressors, blowers, vacuum pumps, and precision handling solutions for liquids, gases, and power applications. Its offerings span two main segments: Industrial Technologies and Services, and Precision and Science Technologies, serving diverse industrial and life science markets. Ingersoll Rand was listed as a ransomware victim associated with the threat actor 0apt, marking its inclusion in threat-intelligence records regarding cyber incidents in the manufacturing sector. |
|||||
| Ransomware | Masimo (USA) id26189 View details | United States | Healthcare / Pharma | — | |
|
Masimo is a U.S.-based medical technology company headquartered in Irvine, California. It develops and markets patient monitoring technologies and connectivity solutions for hospitals, emergency medical services, home care providers, physicians’ offices, long-term care facilities, and consumers. The company operates healthcare and non-healthcare segments, with its healthcare business centered on sensors, software, cables, and monitors used in clinical care. In threat-intelligence listings, Masimo was identified as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Halma plc (UK) id26188 View details | United Kingdom | IT | — | |
|
Halma plc is a United Kingdom-based public limited company headquartered in Amersham, Buckinghamshire. It is a global group of around 50 specialist technology businesses that provide life-saving technologies and solutions to major challenges, spanning software and hardware offerings. Its portfolio is organized around niche markets with global reach and a focus on safer, cleaner, healthier outcomes. The company was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | PerkinElmer (USA) id26187 View details | United States | Other | — | |
|
PerkinElmer is a US-based science and technology company headquartered in Shelton, Connecticut, with additional offices in the United States. It provides end-to-end discovery, measurement, and testing solutions, along with specialized pharma services manufacturing workflows, serving scientific and laboratory customers. The company also describes itself as a provider of analytics services and solutions for biopharma, food, environmental, safety, and applied end markets. In threat-intelligence indexing, PerkinElmer (USA) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Zebra Technologies (USA) id26186 View details | United States | IT | — | |
|
Zebra Technologies is a US-based technology company headquartered in Lincolnshire, Illinois, that provides intelligent operations solutions for frontline workflows. Its portfolio includes mobile computers, barcode scanners, printers, RFID readers, and related software used across retail, healthcare, manufacturing, transportation and logistics. The company is known for automatic identification and data capture products that help organizations digitize and automate operations. In threat-intelligence indexing, Zebra Technologies (USA) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Andritz Group (Austria) id26185 View details | Austria | Manufacturing / Engineering | — | |
|
Andritz AG is an international technology group headquartered in Graz, Austria, offering plants, equipment, systems, and services for diverse industries including hydropower, pulp and paper, metals, and environment and energy. The company employs over 29,100 people across more than 280 production and service facilities in over 40 countries, reporting EUR€7.5 billion in revenue in 2022. Since January 2024, its business activities are organized into four independent areas: Andritz Hydro Power, Andritz Pulp & Paper, Andritz Environment & Energy, and Andritz Metals. Andritz Group was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Prince Court Medical (Malaysia) id26184 View details | Malaysia | Healthcare / Pharma | — | |
|
Prince Court Medical Centre is a private tertiary hospital in Kuala Lumpur, Malaysia, serving patients with specialist care, surgery, outpatient services, emergency treatment, and health screening. It operates in the healthcare sector and is part of IHH Healthcare’s hospital network, with published service information including 24-hour emergency care and multiple licensed operating theatres. The hospital describes itself as a premier medical centre in Kuala Lumpur, offering broad clinical specialties and patient-focused care. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Hexagon AB (Sweden) id26183 View details | Sweden | Other | — | |
|
Hexagon AB is a Stockholm, Sweden-based industrial technology group that provides sensors, software and autonomous solutions. The company serves industries including manufacturing, infrastructure, safety, mobility and related enterprise applications through its measurement, geospatial and automation offerings. Its business profile emphasizes data-driven tools that support precision, productivity and operational efficiency across industrial environments. Hexagon AB was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Al-Futtaim Conglomerate (UAE) id26182 View details | United Arab Emirates | Manufacturing / Engineering | — | |
|
Al-Futtaim Conglomerate (UAE), also known as Al-Futtaim Group, is an Emirati conglomerate headquartered in Dubai, United Arab Emirates. The organization operates a multi-disciplinary engineering division, Al-Futtaim Engineering, which provides expert solutions across the UAE, Saudi Arabia, Qatar, and Egypt. It delivers a complete range of facilities and asset management services, including electrical and mechanical workshop solutions, supply and installation of motors, pumps, generators, and compressors. The conglomerate serves a large portfolio of key clients and meets the highest industry standards, complying with ISO 9001: 2008 guidelines. Al-Futtaim Conglomerate (UAE) was listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Sandvik Coromant (Sweden) id26181 View details | Sweden | Manufacturing / Engineering | — | |
|
Sandvik Coromant is a Sweden-based industrial engineering company focused on manufacturing tools, machining solutions, and metal-cutting systems for advanced manufacturing customers. Part of the Sandvik group, it supplies tooling solutions and related services to engineering industries worldwide, with operations in Sandviken, Sweden. Its portfolio includes tooling systems, digital manufacturing, and engineering support for metal-cutting applications. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Teleflex (USA) id26180 View details | United States | Healthcare / Pharma | — | |
|
Teleflex Incorporated is a U.S.-based global medical technology company headquartered in Wayne, Pennsylvania, serving hospitals and healthcare providers. It designs, manufactures, and supplies single-use medical devices and specialty products for critical care, surgical care, anesthesia, vascular access, respiratory care, urology, and emergency medicine. The company operates internationally and markets its portfolio across more than 150 countries. In threat-intelligence catalogs, Teleflex (USA) is listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | ResMed (USA) id26179 View details | United States | Healthcare / Pharma | — | |
|
ResMed is a U.S.-based healthcare technology company focused on sleep health, respiratory care, and digital health solutions. Its offerings include cloud-connected medical devices, software, and related therapies for conditions such as sleep apnea and COPD. The company describes itself as a global leader in sleep technology and connected health, serving patients with chronic respiratory and sleep-related needs. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Epworth Private Healthcare (Australia) id26178 View details | Australia | Healthcare / Pharma | — | |
|
Epworth HealthCare is a not-for-profit private hospital group in Melbourne, Victoria, Australia, providing acute medical, surgical, and rehabilitation services. It is Victoria’s largest private hospital group and operates multiple sites across Melbourne and Geelong, with services spanning inpatient care and rehabilitation. In threat-intelligence catalogs, Epworth Private Healthcare (Australia) is indexed under the healthcare/pharma sector to support sector-based risk tracking and incident correlation. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Tetra Pak International (Switzerland) id26177 View details | Switzerland | Agriculture / Food | — | |
|
Tetra Pak International S.A. is a Swiss-headquartered food packaging and processing company based in Pully, Switzerland, that serves customers worldwide with carton packaging, filling systems, processing equipment, automation, and related services. Its offerings support dairy, beverages, plant-based products, and prepared foods across a broad industrial supply chain. The company operates internationally from Switzerland and is known for integrated food-production and packaging solutions. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Flowserve Corporation (USA) id26176 View details | United States | Energy | — | |
|
Flowserve Corporation is an American industrial company based in Irving, Texas, serving the energy sector and other heavy industries. It develops, manufactures, and services flow control equipment, including pumps, valves, seals, and automation systems used in essential infrastructure. The company also provides aftermarket support and related services to customers worldwide. In threat-intelligence records, Flowserve Corporation was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | GlaxoSmithKline (UK) id26175 View details | United Kingdom | Healthcare / Pharma | — | |
|
GlaxoSmithKline (UK) is the UK arm of GSK, a British biopharmaceutical company headquartered in London that develops and delivers medicines and vaccines. Its UK operations include research, commercial, and manufacturing activity, with investment in pharmaceutical production and R&D across the country. GSK’s portfolio spans areas such as respiratory, HIV, immunology, infectious diseases, oncology, and general medicines. In threat-intelligence catalogs, GlaxoSmithKline (UK) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Dormakaba (Switzerland) id26174 View details | Switzerland | Other | — | |
|
Dormakaba Switzerland AG is a Swiss access solutions company based in Wetzikon, Switzerland, and part of the dormakaba Group. It provides access management and door and access systems, including keys, cylinders, physical access systems, and related security solutions for buildings and rooms. The company presents itself as a provider of end-to-end access solutions and industry-proven products for secure access environments. In threat-intelligence catalogs, it was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Prysmian Group (Italy) id26173 View details | Italy | Communication / Marketing | — | |
|
Prysmian Group is an Italian multinational company headquartered in Milan, Italy, and listed on the Italian Stock Exchange. It develops and manufactures cable systems and network solutions for the power and telecommunications sectors, including underground and submarine cables for energy transmission and distribution. The group describes itself as a cable manufacturer and network solution provider serving infrastructure and communications markets. Prysmian Group (Italy) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Crane Co. (USA) id26172 View details | United States | Manufacturing / Engineering | — | |
|
Crane Co. is an American industrial products company headquartered in Stamford, Connecticut, with operations in the United States. It delivers engineered solutions for aerospace, defense, flow technologies, and other critical industries, including valves, fittings, specialty castings, and related manufacturing and engineering offerings. The company’s business profile places it within the Manufacturing / Engineering sector and reflects a long-standing industrial footprint. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Wärtsilä Marine Power (Finland) id26171 View details | Finland | Energy | — | |
|
Wärtsilä is a Finnish technology group based in Helsinki that develops and services power sources and other equipment for the marine and energy markets. Its marine business includes engines, propulsion systems, hybrid technology, and integrated lifecycle solutions for vessels and related operations. In Finland, the company also invests in expanding production capacity to support global demand in energy and marine technologies. Wärtsilä Marine Power (Finland) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Straumann Group (Switzerland) id26170 View details | Switzerland | Healthcare / Pharma | — | |
|
Straumann Group is a Swiss company based in Basel manufacturing dental implants and specialized in related technologies. The group researches, develops, manufactures and supplies dental implants, instruments, biomaterials, CADCAM prosthetics, digital equipment, software, and clear aligners for applications in replacement, restorative, orthodontic and preventative dentistry. Straumann is active in the business of replacement and restoration of teeth, and prevention of tooth loss, collaborating with clinics, research institutes and universities. The company was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | IDEX Corporation (USA) id26169 View details | United States | Communication / Marketing | — | |
|
IDEX Corporation is a U.S.-based applied solutions company headquartered in Northbrook, Illinois, with operations focused on engineered products for niche markets. Its businesses span fluid and metering technologies, health and science technologies, fire and safety systems, and other specialized industrial solutions. Company materials also describe marketing, business communication, and product promotion functions supporting its commercial operations. In threat-intelligence listings, IDEX Corporation was identified as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Mount Elizabeth Hospitals (Singapore) id26168 View details | Singapore | Healthcare / Pharma | — | |
|
