// THREAT ACTOR
SECP0_
ActiveSECP0 is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of SECP0 — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2026 8
- 2025 5
Leak site mirrors
8 mirrors tracked, 4 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
secponewsxgrlnirowclps2kllzaotaf5w2bsvktdnz4qhjr2jnwvvyd.onionSECP0 News snapshot · 2026-08-06 21:39 -
secp0-news.netSECP0 News snapshot · 2025-05-15 18:11 -
secponewsxgrlnirowclps2kllzaotaf5w2bsvktdnz4qhjr2jnwvvyd.onionSECP0 News - /files/12b3429e1124122e/ snapshot · 2026-08-06 21:03 -
bhn2xz5jer2xeibxjzhgfp7qclttnbvkkvd4hvlmjbnz66jxq7yzn6ad.onion404 Not Found snapshot · 2026-08-06 21:13 -
2a6w667vebiebciji7vm3vj43svegvozoqypttdgojzgdcbnfsu5wiid.onion404 Not Found snapshot · 2026-08-06 21:10 -
secp0-support.netsnapshot · 2025-07-21 17:40 -
secp0-support.cfd404 Not Found snapshot · 2026-05-02 15:10 -
secp0-news.wsSECP0 News snapshot · 2026-05-02 15:12
Recent victims
The 50 most recent victims claimed by SECP0. Total in the index: 13.
| Date listed | Victim | Description |
|---|---|---|
| 2026-04-30 | Leak: Color Communications LLC | The exposed dataset includes over 200,000 unique files containing sens… |
| 2026-04-29 | Color Communications LLC | The exposed dataset includes over 200,000 unique files containing sens… |
| 2026-03-09 | /files/12b3429e1124122e/ | |
| 2026-03-09 | Leak: Mike Brandner Law | The total volume of extracted data amounts to approximately 489 GB (45… |
| 2026-03-09 | Leak: Richmond Plywood Corporation Limited | The total volume of extracted data amounts to approximately 1.09TB (52… |
| 2026-03-09 | Important Announcement | Our colleagues in offensive security at lexfo.fr published a review of… |
| 2026-03-09 | Leak: Indigo Group | The exposed dataset includes over 897,000 unique files (1,707,433 with… |
| 2026-03-09 | Leak: JM Bozeman Enterprises | The exposed dataset includes over 100,000 unique files (192,993 with d… |
| 2025-07-21 | Publication hold announcement | Hello everyone! We have a substantial queue of companies waiting fo… |
| 2025-04-28 | Announcement for the Terralogic and its clients | Due to Terralogic's unwillingness to cooperate, we are publishing evid… |
| 2025-03-06 | Response to PRODAFT journalists | Hello, PRODAFT! Could you clarify where exactly you saw information ab… |
| 2025-03-05 | Passwordstate weak encryption article | Some time ago I came across a server running Passwordstate software, w… |
| 2025-03-05 | Welcome | We are pleased to welcome you to our blog, a dedicated space designed … |