Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

BLACKBYTE · Threat actor profile

THREAT ACTOR

BLACKBYTE_

Dormant

BLACKBYTE is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.

For Ransomnews editorial coverage of BLACKBYTE, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.

131 Victims tracked
0 / 13 Active mirrors
2021-10-04 First listing
2025-07-29 Most recent

Victims by year

  • 2025 7
  • 2024 4
  • 2023 41
  • 2022 37
  • 2021 42

Leak site mirrors

13 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.

  • 6iaj3efye3q62xjgfxyegrufhewxew7yt4scxjd45tlfafyja6q4ctqd.onion
  • f5uzduboq4fa2xkjloprmctk7ve3dm46ff7aniis66cbekakvksxgeqd.onion BlackByte BLOG snapshot · 2021-12-30 10:07
  • dlyo7r3n4qy5fzv4645nddjwarj7wjdd6wzckomcyc7akskkxp4glcad.onion
  • fl3xpz5bmgzxy4fmebhgsbycgnz24uosp3u4g33oiln627qq3gyw37ad.onion BlackByte BLOG snapshot · 2022-04-24 21:13
  • jbeg2dct2zhku6c2vwnpxtm2psnjo2xnqvvpoiiwr5hxnc6wrp3uhnad.onion BB Auction snapshot · 2023-10-21 00:02
  • 53d5skw4ypzku4bfq2tk2mr3xh5yqrzss25sooiubmjz67lb3gdivcad.onion BB Auction snapshot · 2025-05-17 09:02
  • a2dbso6dijaqsmut36r6y4nps4cwivmfog5bpzf6uojovce6f3gl36id.onion snapshot · 2024-12-09 18:50
  • vzzf6yg67cffqndnwg56e4psw45rup45f2mis7bwblg5fs7e5voagsqd.onion snapshot · 2024-12-09 18:50
  • inbukcc4xk67uzbgkzufdqq3q3ikhwtebqxza5zlfbtzwm2g6usxidqd.onion snapshot · 2024-12-09 18:51
  • p5quu5ujzzswxv4nxyuhgg3fjj2vy2a3zmtcowalkip2temdfadanlyd.onion snapshot · 2024-12-09 18:51
  • tj3ty2q5jm5au3bmd2embtjscd3qjt7nfio2o7cr6moyy5kgil5pieqd.onion File downloader snapshot · 2024-12-13 20:14
  • kpfj3bmo77bwpy2f5zzwj4knatueuv7t3ldlpp4tlrmv2buiziw2tdyd.onion snapshot · 2024-12-11 13:11
  • ce6roic2ykdjunyzazsxmjpz5wsar4pflpoqzntyww5c2eskcp7dq4yd.onion snapshot · 2025-07-08 17:43

Recent victims

The 50 most recent victims claimed by BLACKBYTE. Total in the index: 131.

Date listed Victim Description
2025-07-29 DARA Pharma Dara Pharmaceutical designs, develops, and manufactures packaging equi…
2025-07-29 Lee & Associates In 1979, Bill Lees vision became reality when he opened the first offi…
2025-07-18 GreenLight Biosciences Founded in 2008, GreenLight Bioscience is a pre-commercial stage synth…
2025-07-18 T2 Group We are people that value the journey towards excellence, actively seek…
2025-07-18 Ark Consultancy ARK Consultancy Limited is a leading management and technical consulta…
2025-07-18 Allstarmg Founded in 1999, Allstar Marketing Group is a Performance Marketing co…
2025-07-18 Helpsonv HELP of Southern Nevada provides assistance to families and individual…
2024-09-30 TOTVS
2024-07-17 Modernauto
2024-06-23 City of Newburgh
2024-03-14 Encina Wastewater Authority
2023-10-05 Meridian Cooperative
2023-09-18 Hoteles Xcaret
2023-09-12 Alps Alpine
2023-09-09 Kirby Risk
2023-09-08 FOCUS Business Solutions
2023-09-08 Chambersburg Area School District
2023-09-06 Smead
2023-08-24 Ontellus
2023-07-05 Avalign Technologies
2023-07-03 Brett Martin
2023-06-16 Kisco Senior Living
2023-06-16 Multistack
2023-06-15 Fiege Sp. z o.o.
2023-06-15 NEBRASKALAND
2023-06-15 The Texwipe
2023-06-15 YAMAHA CORPORATION OF AMERICA
2023-05-26 City of Augusta
2023-05-17 Magic-Aire
2023-05-12 Sterling Solutions
2023-05-04 PRESS-SERVICE Monitoring Mediów
2023-04-25 Dacotah Paper
2023-04-23 Easy Automation
2023-04-15 Esperanza Viva Jóvenes de México
2023-04-15 Gulliver International
2023-04-15 Saobacdau Technologies Group
2023-04-09 City of Collegedale
2023-04-09 Creation Baumann
2023-04-09 Crown Grinding & Machining
2023-04-09 Cementos Bio-Bio
2023-03-20 Kelly Group
2023-03-16 Etex Communications
2023-03-09 Falcon Holdings
2023-03-08 Wagner CAT
2023-02-12 Inland Group
2023-02-07 Penn Power Group
2023-01-17 ARC
2023-01-14 K2 Sports
2023-01-06 Kansas City Homes
2023-01-05 Ellison Technologies