Mount Elizabeth Hospitals is a 345-bed private hospital in Singapore operated by Parkway Pantai, specializing in cardiology, oncology, and neuroscience among other tertiary services. Located on Orchard Road near Mount Elizabeth, it is accredited by Joint Commission International and offers multi-organ transplant specialty care. The hospital operates two locations: Mount Elizabeth Orchard at 3 Mount Elizabeth and Mount Elizabeth Novena at 38 Irrawaddy Road, providing advanced healthcare with modern medical technology. Mount Elizabeth Hospitals was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Thermo Fisher Scientific (USA) id26167 View details | United States | IT | — | |
|
Thermo Fisher Scientific Inc. is the world leader in serving science, headquartered in Waltham, Massachusetts, USA, with annual revenue exceeding $45 billion. The company enables customers to make the world healthier, cleaner, and safer by delivering technology, pharmaceutical, and biotechnology solutions across life sciences. Operating in the IT sector, it provides critical tools and services for research, diagnostics, and industrial applications globally. Thermo Fisher Scientific was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Smith & Nephew (UK) id26166 View details | United Kingdom | Healthcare / Pharma | — | |
|
Smith & Nephew (UK) is a British multinational medical technology company headquartered in Watford, England, and registered in Hertfordshire. It develops and manufactures products for advanced wound management, orthopaedics, sports medicine, ENT, trauma, and related clinical therapies, serving healthcare providers in more than 100 countries. The company operates as a portfolio medtech business focused on the repair, regeneration, and replacement of soft and hard tissue. In this index, Smith & Nephew (UK) is listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Kone Cranes International (Finland) id26165 View details | Finland | Manufacturing / Engineering | — | |
|
Kone Cranes International is part of Konecranes, a Finnish company headquartered in Hyvinkää, Finland, that specializes in the manufacture and service of cranes and lifting equipment. It serves manufacturing and process industries with material handling solutions, including industrial crane systems and related services. The company operates in Finland and internationally, with production and service functions supporting industrial customers. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Acuity Brands (USA) id26164 View details | United States | Construction / Real Estate | — | |
|
Acuity Brands is a U.S.-based industrial technology company headquartered in Atlanta, Georgia. It develops lighting and lighting-control products and related technologies for spaces, serving construction and real estate markets across North America and beyond. The company is widely known as a major lighting manufacturer and maintains a broad operational footprint. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Cleveland Clinic Abu Dhabi (UAE) id26163 View details | United Arab Emirates | Healthcare / Pharma | — | |
|
Cleveland Clinic Abu Dhabi is a physician-led medical institution located on Al Maryah Island in Abu Dhabi, UAE, serving patients with board-certified physicians and multidisciplinary teams. The hospital, which opened in May 2015 and has 364 beds, offers advanced care including the Gulf Region's first Laser Interstitial Thermal Therapy for epilepsy and the UAE's first multi-organ transplant center. It provides 24/7 emergency services, pharmacy, and laboratory access, recognized for inclusive healthcare for people of determination. Cleveland Clinic Abu Dhabi was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Bio-Rad Laboratories (USA) id26162 View details | United States | Healthcare / Pharma | — | |
|
Bio-Rad Laboratories, Inc. is a U.S.-based life science and clinical diagnostics company headquartered in Hercules, California, with operations in the United States and internationally. It develops, manufactures, and distributes products used by life science researchers, clinical laboratories, and healthcare organizations, supporting research and diagnostic workflows across the healthcare and pharmaceutical sectors. The company’s offerings are positioned around specialized technologies for research and clinical testing, reflecting its role in biomedical and diagnostics markets. Bio-Rad Laboratories (USA) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Spectris plc (UK) id26161 View details | United Kingdom | Communication / Marketing | — | |
|
Spectris plc is a UK-based precision instrumentation and controls company headquartered in London, England, and it serves industrial customers with high-tech instruments, test equipment, and software. The business focuses on demanding applications where accurate measurement, control, and performance insight are critical, and it operates as a global technology group. Public company information and corporate materials describe Spectris as a market-leading provider of precision measurement solutions with a broad international footprint. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Integer Holdings (USA) id26160 View details | United States | Healthcare / Pharma | — | |
|
Integer Holdings Corporation is a U.S.-based medical device contract development and manufacturing organization (CDMO) with its corporate office in Plano, Texas. It operates as a leader in advanced medical device outsourcing and supports innovation and manufacturing across a broad network of U.S. and international locations. The company is one of the largest medical device CDMOs in the world, serving healthcare and pharma-related customers with outsourced development and production capabilities. Integer Holdings (USA) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Rotork (UK) id26159 View details | United Kingdom | Energy | — | |
|
Rotork (UK) is a trusted global partner in the renewable energy industry, specializing in electric, pneumatic, and flow control solutions for wind, solar, hydroelectric, biomass, and geothermal applications. The company, headquartered in Bath, United Kingdom, operates across three end-market divisions: Oil & Gas, Water & Power, and Chemical, Process & Industrial. Rotork delivers advanced flow control systems that enhance the safety, reliability, and performance of industrial equipment and transportation systems. It was listed as a ransomware victim associated with the 0apt threat actor. |
|||||
| Ransomware | Cognex Corporation (USA) id26158 View details | United States | IT | — | |
|
Cognex Corporation is a U.S.-based technology company headquartered in Natick, Massachusetts, that develops machine vision systems, software, and sensors. Its products help industrial customers automate inspection, identification, assembly, and other manufacturing and logistics tasks. The company serves global customers across sectors including manufacturing, logistics, automotive, aerospace, consumer electronics, and pharmaceuticals. In threat-intelligence catalogs, Cognex Corporation was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Sonova Holding (Switzerland) id26157 View details | Switzerland | Communication / Marketing | — | |
|
Sonova Holding AG is a Swiss company headquartered in Stäfa, Switzerland, and is part of the global hearing care sector. It develops and markets hearing care solutions, including hearing aids, cochlear implants, wireless communication systems, personal audio devices, and related audiological care services. The Sonova Group describes itself as a vertically integrated provider across wholesale, retail, and cochlear implant activities. In a threat-intelligence context, Sonova Holding (Switzerland) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Watts Water Technologies (USA) id26156 View details | United States | IT | — | |
|
Watts Water Technologies, Inc. is a US-based manufacturer headquartered in North Andover, Massachusetts, with a global business focused on water-related solutions for residential, industrial, municipal, and commercial use. Its product portfolio includes plumbing and flow control, HVAC and hot water, drainage, backflow prevention, and water quality systems. The company describes itself as a global leader in water solutions and operates across multiple countries and facilities. In threat-intelligence indexing, it was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Getinge AB (Sweden) id26155 View details | Sweden | IT | — | |
|
Getinge AB is a leading medical technology company founded in 1904 in Getinge, Sweden, specializing in equipment, systems, operating rooms, and intensive-care units for healthcare and life science institutions. The company provides products and solutions aimed at improving clinical results and optimizing workflows for hospitals and life science organizations globally. Headquartered on the Swedish west coast, Getinge operates internationally with offices in multiple countries including the US, Italy, Spain, and China. As a prominent medtech firm, it stands behind critical moments in healthcare, trusted by surgeons and medical professionals worldwide. Getinge AB was listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Mueller Industries (USA) id26154 View details | United States | Manufacturing / Engineering | — | |
|
Mueller Industries, Inc. is a US-based manufacturing and engineering company specializing in piping systems, climate control products, and industrial metals and components. The firm manufactures products for plumbing, HVAC, and refrigeration applications, serving global markets with premium-performance valves and brass fittings. Headquartered in the United States, Mueller Industries operates multiple facilities and employs professionals in roles such as manufacturing engineering and CNC machining. The company was listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | ConvaTec Group (UK) id26153 View details | United Kingdom | Healthcare / Pharma | — | |
|
ConvaTec Group (UK), also known as Convatec Group plc, is a medical products and technologies company based in London, England, offering advanced wound care, ostomy care, continence care, and infusion care solutions to healthcare providers. The firm, headquartered at 20 Eastbourne Terrace in London, also manufactures catheters and drug delivery systems for the healthcare and pharma sector. ConvaTec Group (UK) serves patients and healthcare providers with pioneering trusted medical solutions to improve lives across the United Kingdom and globally. The company was listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Spirax-Sarco Engineering (UK) id26152 View details | United Kingdom | Manufacturing / Engineering | — | |
|
Spirax-Sarco Engineering plc, now known as Spirax Group plc, is a British manufacturer headquartered in Cheltenham, England, specializing in steam management systems and peristaltic pumps. The company is the world's leading manufacturer of steam traps and a top producer of peristaltic pumps through its subsidiary Watson-Marlow. It offers a range of technologies for the efficient control and use of steam and industrial fluids, supporting sustainability and thermal energy optimization. Spirax-Sarco Engineering UK was listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Bruker Corporation (USA) id26151 View details | United States | Communication / Marketing | — | |
|
Bruker Corporation is a U.S.-based company headquartered in Billerica, Massachusetts, and it develops, manufactures, and distributes scientific instruments and analytical and diagnostic solutions. Its portfolio supports molecular and materials research, life sciences, and industrial and applied analysis across research and commercial settings. Public company and directory sources describe Bruker as a leading analytical instrumentation manufacturer with business groups spanning multiple scientific disciplines. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Cochlear Limited (Australia) id26150 View details | Australia | Other | — | |
|
Cochlear Limited is an Australian-based medical device company that designs, manufactures, and supplies implantable hearing solutions, including the Nucleus cochlear implant and Baha bone conduction implant. Headquartered in Sydney, the company is the global leader in implantable hearing solutions and has helped over 700,000 people restore their hearing since its founding in 1981. Its products serve both pediatric and adult populations across more than 180 countries, focusing on innovation and research to treat moderate to profound hearing impairment. Cochlear Limited was listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Ansell Limited (Australia) id26149 View details | Australia | Manufacturing / Engineering | — | |
|
Ansell Limited is an Australian company based in Richmond, Victoria, with operations in manufacturing and engineering-related safety markets. It produces and distributes personal protective equipment and other protective products for healthcare, industrial, and professional use. The company is known for gloves and broader workplace safety solutions, serving customers across multiple regions. In threat-intelligence indexing, Ansell Limited was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Elekta (Sweden) id26148 View details | Sweden | Healthcare / Pharma | — | |
|
Elekta is a Swedish medical technology company headquartered in Stockholm, Sweden. It develops and supplies radiotherapy, radiosurgery, and oncology software solutions used in cancer and brain disorder treatment. The company serves healthcare providers globally and is known for products such as linear accelerators, Gamma Knife systems, and treatment-planning software. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Dentsply Sirona (USA) id26147 View details | United States | Healthcare / Pharma | — | |
|
Dentsply Sirona is a U.S.-based dental products and technology company headquartered in Charlotte, North Carolina, with major operations in York, Pennsylvania. It is described as the world’s largest manufacturer of professional dental products and technologies, serving dental professionals with equipment, consumables, software, and practice solutions. Its portfolio supports dentistry across restorative, endodontic, imaging, and digital workflow applications, and it markets products in more than 120 countries. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Fortis International Clinics (UAE) id26146 View details | United Arab Emirates | Healthcare / Pharma | — | |
