Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

RANSOMED · Threat actor profile

THREAT ACTOR

RANSOMED_

Dormant

RANSOMED is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.

For Ransomnews editorial coverage of RANSOMED, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.

78 Victims tracked
0 / 4 Active mirrors
2023-08-21 First listing
2023-10-30 Most recent

Victims by year

  • 2023 78

Leak site mirrors

4 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.

  • ransomed.vc ScreenConnect Remote Support Software snapshot · 2026-03-14 11:08
  • k63fo4qmdnl4cbt54sso3g6s5ycw7gf7i6nvxl3wcf3u6la2mlawt5qd.onion 404 Not Found snapshot · 2023-09-08 20:04
  • f6amq3izzsgtna4vw24rpyhy3ofwazlgex2zqdssavevvkklmtudxjad.onion snapshot · 2024-06-07 23:04
  • g6ocfx3bb3pvdfawbgrbt3fqoht5t6dwc3hfmmueo76hz46qepidnxid.onion snapshot · 2024-12-10 16:03

Recent victims

The 50 most recent victims claimed by RANSOMED. Total in the index: 78.

Date listed Victim Description
2023-10-30 RANSOMEDVC is for sale I do not want to continue being monitored by federal agencies and i wo…
2023-10-22 Ransomedvc Launches A forum Visit us: http://g6ocfx3bb3pvdfawbgrbt3fqoht5t6dwc3hfmmueo76hz46qepidn…
2023-10-20 We Hire Pentesters(5BTC Payout) @RansomedSupport on telegram to join Ransomed.vc is in need of only ad…
2023-10-16 Ransomedvc Pentest Services! Ransomedvc now offers pentesting services! share your targets with us …
2023-10-16 Rob Lee Evidence : Sneak Peek Note : Threat actor Rob Lee has failed to cooperate with the demands m…
2023-10-15 RE : Clarification Third-party involvement in the editing of the last 2 posts cannot be m…
2023-10-15 webpag.com.br database leaked
2023-10-14 Accenture Breach Evidence & Debunking Rob Lee’s Lies How ironic! Rob Lee, the outed threat actor, working under the guise o…
2023-10-14 Colonial Pipeline Company Threat actors – they hide amongst us. It is becoming increasingly diff…
2023-10-12 NEW TWITTER Tweets by RansomedSupport
2023-10-12 Fuck Palestine! We buy your access!! Ransomedvc is now buying access on gaza countries + iran. message our …
2023-10-08 Metroclub.org We successfully extracted the entire content of the metroclub.org webs…
2023-10-08 Optimity UK We’ve successfully obtained control of their entire Azure cloud enviro…
2023-10-08 Baumit Bulgaria We have successfuly obtained all data from Balmit.bg. We have got all …
2023-10-08 Kasida.bg Database Leaked, Download https://qu.ax/nUmY.7z
2023-10-08 I&G Brokers Database, Download Now https://qu.ax/nEqR.7z
2023-10-08 pilini.bg Database, Download Now! https://qu.ax/fiSD.sql
2023-10-08 iLife.bg https://qu.ax/danH.7z
2023-10-08 novoingresso.com.br Our group was able to access everything from the main company servers,…
2023-10-08 webpag.com.br Sample: https://qu.ax/LHRf.gOur group was able to access everything fr…
2023-10-08 rodoviariaonline.com.br Our group was able to access everything from the main company servers,…
2023-10-07 DallBogg Breach We have taken everything from your servers, you failed to contact us b…
2023-10-07 Partnership With Breachforums links: http://breachedu76kdyavc6szj6ppbplfqoz3pgrk3zw57my4vybgblpfeayd…
2023-10-06 BNM.bg We will leak all of the info we have on you if we dont get paid.We req…
2023-10-06 SONY.com Sony Group Corporation, formerly Tokyo Telecommunications Engineering …
2023-10-06 NTT Docomo With approximately 310,000 employees worldwide, NTT (Nippon Telegraph …
2023-10-06 (SALE) District Of Columbia Elections 600k lines VOTERS DATA We have successfully breached the District of Columbia Board Of Electi…
2023-09-26 NTT Docomo - Japan 1st Mobile Operator With approximately 310,000 employees worldwide, NTT (Nippon Telegraph …
2023-09-24 SONY.COM Sony Group Corporation, formerly Tokyo Telecommunications Engineering …
2023-09-24 bnm.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 mango.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 ebag.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 popolo.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 andrews.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 ardes.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 myshoes.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 ecco.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 districtshoes.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 footshop.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 Punto.bg We have locked and deleted everything from your systems, be aware we a…
2023-09-24 arelion.com If you want to decrypt your system and get back your customer data, yo…
2023-09-15 gov.la Did I hear gov? Yep. We have accessed the majorty of their servers tha…
2023-09-09 proxy-sale.com We have been able to access all of linktera critical infrastructure in…
2023-09-09 airelec.bg All of your customer data,records and private documents are mine now, …
2023-09-09 pilini.bg You have been hacked, all your data is now mine, if you want to get yo…
2023-09-09 kasida.bg We have been able to access all of linktera critical infrastructure in…
2023-09-08 Linktera We have been able to access all of linktera critical infrastructure in…
2023-09-05 nucleus.live we have access everything on their servers, including the Database,Cus…
2023-09-05 wantager.com we have access everything on their servers, including the Database,Cus…
2023-09-04 easydentalcare.us We Have accessed all of the critical infrasrtucture of the company, we…

← Back to Ransomtracker

Statistics on this page are computed by Ransomnews from a live leak-site monitoring feed. Numbers update every ten minutes. Operator-written victim descriptions are truncated and shown in snippet form only. Source data: RansomLook (CC BY 4.0), aggregated and adapted by Ransomnews.

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,613 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.