THREAT ACTOR
SIEGEDSEC_
DormantSIEGEDSEC is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of SIEGEDSEC, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2023 19
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
nv5p2mmpctvyqdyyi5zwh4gnifq2uxdx4etvnmaheqlrw6ordrjwxryd.onionsnapshot · 2024-03-25 17:13
Recent victims
The 50 most recent victims claimed by SIEGEDSEC. Total in the index: 19.
| Date listed | Victim | Description |
|---|---|---|
| 2023-12-09 | OpTransRights - 2 | healthcare |
| 2023-12-09 | Telerad | healthcare |
| 2023-12-09 | Technical University of Mombasa | kenyan education |
| 2023-12-09 | National Office for centralized procurement | romanian government |
| 2023-12-09 | Portland Government & United states government | governmental |
| 2023-12-09 | Staples | retail |
| 2023-12-09 | Deqing County | chinese citizens |
| 2023-12-09 | Colombian National Registry | corrective measures, police |
| 2023-12-09 | Idaho National Laboratory | nuclear research, nuclear power, power plant |
| 2023-12-09 | Operation Israel - 1 | government sector, supermarket chain, airline |
| 2023-12-09 | Cellcom | telecommunications |
| 2023-12-09 | Bezeq | telecommunications, fixed-line, mobile telephony |
| 2023-12-09 | GNSS, BACNet & ModBus | navigation satellite system, building automation and control systems, … |
| 2023-12-09 | Operation Jane | industrial control systems, government |
| 2023-12-09 | Atlassian | software developers, project managers, it service management |
| 2023-12-09 | Faroe Islands | tourism, travel guides, accommodation |
| 2023-12-09 | NATO Leak - 2 | intergovernmental, military alliance |
| 2023-12-09 | NATO Leak - 1 | intergovernmental, military alliance |
| 2023-12-09 | Grupo Televisa | mass media, entertainment, media corporation |
CONFIRMED ATTACKS
Siegedsec confirmed attacks: 4 verified incidents
Ransomnews has verified 4 Siegedsec incidents against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. The confirmed record runs from March 2023 to November 2023. United States accounts for 2 of them (50%), with victims recorded in 3 countries in total. The most affected sector is government, at 2 confirmed victims. Where a figure was disclosed (2 cases), these incidents account for 145,690 exposed records.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified Siegedsec incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| November 2023 | Idaho National Laboratory | Government | Idaho, United States | 45,047 | Unknown | Source |
| November 2023 | Bezeq | Utilities | Tel Aviv-Yafo, Israel | — | Unknown | Source |
| June 2023 | South Austin Health Imaging LLC dba Longhorn Imaging Center | Healthcare | Texas, United States | 100,643 | Unknown | Source |
| March 2023 | Visit Faroe Islands | Government | Torshavn, Faroe Islands | — | Unknown | Source |
Claimed vs confirmed. The figures above the fold on this page come from Siegedsec's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.