|
Fortis International Clinics in the UAE is part of the Fortis healthcare brand, which provides hospital and clinic-based medical services for patients in Dubai and other markets. Available descriptions of the Fortis network indicate a broad healthcare footprint with services ranging from specialist treatment to international-patient support and coordinated care. In the UAE context, its offerings are associated with outpatient and clinic-oriented medical services within the healthcare and pharma sector. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Bumrungrad Medical Center (Thailand) id26145 View details | Thailand | Healthcare / Pharma | — | |
|
Bumrungrad Medical Center is a healthcare provider in Thailand, based in Bangkok, and known for delivering multi-specialty medical services to local and international patients. Its offerings include comprehensive health screening, specialist treatment, and advanced clinical care across major disciplines such as cardiology, oncology, orthopedics, neurology, fertility, and other hospital services. The institution operates as a private hospital with a broad care model centered on diagnostics, treatment, and preventive medicine. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | SKF Group (Sweden) id26144 View details | Sweden | Manufacturing / Engineering | — | |
|
SKF Group is a Swedish industrial company headquartered in Gothenburg, Sweden, with roots dating back to 1907. It develops and supplies bearings, seals, lubrication systems, maintenance products, mechatronics, condition monitoring, and related engineering services for global industrial customers. The group focuses on engineering, maintenance, condition monitoring, and remanufacturing across a broad range of industries. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Amcor Packaging Global (Australia) id26143 View details | Australia | Services | — | |
|
Amcor Packaging Global (Australia) is an Australia-based packaging company in the services sector, operating as part of Amcor’s broader global packaging business. Amcor develops and produces flexible packaging, rigid containers, specialty cartons, closures, and related packaging services for food, beverage, pharmaceutical, medical-device, home, and personal-care markets. The company is based in Australia and operates within a large multinational packaging footprint spanning multiple countries. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Atlas Copco (Sweden) id26142 View details | Sweden | Manufacturing / Engineering | — | |
|
Atlas Copco is a Swedish multinational industrial company headquartered in Nacka, near Stockholm, Sweden. It develops and supplies compressors, vacuum solutions, air treatment systems, industrial tools, and related services for manufacturing and other industrial applications. The group serves customers across sectors such as industrial machinery, electronics, and process-driven production, with a strong focus on productivity and energy efficiency. In threat-intelligence catalogs, Atlas Copco (SE) is listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Sandvik Mining and Rock (Sweden) id26141 View details | Sweden | Manufacturing / Engineering | — | |
|
Sandvik Mining and Rock Technology is a Swedish business unit of Sandvik, a global engineering group headquartered in Stockholm, Sweden. It supplies equipment, tools, service, and technical solutions for mining and rock excavation, including rock drilling, rock cutting, crushing, and related support products. The unit serves mining and construction operations with products designed to improve productivity, safety, and efficiency. In threat-intelligence indexing, Sandvik Mining and Rock (Sweden) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Fujitsu Industrial (Japan) id26140 View details | Japan | Manufacturing / Engineering | — | |
|
Fujitsu Industrial (Japan) is part of Fujitsu’s manufacturing and engineering operations in Japan, supporting industrial production and related technology services. Fujitsu’s Japan-based facilities and manufacturing initiatives include precision component production, factory engineering, and manufacturing DX support across the country. The company is associated with Japan’s manufacturing sector and reflects Fujitsu’s broader role in industrial systems, production engineering, and factory operations. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Fanuc Corporation (Japan) id26139 View details | Japan | Manufacturing / Engineering | — | |
|
FANUC Corporation is a Japanese industrial automation company headquartered in Oshino-mura, Yamanashi Prefecture, Japan. It develops and sells computer numerical control systems, industrial robots, and factory automation equipment for manufacturing operations. The company is widely known for robotics and CNC technologies used in precision production environments. In this threat-intelligence index, FANUC is listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Freudenberg Technology Group (Germany) id26138 View details | Germany | IT | — | |
|
Freudenberg Technology Group is part of the Freudenberg Group, a global, family-owned technology and materials company headquartered in Weinheim, Germany. In Germany, Freudenberg operates across more than 100 locations and serves a range of industries through business groups spanning sealing technologies, filtration, performance materials, home and cleaning solutions, medical products, and related industrial offerings. The company describes itself as a technology group focused on developing solutions for customers and society through innovation. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | AdventHealth Group (USA) id26137 View details | United States | Healthcare / Pharma | — | |
|
AdventHealth Group is a US healthcare organization associated with AdventHealth’s multi-state care network, which provides primary care, specialty care, urgent care, imaging, rehabilitation, and home health services. AdventHealth describes itself as a leader in whole-person health care with locations across the country and a broad menu of physician and patient services. The group’s offerings are centered on prevention, chronic disease management, wellness, and coordinated clinical care for patients and families. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Legrand Building Infra (France) id26136 View details | France | Construction / Real Estate | — | |
|
Legrand Building Infra is a French specialist in electrical and digital building infrastructure, operating within the construction and real estate sector in France. The company provides products such as switches, sockets, circuit protection, power distribution, cable management, structured cabling, rack power units, uninterruptible power supplies, audiovisual infrastructure, door-entry systems, and connected controls for homes, offices, hospitals, and data centers. Its offerings are designed to sit inside buildings and data centers, supporting technological, societal, and environmental change. Legrand Building Infra was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Sika Construction Chemicals (Switzerland) id26135 View details | Switzerland | Manufacturing / Engineering | — | |
|
Sika Construction Chemicals (Switzerland), known as Sika AG, is a Swiss multinational specialty chemical company headquartered in Baar, CH, serving the building and motor vehicle industries. The company develops and produces systems and products for bonding, sealing, damping, reinforcing, and protecting in construction and automotive sectors. Its product lines include sealants, adhesives, admixtures, mortars, roofing, and waterproofing systems for construction and industrial manufacturing applications. Sika Construction Chemicals (Switzerland) was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Bupa Global Health (UK) id26134 View details | United Kingdom | Healthcare / Pharma | — | |
|
Bupa Global Health (UK) is part of Bupa’s premium international private healthcare and insurance business, serving customers from the United Kingdom and other markets. It provides international private medical insurance and access to global healthcare networks, including specialist care and treatment support abroad. Bupa Group also operates across clinics, digital health services, hospitals, dental centres, and aged care facilities, reflecting its wider healthcare footprint in GB and beyond. In threat-intelligence indexing, Bupa Global Health (UK) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Magna Automotive Systems (Canada) id26133 View details | Canada | Manufacturing / Engineering | — | |
|
Magna Automotive Systems (Canada) is part of Magna International, a Canadian automotive supplier headquartered in Aurora, Ontario, with manufacturing, engineering, and sales operations in Canada and abroad. The company develops and manufactures automotive systems, assemblies, modules, and components, and provides complete vehicle engineering and contract manufacturing services for global vehicle makers. Its product portfolio includes body exteriors and structures, power and vision technologies, seating systems, and related mobility systems. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Mediclinic Middle East (UAE) id26132 View details | United Arab Emirates | Healthcare / Pharma | — | |
|
Mediclinic Middle East is a leading private healthcare provider in the United Arab Emirates, with most of its operations in Dubai and Abu Dhabi, including Al Ain. It operates hospitals and clinics that deliver acute, specialist, and multidisciplinary medical care across the country. Public company materials describe a broad care network that includes hospitals, outpatient services, and other clinic-based offerings in the UAE. In threat-intelligence indexing, Mediclinic Middle East was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | SMC Corporation (Japan) id26131 View details | Japan | Manufacturing / Engineering | — | |
|
SMC Corporation is a Japanese manufacturing and engineering company headquartered in Sotokanda, Chiyoda-ku, Tokyo. Founded in 1959, it specializes in pneumatic control engineering and provides automation technologies and components used across industrial applications. The company is known for supporting factory and industrial automation with compressed-air-based control devices and related systems. In threat-intelligence indexing, SMC Corporation (Japan) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Fresenius Medical Care (Germany) id26130 View details | Germany | Healthcare / Pharma | — | |
|
Fresenius Medical Care is a German healthcare company based in Bad Homburg, Germany, and a leading provider of products and services for people with chronic kidney failure. Its portfolio includes kidney dialysis, therapeutic apheresis, vascular access care, renal pharmacy, and laboratory and diagnostic services. The company operates across the renal care value chain and serves patients through products, therapies, and clinical services. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Sunnybrook Health Sciences (Canada) id26129 View details | Canada | Healthcare / Pharma | — | |
|
Sunnybrook Health Sciences Centre is a major healthcare organization in Toronto, Ontario, Canada, operating at 2075 Bayview Avenue. It provides hospital-based medical care and is known for services including heart and stroke care, cancer care, trauma care, women’s health, research, and medical education. Sunnybrook works in partnership with the University of Toronto and supports clinical innovation, patient care, and academic health sciences activity. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Mayo Clinic (USA) id26128 View details | United States | Healthcare / Pharma | — | |
|
Mayo Clinic is a private American academic medical center focused on integrated healthcare, education, and research, with major campuses in Rochester, Minnesota; Jacksonville, Florida; and Phoenix/Scottsdale, Arizona. It maintains a nonprofit hospital system offering comprehensive medical specialties and virtual care 24/7 through its patient portal. The organization serves patients from over 130 countries with world-class expertise in diagnosing and treating complex medical challenges. Mayo Clinic was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | King Faisal Specialist (Saudi Arabia) id26127 View details | Saudi Arabia | Healthcare / Pharma | — | |
|
King Faisal Specialist Hospital and Research Centre is a non-profit tertiary healthcare institution headquartered in Riyadh, Saudi Arabia, with facilities in Riyadh, Jeddah, and Madinah. It provides specialized healthcare in an integrated educational and research setting, including tertiary and quaternary care services across major clinical specialties. Publicly described services include critical care, oncology, outpatient care, and health outreach support for patients across the Kingdom. In threat-intelligence indexes, King Faisal Specialist (Saudi Arabia) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Oerlikon Surface Solutions (Switzerland) id26126 View details | Switzerland | Services | — | |
|
Oerlikon Surface Solutions is part of the Switzerland-based Oerlikon Group, a listed technology company headquartered in Pfäffikon, Switzerland. It develops surface technologies that include materials, coating equipment, and coating services for industrial applications. The business serves demanding environments where its solutions help reduce wear, friction, heat, and corrosion, and it operates across multiple industries and countries. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Spire Diagnostics (Global/UK) id26125 View details | United Kingdom | Services | — | |
|
Spire Diagnostics (Global/UK) is a United Kingdom-based services company associated with private healthcare and diagnostic provision under the Spire name. Public company information for Spire Healthcare shows a London headquarters and a UK-wide network of hospitals and clinics offering private and NHS care, which aligns with a healthcare-services footprint in the UK. The company operates in a regulated care environment where diagnostic, clinical, and outpatient services are central to patient delivery. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Medtronic (Global/Ireland) id26124 View details | Ireland | Healthcare / Pharma | — | |
