Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

QUANTUM · Threat actor profile

THREAT ACTOR

QUANTUM_

Dormant

QUANTUM is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.

For Ransomnews editorial coverage of QUANTUM, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.

74 Victims tracked
0 / 36 Active mirrors
2021-11-04 First listing
2022-12-09 Most recent

Victims by year

  • 2022 63
  • 2021 11

Leak site mirrors

36 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.

  • quantum445bh3gzuyilxdzs5xdepf3b7lkcupswvkryf3n7hgzpxebid.onion Quantum Blog snapshot · 2024-01-16 03:08
  • quantum445bh3gzuyilxdzs5xdepf3b7lkcupswvkryf3n7hgzpxebid.onion Quantum Blog snapshot · 2024-01-16 03:08
  • 26gzvue4vlgxuiaaotxl3bbdepuf55sdrsailywbrc7kdrcgwo62ghqd.onion snapshot · 2024-12-10 16:17
  • 275dg33wjetp6arghjtp3d7265nsknx2heho5n6bqioy2ehl7c3i3iyd.onion snapshot · 2024-12-10 16:17
  • 2gknqtqreqfoedfd3sey4vqgp7fhc4xyagtj6yl3pz6swkliuakfx7ad.onion snapshot · 2024-12-10 16:17
  • 2k5qdebrbzv2uj2xz25f53bhjyqgmv2vixyy7p3vaeeb2bqz6jhnalad.onion snapshot · 2024-12-10 16:17
  • 3uzycwcxrccpvrwx43mpr3gxwcqqgu4x72kedws6zuolp45gopjrzqyd.onion snapshot · 2024-12-10 16:17
  • 6kkjbpmqavf2nvs33furf3hywg2z4e4zrnwnmzegcpq4atfyp3jilnid.onion snapshot · 2024-12-10 16:18
  • 77jtf3wyb4rtsemeodl6h3hfblhgwj32ex3r7ywigg5mzfaqf7w5x7qd.onion snapshot · 2024-12-10 16:18
  • 7qlb63hy45ijihaeal26uyoms4r33dlrg64dr7ry7blnzhhwhov6jsad.onion snapshot · 2024-12-10 16:18
  • 7sqjgyldxtur4p3nkpdzacldqonnovklnibxhz4y6saremsrmh6vf2yd.onion snapshot · 2024-12-10 16:18
  • agxyd52t6tfoahsvi6mfk7nqwpoe2xj6wp75vnv7ffrfxg5vtw6guxid.onion snapshot · 2024-12-10 16:18
  • b2rt3dmb62jo62e2rr5rfrpyomka477tjkcni2fsamjd3wksolae5wqd.onion snapshot · 2024-12-10 16:18
  • bfdwhgjey6xb25e6pc6i7upnswh4znqwwnmlmgzapiwfmt7ugzcwvyyd.onion snapshot · 2024-12-10 16:19
  • bi7v6o5djhfji22usugjzpk26nvvwugaubrf3yypyvmkzw7su2nad5id.onion snapshot · 2024-12-10 16:19
  • cee77a5wsey5vohubq76en4bgsqbdrasito3zn7ziu5vouhbzxtx6syd.onion snapshot · 2024-12-10 16:19
  • ct7jsq3dbwcvcafnwli7tfv2pf62y2rfhos4a66gu7twqkcclkih6wqd.onion snapshot · 2024-12-10 16:19
  • dblgdn4manmaiewnsqa3vgm26v7ujtx75wtev5pyfmtpww4ofqrqpiid.onion snapshot · 2024-12-10 16:19
  • dw6sy3pt54fh6d3yo4wpb7qjtwdlyyi3qd5oabdwlmlmuyhsxvnblvqd.onion snapshot · 2024-12-10 16:21
  • fjlprvuqzs6h4ielcdkmof5nju3ent7c34esaptm7677xono7osvp5yd.onion snapshot · 2024-12-10 16:21
  • friazjtqhznoknwi5354lnkwa4lhgjti74l4asfhsjeoe5dulwitpcqd.onion snapshot · 2024-12-10 16:21
  • k2j6llaw66bvlgxcy67uj2prdqqzbl7aj46wab4mpdyizpmati55kfad.onion snapshot · 2024-12-10 16:21
  • leqg2fthiage4ockldnf7trwdx3bvehni7vjf6wbwsitnbjtotbv3nid.onion snapshot · 2024-12-10 16:21
  • nugus3xk456m3xhokm2q5zusujhqodirm5vfke6jmsej2jy6sgbn4oqd.onion snapshot · 2024-12-10 16:21
  • nxvvamxmbdn3latdplq6azgeeuieaek32h674nl6lzavcod2f2obvxyd.onion snapshot · 2024-12-10 16:21
  • ohmhgcrvte6aftgnm5lefq7ztannicarzo6lus2bih3zg6ugklf4tsyd.onion snapshot · 2024-12-10 16:22
  • oyjydoka32xa24doeymhq4thoibxqdd7i7hnngojpycd74frggkvhyyd.onion snapshot · 2024-12-10 16:22
  • q45frho6hatxtx7qxjytt4cswinakvc2h6iag65jlsaws32xdzz47kyd.onion snapshot · 2024-12-10 16:22
  • rrmywkltwjpntybqj7migd5ibdzzxulnhgndb6dnoe6unlljslqb7lid.onion snapshot · 2024-12-10 16:22
  • uwr2mmcqtroeyu6bzgivwwzdcpe2a4e74r2srlzveyltsi57n5bnsbqd.onion snapshot · 2024-12-10 16:22

