Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

RANSOMED · Threat actor profile

// THREAT ACTOR

RANSOMED_

Dormant

RANSOMED is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.

For Ransomnews editorial coverage of RANSOMED — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.

78 Victims tracked
0 / 4 Active mirrors
2023-08-21 First listing
2023-10-30 Most recent

Victims by year

  • 2023 78

Leak site mirrors

4 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.

  • ransomed.vc ScreenConnect Remote Support Software snapshot · 2026-03-14 11:08
  • k63fo4qmdnl4cbt54sso3g6s5ycw7gf7i6nvxl3wcf3u6la2mlawt5qd.onion 404 Not Found snapshot · 2023-09-08 20:04
  • f6amq3izzsgtna4vw24rpyhy3ofwazlgex2zqdssavevvkklmtudxjad.onion snapshot · 2024-06-07 23:04
  • g6ocfx3bb3pvdfawbgrbt3fqoht5t6dwc3hfmmueo76hz46qepidnxid.onion snapshot · 2024-12-10 16:03

Recent victims

The 50 most recent victims claimed by RANSOMED. Total in the index: 78.

Date listed Victim Description
2023-10-30 RANSOMEDVC is for sale I do not want to continue being monitored by federal agencies and i wo…
2023-10-22 Ransomedvc Launches A forum Visit us: http://g6ocfx3bb3pvdfawbgrbt3fqoht5t6dwc3hfmmueo76hz46qepidn…
2023-10-20 We Hire Pentesters(5BTC Payout) @RansomedSupport on telegram to join Ransomed.vc is in need of only ad…
2023-10-16 Ransomedvc Pentest Services! Ransomedvc now offers pentesting services! share your targets with us …
2023-10-16 Rob Lee Evidence : Sneak Peek Note : Threat actor Rob Lee has failed to cooperate with the demands m…
2023-10-15 RE : Clarification Third-party involvement in the editing of the last 2 posts cannot be m…
2023-10-15 webpag.com.br database leaked
2023-10-14 Accenture Breach Evidence & Debunking Rob Lee’s Lies How ironic! Rob Lee, the outed threat actor, working under the guise o…
2023-10-14 Colonial Pipeline Company Threat actors – they hide amongst us. It is becoming increasingly diff…
2023-10-12 NEW TWITTER Tweets by RansomedSupport
2023-10-12 Fuck Palestine! We buy your access!! Ransomedvc is now buying access on gaza countries + iran. message our …
2023-10-08 Metroclub.org We successfully extracted the entire content of the metroclub.org webs…
2023-10-08 Optimity UK We’ve successfully obtained control of their entire Azure cloud enviro…
2023-10-08 Baumit Bulgaria We have successfuly obtained all data from Balmit.bg. We have got all …
2023-10-08 Kasida.bg Database Leaked, Download https://qu.ax/nUmY.7z
2023-10-08 I&G Brokers Database, Download Now https://qu.ax/nEqR.7z
2023-10-08 pilini.bg Database, Download Now! https://qu.ax/fiSD.sql
2023-10-08 iLife.bg https://qu.ax/danH.7z
2023-10-08 novoingresso.com.br Our group was able to access everything from the main company servers,…
2023-10-08 webpag.com.br Sample: https://qu.ax/LHRf.gOur group was able to access everything fr…
2023-10-08 rodoviariaonline.com.br Our group was able to access everything from the main company servers,…
2023-10-07 DallBogg Breach We have taken everything from your servers, you failed to contact us b…
2023-10-07 Partnership With Breachforums links: http://breachedu76kdyavc6szj6ppbplfqoz3pgrk3zw57my4vybgblpfeayd…
2023-10-06 BNM.bg We will leak all of the info we have on you if we dont get paid.We req…
2023-10-06 SONY.com Sony Group Corporation, formerly Tokyo Telecommunications Engineering …
2023-10-06 NTT Docomo With approximately 310,000 employees worldwide, NTT (Nippon Telegraph …
2023-10-06 (SALE) District Of Columbia Elections 600k lines VOTERS DATA We have successfully breached the District of Columbia Board Of Electi…
2023-09-26 NTT Docomo - Japan 1st Mobile Operator With approximately 310,000 employees worldwide, NTT (Nippon Telegraph …
2023-09-24 SONY.COM Sony Group Corporation, formerly Tokyo Telecommunications Engineering …
2023-09-24 bnm.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 mango.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 ebag.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 popolo.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 andrews.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 ardes.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 myshoes.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 ecco.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 districtshoes.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 footshop.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 Punto.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 arelion.com If you want to decrypt your system and get back your customer data, yo…
2023-09-15 gov.la Did I hear gov? Yep. We have accessed the majorty of their servers tha…
2023-09-09 proxy-sale.com We have been able to access all of linktera critical infrastructure in…
2023-09-09 airelec.bg All of your customer data,records and private documents are mine now, …
2023-09-09 pilini.bg You have been hacked, all your data is now mine, if you want to get yo…
2023-09-09 kasida.bg We have been able to access all of linktera critical infrastructure in…
2023-09-08 Linktera We have been able to access all of linktera critical infrastructure in…
2023-09-05 nucleus.live we have access everything on their servers, including the Database,Cus…
2023-09-05 wantager.com we have access everything on their servers, including the Database,Cus…
2023-09-04 easydentalcare.us We Have accessed all of the critical infrasrtucture of the company, we…

← Back to Ransomtracker

Statistics on this page are computed by Ransomnews from a live leak-site monitoring feed. Numbers update every ten minutes. Operator-written victim descriptions are truncated and shown in snippet form only. Source data: RansomLook (CC BY 4.0), aggregated and adapted by Ransomnews.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.