THREAT ACTOR
CUBA_
DormantCUBA is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of CUBA, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2024 2
- 2023 18
- 2022 73
- 2021 12
Leak site mirrors
4 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
cuba4mp6ximo2zlo.onionCuba snapshot · 2022-08-28 10:03 -
cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onionCuba snapshot · 2024-02-08 11:10 -
i34gbmo5rxx3bxc4yl7f4erkyo2oldwavhpdragnjjvhni6fwvptp2id.onionsnapshot · 2024-12-11 12:06 -
kcfgfs7cclscxloy3bf2xtwnayimawtzrbfirfbvl47xt7n2brfiizyd.onionsnapshot · 2025-01-25 02:46
Recent victims
The 50 most recent victims claimed by CUBA. Total in the index: 105.
| Date listed | Victim | Description |
|---|---|---|
| 2024-02-01 | dms-imaging | |
| 2024-01-22 | deknudtframes.be | |
| 2023-11-14 | diagnostechs | |
| 2023-11-13 | portadelaidefc | |
| 2023-11-07 | panaya | |
| 2023-11-07 | prime-art | |
| 2023-10-23 | Newconcepttech | |
| 2023-10-10 | mountstmarys | |
| 2023-10-03 | co.rock.wi.us | |
| 2023-08-19 | goldmedalbakery | |
| 2023-07-31 | hydrex.co.uk | |
| 2023-07-31 | txmplant.co.uk | |
| 2023-07-11 | gis4.addison-il | |
| 2023-05-23 | Inquirer | |
| 2023-05-10 | Vdi | |
| 2023-05-04 | 2networkit | |
| 2023-05-04 | Sae-a | |
| 2023-05-04 | pu.edu.lb | |
| 2023-05-04 | Gihealthcare | |
| 2023-05-04 | cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion | |
| 2022-12-02 | learning_resources | |
| 2022-12-02 | usairports | |
| 2022-12-02 | first_coast_logistics_services | |
| 2022-12-02 | e.h._wachs_pipe_cutters | |
| 2022-12-02 | datamatics | |
| 2022-12-02 | the_rose_executive_team | |
| 2022-12-02 | afts | |
| 2022-12-02 | otrcapital | |
| 2022-12-02 | forefront_dermatology | |
| 2022-12-02 | innovairre | |
| 2022-12-02 | megaforce | |
| 2022-12-02 | gascaribe | |
| 2022-12-02 | quercus | |
| 2022-12-02 | blackhawk | |
| 2022-12-02 | lycra | |
| 2022-12-02 | technicote | |
| 2022-12-02 | berding-weil | |
| 2022-12-02 | nwdusa | |
| 2022-12-02 | creditriskmonitor | |
| 2022-12-02 | linkmfg | |
| 2022-12-02 | axley | |
| 2022-12-02 | schultheis-ins | |
| 2022-12-02 | meriplex | |
| 2022-12-02 | ohagin | |
| 2022-12-02 | landofrost | |
| 2022-12-02 | ncmutuallife2 | |
| 2022-12-02 | get-integrated | |
| 2022-12-02 | trant.co.uk | |
| 2022-12-02 | bcintlgroup.com | |
| 2022-12-02 | stm.com.tw |
CONFIRMED ATTACKS
Cuba confirmed attacks: 14 verified incidents
Ransomnews has verified 14 Cuba incidents against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. The confirmed record runs from February 2020 to November 2023. United States accounts for 8 of them (57%), with victims recorded in 7 countries in total. The most affected sector is government, at 4 confirmed victims. A ransom payment was publicly confirmed in 0 cases and publicly refused in 5; the outcome is unrecorded in the remaining 9. Where a figure was disclosed (6 cases), these incidents account for 2,485,074 exposed records.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified Cuba incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| November 2023 | Port Adelaide Football Club | Other | Alberton, Australia | — | Unknown | Source |
| October 2023 | PAJ, Inc. (Prime Art & Jewel) | Manufacturing | Texas, United States | 375 | Unknown | Source |
| September 2023 | Rock County | Government | Wisconsin, United States | 25,823 | No | Source |
| May 2023 | Transporto Kompetencijų Agentūra | Government | Vilnius, Lithuania | — | Unknown | Source |
| May 2023 | The Philadelphia Inquirer | Other | Pennsylvania, United States | 25,549 | Unknown | Source |
| December 2022 | Landau Media | Other | Berlin, Germany | — | Unknown | Source |
| December 2022 | 2NetworkIT | Technology | Ottawa, Canada | — | No | Source |
| October 2022 | Ville de Chaville | Government | Chaville, France | — | No | Source |
| August 2022 | Government of Montenegro | Government | Podgorica, Montenegro | — | No | Source |
| May 2022 | FRONTEO USA, Inc. | Technology | New York, United States | — | Unknown | Source |
| September 2021 | Professional Healthcare Management, Inc. | Healthcare | Tennessee, United States | 17,710 | Unknown | Source |
| May 2021 | Forefront Dermatology, S.C. | Healthcare | Wisconsin, United States | 2,413,553 | Unknown | Source |
| February 2021 | Automatic Funds Transfer Services | Finance | Washington, United States | 2,064 | No | Source |
| February 2020 | E.H. Wachs | Manufacturing | Illinois, United States | — | Unknown | Source |
Claimed vs confirmed. The figures above the fold on this page come from Cuba's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.