CONFIRMED ATTACKS

BlackByte confirmed attacks: 32 verified incidents

Ransomnews has verified 32 BlackByte incidents against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. The confirmed record runs from October 2021 to June 2025. United States accounts for 23 of them (72%), with victims recorded in 9 countries in total. The most affected sector is government, at 10 confirmed victims. A ransom payment was publicly confirmed in 0 cases and publicly refused in 2; the outcome is unrecorded in the remaining 30. Where a figure was disclosed (14 cases), these incidents account for 252,510 exposed records.

32Verified incidents
9Countries
2021–2025Active range
0%Paid, where outcome known

Confirmed victims by year

  • 20214
  • 202215
  • 20239
  • 20243
  • 20251

Most affected sectors

  • Government10
  • Healthcare4
  • Food and Beverage3
  • Retail3
  • Finance2
  • Service2
  • Manufacturing2
  • Other2

Most affected countries

  • United States23
  • Mexico2
  • Colombia1
  • Japan1
  • Sint Maarten1
  • Peru1
  • Italy1
  • Switzerland1

Verified BlackByte incidents

DateOrganisationSector LocationRecordsRansom paidSource
June 2025 Towne Mortgage Company Finance Michigan, United States 474 Unknown Source
July 2024 Modern Automotive Network, LLC Retail North Carolina, United States — Unknown Source
June 2024 City of Newburgh Government New York, United States — Unknown Source
February 2024 Encina Wastewater Authority Government California, United States — Unknown Source
August 2023 Chambersburg Area School District Education Pennsylvania, United States 4,265 Unknown Source
July 2023 Alps Alpine North America, Inc. Manufacturing Ohio, United States 1,039 Unknown Source
June 2023 Kisco Senior Living Healthcare California, United States 26,663 Unknown Source
May 2023 City of Augusta Government Georgia, United States — Unknown Source
April 2023 Comisión Nacional del Agua (CONAGUA) Government Mexico City, Mexico — Unknown Source
April 2023 City of Collegedale Government Tennessee, United States — Unknown Source
March 2023 Gulliver International Co Retail Tokyo, Japan — Unknown Source
January 2023 ARC Document Solutions, Inc. Service California, United States 4,888 Unknown Source
January 2023 Penn Power Group Service Pennsylvania, United States 1,960 Unknown Source
December 2022 Community Action Partnership of Madera County Other California, United States 2,643 Unknown Source
October 2022 Altek Electronics, Inc. Manufacturing Connecticut, United States — Unknown Source
October 2022 Pitman Family Farms, Inc. Food and Beverage California, United States — Unknown Source
September 2022 Gobierno Municipal de Chihuahua Government Chihuahua, Mexico — No Source
September 2022 Northern Macedonia Ministry of Agriculture Government Skopje, North Macedonia — Unknown Source
August 2022 Apex Capital Corp. (TCS Fuel) Finance Texas, United States 743 Unknown Source
June 2022 Napa Valley College Education California, United States 9,341 Unknown Source
June 2022 Lamoille Health Partners Healthcare Vermont, United States 59,381 Unknown Source
June 2022 Gateway Rehabilitation Center Healthcare Pennsylvania, United States 119,000 Unknown Source
May 2022 La Contraloría General de la República de Perú Government Lima, Peru — Unknown Source
May 2022 ATS Insubria Healthcare Varese, Italy 800 No Source
April 2022 M+R Spedag Group Transportation Muttenz, Switzerland — Unknown Source
March 2022 NV GEBE Utilities Philipsburg, Sint Maarten — Unknown Source
February 2022 San Francisco 49ers Other California, United States 20,930 Unknown Source
February 2022 Instituto Nacional de Vigilancia de Medicamentos y Alimentos (Invima) Government Bogota, Colombia — Unknown Source
October 2021 Farmers Cooperative Elevator Co Food and Beverage Iowa, United States — Unknown Source
October 2021 Tom Lange Company, Inc. Food and Beverage Missouri, United States 383 Unknown Source
October 2021 Martin County Tax Collector’s Office Government Florida, United States — Unknown Source
October 2021 Goss Dodge, Inc. Retail Vermont, United States — Unknown Source

Claimed vs confirmed. The figures above the fold on this page come from BlackByte's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.

← Back to Ransomtracker

Statistics on this page are computed by Ransomnews from a live leak-site monitoring feed. Numbers update every ten minutes. Operator-written victim descriptions are truncated and shown in snippet form only. Source data: RansomLook (CC BY 4.0), aggregated and adapted by Ransomnews.

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,613 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.