// THREAT ACTOR
ORCA_
DormantORCA is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of ORCA — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2025 2
- 2024 4
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
orca66hwnpciepupe5626k2ib6dds6zizjwuuashz67usjps2wehz4id.onionLeaks snapshot · 2026-02-03 14:07
Recent victims
The 50 most recent victims claimed by ORCA. Total in the index: 6.
| Date listed | Victim | Description |
|---|---|---|
| 2025-05-07 | Transport Lutztulln | Lutz GmbH, operating under the name Transport Lutz Tulln, is a privat… |
| 2025-03-16 | Casale Del Giglio | Casale del Giglio was founded in 1967 by Dr. Berardino Santarelli, a n… |
| 2024-10-04 | Transtec SAS | Transtec SAS is a company that operates in the Commercial Printing ind… |
| 2024-09-18 | Chernan Technology | Chernan Technology Co. Ltd. was founded on April 10th, 1984, as a subs… |
| 2024-09-16 | INTRODUCTION | Orca Ransomware's primary motivation is driven by financial incentives… |
| 2024-09-16 | ExcelPlast Tunisie | Company product portfolio covers PP and Polyester plastic sheeting wit… |