Recent victims

The 50 most recent victims claimed by QUANTUM. Total in the index: 74.

Date listed Victim Description
2022-12-09 Radical Sportscars Radical Sportscars is headquartered in Peterborough, UK and is respons…
2022-12-09 Orotex Orotex Corporation's goal is to achieve complete customer satisfaction…
2022-12-09 Pilenpak We continuously increase the value we create for our stakeholders by p…
2022-12-09 AHT Wisconsin Windows AHT Wisconsin Windows is ready to help you make your home more beautif…
2022-12-09 ChemiFlex For over 40 years, Chemi-Flex has served as the leading designer and m…
2022-12-09 Acquarius Trust Group Based in Gibraltar, the Acquarius Trust Group is a group of inter-rela…
2022-11-13 Midland Cogeneration Venture Midland Cogeneration Venture (MCV) is the largest natural gas fired co…
2022-11-02 MCV Holding Company LLC At Capital Power, we’re working to create a brighter world powered by …
2022-11-01 Midland Cogeneration Venture, Michigan Midland Cogeneration Venture is the largest natural gas-fired combined…
2022-10-21 Lightbank Why Eric Lefkofsky https://en.wikipedia.org/wiki/Eric_Lefkofsky bought…
2022-10-18 Rosenblatt Securities About Rosenblatt Securities: Rosenblatt Securities is a boutique tech …
2022-09-02 Instituto Agrario Dominicano The Dominican Agrarian Institute is a decentralized government agency …
2022-09-01 Moscone Center Founded in 1981. Moscone Center is headquartered in San Fransisco, Cal…
2022-08-23 Moskowitz, Mandell & Salim, P.A. Moskowitz, Mandell & Salim, P.A. was established in 1985 and provides …
2022-08-20 Shaw & Slavsky Shaw & Slavsky was founded in 1932 as a manufacturer of POP signs for …
2022-08-18 Florida Department of Veterans' Affairs Connecting veterans to federal and state benefits they have earned.
2022-08-18 Hirsch Watch Straps & Accessories HIRSCH develops and manufactures the most advanced, the most detailed …
2022-08-18 Digital Workplace Services & Solutions Digital Workplace | Enterprise Mobility | IoT | ISEC7 SPHERE | Mobile …
2022-08-18 Lewis & Clark College L&C, founded in 1970, is a two-year higher education institution with …
2022-08-18 Service Employees' International Union SEIU represents approximately 100,000 members. SEIU represents members…
2022-08-18 Delon Hampton & Associates, Chartered In January 1973, Delon Hampton and Associates, Chartered was founded w…
2022-08-08 Freyr Solutions Freyr is one of the largest, global, Regulatory-focused solutions and …
2022-08-04 Liftow LTD Founded in 1960, Liftow is a Toyota forklift dealer group in North Ame…
2022-08-04 BEESENSE BeeSense designs, develops and manufactures advanced, unique, multi-se…
2022-07-19 Delon Hampton & Associates, Chartered
2022-07-19 Autohaus
2022-07-19 Broshuis | Driving innovation Broshuis B.V. is a 100% family owned, Dutch company and one of the lar…
2022-07-14 ZEUS Scientific This company provides medical testing equipment and diagnostic service…
2022-07-12 American International Industries Founded in 1971, American International Industries is a manufacturer a…
2022-07-02 Avante Health Solutions Avante Health Solutions is a single source provider of medical, surgic…
2022-07-02 Crupi Group The Crupi Group is an assembly of companies surrounding D. Crupi and S…
2022-06-16 RG Alliance Group R.G. Alliance is an Outsourced Financial Consulting firm based in San …
2022-06-14 Shred Station Shred Station understand that secure destruction of your confidential …
2022-06-14 M. Green and Company LLP Certified Public Accountants
2022-06-14 YMCA YMCA of South Florida has been dedicated to building healthy, confiden…
2022-06-14 Medlab Pathology Medlab Pathology is one of Australia's largest, privately owned indepe…
2022-05-27 Florida Department of Veterans' Affairs
2022-05-23 Active Communications International
2022-05-23 Transsion Holdings
2022-05-23 Eurocept
2022-05-17 Tex-Isle Supply Tex-Isle Supply, Inc. is a leading distributor of high quality energy …
2022-05-17 Hirsch Watch Straps & Accessories
2022-05-17 InnPower
2022-04-30 Hufcor Movable glass wall company
2022-04-30 Valley Rentals real estate investment company
2022-04-30 Petro Serve Largest supplier of home heating, commercial and agricultural fuel, an…
2022-04-29 Grosvenor Engineering Group Building services partner in Australia and New Zealand
2022-04-29 Drive Products Drive Products now offers a complete range of truck mounted equipment,…
2022-04-29 Henry Henry Company is an innovator of building envelope systems and develop…
2022-04-28 Tehama County Social Services Tehama County in California

