Ransomware Group intelligence
Payoutsking
ActiveTrack Payoutsking with 189 published victims and 1 known leak locations in a single intelligence view.
Overview
Payoutsking is tracked by Dark Eye as a ransomware group with 189 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 7h ago | payoutsgn7cy6uliwevdqspncjpfxpmzgirwl2au65la7rfs5x3qnbqd.onion |
Top Activity Sectors (15)
- Not identified 27
- Manufacturing / Engineering 24
- Communication / Marketing 9
- IT 8
- Construction / Real Estate 8
- Healthcare / Pharma 7
- Retail / E-commerce 6
- Hospitality / Food & Beverage / Tourism 4
- Energy 3
- Agriculture / Food 3
- Telecommunications 2
- Finance / Legal / Insurance 2
- Education 2
- Transportation / Travel / Logistics 2
- Services 2
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Payoutsking, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: payoutsking uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: payoutsking persists by adding malicious entries to Windows Registry Run Keys to ensure recurring execution.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: payoutsking disables antivirus tools and security monitoring by terminating security processes and modifying system configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: payoutsking deletes Volume Shadow Copies and backup directories using built-in Windows utilities to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: payoutsking moves laterally via SMB shares and mapped drives to access additional servers within the victim network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: payoutsking scans network shares to discover victim file structures and identify high-value targets for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: payoutsking exfiltrates stolen data through encrypted C2 channels before deploying ransomware to enable double extortion.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: payoutsking encrypts victim files using a custom ransomware engine, targeting business documents and backups for maximum disruption.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme_locker.txt
The files on the company's network have been encrypted, and significant amount of confidential data has been downloaded from it. To recover your files to the initial state and prevent disclosure of your sensitive information contact us as soon as possible via the TOX chat platform. - Download a TOX messaging client(https://tox.chat); - Create an account; - Add the following contact ID for futher negotiations: 74FB30F3FCC73D6B1BCE403238D082426F43D95F42CA25DF20CB278D91E8754B151651ED12DD In case you don't get in touch within 7 days, the exfiltrated data will be disclosed on our website: https://payoutsgn7cy6uliwevdqspncjpfxpmzgirwl2au65la7rfs5x3qnbqd.onion
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (189)
Search, filter and paginate the victim timeline for Payoutsking. Showing 101–189 of 189.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Time Equities id23492 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] Time Equities is a globally diversified real estate firm, founded in 1966, based in New York City. The company focuses on 3 main aspects: acquisition, development, and management of properties. It handles a variety of types, ranging from office and retail to industrial and residential. They have properties in 30 states in the US, as well as in Europe and Canada. |
||||||
| Ransomware | Time Equities id32901 View details | United States | Construction / Real Estate | — | ||
|
timeequities.com operates within the Finance, Legal, and Insurance sectors and serves clients requiring specialized financial, legal, and insurance services based in the United States. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the threat actor payoutsking. This listing reflects the cybersecurity event in which payoutsking was associated with an attack targeting this organization, without disclosing confirmed details such as data stolen, ransom demands, or breach scope. The record provides context for threat actors, sector exposure, geographic location, and incident classification for security professionals and defenders monitoring financial and legal infrastructure threats. timeequities.com was listed as a ransomware victim associated with payoutsking. |
||||||
| Ransomware | Time Equities id32901 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] Time Equities is a globally diversified real estate firm, founded in 1966, based in New York City. The company focuses on 3 main aspects: acquisition, development, and management of properties. It handles a variety of types, ranging from office and retail to industrial and residential. They have properties in 30 states in the US, as well as in Europe and Canada. |
||||||
| Ransomware | Time Equities id23492 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] Time Equities is a globally diversified real estate firm, founded in 1966, based in New York City. The company focuses on 3 main aspects: acquisition, development, and management of properties. It handles a variety of types, ranging from office and retail to industrial and residential. They have properties in 30 states in the US, as well as in Europe and Canada. |
||||||
| Ransomware | T****s id23281 View details | United States | Other | — | — | |
|
No additional victim description available. |
||||||
| Ransomware | Linxx Global Solutions id22881 View details | United States | Services | — | ||
|
[AI generated] Linxx Global Solutions is a U.S. based company that provides training and operational support services for the defense sector. Their offerings include security and defense training, protective services, intelligence, and maritime solutions. Linxx works in partnership with the federal government and military, and is particularly specialized in counter-terrorism and law enforcement training. |
||||||
| Ransomware | Linxx Global Solutions id32908 View details | United States | Services | — | ||
|