|
Medtronic is a world-leading medical technology company headquartered in Galway, Ireland, developing and manufacturing a vast array of medical devices and therapies including pacemakers, insulin pumps, and robotic-assisted surgery systems. The company has invested approximately 11 billion euros in Ireland, with 1.2 billion euros dedicated to research and development, and operates a European software hub in Galway focused on cardiac care systems. Medtronic addresses over 70 health conditions globally through its advanced healthcare technology portfolio, aiming to alleviate pain, restore health, and extend life. The company was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Spire Healthcare (UK) id26123 View details | United Kingdom | Healthcare / Pharma | — | |
|
Spire Healthcare Group plc is a UK private healthcare provider that operates hospitals, clinics, consulting rooms and medical centres, serving both private patients and the NHS. It offers a broad range of services, including prevention, diagnostics, treatment and surgery, across its healthcare network in Great Britain. The company is positioned as a major provider in the UK healthcare market and focuses on clinical care and patient services. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Raffles Medical Group (Singapore) id26122 View details | Singapore | Healthcare / Pharma | — | |
|
Raffles Medical Group is a Singapore-based private healthcare provider operating hospitals, clinics, dental and Chinese medicine services, health screening, and insurance offerings. It serves patients through medical facilities in Singapore and across other Asian cities, and describes itself as one of the region’s largest private healthcare groups. The group also provides supplements and related health services through affiliated businesses. In threat-intelligence listings, Raffles Medical Group (Singapore) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | St. Jude Children's Research Hospital (USA) id26121 View details | United States | Healthcare / Pharma | — | |
|
St. Jude Children's Research Hospital is a nonprofit pediatric medical center and research institution in Memphis, Tennessee, focused on treating and studying catastrophic childhood diseases, especially cancer. It provides specialized hospital care, clinical research, and prevention work for pediatric patients while advancing cures for life-threatening conditions. The institution is widely recognized for its national cancer-center status and its mission-driven role in pediatric healthcare and biomedical research. In threat-intelligence listings, it was recorded as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Singapore Health Services (SingHealth) id26120 View details | Singapore | Healthcare / Pharma | — | |
|
Singapore Health Services (SingHealth) is Singapore’s largest healthcare group, based in Singapore, and operates a broad network of acute hospitals, community hospitals, national specialty centres, and polyclinics. It provides healthcare services across more than 40 clinical specialties and supports care delivery through hospitals, specialist centres, and primary care facilities. SingHealth focuses on affordable, accessible, and quality healthcare for patients across the city-state. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Kaiser Permanente (USA) id26119 View details | United States | Healthcare / Pharma | — | |
|
Kaiser Permanente is a US-based integrated healthcare organization headquartered in Oakland, California, serving members through health plan coverage, hospitals, and affiliated medical groups. Its model combines medical services and insurance coverage across multiple states, with care that includes preventive, primary, specialty, and hospital services. The organization operates as a major provider in the healthcare sector and supports patients through coordinated clinical and coverage offerings. In threat-intelligence indexing, Kaiser Permanente (USA) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Stryker Corporation (USA) id26118 View details | United States | Healthcare / Pharma | — | |
|
Stryker Corporation is an American medical technology company headquartered in Portage, Michigan, in the United States. It develops products used in medical surgery, neurotechnology, orthopedic surgery, and related healthcare workflows, including surgical equipment, implants, patient safety technologies, and emergency medical devices. The company serves hospitals and clinicians across global markets and reports a broad portfolio spanning MedSurg and orthopedic solutions. In threat-intelligence indexing, Stryker Corporation (USA) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Metso Mining Solutions (Finland) id26117 View details | Finland | Services | — | |
|
Metso Mining Solutions is part of Metso, a Finnish industrial technology company based in Espoo, Finland, with operations focused on mining and related process industries. Its mining offering includes plant design expertise, equipment, parts, and services for stages of the mining process, along with digital solutions that help improve throughput, recoveries, uptime, and productivity. The company is part of a broader portfolio serving aggregates, minerals processing, and metals refining customers. In threat-intelligence records, Metso Mining Solutions (Finland) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Gleneagles Hospital Group (Singapore) id26116 View details | Singapore | Healthcare / Pharma | — | |
|
Gleneagles Hospital is a private hospital in Singapore that provides medical and surgical services through a broad range of specialist care. It operates on Napier Road and offers services such as oncology, cardiology, gastroenterology, orthopedics, diagnostic imaging, and other hospital-based treatment. The hospital is part of Parkway Hospitals Singapore and the wider Parkway Pantai/IHH Healthcare network, which serves private healthcare markets across Asia. In threat-intelligence records, Gleneagles Hospital Group (Singapore) was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Linde PLC (UK/Germany) id26115 View details | United Kingdom | Manufacturing / Engineering | — | |
|
Linde plc is a global industrial gases and engineering company headquartered in Woking, United Kingdom, with major operations in Germany and other markets. It supplies atmospheric, process, specialty, industrial, and healthcare gases, and provides related equipment and gas-processing engineering solutions. The company serves customers across manufacturing, chemicals, healthcare, electronics, and other industrial sectors. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Vallourec Tube Manufacturing (France) id26114 View details | France | Manufacturing / Engineering | — | |
|
Vallourec Tube Manufacturing is the French industrial arm of Vallourec, headquartered in France with major sites and an R&D center supporting its global business. The company produces seamless steel tubes, hollow sections, and tubular solutions for energy, industrial, and engineering applications, with a footprint that includes manufacturing and welding technology facilities. Its French operations serve Vallourec’s broader markets across oil and gas, low-carbon energy, hydrogen, and other demanding industrial uses. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Honeywell Aerospace (Global/USA) id26113 View details | United States | Communication / Marketing | — | |
|
Honeywell Aerospace Technologies is Honeywell’s aerospace business, based in Phoenix, Arizona, and it supplies products and services for commercial, defense, and space aircraft worldwide. Its offerings include aircraft propulsion, cockpit systems, satellite and navigation solutions, and related aerospace technologies designed to improve flight safety, efficiency, comfort, and sustainability. The business has been described by Honeywell as a global provider serving virtually every commercial, defense, and space aircraft platform. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Dassault Systèmes (France) id26112 View details | France | Other | — | |
|
Dassault Systèmes is a French multinational software company headquartered in Vélizy-Villacoublay, France, with a global presence and market reach. It develops software for 3D product design, simulation, manufacturing, and other 3D-related applications, and its 3DEXPERIENCE platform supports virtual twin experiences for innovation and production. The company is widely categorized in the software development sector and operates as a public company serving industrial and enterprise customers worldwide. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Yara Global Fertilizers (Norway) id26111 View details | Norway | Manufacturing / Engineering | — | |
|
Yara Global Fertilizers (Norway), operating under Yara International ASA, is a Norwegian chemical company that produces, distributes, and sells nitrogen-based mineral fertilizers and related industrial products. It is one of the world’s largest producers of synthetic fertilizers, with its largest business being nitrogen fertilizers, the world’s most common fertilizer type. The company also manufactures nitrates, ammonia, urea, and other nitrogen-based chemicals, serving over 140 markets across 60 countries. The Norwegian state is its major shareholder, controlling over 40% of the company’s shares. Yara Global Fertilizers (Norway) was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | BASF SE (Germany) id26110 View details | Germany | Manufacturing / Engineering | — | |
|
BASF SE is a German multinational chemical company headquartered in Ludwigshafen, Germany, and widely recognized as the world’s largest chemical producer. It develops and supplies chemicals, materials, and industrial solutions for manufacturing, engineering, and related global markets. The company operates one of the world’s largest integrated chemical complexes at its Ludwigshafen site. In threat-intelligence indexing, BASF SE is listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Liberia Electricity Corporation (LEC) id26066 View details | Liberia | Energy | — | |
|
Liberia Electricity Corporation (LEC) is Liberia’s state-owned electric utility, based in Monrovia, and it is responsible for generating, transmitting, distributing, and supplying electric power across the country. It works to expand grid access, improve reliability, and support electricity services for households and businesses in Liberia. In public descriptions, LEC is also associated with projects to restore and extend the Monrovia grid and develop mini-grids and stand-alone systems in interior areas. The company was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Liberia Revenue Authority id26065 View details | Liberia | Public Sector | — | |
|
The Liberia Revenue Authority is a public sector government organization located in Paynesville, Liberia, established to assess, collect, audit, and account for all national revenues. It administers and enforces Liberia's revenue laws, including taxation and tax exemptions, while facilitating legitimate trade and social protection for the people of Liberia. The Authority replaced the Department of Revenue of the Ministry of Finance to professionally and transparently collect lawful revenues and enhance the government's ability to fund public services. The Liberia Revenue Authority was listed as a ransomware victim associated with the 0apt threat actor. |
|||||
| Ransomware | National Investment Commission Liberia id26064 View details | Liberia | Finance / Legal / Insurance | — | |
|
National Investment Commission Liberia is Liberia’s government investment promotion agency, based in Monrovia, that attracts, facilitates, and supports domestic and foreign investment. It promotes the country’s investment opportunities, helps generate sustainable employment, and works to strengthen Liberia’s economic competitiveness through an investor-friendly environment. Public descriptions also note its role in guiding investors and supporting business registration and licensing services. The entity was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | SoftCore Tech Solutions id26041 View details | India | IT | — | |
|
SoftCore Tech Solutions is an India-based IT company that operates in business technology and ERP services. Public company profiles describe SoftCore Solutions Pvt. Ltd. as a global business technology solutions provider and an ERP, CRM, and cloud implementation partner in India, with SAP Business One among its offerings. It also presents itself as a SAP Business One Gold Partner serving customers across India and international markets. In threat-intelligence indexing, SoftCore Tech Solutions was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Prime Port Authorities id26040 View details | Communication / Marketing | — | ||
|
Prime Port Authorities is a port-authority related organization in the Communication / Marketing sector, a category that commonly covers stakeholder messaging, promotion, and public-facing communications for port and maritime businesses. Port authorities typically use marketing and communications to support business-to-business outreach, community relations, and institutional engagement, with offerings centered on service promotion and stakeholder communication. The entity name suggests a port- or logistics-focused authority or communications function, but publicly available details are limited. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Titan Mining Corp id26039 View details | Canada | Services | — | |
|
Titan Mining Corporation is an Augusta Group company based in Canada with corporate contact information in Vancouver and Toronto, and it operates in the natural resources space rather than the mining-services sector implied by the listing. Public company materials say Titan produces zinc concentrate at its 100%-owned Empire State Mine in New York and is also developing natural flake graphite production. The company presents itself as a growing zinc producer with exposure to graphite, supported by mineral extraction, processing, and project development activities. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Skyline Logistics Group id26038 View details | United States | Transportation / Travel / Logistics | — | |
