THREAT ACTOR
BYOD_
DormantBYOD is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of BYOD, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2026 7
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
byodxn5s7sua6oyyjj74rycgn6afncfckprt5ezskt3cni6lg3wdrgad.onionBYOD snapshot · 2026-10-08 04:22
Recent victims
The 50 most recent victims claimed by BYOD. Total in the index: 7.
| Date listed | Victim | Description |
|---|---|---|
| 2026-10-08 | TMobile | [PSA] You're in big big trouble, oh no, what will you ever do in this … |
| 2026-10-08 | Gate | Crypto Exchange | [PSA] 12 Million Users, Phone numbers, Nicknames, Balance/VIP Tier Lis… |
| 2026-10-05 | Standpointe / Trinite Solutions | [PSA] Finished Financial Statements, Tenant documents & files, Custome… |
| 2026-10-05 | Franklin Empire | [PSA] You know we have over 700GB of Data, AWS Keys to your buckets, (… |
| 2026-10-05 | Trump Mobile Wireless (Telecom) | Trump mobile was informed they had been breached, they then replied wi… |
| 2026-10-05 | Eteam | Eteam was informed they had been breached, just ignored us, we are not… |
| 2026-10-05 | Royal Selangor | [PSA] Both, your Registered Users & Customer list have been affected. … |