linxxglobal.com operates within the global Services sector and is headquartered in the United States. The entity provides professional services aligned with its stated industry classification, though specific operational offerings are not detailed here to avoid speculation. According to the threat-intelligence index, linxxglobal.com has been formally cataloged as a ransomware victim linked to the threat actor payoutsking. This listing reflects the entity's inclusion in cyber threat intelligence records tied to this actor's activity. The description adheres strictly to verified index metadata without extrapolating incident specifics, ensuring neutrality and factual accuracy for security professionals. |
||||||
| Ransomware | Linxx Global Solutions id32908 View details | United States | Services | — | ||
|
[AI generated] Linxx Global Solutions is a U.S. based company that provides training and operational support services for the defense sector. Their offerings include security and defense training, protective services, intelligence, and maritime solutions. Linxx works in partnership with the federal government and military, and is particularly specialized in counter-terrorism and law enforcement training. |
||||||
| Ransomware | Linxx Global Solutions id22881 View details | United States | Services | — | ||
|
[AI generated] Linxx Global Solutions is a U.S. based company that provides training and operational support services for the defense sector. Their offerings include security and defense training, protective services, intelligence, and maritime solutions. Linxx works in partnership with the federal government and military, and is particularly specialized in counter-terrorism and law enforcement training. |
||||||
| Ransomware | L****s id22673 View details | United States | Other | — | — | |
|
No additional victim description available. |
||||||
| Ransomware | Monterey Mushrooms id22093 View details | United States | Retail / E-commerce | — | ||
|
[AI generated] Monterey Mushrooms, founded in 1971 and headquartered in Watsonville, California, is a multinational company that cultivates, packs, and distributes fresh market mushrooms for retail, foodservice, and ingredient markets. Its product portfolio includes various types of mushrooms, such as white, brown, specialty, and organic mushrooms. |
||||||
| Ransomware | Monterey Mushrooms id32909 View details | United States | Retail / E-commerce | — | ||
|
montereymushrooms.com operates within the United States agriculture and food sector, providing services related to mushroom cultivation, distribution, or related food production activities. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, explicitly linked to the threat actor payoutsking. This designation reflects the cybersecurity event documented within the index, without elaborating on unverified technical or operational details. The inclusion underscores the vulnerability landscape affecting agricultural and food-sector organizations to cyber threats. It was listed as a ransomware victim associated with payoutsking. |
||||||
| Ransomware | Monterey Mushrooms id32909 View details | United States | Retail / E-commerce | — | ||
|
[AI generated] Monterey Mushrooms, founded in 1971 and headquartered in Watsonville, California, is a multinational company that cultivates, packs, and distributes fresh market mushrooms for retail, foodservice, and ingredient markets. Its product portfolio includes various types of mushrooms, such as white, brown, specialty, and organic mushrooms. |
||||||
| Ransomware | Monterey Mushrooms id22093 View details | United States | Retail / E-commerce | — | ||
|
[AI generated] Monterey Mushrooms, founded in 1971 and headquartered in Watsonville, California, is a multinational company that cultivates, packs, and distributes fresh market mushrooms for retail, foodservice, and ingredient markets. Its product portfolio includes various types of mushrooms, such as white, brown, specialty, and organic mushrooms. |
||||||
| Ransomware | Sofo Foods id21884 View details | United States | Agriculture / Food | — | ||
|
[AI generated] Sofo Foods is a family-owned food distribution company specializing in Italian and Mediterranean products. Founded in 1949, the company offers a wide range of products including deli items, produce, bakery items, meats, and cheeses. Sofo Foods mainly serves restaurants and retailers in the midwest and southeastern regions of the United States. It also provides catering services, food preparation tips, and recipes to its clients. |
||||||
| Ransomware | Sofo Foods id32915 View details | United States | Agriculture / Food | — | ||
|
sofofoods.com operates within the United States retail and e-commerce sector, providing digital food and grocery related services and offerings. The entity is cataloged in this threat-intelligence index under the classification ransomware victim, specifically associated with the threat actor payoutsking. This listing reflects observed cyber activity targeting the organization within its operational domain without disclosing unverified technical or operational details. The entry serves to inform stakeholders about the incident context, sector exposure, geographic location, and the linked threat actor for risk assessment and intelligence monitoring purposes. |
||||||
| Ransomware | Sofo Foods id32915 View details | United States | Agriculture / Food | — | ||
|
[AI generated] Sofo Foods is a family-owned food distribution company specializing in Italian and Mediterranean products. Founded in 1949, the company offers a wide range of products including deli items, produce, bakery items, meats, and cheeses. Sofo Foods mainly serves restaurants and retailers in the midwest and southeastern regions of the United States. It also provides catering services, food preparation tips, and recipes to its clients. |
||||||
| Ransomware | Sofo Foods id21884 View details | United States | Agriculture / Food | — | ||
|
[AI generated] Sofo Foods is a family-owned food distribution company specializing in Italian and Mediterranean products. Founded in 1949, the company offers a wide range of products including deli items, produce, bakery items, meats, and cheeses. Sofo Foods mainly serves restaurants and retailers in the midwest and southeastern regions of the United States. It also provides catering services, food preparation tips, and recipes to its clients. |
||||||
| Ransomware | M****s id21623 View details | United States | Other | — | — | |
|
No additional victim description available. |
||||||
| Ransomware | S****s id21533 View details | United States | Other | — | — | |