|
Skyline Logistics Group is a US-based transportation and logistics company associated with freight movement, delivery, and related supply-chain services. Public business listings describe Skyline Logistics as operating in freight and logistics services and providing transportation, logistics, and delivery support across the United States. The company is also listed in federal carrier records as a logistics broker, reflecting its role in coordinating transport services. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | EverGreen Agricultural id26037 View details | United States | Agriculture / Food | — | |
|
EverGreen Agricultural is a United States company in the agriculture and food sector, a broad field that includes farming, agronomy, and related food production activities. Publicly available search results do not provide enough verified detail to identify its exact offerings, so this description stays at the sector level. In threat-intelligence indexing, the name is used to identify a U.S.-based agricultural business context rather than a consumer brand. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Lumina Advertising id26036 View details | Romania | Communication / Marketing | — | |
|
Lumina Advertising is a communication and marketing company in Romania, a country in southeastern Europe. The business operates in the advertising and marketing services space, where firms typically support brand strategy, campaign planning, creative production, and client communications. Its name indicates a commercial services provider focused on promotional and market-facing work. In threat-intelligence indexing, Lumina Advertising was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Zenith Aerospace id26035 View details | United States | Communication / Marketing | — | |
|
Zenith Aerospace is a US-based aerospace technology company focused on aerial telecommunications systems and stratospheric aircraft that support internet access without ground infrastructure. Public company profiles describe it as operating in aviation and aerospace component manufacturing, with a Belmont, California presence and offerings aimed at resilient communications for telecom, remote, defense, and recovery use cases. Its work centers on flight systems, autonomy, and communications technologies designed to expand connectivity and data-sharing capabilities. In the threat-intelligence index, Zenith Aerospace was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Metro Food Wholesalers id26034 View details | Agriculture / Food | — | ||
|
Metro Food Wholesalers is a food-sector wholesaler; available business listings describe Metrofoods as a wholesale distributor of food products, cleaning essentials, and packaging solutions based in Auckland, New Zealand. Another company record with a similar name shows a UK-registered Metro Food Wholesale Ltd, but the public results do not clearly confirm which legal entity is meant here. In this context, the name refers to a wholesale food business in the Agriculture / Food sector, serving buyers that need bulk supply and related trade goods. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | IronClad Security Services id26033 View details | Services | — | ||
|
IronClad Security Services, Inc. is a private security company based in Santa Clara, California, serving clients across the San Francisco Bay Area and broader California. Its published offerings include security guard services, patrol services, executive protection, and tailored security strategies for commercial and industrial settings. The company also describes service coverage for manufacturing facilities, storage facilities, commercial buildings, high-tech facilities, and government or military environments. In threat-intelligence indexing, IronClad Security Services is listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | CloudLink Systems id26032 View details | Canada | IT | — | |
|
CloudLink Systems is an IT solutions company headquartered in Canada, specializing in cloud encryption management and innovative technology delivery for organizations across the USA and globally. The firm offers cloud consulting, software development, and machine learning services as a certified AWS Partner, supporting diverse security workloads. Known for its ISO 9001:2015 and ISO 27001 certifications, CloudLink Systems delivers seamless IT solutions to meet business goals. The company was neutrally listed as a ransomware victim associated with the 0apt threat actor, underscoring emerging cyber threats in the IT sector. |
|||||
| Ransomware | EduPro University Group id26031 View details | Education | — | ||
|
EduPro University Group is an education services group headquartered in Vienna, Austria, focused on continuing education, further qualification, and adult learning. It operates across Austria, Germany, and Hungary and offers vocational qualification measures and related training services. The group describes its portfolio as ranging from individual mentoring to certified advanced training for learners and companies. In threat-intelligence indexing, EduPro University Group was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Horizon Energy Partners id26030 View details | United States | Energy | — | |
|
Horizon Energy Partners is an energy-sector company in the United States, identified in business records as a privately held oil and gas exploration and production firm with offices in Denver, Colorado and Houston, Texas. Public company profiles also describe related Horizon Energy Partners entities as operating in oil and gas, placing the name within the broader US energy industry. In cataloging and threat-intelligence contexts, it is treated as an energy-sector target rather than as a consumer-facing brand. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | alex Retail Solutions id26029 View details | Retail / E-commerce | — | ||
|
alex Retail Solutions is an Australia-based software company in Melbourne, Victoria, founded in 2016. It provides an enterprise data operations and metadata management platform, including data cataloging, governance, lineage, quality, glossary, compliance, and privacy tools, and serves sectors such as retail and e-commerce. Its retail offering is designed to help organizations manage operations and customer-related data more effectively. The company is headquartered in Melbourne and positions its platform around trusted data intelligence for business users. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | PureStream Water Corp id26028 View details | United States | Manufacturing / Engineering | — | |
|
PureStream Water Corp is a United States-based company in the manufacturing and engineering space. Public web results do not provide a clear official corporate profile for the exact entity, but the name suggests a water-related industrial business that may operate in treatment, equipment, or services. In the absence of a verified company disclosure, the safest description is a US manufacturing and engineering firm associated with water-sector offerings. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | BioGenix Pharmaceuticals id26027 View details | United States | Healthcare / Pharma | — | |
|
BioGenix Pharmaceuticals is a leading regenerative therapy company based in the United States, specializing in preventative and regenerative medicine to help patients recover from past injuries. The company operates across multiple locations including Houston, Texas, Irvine, California, and San Diego, California, offering advanced therapies that transform healthcare outcomes. BioGenix is recognized as the World's Leading Regenerative Therapy Company, driven by the recognition that regenerative medicine presents hope to patients. It was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Global Media Alliance id26026 View details | Ghana | Communication / Marketing | — | |
|
Global Media Alliance is a Ghana-based communications and media company in Accra, Greater Accra, with a presence in public relations, media consultancy, events management, creative services, digital marketing, and brand activation. Company materials describe it as a leading integrated media and entertainment firm that supports clients with broadcasting, corporate communications, crisis management, and social media marketing. Its footprint extends across multiple African markets, including West Africa. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Vertex Law Chambers id26025 View details | India | Finance / Legal / Insurance | — | |
|
Vertex Law Chambers appears to be a legal-services entity operating in India, where firms in this segment typically advise clients on corporate, litigation, finance, and related regulatory matters. Publicly available business listings and law-firm profiles under the Vertex name point to legal and advisory services, including corporate and banking-related work, though the exact operating footprint of this specific entity is not fully clear from available sources. In catalog and threat-intelligence indexing, the name is therefore best treated as a legal-sector organization in India rather than as a consumer-facing brand. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Silverline Auto Mfg id26024 View details | United States | Manufacturing / Engineering | — | |
|
Silverline Auto Mfg operates in the manufacturing and engineering sector within the United States, focusing on automotive production and related industrial offerings. The entity is based in the US and delivers specialized manufacturing solutions for the automotive industry. While specific product details are not publicly confirmed, its sector alignment indicates involvement in auto component or system fabrication. Silverline Auto Mfg was listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Oceanic Cruise Lines id26023 View details | Other | — | ||
|
Oceanic Cruise Lines appears to refer to Oceania Cruises, a U.S.-based luxury cruise line headquartered in Miami, Florida, and part of Norwegian Cruise Line Holdings. The brand operates small ships and promotes culinary- and destination-focused voyages, with itineraries to more than 600 destinations worldwide. Public company and brand sources describe it as an adults-only, upper-premium cruise operator offering immersive travel, elegant ships, and specialty dining. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Terraform Real Estate id26022 View details | United States | Construction / Real Estate | — | |
|
Terraform Real Estate is a real estate development and investment brand operating in the United States, with listings and company profiles pointing to activity in the construction and real estate space. Publicly available business profiles describe Terraform-related firms as focused on property development, investment management, and net lease projects. The name is also used by real estate businesses in different markets, so sector and location should be read in context. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | FutureTech AI id25984 View details | IT | — | ||
|
FutureTech AI is an IT-sector company associated with AI and data science solutions, presenting itself as a provider that helps enterprise organizations accelerate adoption of advanced AI and related software tools. Public materials describe Future Tech Enterprise, Inc. as an award-winning IT solutions provider with global reach, and its AI-focused offering emphasizes curated data science stacks for enterprise use. Based on the available sources, the company is best characterized as an IT services and AI solutions brand with operations centered on enterprise technology support. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Urban Outfitters Ltd id25983 View details | United States | Services | — | |
|
Urban Outfitters Inc. is a Philadelphia-based U.S. lifestyle retailer in the services and retail space, founded in 1970. It operates a multibrand business that includes stores and e-commerce, with apparel and home goods among its core offerings. Public company profiles describe it as a global lifestyle brand with a broad consumer retail footprint in the United States and abroad. In threat-intelligence indexing, Urban Outfitters Ltd was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | National Rail Network id25982 View details | Telecommunications | — | ||
|
National Rail Network is a telecommunications-focused organization operating within the rail infrastructure sector, primarily serving customers in England, Scotland, and Wales by providing passenger service information and train location data. It functions as a definitive source for customer information on National Rail passenger services across these regions, offering real-time updates on train running and forward progress through its Track Your Train service. The entity reinvests its income into railway operations and operates as a non-departmental public body under the Department for Transport with no shareholders. National Rail Network was listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | CryptoVault Exchange id25981 View details | Norway | Other | — | |
|
CryptoVault Exchange is a cryptocurrency platform operating in Norway, offering digital asset trading and related financial services to users in the crypto sector. As a crypto-friendly location, Norway supports businesses providing secure payment ecosystems for customers, agents, or employees seeking complete access to digital currencies. The platform functions within the broader cryptocurrency market, which continues to expand globally with increasing adoption of trading and investment activities. CryptoVault Exchange was listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Elite Hospitality Group id25980 View details | Bahrain | Healthcare / Pharma | — | |
|
