ZeroHour

ailock

ransomware group · aka Ailock, AI Lock (alternate styling) · unknown (victim base skews heavily toward Japan; operator nationality/infrastructure not established in public reporting) · active since Exact emergence date unknown; publicly documented by security press since at least mid-2025 (including the Ferrovial claim); dashboard tracking of its leak site began 2026-06-15

Victims · 7d
0flat
Victims · 30d
2active targets
Victims · 90d
12
All-time (tracked)
51since 2026-03-03
Last post
08-26 12:28UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Ailock is a ransomware and data-extortion group that operates a public leak site naming victims, with 13 total victims posted since the dashboard began tracking it in June 2026. Its victim base skews heavily toward Japan-based organizations, with additional claimed victims in Spain, Canada, and the United States. The group uses a double-extortion model, publishing stolen data to pressure victims into negotiating. Public technical reporting on Ailock — initial access vectors, tooling, and affiliate relationships — remains limited. Ferrovial's confirmed June 2025 cyber incident is the group's most publicly corroborated attack to date.

Tactics & tooling
  • Double extortion: data theft paired with ransomware encryption and threatened publication (per security press reporting)
  • Operates a dedicated leak/extortion blog to name-and-shame victims and set publication deadlines
  • Victimology shows disproportionate targeting of Japan-based organizations across multiple industries (leak-site listings)
  • Targets mid-sized and large enterprises; listed victims span transportation, construction/infrastructure, real estate, education, and business/IT services
  • Initial access vectors, malware families, and affiliate ties: not documented in detail in public reporting as of 2026 (unknown)
Targeted sectors
transportation and logisticsconstruction and infrastructurereal estatebusiness and IT serviceseducationmanufacturing/industrial services
Notable public victims

Ferrovial (Spain-based multinational infrastructure operator; company confirmed a cybersecurity incident in June 2025, per company statements reported by media; listed on Ailock's leak site), Nihon Kotsu Co., Ltd. (major Japan-based taxi/transport operator; listed on leak site), Richmont Graduate University (Toronto-based graduate school; listed on leak site), Morgan Services (listed on leak site), Pinturas Prisa (listed on leak site)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Integral Analytics · Mar 3, 2026Integral Analytics specializes in data intelligence solutions for the energy sector, focusing on improving planning and forecasting for utilities, producers, manufacturers, and regulators. Their flagship products include LoadSEER, DSMore, and IDROP, which assist in energy efficiency, demand response, and distributed energy resource management.

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .