// THREAT ACTOR
BENZONA_
DormantBENZONA is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of BENZONA — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2026 6
- 2025 8
Leak site mirrors
4 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
rwsu75mtgj5oiz3alkfpnxnopcbiqed6wllyoffpuruuu6my6imjzuqd.onionSupport Chat snapshot · 2026-04-15 16:23 -
benzona6x5ggng3hx52h4mak5sgx5vukrdlrrd3of54g2uppqog2joyd.onionBenzona Ransomware snapshot · 2026-06-17 21:06 -
cpjhb63lxycwbyus2n35ddyhdzxhf756l4rtwdttojzhzgppt3vpmsqd.onionDownloads snapshot · 2026-01-10 11:15 -
wor3mnvotoznof5puzoa35y4bwgtozqe3bae2rpkxmz5dai4xqbcbyad.onionDownloads snapshot · 2026-04-17 20:44
Recent victims
The 50 most recent victims claimed by BENZONA. Total in the index: 14.
| Date listed | Victim | Description |
|---|---|---|
| 2026-01-30 | casamedica.com.gt | |
| 2026-01-22 | empreinte-hotel.com | |
| 2026-01-22 | *a*ame*i*a.com.g* | |
| 2026-01-17 | ccbrt.org | |
| 2026-01-17 | em***int*-ho***.com | |
| 2026-01-12 | cc***.or.*z | |
| 2025-12-22 | taminsho.com | |
| 2025-12-06 | platinumone.in | |
| 2025-12-03 | SUNNYGO.COM.TW | |
| 2025-11-26 | suzuki-ploiesti.ro | |
| 2025-11-26 | poliserv.ro | |
| 2025-11-26 | mazda-ploiesti.ro | |
| 2025-11-26 | dacia-ploiesti.ro | |
| 2025-11-26 | sevci.org |