Elite Hospitality Group is a hospitality company based in the Kingdom of Bahrain, with its main offices in Manama and PO Box 5458. Company materials describe it as a leading Bahrain hospitality brand that offers all-suite four-star accommodation and a range of lifestyle lodging options. Its public profiles also describe it as a provider of quality accommodation services in Bahrain. In threat-intelligence indexing, Elite Hospitality Group was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Noble Pharma id25979 View details | Japan | Healthcare / Pharma | — | |
|
Nobelpharma Co., Ltd. is a Japanese pharmaceutical company headquartered in Tokyo, Japan, with a focus on research, development, approval, and commercialization of medicines and medical devices. The company emphasizes treatments for unmet medical needs, including drugs for rare or difficult diseases that larger firms may overlook. Its profile describes a business that advances products through later-stage clinical trials, regulatory review, approval, pricing, and sales in Japan. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Rapid Courier Services id25978 View details | Services | — | ||
|
Rapid Courier Services is a San Diego, California-based courier company in the Services sector, described in business listings as providing medical and general delivery services. Its offerings include secure, compliant medical logistics as well as broader business courier support for documents, packages, and specialized deliveries. The company profile also identifies it as an established courier provider serving local delivery needs. Rapid Courier Services was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Global News Corp id25977 View details | Services | — | ||
|
Global News Corp Ltd is a United Kingdom company in the services sector, with public corporate filings showing it as a registered business in the UK. Available records identify the entity by its corporate registration and administrative profile rather than by a detailed public product or service description. In threat-intelligence indexes, the name should be treated as a distinct company record and not conflated with similarly named global media groups. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Zenith Telecom id25976 View details | Telecommunications | — | ||
|
Zenith Telecom is a telecommunications company operating in the communications sector, serving business and network-related connectivity needs. Public business profiles describe it as a telecoms and systems-integration consultancy, while other listings use the name for telecom services firms in different countries, so the exact legal entity and location should be verified from primary records. In the telecommunications industry, companies under this name are associated with providing voice, data, connectivity, or related support services to commercial clients. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Visionary Architects id25975 View details | Communication / Marketing | — | ||
|
Visionary Architects is associated with communication and marketing services in the United States, a sector that typically includes branding, outreach, and related client-facing work. Public directory and profile listings describe Visionary Architects as a design and architecture-related firm, with references to integrated design, master planning, and marketing-oriented services across similar business records. The name is also used in profiles tied to architecture and marketing communications, so the entity should be understood in that broader professional-services context. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Titan Construction id25974 View details | Construction / Real Estate | — | ||
|
Titan Construction is a construction company profile associated with the construction and real estate sector in the United States. Public business listings describe Titan Construction Group as a Midlothian, Virginia–based regional general contractor specializing in retail, restaurant, and office construction, with services that include project budgeting, development, and design/build. Separate business records also use the Titan Construction name for construction and remodeling firms in Indiana and Kansas, reflecting the broader, industry-specific branding behind the name. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Metro General Hospital id25973 View details | Healthcare / Pharma | — | ||
|
Metro General Hospital is a hospital listing in the Healthcare / Pharma sector, described as a provider of patient care services in a medical setting. The name is used by several hospital entities in the United States, including hospitals serving Cleveland and Nashville, which offer inpatient and outpatient care, emergency services, and other clinical treatment options. Because the query does not identify a single verified location, this entry is kept general and limited to the healthcare context supported by the available sources. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Obsidian Tech Labs id25972 View details | United States | IT | — | |
|
Obsidian Tech Labs is an IT-related technology company in the United States, appearing in public company listings under the Obsidian name and associated with software and digital infrastructure work. Available public profiles identify it as a U.S.-based technology business with a Delaware location and a focus on gaming and crypto-adjacent infrastructure offerings. A separate threat-intelligence report states that 0apt claimed responsibility for a ransomware attack against Obsidian Tech Labs on January 30, 2026. The listing identifies Obsidian Tech Labs as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Diamond Deep Drilling id25971 View details | Energy | — | ||
|
Diamond Deep Drilling is an Energy-sector company name associated with drilling services, a field that commonly supports exploration and production work in the energy industry. In this context, drilling companies may operate rigs, core samples, and related field services for subsurface evaluation and resource development. Available public search results did not provide a reliable official company profile, so a more detailed location or offerings description cannot be confirmed here without risking inaccuracy. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Solaris Renewable Energy id25970 View details | Energy | — | ||
|
Solaris Renewable Energy is an Energy-sector company associated with solar development, financing, and asset management services. Public company profiles describe it as based in Fort Collins, Colorado, and focused on distributed solar energy systems for non-residential customers, including low-cost financing arrangements and asset management. Its offerings are presented as part of the broader renewable energy transition, with services that support project development and long-term operation. In threat-intelligence indexing, Solaris Renewable Energy was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Sapphire Jewelry id25969 View details | Other | — | ||
|
Sapphire Jewelry is a jewelry business that operates in the broader jewelry sector, a category that includes sapphire rings, gemstone jewelry, and related retail offerings. Publicly available business listings and industry sources show that sapphire jewelry retailers commonly sell rings, necklaces, bracelets, and other gemstone pieces, with some firms also offering custom or luxury jewelry services. In this context, Sapphire Jewelry is cataloged as an entity in the jewelry market rather than a technology or services firm. The listing identifies Sapphire Jewelry as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Pacific Ocean Cargo id25968 View details | Transportation / Travel / Logistics | — | ||
|
Pacific Ocean Cargo appears to operate in the transportation, travel, and logistics sector, where companies coordinate freight movement, warehousing, and related supply-chain services. Public web results for similarly named Pacific Ocean logistics businesses describe ocean freight, air freight, road transport, forwarding, and container-handling services in the United States and abroad. In this industry, firms typically manage shipping flows across ports, carriers, and inland routes for commercial customers. Pacific Ocean Cargo was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | IronClad Security id25967 View details | Other | — | ||
|
IronClad Security appears to be a security services business in the United States, offering guard, patrol, and executive protection services. Public directory listings place Ironclad Security Services in Santa Clara, California, and describe service coverage across the San Francisco Bay Area and California. Another business profile for Ironclad Security, LLC identifies the company in the investigation and security services industry. In this index, IronClad Security was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Emerald Agriculture id25966 View details | Agriculture / Food | — | ||
|
Emerald Agriculture is an agriculture and food-sector company; available public records also point to a related U.S. business, Emerald BioAgriculture, based in Butte, Montana, that develops and supplies bio-nutrient and biostimulant products for crop performance. In sector terms, its offering aligns with plant nutrition, yield enhancement, and broader farm-input solutions used in agricultural production. Public company listings and industry materials indicate a small specialist operation rather than a diversified agribusiness, with a U.S. presence centered in Montana. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | GreenValley Agriculture id25965 View details | Agriculture / Food | — | ||
|
GreenValley Agriculture is an Egyptian agricultural company established in 2010 that grows, packs, and exports fresh produce. Its product range includes green beans, grapes, sugar snap peas, pomegranates, watermelon, and eggplant, and the company says it operates with multiple offices and packhouse capacity for seasonal output. Public company materials present it as a supplier of high-quality fresh produce with certifications including GlobalG.A.P., BRC, and TNC. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Crimson Fashion House id25964 View details | Other | — | ||
|
Crimson Fashion House is a Pakistan-based fashion retailer associated with Crimson, a clothing brand that sells embroidered and ready-to-wear apparel through an online retailer network. Its retailer page lists stockists in Pakistan and also shows international outlets in Bangladesh, Dubai, India, the United Kingdom, and the United States. The brand’s retail footprint indicates a consumer-facing apparel business with distribution beyond its home market. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Golden Chip Casino id25963 View details | Other | — | ||
|
Golden Chip Casino is a casino-branded entity in the Other sector; available web results do not provide a verified operating profile, location, or service details for a specific company by that name. The name may also overlap with casino loyalty or promotional terms used by online gaming brands, so public information should be treated cautiously. In threat-intelligence contexts, the listing identifies the entity by name rather than confirming the full scope of its business. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | EduTech Systems id25962 View details | IT | — | ||
|
EduTech Systems appears to be an IT-sector company associated with digital education services and related technology offerings. Publicly available references describe EduTech Systems as supporting the full spectrum of digital education, including interactive learning platforms and data-driven school management systems. The name and sector indicate an organization operating in education technology or adjacent software services, but no authoritative public profile in the provided results confirms a more specific corporate location or product line. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Silver City Bank id25961 View details | United States | Finance / Legal / Insurance | — | |
|
Silver City Bank is a U.S. financial institution name associated with the banking sector, where firms typically provide deposit, lending, and related account services to consumers and businesses. In catalog and threat-intelligence contexts, the name is used to identify a finance-sector entity operating in the United States, with a profile aligned to banking and adjacent legal or insurance services. Publicly available search evidence was insufficient to verify a detailed, first-party business profile for this exact entity, so this description remains limited to the sector and country provided. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Unity Insurance id25960 View details | Finance / Legal / Insurance | — | ||
|
Unity Insurance is an insurance company in the United States that provides insurance services and related coverage options through a local agency model. Public listings describe Unity Insurance and Investments as serving Minnesota and North Dakota, with offices in Red Lake Falls, Mentor, and Plummer, and offering free quotes on personal and commercial insurance products. Other public profiles describe Unity Insurance as a full-service independent insurance agency with a broad portfolio of insurance solutions. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Blue Water Utilities id25959 View details | Energy | — | ||
|
Blue Water Utilities is an energy-sector entity, and the name indicates a utility or utility-related business serving energy operations in the United States. Publicly available company profiles tied to the Blue Water name describe energy services such as technical support, offshore solutions, power-sector support, and related industrial services. Energy utilities and service providers typically support generation, operations, infrastructure, or field services across the power and industrial supply chain. In threat-intelligence listings, Blue Water Utilities was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Harbor Port Authority id25958 View details | Public Sector | — | ||
|
