// THREAT ACTOR
FREECIVILIAN_
DormantFREECIVILIAN is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of FREECIVILIAN — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2022 14
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
gcbejm2rcjftouqbxuhimj5oroouqcuxb2my4raxqa7efkz5bd5464id.onionFree Civilian snapshot · 2023-06-01 20:10
Recent victims
The 50 most recent victims claimed by FREECIVILIAN. Total in the index: 14.
| Date listed | Victim | Description |
|---|---|---|
| 2022-08-18 | mfa.gov.ua | |
| 2022-08-18 | minagro.gov.ua | |
| 2022-08-18 | mon.gov.ua | |
| 2022-08-18 | kmu.gov.ua | |
| 2022-08-18 | gkh.in.ua | |
| 2022-08-18 | bdr.mvs.gov.ua | |
| 2022-08-18 | kyivcity.com | |
| 2022-08-18 | motorsich.com | |
| 2022-08-18 | mtsbu.ua | |
| 2022-08-18 | health.mia | |
| 2022-08-18 | minregion.gov.ua | |
| 2022-08-18 | wanted.mvs.gov.ua | |
| 2022-08-18 | e-driver.hsc.gov.ua | |
| 2022-08-18 | diia.gov.ua |