CONFIRMED ATTACKS

Quantum confirmed attacks: 9 verified incidents

Ransomnews has verified 9 Quantum incidents against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. The confirmed record runs from November 2021 to August 2022. United States accounts for 5 of them (56%), with victims recorded in 5 countries in total. The most affected sector is government, at 3 confirmed victims. A ransom payment was publicly confirmed in 1 case and publicly refused in 2; the outcome is unrecorded in the remaining 6. Where a figure was disclosed (4 cases), these incidents account for 2,212,484 exposed records.

9Verified incidents
5Countries
2021–2022Active range
33%Paid, where outcome known

Confirmed victims by year

  • 20211
  • 20228

Most affected sectors

  • Government3
  • Finance2
  • Healthcare2
  • Manufacturing1
  • Education1

Most affected countries

  • United States5
  • Dominican Republic1
  • Australia1
  • Netherlands1
  • Italy1

Verified Quantum incidents

DateOrganisationSector LocationRecordsRansom paidSource
August 2022 Instituto Agrario Dominicano Government Santo Domingo, Dominican Republic — No Source
May 2022 M. Green and Company Finance California, United States 15,000 Unknown Source
May 2022 Jordan Health Products, LLC d/b/a Avante Health Solutions Healthcare Illinois, United States 1,785 Unknown Source
April 2022 Glenn County Office of Education and School Districts Education California, United States — Yes Source
February 2022 Professional Finance Company, Inc. Finance Colorado, United States 1,972,699 Unknown Source
February 2022 Regione Autonoma della Sardegna Government Sardegna, Italy — No Source
February 2022 Australian Clinical Labs - Medlab Pathology Healthcare Auburn, Australia 223,000 Unknown Source
January 2022 Broshius BV Manufacturing Kampen, Netherlands — Unknown Source
November 2021 County of Tehama Government California, United States — Unknown Source

Claimed vs confirmed. The figures above the fold on this page come from Quantum's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.

← Back to Ransomtracker

Statistics on this page are computed by Ransomnews from a live leak-site monitoring feed. Numbers update every ten minutes. Operator-written victim descriptions are truncated and shown in snippet form only. Source data: RansomLook (CC BY 4.0), aggregated and adapted by Ransomnews.

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,613 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.