THREAT ACTOR
SHADOWBYT3_
ActiveSHADOWBYT3 is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of SHADOWBYT3, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2026 41
Leak site mirrors
9 mirrors tracked, 1 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
shadowbyt3s.8bit.caShadowByt3$ snapshot · 2026-02-28 21:00 -
shadowsblog.cloud-ip.ccShadowByt3$ snapshot · 2026-02-28 21:27 -
shadoz22.iosnapshot · 2026-02-24 17:25 -
45.84.0.211.IIS Windows Server snapshot · 2026-06-30 18:07 -
mfbbt65kir2drc7tuoukwibikgvxquauscnzgbeltkmidjtgqlzm2qad.onionLeaks snapshot · 2026-04-24 05:34 -
sdwbytqeb664krp2wz2qs3lxxah2rhneuotot5hy7g4jpn2pindigcad.onionLeaks snapshot · 2026-04-24 05:02 -
shdwbt3ja2ptjt6poluegas44i35727lgmoqqquoww642x3zyocyhuqd.onionSB Group snapshot · 2026-06-18 22:16 -
ttp.SB Data Leak Site snapshot · 2026-06-18 22:30 -
sdwbyttda4uzwdffbt4m7niuodiwhcgmkyxqg5nly2bjxqa6xtbe3fyd.onionCAPTCHA | ShadowByt3$ 2.0 snapshot · 2026-09-23 05:36
Recent victims
The 50 most recent victims claimed by SHADOWBYT3. Total in the index: 41.
| Date listed | Victim | Description |
|---|---|---|
| 2026-06-16 | TINYpulse NINTENDO BREACH (nintendo.com) | This will be quick. You don't even want to read the private messages a… |
| 2026-06-14 | TinyPulse Nintendo (Nintendo.com) nintendo_file_tree.txt | The breach has been confusing some people like they didn't breach nint… |
| 2026-06-13 | Stride Learning | Stride Learning Should've Paid the ransom. We were only asking $500,00… |
| 2026-06-13 | University Of Georgia | ShadowByt3$ has breached University of Georgia. The full data is on ar… |
| 2026-06-13 | StarBucks Company (StarBucks.com | StarBucks Failed to reach out to us and didn't pay even $500,000 when … |
| 2026-06-13 | Hotelogix Company (Hotelogix.com) | Should've not messed with us Hotelogix. We gave you guys numerous time… |
| 2026-06-13 | BreachForums is Back (breachforu.ms) | This is not a leak just an announcement that will stay up for however … |
| 2026-06-13 | Lead Company (Leadership Boulevard) | Company Site: leadschool.in size: 765.9MB This is will be quick. The f… |
| 2026-06-13 | Cropwise (Syngenta Group) | Company Site: leadschool.in size: 765.9MB This is will be quick. The f… |
| 2026-06-13 | Nintendo Company (Nintendo.com) | proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are S… |
| 2026-04-22 | Eric J Taylor Doxx | |
| 2026-04-21 | Stride Learning Full Breach (stridelearning.com) | |
| 2026-04-21 | Ellucian PowerCapus (ellucian.com) | |
| 2026-04-21 | Stride Learning (Stridelearning.com) | |
| 2026-04-17 | Ellucian PowerCampus Sample (ellucian.com) | |
| 2026-04-17 | Ellucian PowerCampus (ellucian.com) | |
| 2026-04-17 | Stride Learning Parent Company (stridelearning.com) | |
| 2026-04-14 | Amplify Technology (amplifytechnology.co.uk) | |
| 2026-04-14 | University Of Georgia (uga.edu) | |
| 2026-04-14 | UMSA Argentina | |
| 2026-04-14 | StarBucks (Starbucks.com) | |
| 2026-04-12 | Amplify_Technology_breached_032326 | |
| 2026-04-12 | Hotelogix (Hotelogix.com) | |
| 2026-04-12 | Proof Sample Hotelogix (Hotelogix.com) | |
| 2026-04-10 | https://anonfilesnew.com/7N0EOmzgCpg/sample_Pay_or_gets_leaked_and_sold_and_on_news. | |
| 2026-04-10 | sample_Pay_or_gets_leaked_and_sold_and_on_news | |
| 2026-04-09 | Sample_Forestal Atlántico Sur (FAS)_fas.com.uy | |
| 2026-04-09 | Pay_until_timer_runs_outForestal Atlántico Sur (FAS)_fas.com.uy | |
| 2026-04-06 | University_Of_Georgia | |
| 2026-04-06 | StarBucks_Sample | |
| 2026-04-06 | StarBucks_10GB_Pay_or_gets_leaked | |
| 2026-04-06 | nyayanagarpublicschool_in_part_1 | |
| 2026-04-06 | nyayanagarpublicschool_in_part_4 | |
| 2026-04-06 | nyayanagarpublicschool_in_part_2 | |
| 2026-04-06 | nyayanagarpublicschool_in_part_5 | |
| 2026-04-06 | nyayanagarpublicschool_in_part_3 | |
| 2026-04-06 | Eurobetscasino | |
| 2026-04-06 | UMSA_Argentina_All_15GB | |
| 2026-04-06 | $HADOWBYT3$_1.0_Leak | |
| 2026-04-06 | PGP_Verified_Public_key | |
| 2026-02-24 | UMSA_LEAK.7z |
CONFIRMED ATTACKS
Shadowbyt3$ confirmed attacks: 1 verified incident
Ransomnews has verified 1 Shadowbyt3$ incident against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. All of them fall in June 2026. United States accounts for 1 of them (100%). The most affected sector is healthcare, at 1 confirmed victim.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified Shadowbyt3$ incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| June 2026 | TINYpulse (WebMD Health Services) | Healthcare | Oregon, United States | — | Unknown | Source |
Claimed vs confirmed. The figures above the fold on this page come from Shadowbyt3$'s own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.