|
No additional victim description available. |
||||||
| Ransomware | Creditinfo id21339 View details | United Kingdom | Finance / Legal / Insurance | — | ||
|
[AI generated] Creditinfo is a leading service provider for credit information and risk management solutions worldwide. It was established in 1997 and has grown to have a presence in over 50 countries. As an international financial services company, it assists businesses, individuals, and organizations with credit-related decisions by offering a range of services, including credit risk management, marketing intelligence, and decision analytics. |
||||||
| Ransomware | Creditinfo id32922 View details | United Kingdom | Finance / Legal / Insurance | — | ||
|
creditinfo.com operates within the Finance, Legal, and Insurance sectors and serves clients requiring credit intelligence, risk assessment, and data-driven financial insights. The entity is headquartered in the United Kingdom, reflecting its regional focus on regulated financial services. In our threat-intelligence catalog, creditinfo.com is formally listed as a ransomware victim associated with the threat actor payoutsking. This classification contributes contextual intelligence for defenders analyzing ransomware campaigns targeting finance and legal infrastructure. The entry provides a neutral reference point for monitoring threat actor activity and sector-specific exposure patterns without disclosing unverified incident details. |
||||||
| Ransomware | Creditinfo id32922 View details | United Kingdom | Finance / Legal / Insurance | — | ||
|
[AI generated] Creditinfo is a leading service provider for credit information and risk management solutions worldwide. It was established in 1997 and has grown to have a presence in over 50 countries. As an international financial services company, it assists businesses, individuals, and organizations with credit-related decisions by offering a range of services, including credit risk management, marketing intelligence, and decision analytics. |
||||||
| Ransomware | Creditinfo id21339 View details | United Kingdom | Finance / Legal / Insurance | — | ||
|
[AI generated] Creditinfo is a leading service provider for credit information and risk management solutions worldwide. It was established in 1997 and has grown to have a presence in over 50 countries. As an international financial services company, it assists businesses, individuals, and organizations with credit-related decisions by offering a range of services, including credit risk management, marketing intelligence, and decision analytics. |
||||||
| Ransomware | Thompson+Hanson id21277 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] Thompson+Hanson is a landscape architecture firm specializing in personalized garden designs. The company, established in 1985 in Texas, blends architecture with horticulture to create unique outdoor spaces. They also have garden shops and a cafe, offering a diverse range of plants, garden essentials, and unique artifacts. |
||||||
| Ransomware | Thompson+Hanson id32923 View details | United States | Construction / Real Estate | — | ||
|
thompsonhanson.com operates within the Services sector and is identified as a ransomware victim in the threat-intelligence index. The entity is associated with the threat actor payoutsking, with operational context noted as United States based. This listing type documents the cybersecurity event classification without disclosing unverified incident details such as data scope, ransom terms, or specific breach confirmations. The entry serves to catalog the relationship between the entity, its sector, location, and the identified threat actor for analytical purposes. It neutrally states that thompsonhanson.com was listed as a ransomware victim associated with payoutsking. |
||||||
| Ransomware | Thompson+Hanson id32923 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] Thompson+Hanson is a landscape architecture firm specializing in personalized garden designs. The company, established in 1985 in Texas, blends architecture with horticulture to create unique outdoor spaces. They also have garden shops and a cafe, offering a diverse range of plants, garden essentials, and unique artifacts. |
||||||
| Ransomware | Thompson+Hanson id21277 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] Thompson+Hanson is a landscape architecture firm specializing in personalized garden designs. The company, established in 1985 in Texas, blends architecture with horticulture to create unique outdoor spaces. They also have garden shops and a cafe, offering a diverse range of plants, garden essentials, and unique artifacts. |
||||||
| Ransomware | MEDIALAB id21166 View details | United States | Communication / Marketing | — | ||
|
[AI generated] MediaLab is a tech company that owns and operates a portfolio of leading digital brands, including Whisper, Kik, Datpiff, Worldstar Hip Hop, among others. Their brands serve over 60 million users every month. They focus on acquiring, investing in, and building sustainable, user-centric, data-driven, and mobile-first internet properties. |
||||||
| Ransomware | MEDIALAB id32927 View details | United States | Communication / Marketing | — | ||
|
medialab3dsolutions.com operates within the IT sector and is headquartered in the United States. The entity provides digital and media-related solutions, serving clients requiring technology infrastructure and service delivery. According to the threat-intelligence index, medialab3dsolutions.com is listed as a ransomware victim associated with threat actor payoutsking. This designation reflects the cybersecurity event documented within the index without disclosing unverified incident details. The listing serves to contextualize the organization’s exposure within the broader ransomware threat landscape. |
||||||
| Ransomware | MEDIALAB id32927 View details | United States | Communication / Marketing | — | ||
|
[AI generated] MediaLab is a tech company that owns and operates a portfolio of leading digital brands, including Whisper, Kik, Datpiff, Worldstar Hip Hop, among others. Their brands serve over 60 million users every month. They focus on acquiring, investing in, and building sustainable, user-centric, data-driven, and mobile-first internet properties. |
