// THREAT ACTOR
EXITIUM_
ActiveEXITIUM is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of EXITIUM — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2026 7
Leak site mirrors
1 mirror tracked, 1 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
m3ksukzn2glzfdvlusohril7n3iyk4z4fudf6mm22lwhpbpt5aiee5qd.onionExitium snapshot · 2026-08-06 21:21
Recent victims
The 50 most recent victims claimed by EXITIUM. Total in the index: 7.
| Date listed | Victim | Description |
|---|---|---|
| 2026-05-16 | Gastroenterology & Hepatology of CNY[FULL_LEAK] | We decided to leak all patient records. Enjoy) |
| 2026-04-11 | Gastroenterology & Hepatology of CNY | Website: gandhofcny.com Zoominfo: https://www.zoominfo.com/c/gastroent… |
| 2026-03-29 | Ming Hwei Energy | Zoominfo: https://www.zoominfo.com/c/ming-hwei-energy-co-ltd/446006038… |
| 2026-03-28 | IKRON | Zoominfo: https://www.zoominfo.com/c/ikron-corp/1307855073 Totally st… |
| 2026-03-17 | Classified | Information will be available after publication |
| 2026-03-12 | Fannin CAD | Zoominfo: https://www.zoominfo.com/pic/fannin-central-appraisal-distri… |
| 2026-03-12 | Marborges Agroindustria | Zoominfo: https://www.zoominfo.com/c/marborges-agroindustria/547271801… |