THREAT ACTOR
TITAN_
ActiveTITAN is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of TITAN, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2026 26
Leak site mirrors
3 mirrors tracked, 2 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
x4bccxlsmjsxlnnf3ocvndlshgfkagzytpqmsjnlfykceumnw6i4hkqd.onionTITAN snapshot · 2026-09-23 00:10 -
titanblog.orgTITAN snapshot · 2026-09-23 01:18 -
x4bccxlsmjsxlnnf3ocvndlshgfkagzytpqmsjnlfykceumnw6i4hkqd.onionTITAN snapshot · 2026-09-23 01:00
Recent victims
The 50 most recent victims claimed by TITAN. Total in the index: 26.
| Date listed | Victim | Description |
|---|---|---|
| 2026-09-22 | Grupo Hospifar S.R.L. | |
| 2026-09-22 | Sherman Chan, DDS, Inc. | |
| 2026-08-20 | Termotecnica Industriale S.r.l. | |
| 2026-08-20 | Elbor S.p.A. | |
| 2026-08-20 | CTP S.r.l. | |
| 2026-08-20 | Alto Calore Servizi SPA | |
| 2026-08-20 | Tedesco & Partners STP srl | |
| 2026-08-20 | POEMA S.r.l. | |
| 2026-08-20 | TECNOLOGICA S.r.l. | |
| 2026-08-20 | CONDOR SPA | |
| 2026-08-20 | ELCON MEGARAD S.p.A | |
| 2026-07-22 | PERTINENT HEALTHCARE BUSINESS SOLUTIONS PRIVATE LIMITED | |
| 2026-07-13 | Cooperate consulting CZ s.r.o. | |
| 2026-07-13 | DataOstrov s.r.o. | |
| 2026-07-13 | Ozmit s.r.o. | |
| 2026-07-12 | Cooperate service CZ s.r.o. | |
| 2026-07-04 | Eureka Construction INC | |
| 2026-05-19 | Apex Maritime Co., Inc. | |
| 2026-05-19 | SIRILAK SEAFOOD (PW) LTD. | |
| 2026-05-19 | Mezta Corporativo, S.A. de C.V. | |
| 2026-05-19 | Abp Autoricambi Srl | |
| 2026-05-19 | DFI AMERICA, LLC | |
| 2026-05-19 | CRIT Tunisie | |
| 2026-05-19 | Groupe CRIT SA | |
| 2026-05-19 | ETM-ELECTROMATIC, INC. | |
| 2026-05-19 | Quahe Woo & Palmer LLC |
CONFIRMED ATTACKS
Titan confirmed attacks: 2 verified incidents
Ransomnews has verified 2 Titan incidents against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. The confirmed record runs from May 2026 to August 2026. Italy accounts for 1 of them (50%), with victims recorded in 2 countries in total. The most affected sector is utilities, at 1 confirmed victim.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified Titan incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| August 2026 | Alto Calore Servizi S.p.A. | Utilities | Avellino, Italy | — | Unknown | Source |
| May 2026 | Groupe CRIT (Crit Tunisie and Crit RH) | Service | Tunis, Tunisia | — | Unknown | Source |
Claimed vs confirmed. The figures above the fold on this page come from Titan's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.