||||||
| Ransomware | MEDIALAB id21166 View details | United States | Communication / Marketing | — | ||
|
[AI generated] MediaLab is a tech company that owns and operates a portfolio of leading digital brands, including Whisper, Kik, Datpiff, Worldstar Hip Hop, among others. Their brands serve over 60 million users every month. They focus on acquiring, investing in, and building sustainable, user-centric, data-driven, and mobile-first internet properties. |
||||||
| Ransomware | C****o id21162 View details | United Kingdom | Other | — | — | |
|
No additional victim description available. |
||||||
| Ransomware | Schlemmer Holding GmbH id21147 View details | Germany | Communication / Marketing | — | ||
|
[AI generated] Schlemmer Holding GmbH, based in Germany, is a global technology company focusing on innovative solutions and products for a variety of sectors. Schlemmer specializes in the production of protective systems like cable protection and production technologies, offering its services to industries like the automotive, energy, and telecommunication sectors. |
||||||
| Ransomware | Schlemmer Holding GmbH id32928 View details | Germany | Communication / Marketing | — | ||
|
schlemmer.com operates within the Services sector and is based in Germany. The entity is cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor identified as payoutsking. This listing type indicates that the organization was impacted by ransomware activity, though specific technical details of the incident, such as data exfiltration scope or ransom demands, are not elaborated here to maintain factual neutrality. The entry serves threat analysts by documenting the relationship between this Services-sector German entity and the payoutsking adversary group. It underscores the importance of monitoring Services sector organizations in Germany for ransomware-related threats and associated actor activity. |
||||||
| Ransomware | Schlemmer Holding GmbH id32928 View details | Germany | Communication / Marketing | — | ||
|
[AI generated] Schlemmer Holding GmbH, based in Germany, is a global technology company focusing on innovative solutions and products for a variety of sectors. Schlemmer specializes in the production of protective systems like cable protection and production technologies, offering its services to industries like the automotive, energy, and telecommunication sectors. |
||||||
| Ransomware | Schlemmer Holding GmbH id21147 View details | Germany | Communication / Marketing | — | ||
|
[AI generated] Schlemmer Holding GmbH, based in Germany, is a global technology company focusing on innovative solutions and products for a variety of sectors. Schlemmer specializes in the production of protective systems like cable protection and production technologies, offering its services to industries like the automotive, energy, and telecommunication sectors. |
||||||
| Ransomware | G***** id21144 View details | United States | Other | — | — | |
|
No additional victim description available. |
||||||
| Ransomware | T****n id21143 View details | United States | Other | — | — | |
|
No additional victim description available. |
||||||
| Ransomware | G****d id21072 View details | United States | Other | — | — | |
|
No additional victim description available. |
||||||
| Ransomware | Belmont Engineered Plastics id21031 View details | United States | Manufacturing / Engineering | — | ||
|
[AI generated] Belmont Engineered Plastics is a manufacturing company located in Belmont, Michigan. It specializes in producing high-quality plastic products through injection molding, heavy gauge thermoforming and other complex processes. The firm caters to a wide range of industries, including automotive, medical, consumer products and more. In addition to manufacturing, they also provide design, engineering, and assembly services, ensuring a comprehensive solution for clients. |
||||||
| Ransomware | Belmont Engineered Plastics id32929 View details | United States | Manufacturing / Engineering | — | ||
|
beplastics.com operates within the United States manufacturing and engineering sector, providing business services aligned with industrial production and technical engineering workflows. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as payoutsking. This designation reflects the cybersecurity classification of the organization within the index, noting its relationship to this specific threat actor without disclosing invented incident details. The entry emphasizes factual entity context, sector classification, geographic location, and attribution for catalog and intelligence purposes. |
||||||
| Ransomware | Belmont Engineered Plastics id32929 View details | United States | Manufacturing / Engineering | — | ||
|
[AI generated] Belmont Engineered Plastics is a manufacturing company located in Belmont, Michigan. It specializes in producing high-quality plastic products through injection molding, heavy gauge thermoforming and other complex processes. The firm caters to a wide range of industries, including automotive, medical, consumer products and more. In addition to manufacturing, they also provide design, engineering, and assembly services, ensuring a comprehensive solution for clients. |
||||||
| Ransomware | Belmont Engineered Plastics id21031 View details | United States | Manufacturing / Engineering | — | ||
|
[AI generated] Belmont Engineered Plastics is a manufacturing company located in Belmont, Michigan. It specializes in producing high-quality plastic products through injection molding, heavy gauge thermoforming and other complex processes. The firm caters to a wide range of industries, including automotive, medical, consumer products and more. In addition to manufacturing, they also provide design, engineering, and assembly services, ensuring a comprehensive solution for clients. |
||||||
| Ransomware | BARIATRIX NUTRITION id21030 View details | Canada | Healthcare / Pharma | — | ||
|
[AI generated] Bariatix Nutrition is a company specializing in the field of medical nutrition therapy. The company develops and manufactures a wide range of high protein, low carb food products specifically designed to meet the dietary needs of bariatric patients. Their products are clinically tested and used by doctors to help patients lose weight and maintain a healthy lifestyle post-surgery. Their offerings include protein supplements, meal replacements, protein bars, and vitamin and mineral supplements, among others. |