Harbor Port Authority is a public sector port authority in the United States, a type of agency that manages port assets, supports harbor protection and navigation safety, and oversees infrastructure and services that keep maritime trade moving. Port authorities commonly regulate fees and safety, maintain piers and waterways, and may also coordinate cargo handling, warehousing, and other day-to-day port functions. In practice, they help facilitate trade, support local economic activity, and manage the public infrastructure that serves the port community. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Ironworks Construction id25957 View details | Construction / Real Estate | — | ||
|
Ironworks Construction is presented as a company in the construction and real estate space, a sector that typically includes building, renovation, property development, and related project services. Publicly available search results do not provide enough verified detail to confirm its exact location or full service profile, so this listing treats the firm conservatively as a construction-sector entity with real estate ties. In threat-intelligence indexing, such entities are often cataloged by industry to help analysts track exposure patterns across infrastructure-adjacent organizations. Ironworks Construction was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | North Star Media id25956 View details | United States | Communication / Marketing | — | |
|
North Star Media Group is a full-service advertising and media buying agency based in the United States, specializing in strategic planning and placement of radio commercials, programs, and print advertising both locally and nationally. The agency offers services including media placement, audio and print production, creative design, and graphic design, positioning itself as a leading media buyer for radio paid programming placement. Operating primarily in the Communication and Marketing sector, the company serves clients across the US with comprehensive media buying solutions. The firm was neutrally listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | Radiant Solar Farms id25955 View details | Agriculture / Food | — | ||
|
Radiant Solar Farms is an Agriculture / Food-sector company in the United States, a category that often includes farming operations and related agricultural production. The name suggests a business focused on solar-linked farm activity or land use, but no authoritative public source in the provided results identifies its exact offerings or location. In agrivoltaic settings, agriculture and solar power are co-located on the same land, supporting crops, livestock, or other farm uses alongside energy generation. Radiant Solar Farms was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Kinetic Auto Makers id25954 View details | India | Other | — | |
|
Kinetic Auto Makers appears to be an India-based automotive company associated with the country’s broader automotive manufacturing and parts ecosystem. Publicly available sources on similarly named Kinetic entities describe businesses involved in vehicle, parts, or mobility-related offerings, but the exact public profile for Kinetic Auto Makers is limited in the available record. In threat-intelligence contexts, such listings help identify organizations connected to ransomware activity without asserting unverified incident details. Kinetic Auto Makers was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Velocity Automotive id25953 View details | Manufacturing / Engineering | — | ||
|
Velocity Automotive is a U.S.-based automotive technology company that provides software for dealerships, with tools aimed at sharing car-buying information, streamlining vehicle acquisition, and improving reconditioning and merchandising workflows. Its public website says the platform is built for faster, more efficient vehicle acquisition, reconditioning, and merchandising, and lists a Florida business address. In industry terms, it sits at the intersection of manufacturing and engineering software for automotive retail operations. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Stellar Aviation Parts id25952 View details | Manufacturing / Engineering | — | ||
|
Stellar Aviation Parts is a U.S.-based aviation business in the manufacturing and engineering space, with web listings tied to aircraft parts supply and aviation services. Publicly available company pages indicate offerings that include sourcing, supplying, and supporting aircraft parts and related aviation operations, with locations in Nevada and other U.S. markets. The name is associated online with Stellar Aviation Group and related aviation service entities, which present themselves as providers of aircraft parts and FBO support. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Quantum Research Labs id25951 View details | Other | — | ||
|
Quantum Research Labs is a research-focused organization in the quantum science and technology space, a sector that develops controlled environments and advanced systems for studying and building quantum devices. Publicly available search results do not provide a verified company profile, location, or product catalog for this exact entity, so its offerings cannot be stated beyond its name and sector. In threat-intelligence indexing, the name is treated as an organization in the research domain rather than as a confirmed manufacturer or service provider. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Noble & Associates Law id25950 View details | United States | Finance / Legal / Insurance | — | |
|
Noble & Associates Law is a US law firm based in Naperville, Illinois, that specializes in workers' compensation defense and general legal representation for related matters. Public business listings and the firm’s own site describe it as serving clients in the legal services sector, with an emphasis on defending workers' compensation cases in Illinois. In the broader Finance / Legal / Insurance category, it fits the profile of a professional-services firm handling regulated client matters and claims-related work. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Pacific Fisheries id25949 View details | Other | — | ||
|
Pacific Fisheries is a U.S.-based seafood business name associated in public sources with Pacific Seafood, a family-owned company founded in 1941 and headquartered in Clackamas, Oregon. The company supplies seafood products and works across the fishing supply chain, including direct relationships with independent commercial fishing vessels. It operates in the broader Other sector as a private-sector food and fisheries enterprise. Pacific Fisheries was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Apex Law Firm id25948 View details | United States | Finance / Legal / Insurance | — | |
|
Apex Law Firm is a US-based law firm serving clients in the legal sector, with publicly available listings that place it in Tampa, Florida, and describe practice areas including personal injury and insurance-related matters. Its website also references representation in complex litigation and financial services, indicating a broader civil litigation and advisory focus. Public business profiles and site pages identify it as a law office that helps clients pursue claims and handle disputes with insurers and other responsible parties. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Quantum Physics Lab id25947 View details | Other | — | ||
|
Quantum Physics Lab is listed in the Other sector, but the available results do not identify a specific public-company profile, location, or service portfolio for that exact name. In general, a quantum physics lab is a specialized research environment that studies quantum mechanics and may support experimental physics, instrumentation, and quantum technology development. Public sources on quantum laboratories describe them as carefully controlled facilities where scientists design, build, and test quantum devices and computing systems. The entity was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | BlueSky Aviation id25946 View details | Kenya | Transportation / Travel / Logistics | — | |
|
BlueSky Aviation is a transportation and logistics company based in Kenya (KE), specializing in air freight, cargo charter services, and comprehensive travel solutions for the region. The firm operates its own fleet of aircraft to deliver economical to urgent shipments across Europe and beyond, catering to time-sensitive logistics needs in the travel and freight sector. As a key player in Kenya’s transportation industry, it provides customized air capacity options and charter services tailored to diverse client requirements. BlueSky Aviation was listed as a ransomware victim associated with the threat actor 0apt, marking a significant incident in the country’s logistics sector. |
|||||
| Ransomware | Summit Education Trust id25945 View details | South Africa | Education | — | |
|
Summit Education Trust is an education-related organisation in South Africa, placing it within the education sector and the ZA country context. Publicly available references show Summit Educational Trust as a South African trust focused on improving education and related community outcomes, while similarly named Summit Education Trust entities are associated with school and learning initiatives. Based on the available information, it is best described as an education-focused trust or institution operating in South Africa. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Horizon Travel Agency id25944 View details | Transportation / Travel | — | ||
|
Horizon Travel Agency is a travel-services business in the Transportation / Travel sector, operating as a full-service agency with locations reported in the United States and India. Public business listings describe it as offering vacation packages, cruises, international travel, and concierge-style support for corporate and leisure trips. Other company profiles also indicate travel planning services that can include transportation, accommodations, and custom itineraries. In threat-intelligence indexing, it was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | City Transit Authority id25943 View details | Public Sector | — | ||
|
City Transit Authority is a public sector transit organization that provides local transportation services for residents and visitors in its service area. Such authorities typically manage bus, rail, or paratransit operations and support day-to-day mobility for the communities they serve. In public-sector transit, the agency’s role centers on operating routes, maintaining service continuity, and coordinating rider access across the network. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Eclipse Software House id25942 View details | Poland | IT | — | |
|
Eclipse Software House is an IT-sector company in Poland, and available business records place Eclipse Poland Limited Sp. z o.o. in Wroclaw, with operations classified under computer systems design and related services. It is described as a software company in the Polish market, consistent with a provider of software development and related IT services. Public company data identify its headquarters in Wroclaw, Dolnoslaskie, Poland. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Omega Manufacturing id25941 View details | Manufacturing / Engineering | — | ||
|
Omega Manufacturing is a North Carolina-based precision machining company in the manufacturing and engineering sector. It specializes in high-quality parts made from metals, plastics, and machinable ceramics, with custom machining work including Wire EDM and prototype production. Public business profiles place it in Charlotte, North Carolina, and describe it as serving industrial customers across the United States. In threat-intelligence indexing, it was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Vanguard Security id25940 View details | Other | — | ||
|
Vanguard Security is a UK-based security services company associated with physical protection and facility support offerings, including bespoke security solutions and one-stop facility management services. Company listings place Vanguard Security Services Limited in Normanton, West Yorkshire, while other business records show a related Vanguard Security entity registered in England. In this context, the name refers to a commercial security provider rather than a cybercrime group or software vendor. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Meridian Logistics id25939 View details | Transportation / Travel / Logistics | — | ||
|
Meridian Logistics S A is a Colombia-based company headquartered in Bogotá D.C. that operates in support activities for transportation and related logistics services. Company profile data shows it has served the Colombian market since 2003 and is part of the transportation and travel logistics sector. Public business directories describe the firm as focused on transportation support and logistics-related operations. Meridian Logistics was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Prime Estate Developers id25938 View details | Communication / Marketing | — | ||
|
Prime Estate Developers is a real estate development company based in Pakistan, operating under the Prime Estate Developers name and presenting itself as a provider of property development services. Its public materials emphasize customer service and personalized experiences, indicating a business focused on real estate development and related client engagement. The company appears in the communication/marketing context of the threat-intelligence index because of its online profile and sector tagging. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Solstice Energy Grid id25937 View details | Energy | — | ||
|
Solstice Energy Grid is an energy-sector company in the United States. Publicly available references to the Solstice brand describe a clean-energy business focused on solar and community-solar offerings, helping customers access and save on electricity through renewable-energy programs. Available sources also place related Solstice operations in Salt Lake City, Utah, and Houston, Texas, reflecting a U.S. footprint in distributed energy services. In a threat-intelligence context, Solstice Energy Grid was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Nexus IT Services id25936 View details | India | Services | — | |
|
