THREAT ACTOR
VANHELSING_
DormantVANHELSING is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of VANHELSING, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2025 8
Leak site mirrors
10 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
vanhelqmjstkvlhrjwzgjzpq422iku6wlggiz5y5r3rmfdeiaj3ljaid.onionVanHelsing Chat snapshot · 2025-05-13 05:01 -
vanhelvuuo4k3xsiq626zkqvp6kobc2abry5wowxqysibmqs5yjh4uqd.onionVanHelsing Blog snapshot · 2025-05-14 21:09 -
vanhelxjo52qr2ixcmtjayqqrcodkuh36n7uq7q7xj23ggotyr3y72yd.onionVanHelsing Blog snapshot · 2025-05-14 21:11 -
vanhelsokskrlaacilyfmtuqqa5haikubsjaokw47f3pt3uoivh6cgad.onionVanHelsing Chat snapshot · 2025-05-13 05:04 -
vanhelwmbf2bwzw7gmseg36qqm4ekc5uuhqbsew4eihzcahyq7sukzad.onionVanHelsing Blog snapshot · 2025-05-14 20:24 -
vanhelcbxqt4tqie6fuevfng2bsdtxgc7xslo2yo7nitaacdfrlpxnqd.onionVanHelsing Chat snapshot · 2025-05-13 05:19 -
vanheltarnbfjhuvggbncniap56dscnzz5yf6yjmxqivqmb5r2gmllad.onionVanHelsing Chat snapshot · 2025-05-13 05:20 -
vanhelln5ly3sw63b5ke25gxvp5rr67wd7rgzezo4mhegm4qpsolbkqd.onionsnapshot · 2025-05-26 13:08 -
vanhel4wqo425m7rdjolykd22js3hkrvpwld6iyvpjslj63l5ocaqoqd.onionsnapshot · 2025-05-26 13:09 -
vanhelq3jf5afpkwwlcfm32sdblpfkx2cfa4kxaeoabtnxjpu2qnt7id.onionsnapshot · 2025-05-26 13:10
Recent victims
The 50 most recent victims claimed by VANHELSING. Total in the index: 8.
| Date listed | Victim | Description |
|---|---|---|
| 2025-04-01 | attorneykohm.com | Attorney David KohmOffices throughout the Dallas Fort Worth AreaThe La… |
| 2025-04-01 | alertenterprise.com | At the core of our mission is the seamless convergence of advanced phy… |
| 2025-03-27 | Studiocdlvallone.it | We put commitment, curiosity, passion, optimism into our work every da… |
| 2025-03-26 | compumedics.com.au AND neuromedicalsupplies.com | A global leader in the development, manufacture and commercialisation … |
| 2025-03-24 | studiocdlvallone.it | We put commitment, curiosity, passion, optimism into our work every da… |
| 2025-03-19 | www.medsrx.com | In a world where technology makes everything easier, the old school ph… |
| 2025-03-19 | www.atos-racks.com | ATOS designs, develops and manufactures in France enclosure products f… |
| 2025-03-17 | www.cityofbellville.com | Bellville is a city in and the county seat of Austin County, Texas, in… |
CONFIRMED ATTACKS
VanHelsing confirmed attacks: 1 verified incident
Ransomnews has verified 1 VanHelsing incident against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. All of them fall in March 2025. Australia accounts for 1 of them (100%). The most affected sector is healthcare, at 1 confirmed victim. Where a figure was disclosed (1 case), these incidents account for 320,404 exposed records.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified VanHelsing incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| March 2025 | Compumedics Limited | Healthcare | Abbotsford, Australia | 320,404 | Unknown | Source |
Claimed vs confirmed. The figures above the fold on this page come from VanHelsing's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.