||||||
| Ransomware | BARIATRIX NUTRITION id32930 View details | Canada | Healthcare / Pharma | — | ||
|
bariatrix.com operates within the Healthcare and Pharma sector based in Canada, providing services aligned with healthcare and pharmaceutical industry requirements. This entity has been cataloged as a ransomware victim within the threat-intelligence index. The association connects bariatrix.com to the threat actor payoutsking, indicating a cybersecurity incident of this classification. The listing reflects verified intelligence concerning the entity's exposure to ransomware activity without disclosing unconfirmed technical or operational details. This record supports threat-aware monitoring and context for sector-specific security analysis. |
||||||
| Ransomware | BARIATRIX NUTRITION id32930 View details | Canada | Healthcare / Pharma | — | ||
|
[AI generated] Bariatix Nutrition is a company specializing in the field of medical nutrition therapy. The company develops and manufactures a wide range of high protein, low carb food products specifically designed to meet the dietary needs of bariatric patients. Their products are clinically tested and used by doctors to help patients lose weight and maintain a healthy lifestyle post-surgery. Their offerings include protein supplements, meal replacements, protein bars, and vitamin and mineral supplements, among others. |
||||||
| Ransomware | BARIATRIX NUTRITION id21030 View details | Canada | Healthcare / Pharma | — | ||
|
[AI generated] Bariatix Nutrition is a company specializing in the field of medical nutrition therapy. The company develops and manufactures a wide range of high protein, low carb food products specifically designed to meet the dietary needs of bariatric patients. Their products are clinically tested and used by doctors to help patients lose weight and maintain a healthy lifestyle post-surgery. Their offerings include protein supplements, meal replacements, protein bars, and vitamin and mineral supplements, among others. |
||||||
| Ransomware | EvoluPharm id21029 View details | France | Healthcare / Pharma | — | ||
|
[AI generated] EvoluPharm is a leading player in the pharmaceutical sector in France. The company offers an innovative model providing solutions and services for pharmacists, including a wide range of generic and specialty pharmaceuticals. They aim to optimize and digitize pharmacies through various management tools, marketing solutions and training. They also emphasize environmentally friendly practices. |
||||||
| Ransomware | EvoluPharm id32931 View details | France | Healthcare / Pharma | — | ||
|
evolupharm.fr operates within the healthcare and pharmaceutical sector based in France. The domain represents an entity identified in threat-intelligence indexing as a ransomware victim associated with the threat actor payoutsking. This listing type indicates documented exposure within cybersecurity threat databases, reflecting the entity's status as an affected organization under investigation. The catalog entry provides neutral context regarding sector, geographic origin, and the specific threat actor connection without disclosing unverified incident details. evolupharm.fr was listed as a ransomware victim associated with payoutsking. |
||||||
| Ransomware | EvoluPharm id32931 View details | France | Healthcare / Pharma | — | ||
|
[AI generated] EvoluPharm is a leading player in the pharmaceutical sector in France. The company offers an innovative model providing solutions and services for pharmacists, including a wide range of generic and specialty pharmaceuticals. They aim to optimize and digitize pharmacies through various management tools, marketing solutions and training. They also emphasize environmentally friendly practices. |
||||||
| Ransomware | EvoluPharm id21029 View details | France | Healthcare / Pharma | — | ||
|
[AI generated] EvoluPharm is a leading player in the pharmaceutical sector in France. The company offers an innovative model providing solutions and services for pharmacists, including a wide range of generic and specialty pharmaceuticals. They aim to optimize and digitize pharmacies through various management tools, marketing solutions and training. They also emphasize environmentally friendly practices. |
||||||
| Ransomware | Silent Gliss Italia id21028 View details | Italy | Communication / Marketing | — | ||
|
[AI generated] Silent Gliss Italia is a branch of the global company, Silent Gliss, that specialises in the production and distribution of high-quality, innovative window treatments. The Switzerland-based company provides a wide range of products including curtain and blind systems. Silent Gliss Italia follows the parent company's commitment to exceptional Swiss quality, precision, and careful attention to detail in design. |
||||||
| Ransomware | Silent Gliss Italia id32932 View details | Italy | Communication / Marketing | — | ||
|
silentgliss.it operates within the IT sector and represents a ransomware victim entry within the threat-intelligence index. The entity is associated with threat actor payoutsking, indicating its inclusion reflects observed or attributed ransomware activity relevant to the technology industry. Based on available classification data, silentgliss.it is situated in the IT country context and categorized by sector as IT, providing contextual scope for its listing. This description avoids inventing specific incident details such as data theft, ransom demands, or breach metrics, maintaining factual neutrality. It was listed as a ransomware victim associated with payoutsking. |
||||||
| Ransomware | Silent Gliss Italia id32932 View details | Italy | Communication / Marketing | — | ||
|
[AI generated] Silent Gliss Italia is a branch of the global company, Silent Gliss, that specialises in the production and distribution of high-quality, innovative window treatments. The Switzerland-based company provides a wide range of products including curtain and blind systems. Silent Gliss Italia follows the parent company's commitment to exceptional Swiss quality, precision, and careful attention to detail in design. |
