// THREAT ACTOR
MINTEYE_
DormantMINTEYE is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of MINTEYE — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2025 5
Leak site mirrors
2 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
85.121.48.68MintEye blog snapshot · 2026-01-10 06:08 -
i6575ykikb3yvut4btucoqjshbktouxxyu3eb3ffa3ukvyvtam5y5pqd.onionsnapshot · 2025-12-24 07:04
Recent victims
The 50 most recent victims claimed by MINTEYE. Total in the index: 5.
| Date listed | Victim | Description |
|---|---|---|
| 2025-12-13 | Keylogistics Chile SA | Keylogistics Chile S.A is a premier Warehousing Companies located in -… |
| 2025-12-13 | Inter-American Tropical Tuna Commission (IATTC) | IATTC is the oldest of the five tuna Regional Fisheries Management Org… |
| 2025-12-13 | Sponseller Group, Inc. | Sponseller Group Inc. is a trusted supplier of engineering and design … |
| 2025-12-13 | Cranford, Buckley, Schultze, Tomchin, Allen & Buie, P.A. | Cranford, Buckley, Schultze, Tomchin, Allen & Buie, P.A. is a South Ch… |
| 2025-12-13 | David M. Schwarz Architects | David M. Schwarz Architects, Inc. (DMSAS) is a design firm based in Wa… |