Nexus IT Services is a managed IT services provider operating in the Services sector, offering high-impact IT solutions to help businesses focus on their core operations. The company specializes in delivering strategic managed services, cybersecurity, and cloud solutions to regulated and growth-focused organizations. Based in India, Nexus IT Services empowers clients by providing proactive security, innovative technology, and seamless support. The organization was neutrally listed as a ransomware victim associated with the 0apt threat actor. |
|||||
| Ransomware | Delta Energy Corp id25935 View details | United States | Energy | — | |
|
Delta Energy Corp is a United States energy-sector company, but publicly available search results do not provide enough reliable detail to confirm its exact offerings or operating profile. In general, entities in this sector may be involved in power, fuels, utilities, or related energy services, but this listing should not be read as a definitive company profile. The record is presented for threat-intelligence indexing purposes and uses the company name and sector as provided. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Terra Real Estate id25934 View details | Türkiye | Construction / Real Estate | — | |
|
Terra Real Estate is a licensed real estate agency based in Alanya, Antalya, Turkey, operating under the legal entity TERRA Real Estate Emlak İnşaat Limited Şirketi. The company presents itself as a property specialist in Turkey, offering sales and consulting services across locations including Alanya, Antalya, Belek, Bodrum, Gazipaşa, Istanbul, Kemer, Mersin, and Side. Its public materials describe property search, investment support, and related real estate services for buyers in the Turkish market. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Silverline Hospitals id25933 View details | India | Healthcare / Pharma | — | |
|
Silverline Hospitals is a healthcare provider in Kochi, Kerala, India, operating from Kadavanthara and serving patients in the city and surrounding region. Public listings describe it as a hospital focused on diabetes, thyroid, obesity, and other endocrine disorders, with additional departments such as cardiology, ophthalmology, urology, podiatry, and physiotherapy. The hospital also advertises outpatient support, consultations, and patient-assistance services typical of a multi-specialty medical facility. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Prism Media Network id25932 View details | Communication / Marketing | — | ||
|
Prism Media Network operates within the Communication and Marketing sector, delivering content creation and strategic marketing services to clients across the United States. The organization specializes in developing compelling content, managing social media campaigns, and providing expert marketing solutions such as paid search and web analytics to drive business success. Its offerings are designed to help clients navigate digital marketing with confidence while ensuring clear and effective communication. Prism Media Network was listed as a ransomware victim associated with the threat actor 0apt. |
|||||
| Ransomware | NeoTech Solutions id25931 View details | IT | — | ||
|
NeoTech Solutions is an IT and digital services company based in Edison, New Jersey, with additional operations in the United States and India. Its public materials describe offerings in digital and engineering solutions, including custom software and related business technology services. Company listings and profiles also place it in the IT consulting and software development space. In threat-intelligence catalogs, NeoTech Solutions was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Aegis Defense Systems id25930 View details | United States | Communication / Marketing | — | |
|
Aegis Defense Systems is a US-based company in the communication and marketing sector, a field centered on brand messaging, audience engagement, and promotional services. Publicly available search results do not provide enough reliable detail to confirm its exact product lineup or service scope, so a conservative catalog description is most accurate. In threat-intelligence indexing, it is identified by name, sector, and country rather than by unverified operational claims. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Omni Retail Group id25929 View details | United States | Retail / E-commerce | — | |
|
OMNI Retail Group is a Seattle-based US company serving the retail and e-commerce market with an omnichannel, cloud-based shopping solution for retailers and manufacturers. Its materials describe the business as focused on helping enterprise retailers improve conversion and shopper experience through a digitally integrated commerce platform. Public company-profile sources also place its headquarters in Seattle, Washington. OMNI Retail Group was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Summit Financial Group id25928 View details | United States | Finance / Legal / Insurance | — | |
|
Summit Financial Group is a US-based financial services company associated with the finance, legal, and insurance space, with publicly available listings describing offerings that include investment advisory, wealth management, benefits, risk management, and insurance-related services. Depending on the specific Summit Financial Group entity, its public profiles indicate operations tied to advisors, clients, or benefit-plan and insurance support. As a catalog entry, it is best treated as a financial-services organization rather than a technology or industrial firm. Summit Financial Group was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Cobalt Mining Corp id25927 View details | Canada | Services | — | |
|
Cobalt Mining Corp is a Canadian services-sector company. Based on its name, it appears to be associated with mining-related services rather than mineral production, but publicly available source material in this search set does not provide a fuller corporate profile. The company is identified here as a Canada-based services entity in a threat-intelligence listing context. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Global Logistics Hub id25926 View details | Transportation / Travel / Logistics | — | ||
|
Global Logistics HUB LTD is a logistics company in Ukraine that says it provides a full range of freight forwarding services from its office in Bila Tserkva, Kyiv Oblast. In logistics, a hub is a central node used to receive, sort, store, consolidate, and redistribute goods across supply chains. The company’s public materials present it as a modern logistics operator serving shipment movement and coordination needs. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Stratos Aerospace id25925 View details | Communication / Marketing | — | ||
|
Stratos Aerospace is a Fort Worth, Texas-based aerospace hardware supplier that sells fasteners and related fabricated metal products for aerospace applications. Its public company information describes a focus on aerospace hardware, including nuts, bolts, rivets, brackets, and other specialty fasteners, with operations centered in Fort Worth, Texas. The business is also described in industry listings as serving aerospace and aviation customers. In threat-intelligence catalogs, Stratos Aerospace was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Quantum Financial Corp id25900 View details | United States | Finance / Legal / Insurance | — | |
|
Quantum Financial Corp is a US-based entity in the finance, legal, and insurance space, a sector that commonly includes advisory, insurance, and related financial services. Public search results do not provide a definitive company profile for this exact name, so this listing treats it as a financial-services organization operating in the United States. In threat-intelligence contexts, such firms are often indexed because their names appear in incident reporting or victim disclosures tied to cyber extortion activity. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Summit Global Energy id25884 View details | Energy | — | ||
|
Summit Global Energy is an energy-sector company in the United States, operating in a field that includes the production, trading, distribution, or support of energy-related products and services. The name indicates a business centered on energy markets rather than a consumer-facing brand, and the sector places it among organizations that manage critical infrastructure, supply chains, or commercial energy services. Publicly available information does not provide enough reliable detail here to confirm a more specific location or product mix without risking invention. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Nebula Bio-Tech Labs id25883 View details | IT | — | ||
|
Nebula Bio-Tech Labs is presented as an IT-sector company in France. Publicly available material does not provide enough reliable detail to confirm its exact offerings, so a cautious description is appropriate. The name suggests a technology-focused lab or services business, but the available sources do not verify more specific operations. In threat-intelligence catalogs, it is referenced in connection with a ransomware incident attribution to 0apt. |
|||||
| Ransomware | Orion Legal Partners id25880 View details | United States | Finance / Legal / Insurance | — | |
|
Orion Legal Partners is a U.S.-based legal-services organization in the Finance / Legal / Insurance space. Public transaction disclosures describe Orion Legal MSO as a managed service organization supporting plaintiff law firms, with nonlegal operational support that can include marketing, technology, finance, talent, and administrative infrastructure. Its platform is designed to help partner firms run more efficiently while attorneys focus on legal work. In threat-intelligence listings, Orion Legal Partners was named as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Dr. Smith Dental Clinics id25879 View details | Healthcare / Pharma | — | ||
|
Dr. Smith Dental Clinics is a dental care provider in the Healthcare/Pharma sector, offering patient-focused oral health services and routine clinic-based treatment. Public listings for similarly named Smith dental practices show U.S. locations and offerings such as preventive care, cleanings, restorations, and other general dentistry services. As a healthcare entity, it falls within a sector frequently tracked in cyber-threat-intelligence reporting because patient-facing operations depend on continuous access to clinical systems. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Rapid Food Distributors id25878 View details | United States | Agriculture / Food | — | |
|
Rapid Food Distributors is a United States company in the agriculture and food sector. Food distributors in this industry buy, store, and move products through warehouse and logistics networks to supply downstream customers such as retailers, restaurants, and other foodservice buyers. Rapid Food Distributors is described as part of that distribution chain, serving the movement of food products across the supply network. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Sunrise Manufacturing Ltd. id25877 View details | Manufacturing / Engineering | — | ||
|
Sunrise Manufacturing Ltd. is a manufacturing and engineering company based in Rancho Cordova, California, with additional U.S. locations in Georgia, New Mexico, Washington, and Texas. It specializes in honeycomb dunnage materials, load securement solutions, void fill, and freight protection products for shipping and transit. The company says it has served customers since 1981 and supports industries such as electronics and food and beverage. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | GreenValley Regional College id25876 View details | Education | — | ||
|
GreenValley Regional College is an educational institution in the United States that operates in the education sector and offers college-level instruction and training. Publicly available references identify it as a college serving students through academic programs rather than as a commercial enterprise. In catalog and threat-intelligence contexts, it is described as a GreenValley Regional College ransomware victim associated with the 0apt threat actor. |
|||||
| Ransomware | TechnoSoft IT Services id25875 View details | India | IT | — | |
|
TechnoSoft IT Services is an India-based IT services provider that offers comprehensive technology support, technical services, mission-critical site maintenance, and manpower deployment. Its service profile also includes customized application support, consulting, process optimization, electrical and mechanical services, and 24/7 operational support for industrial environments. The company positions itself around keeping client systems stable, efficient, and continuously available across business operations. In the threat-intelligence index, TechnoSoft IT Services was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Apex Logistics Solutions id25874 View details | Australia | Transportation / Travel / Logistics | — | |
|
Apex Logistics Solutions is an Australian company in the transportation, travel and logistics sector, with operations tied to freight movement and supply-chain services. Public business listings for Apex-branded logistics firms indicate services such as freight forwarding, contract logistics, and transportation support, alongside a footprint that includes Australia. The name suggests a logistics-focused provider serving commercial shipping and distribution needs across domestic and international lanes. It was listed as a ransomware victim associated with 0apt. |
|||||
| Ransomware | Metropolis City Municipal id25873 View details | Public Sector | — | ||
|
Metropolis City Municipal refers to the City of Metropolis, Illinois, a public sector municipal government in the United States that provides essential city services to residents. The city’s official site says it offers utilities including electric, water, sewer, and garbage service, and it describes its mission as providing efficient and responsive city services. It also supports local infrastructure and economic development through municipal operations and public administration. It was listed as a ransomware victim associated with 0apt. |
|||||