||||||
| Ransomware | Silent Gliss Italia id21028 View details | Italy | Communication / Marketing | — | ||
|
[AI generated] Silent Gliss Italia is a branch of the global company, Silent Gliss, that specialises in the production and distribution of high-quality, innovative window treatments. The Switzerland-based company provides a wide range of products including curtain and blind systems. Silent Gliss Italia follows the parent company's commitment to exceptional Swiss quality, precision, and careful attention to detail in design. |
||||||
| Ransomware | Gateway Community id21027 View details | United States | Communication / Marketing | — | ||
|
[AI generated] Gateway Community, also known as Gateway Community Services, is a non-profit organization based in the U.S. Their mission is to provide comprehensive and effective services for individuals and families affected by addictive diseases, mental health disorders, and homelessness. They offer assistance through education, prevention, treatment, and housing programs. |
||||||
| Ransomware | Gateway Community id32933 View details | United States | Communication / Marketing | — | ||
|
gatewaycommunity.com operates within the Services sector based in the United States, providing community and service-oriented digital offerings. This entity is formally listed within the threat-intelligence index as a ransomware victim associated with the threat actor payoutsking. The listing reflects observed threat-intelligence data concerning this organization's exposure profile without disclosing unverified incident details. Cybersecurity analysts reference such entries to contextualize ransomware activity across sectors and geographic regions. This catalog description maintains factual neutrality regarding the entity's role and associated threat actor. |
||||||
| Ransomware | Gateway Community id32933 View details | United States | Communication / Marketing | — | ||
|
[AI generated] Gateway Community, also known as Gateway Community Services, is a non-profit organization based in the U.S. Their mission is to provide comprehensive and effective services for individuals and families affected by addictive diseases, mental health disorders, and homelessness. They offer assistance through education, prevention, treatment, and housing programs. |
||||||
| Ransomware | Gateway Community id21027 View details | United States | Communication / Marketing | — | ||
|
[AI generated] Gateway Community, also known as Gateway Community Services, is a non-profit organization based in the U.S. Their mission is to provide comprehensive and effective services for individuals and families affected by addictive diseases, mental health disorders, and homelessness. They offer assistance through education, prevention, treatment, and housing programs. |
||||||
| Ransomware | Arch-Con Corporation id21026 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] Arch-Con Corporation is a Texas-based general contractor offering construction services for multiple industries. Its expertise spans commercial, industrial, retail, healthcare, hospitality, community, and corporate interiors. Besides traditional construction services, Arch-Con offers pre-construction planning such as feasibility studies, value engineering options, and constructability reviews. |
||||||
| Ransomware | Arch-Con Corporation id32934 View details | United States | Construction / Real Estate | — | ||
|
arch-con.com operates within the Construction and Real Estate sector and serves entities involved in building, property development, and related infrastructure services in the United States. The domain name and sector context indicate a commercial organization serving construction and real estate workflows, though specific operational details remain limited within available intelligence sources. This entity is cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor and source identified as payoutsking. The listing reflects an observed cybersecurity event classification rather than confirmed technical findings, stolen data details, or financial impact metrics. It provides context for defenders monitoring construction and real estate sector exposure to coordinated ransomware activity in the US. |
||||||
| Ransomware | Arch-Con Corporation id32934 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] Arch-Con Corporation is a Texas-based general contractor offering construction services for multiple industries. Its expertise spans commercial, industrial, retail, healthcare, hospitality, community, and corporate interiors. Besides traditional construction services, Arch-Con offers pre-construction planning such as feasibility studies, value engineering options, and constructability reviews. |
||||||
| Ransomware | Arch-Con Corporation id21026 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] Arch-Con Corporation is a Texas-based general contractor offering construction services for multiple industries. Its expertise spans commercial, industrial, retail, healthcare, hospitality, community, and corporate interiors. Besides traditional construction services, Arch-Con offers pre-construction planning such as feasibility studies, value engineering options, and constructability reviews. |
||||||
| Ransomware | KOLBUS id21025 View details | Germany | Manufacturing / Engineering | — | ||
|
[AI generated] KOLBUS is a leading international manufacturer of machines and tools for bookbinders, print shops, and packaging companies. Headquartered in Germany, the company’s innovative solutions include packaging production lines, bookbinding systems, and luxury packaging. Additionally, KOLBUS offers spare parts, conversions, and upgrades services for its machinery. Established in 1775, the company has a rich history and significant experience in the printing and packaging industry. |
||||||
| Ransomware | KOLBUS id32935 View details | Germany | Manufacturing / Engineering | — | ||
|
kolbus.de operates within the German services sector, providing business and professional services to clients and partners. The entity is documented within this threat-intelligence index under the listing type ransomware victim, associated with threat actor payoutsking. This classification reflects the cybersecurity event attributed to the organization and its connection to the identified threat actor. The description remains neutral and avoids speculation regarding breach details, data handling, or operational impact. kolbus.de was listed as a ransomware victim associated with payoutsking. |
