// THREAT ACTOR
LINKC_
DormantLINKC is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of LINKC — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2026 6
- 2025 1
Leak site mirrors
2 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
iywqjjaf2zioehzzauys3sktbcdmuzm2fsjkqsblnm7dt6axjfpoxwid.onionLinkc Pub snapshot · 2026-08-04 15:10 -
xs4psqhvekjle3qwyiav7dzccuo4ylw2eylvd3peuqrld74kzzjzhcyd.onionsnapshot · 2025-09-06 22:17
Recent victims
The 50 most recent victims claimed by LINKC. Total in the index: 7.
| Date listed | Victim | Description |
|---|---|---|
| 2026-04-07 | Sajet Products | 700mb of blueprints including Amazon LEO (satellite) Project Kuiper sc… |
| 2026-03-10 | Sajet Products [SAMPLE PUBLUSHED] | 700mb of blueprints including Amazon LEO (satellite) Project Kuiper sc… |
| 2026-03-02 | StrongLink [SAMPLE PUBLISHED] | DOWNLOAD SAMPLE: https://amber-wooden-prawn-35.mypinata.cloud/ipfs/baf… |
| 2026-02-27 | Network Technology Services of New Jersey | Whole datacenter is encrypted. Waiting for you in chat. |
| 2026-02-03 | Sajet Products (Senior Aerospace) | We have confirmed that due to ransomware attack in early december, you… |
| 2026-02-03 | StrongLink | All repositories with Strong Link source code were successfully exfilt… |
| 2025-02-18 | h2o.ai | As a result of our operation, we have discovered the following concern… |