Ransomware Statistics

Ransomware Groups

580

Last 24 Hours Incidents

16

Incidents Last Week

292

Incidents Last Month

821

Recent Cyberattacks

Date Victim Group Description Link
2026-06-19 23:49:28.767760 themintgaming.com brain cipher Once the timer runs out, we will publish the latest Oasis 360 by Aristocrat database belonging to The Mint Gaming Hall, which contains the personal data of more than 250,000 player... Link
2026-06-19 22:52:06.233195 aasa.ae krybit AASA CP Holding Company (AASA Group) is a multinational business headquartered in Dubai, UAE, with a proud legacy of exc... Link
2026-06-19 22:52:04.404497 www.mupras.com krybit MUPRAS RAM (Mutuelle de Prévoyance et d'Actions Sociales de Royal Air Maroc) is a Moroccan mutual aid and social welfar... Link
2026-06-19 22:51:55.859420 coemi.com.br krybit Coemi Imóveis is a Brazilian real estate company with 41 years of tradition in Brasília, Distrito Federal, Brazil, fou... Link
2026-06-19 20:49:39.636635 Sparkle Pools qilin Construction Link
2026-06-19 20:13:28.622639 Athens Orthopedic Clinic the gentlemen athensorthopedicclinic.com zoominfo.com/c/athens-orthopedic-clinic-greensboro/351501009 Athens Orthopedic Clinic, founded in 1966, is a leading specialized medical practice based in Athens, Georgia.The clinic provides specialized orthopedic care, including joint and spine treatments, imaging, and urgent care across multiple local facilities.It is widely recognized for its innovative solutions and patient-centered approach, actively serving the Northeast Georgia community Link
2026-06-19 19:47:00.519847 mlit.com.my UPDATE-FULL DATA DUMP 10GB stormous FULL DATA DUMP . The compromised data includes highly sensitive internal operations and financial records. Among the leaked files are complete individual Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, and general ledger accounts for several linked entities, including Salesworks Pte Ltd Taiwan Branch and Shaves2u HK Limited. Additionally, we have extracted complete directory trees and file structures from the internal network shares and remote desktop sessions, revealing thousands of corporate folders such as JAG Group, SWGP Excel Import, and various financial databases. Link
2026-06-19 19:46:57.713919 Roth Industries qilin Manufacturing Link
2026-06-19 19:46:55.644082 PJ Daly Contracting qilin Construction Link
2026-06-19 16:48:09.473790 Desert Micro nova DesertMicro.net is a Software & Internet based company located in Jacksonville, Florida, United States with over 25 - 100 employees, data included large sums of costumers data who use the company software service, such curbside waste company invoices and Storage data, foothillsSanitation + GreenEnviromnetal + InlandService + QC + FusionSite companies the same, credit cards Details and payments billings Documents, databases backups and more - Nova Provide tree and samples from stolen data to the company when its get in touch with support department. Link
2026-06-19 16:47:48.939239 Hagerman & Company aurora Hagerman & Company — a 40-year-old Autodesk Platinum Partner headquartered in Mt. Zion, Illinois, serving 250+ enterprise customers across manufacturing, energy, defense, healthcare, and education. The exposed dataset includes: Complete proprietary source code for 15+ commercial products including the HNC Licensing System (License Generator, License Server, License Manager) — enabling unlimited piracy of all Hagerman products. 8+ plaintext database credentials in .udl files, including an Oracle SYS (DBA superuser) account with password "Hagerman@1!" reused across multiple systems. Engineering vault databases for 14+ critical infrastructure entities — NYPA (7 power plants including Niagara Falls), Kinder Morgan (Elba Island LNG terminal), HydroOne (Ontario electricity), Phillips 66, Chevron, and 8+ petroleum refineries. Defense/government data — NASA IT Security Requirements, Lockheed Martin configurations, Boeing-SVS vault data, JPL configurations. Azure DevOps transaction logs (1.6 GB) containing complete source code version history and potentially CI/CD deployment secrets. Third-party database credentials for Michigan State University (3 databases), Cal State Long Beach, and Beth Israel Deaconess Medical Center infrastructure. Link
2026-06-19 14:47:52.029466 Optimum First Mortgage pear Providing fast and reliable mortgage solutions, including home purchases and refinancing options Link
2026-06-19 14:22:52.501000 KTR Real Estate Advisors anubis Real estate client database exposed. Link
2026-06-19 12:45:53.272418 Klue.com icarus As you've probably already heard, Klue.com has been impacted... Link
2026-06-19 11:47:54.717224 ALS Global aurora ALS Limited (ASX:ALQ) — a global testing, inspection, and certification company with AUD 3.19B revenue, 20,500+ employees, and operations in 65+ countries — identified unauthorised access to its IT systems. ~400–500 employee home directories — personal documents, cached credentials, email settings, family photos, personal finance files for employees from Australia to Peru to Sweden to Romania. The company's 1Password team vault emergency recovery kit — a single 45 KB PDF that enables total recovery of every shared credential in ALS's enterprise password vault. 291 plaintext password files including administrator credentials, FTP passwords, portal passwords, and the document control system master password. 1,018 passport and identity document scans — Swedish passports, Mexican passports, Australian passports — each one a 10-year identity-theft enabler. 601 bank account detail files including IBAN, SWIFT routing codes, BSB numbers, and sort codes for employees across 15+ countries, plus Russian-language SWIFT salary payment files. 1,986 salary, payroll, and compensation files — named individuals, exact amounts, pay scales, negotiation records across AU, US, EU, UK, CA, BR, SE, RO. 453 medical, drug test, and workplace injury records — GDPR Art. 9 special category data. 57 complete Outlook email archives (PST files) — years of correspondence, attachments, privileged communications. 7,327 client laboratory results — mining assay data, certificates of analysis, and geochemistry results held under NDA. 20 GB of proprietary analytical method development — ALS's core competitive IP: PFAS, dioxin, acrylamide, glyphosate LC-MS/GC-MS method packages representing years and millions of AUD in R&D. For a TIC company, analytical methods are the product. 7.2 GB of Internal Research reports — 68+ formal research reports (IR153–IR287+) spanning 15 years, including IsaMill grinding R&D, GlyLeach joint-venture process IP (with mutual NDA), flotation, mineralogy, and QEMSCAN data. The FY2025–2026 innovation roadmap — "ALS Environmental Innovation — Priority projects for 2024-25" (10 MB PPTX) and Nordic Innovation Business Plans revealing which methods ALS plans to develop and which markets it plans to enter. 3.7 GB of Cryptosporidium water-testing methods (WA_Crypto) — UKAS-accredited, DWI-regulated detection methods where few UK labs hold accreditation. QuickBooks live bookkeeping, AR aging reports, and stock sale records — taken 12 days before FY26 results announcement. 111 PKI certificates with private keys — corporate WiFi, TLS server certs, personal signing certificates. A compiled Chrome password extraction tool with source code — credential harvesting infrastructure resident on ALS systems. Link
2026-06-19 02:46:31.301996 icsecurity.com shinyhunters Over 2.7 million records and other internal corporate data was compromised. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. Link

Top Gangs

Yearly Attacks