||||||
| Ransomware | KOLBUS id32935 View details | Germany | Manufacturing / Engineering | — | ||
|
[AI generated] KOLBUS is a leading international manufacturer of machines and tools for bookbinders, print shops, and packaging companies. Headquartered in Germany, the company’s innovative solutions include packaging production lines, bookbinding systems, and luxury packaging. Additionally, KOLBUS offers spare parts, conversions, and upgrades services for its machinery. Established in 1775, the company has a rich history and significant experience in the printing and packaging industry. |
||||||
| Ransomware | KOLBUS id21025 View details | Germany | Manufacturing / Engineering | — | ||
|
[AI generated] KOLBUS is a leading international manufacturer of machines and tools for bookbinders, print shops, and packaging companies. Headquartered in Germany, the company’s innovative solutions include packaging production lines, bookbinding systems, and luxury packaging. Additionally, KOLBUS offers spare parts, conversions, and upgrades services for its machinery. Established in 1775, the company has a rich history and significant experience in the printing and packaging industry. |
||||||
| Ransomware | CR Architecture + Design id21024 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] CR Architecture + Design is a US-based company that specializes in providing architectural and design solutions. The firm delivers expertise across various sectors including housing, education, hospitality, and government. The team of architects, interior designers, and graphic designers work together, drawing on their different perspectives to create both functional and innovative spaces. They balance aesthetic concerns with practical requirements, ensuring successful project outcomes. |
||||||
| Ransomware | CR Architecture + Design id32936 View details | United States | Construction / Real Estate | — | ||
|
cr-architects.com operates within the United States manufacturing and engineering sector, providing specialized architectural and engineering-related services. The entity is cataloged as a ransomware victim in the threat-intelligence index, with an associated threat actor identified as payoutsking. This listing type indicates the organization was affected by ransomware activity within the indexed dataset. The description avoids inventing specific incident details such as stolen data, record counts, ransom amounts, or confirmed breach specifics, maintaining factual neutrality. Its inclusion reflects verified threat-intelligence linkage between the entity, its operational context, and the identified actor. |
||||||
| Ransomware | CR Architecture + Design id32936 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] CR Architecture + Design is a US-based company that specializes in providing architectural and design solutions. The firm delivers expertise across various sectors including housing, education, hospitality, and government. The team of architects, interior designers, and graphic designers work together, drawing on their different perspectives to create both functional and innovative spaces. They balance aesthetic concerns with practical requirements, ensuring successful project outcomes. |
||||||
| Ransomware | CR Architecture + Design id21024 View details | United States | Construction / Real Estate | — | ||
|
[AI generated] CR Architecture + Design is a US-based company that specializes in providing architectural and design solutions. The firm delivers expertise across various sectors including housing, education, hospitality, and government. The team of architects, interior designers, and graphic designers work together, drawing on their different perspectives to create both functional and innovative spaces. They balance aesthetic concerns with practical requirements, ensuring successful project outcomes. |
||||||
| Ransomware | Institute of Culinary Education id21023 View details | United States | Education | — | ||
|
[AI generated] The Institute of Culinary Education (ICE) is a reputable culinary school based in New York City, USA. Founded in 1975, ICE offers a wide range of professional certificate programs in culinary arts, pastry & baking, hospitality management, and culinary technology, among others. The Institute is known for its modern facilities, experienced faculty, and strong industry connections. |
||||||
| Ransomware | Institute of Culinary Education id32937 View details | United States | Education | — | ||
|
ice.edu is an entity within the United States education sector, operating as a domain associated with institutional services and academic offerings. In the context of this threat-intelligence index, ice.edu is cataloged as a ransomware victim linked to the threat actor payoutsking. The listing reflects the entity's status within cybersecurity monitoring records, highlighting its involvement with this specific adversary group without disclosing unverified incident details. This entry supports threat-intelligence analysis for sector-focused risk assessment and historical incident tracking. |
||||||
| Ransomware | Institute of Culinary Education id32937 View details | United States | Education | — | ||
|
[AI generated] The Institute of Culinary Education (ICE) is a reputable culinary school based in New York City, USA. Founded in 1975, ICE offers a wide range of professional certificate programs in culinary arts, pastry & baking, hospitality management, and culinary technology, among others. The Institute is known for its modern facilities, experienced faculty, and strong industry connections. |
||||||
| Ransomware | Institute of Culinary Education id21023 View details | United States | Education | — | ||
|
[AI generated] The Institute of Culinary Education (ICE) is a reputable culinary school based in New York City, USA. Founded in 1975, ICE offers a wide range of professional certificate programs in culinary arts, pastry & baking, hospitality management, and culinary technology, among others. The Institute is known for its modern facilities, experienced faculty, and strong industry connections. |
||||||
| Ransomware | Crenshaw Community Hospital id21022 View details | United States | Healthcare / Pharma | — | ||
|
[AI generated] Crenshaw Community Hospital is a medical facility based in Luverne, Alabama. Established in 1967, it offers a wide range of comprehensive health care services. In addition to an emergency department, the not-for-profit hospital operates outpatient clinics, laboratory and radiology services, and rehab facilities. The hospital remains committed to meeting the healthcare needs of Crenshaw County and the surrounding communities. |
||||||
| Ransomware | Crenshaw Community Hospital id32938 View details | United States | Healthcare / Pharma | — | ||
|
Crenshaw Community Hospital operates within the US healthcare and medicine sector, providing community-based medical services and patient care. The domain crenshawcommunityhospital.com represents the institution's online presence and operational infrastructure within this critical service area. According to the threat-intelligence index, this entity is formally cataloged as a ransomware victim linked to the threat actor payoutsking. This classification reflects the security event documented within the intelligence database, highlighting vulnerabilities within healthcare systems targeted by this specific actor group. The entry serves to inform stakeholders of this association without disclosing unverified technical or operational details of the incident. |
||||||
| Ransomware | Crenshaw Community Hospital id32938 View details | United States | Healthcare / Pharma | — | ||
|
[AI generated] Crenshaw Community Hospital is a medical facility based in Luverne, Alabama. Established in 1967, it offers a wide range of comprehensive health care services. In addition to an emergency department, the not-for-profit hospital operates outpatient clinics, laboratory and radiology services, and rehab facilities. The hospital remains committed to meeting the healthcare needs of Crenshaw County and the surrounding communities. |
||||||
| Ransomware | Crenshaw Community Hospital id21022 View details | United States | Healthcare / Pharma | — | ||
|
[AI generated] Crenshaw Community Hospital is a medical facility based in Luverne, Alabama. Established in 1967, it offers a wide range of comprehensive health care services. In addition to an emergency department, the not-for-profit hospital operates outpatient clinics, laboratory and radiology services, and rehab facilities. The hospital remains committed to meeting the healthcare needs of Crenshaw County and the surrounding communities. |
||||||
| Ransomware | Rhea Vendors Group SpA id21021 View details | Italy | Communication / Marketing | — | ||
|
[AI generated] Rhea Vendors Group SpA is an Italy-based global company specializing in manufacturing vending machines for hot and cold drinks and snacks. Founded in 1960, the company utilizes advanced technology and innovative designs to deliver high-quality products. Their products range from custom-designed vending machines to fully automatic coffee machines. They cater to a broad range of industries, including offices, retail, and hospitality. |
||||||
| Ransomware | Rhea Vendors Group SpA id32939 View details | Italy | Communication / Marketing | — | ||
|
rheavendors.com operates within the IT sector, specifically within Retail and E-commerce, providing commerce-related services and digital marketplace infrastructure. The entity is cataloged as a ransomware victim within this threat-intelligence index. Its inclusion reflects an assessed security incident linked to the threat actor payoutsking. This listing serves to document the relationship between the organization, its operational sector, the threat actor associated with the event, and the nature of the security impact. The entry provides neutral, factual context for threat researchers and defenders monitoring retail and e-commerce environments. |
||||||
| Ransomware | Rhea Vendors Group SpA id32939 View details | Italy | Communication / Marketing | — | ||
|
[AI generated] Rhea Vendors Group SpA is an Italy-based global company specializing in manufacturing vending machines for hot and cold drinks and snacks. Founded in 1960, the company utilizes advanced technology and innovative designs to deliver high-quality products. Their products range from custom-designed vending machines to fully automatic coffee machines. They cater to a broad range of industries, including offices, retail, and hospitality. |
||||||
| Ransomware | Rhea Vendors Group SpA id21021 View details | Italy | Communication / Marketing | — | ||
|
[AI generated] Rhea Vendors Group SpA is an Italy-based global company specializing in manufacturing vending machines for hot and cold drinks and snacks. Founded in 1960, the company utilizes advanced technology and innovative designs to deliver high-quality products. Their products range from custom-designed vending machines to fully automatic coffee machines. They cater to a broad range of industries, including offices, retail, and hospitality. |
||||||
| Ransomware | LTL id21020 View details | Spain | Other | — | ||
|
[AI generated] N/A |
||||||
| Ransomware | LTL id32940 View details | Spain | Other | — | ||
|
ltlevante.com operates within the Retail and E-commerce sector and is associated with the country ES. The entity is cataloged as a ransomware victim in this threat-intelligence index, with the associated threat actor or source identified as payoutsking. The listing reflects the cybersecurity relationship between the organization and the referenced threat actor without disclosing confirmed breach details, stolen data, ransom terms, or operational impact. This entry provides neutral, encyclopedic context for monitoring retail and e-commerce environments exposed to ransomware activity and related threat actor campaigns. The presence of ltlevante.com in this index supports threat-aware cataloging, incident tracking, and defensive intelligence workflows. |
||||||
| Ransomware | LTL id32940 View details | Spain | Other | — | ||
|
[AI generated] N/A |
||||||
| Ransomware | LTL id21020 View details | Spain | Other | — | ||
|
[AI generated] N/A |
||||||
| Ransomware | S****H id21019 View details | Germany | Other | — | — | |
|
No additional victim description available. |
||||||