ZeroHour

blackout

ransomware group · aka Blackout, Blackout ransomware · unknown · active since 2022

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
1
All-time (tracked)
13since 2024-02-27
Last post
07-18 22:56UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Blackout is a ransomware and double-extortion group first publicly reported in 2022; it encrypts victim data and posts non-paying victims to a public leak site. Public reporting on the group is limited, and its origin, leadership, and estimated earnings are unknown. Early vendor coverage focused on the group's activity against organizations in India, including banking and oil & gas, while leak-site listings monitored by this dashboard show a low-volume operation targeting mostly small and mid-sized companies across Asia-Pacific, Europe, and the Americas. Tracked activity is quiet but ongoing, with 1 victim in the last 90 days and a most recent post of 2026-07-18 per this dashboard. No specific vulnerabilities are consistently attributed to the group in public reporting, leaving its initial access methods largely undocumented.

Tactics & tooling
  • Double extortion: data encryption combined with public leak-site postings of non-paying victims
  • Ransomware deployment against Windows systems, per public malware analyses
  • Low-volume leak-site output, generally naming small and mid-sized organizations rather than large enterprises
  • Broad sector targeting, including finance, oil & gas, retail/consumer goods, manufacturing, healthcare, shipping, telecom, and travel
  • Victims spread across Asia-Pacific, Europe, and the Americas; early reported incidents centered on India
  • Initial access techniques and exploited CVEs: unknown, not consistently documented in public reporting
Targeted sectors
manufacturingretail/consumer goodsluxury goods distributionshipping/maritimetelecommunicationshealthcaretravel/hospitalitybanking/financial services (early reporting)
Notable public victims

en.yofc.com - Yangtze Optical Fibre and Cable (YOFC), major Chinese optical-fiber manufacturer, bluebellgroup.com - Bluebell Group, luxury goods/brand distribution company, badel1862.hr - Badel 1862, Croatian beverages company, cdc-biodiversite.fr - CDC Biodiversite, French biodiversity/environment services firm, ch-armentieres.fr - Centre Hospitalier d'Armentieres, French hospital, nedamaritime.gr - Neda Maritime, Greek shipping company, mcmtelecom.com - MCM Telecom, Mexican telecommunications provider, ht-hospitaltechnik.de - HT Hospital-Technik, German hospital equipment supplier

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
bluebellgroup.com · Jul 18, 2026Bluebell Group is a Hong Kong-based, family-owned omnichannel brand curat...5
en.yofc.com · Feb 26, 2026Yangtze Optical Fibre and Cable (YOFC) is a leading global supplier of op...2
www.miatech.net · Jul 9, 2025Miatech is a US-based company that provides passenger travel services for...20
yano.tokyo · Mar 20, 2025Yano Electronics Ltd. is a company in the field of microelectronics, we p...19
nedamaritime.gr · Dec 9, 2024Neda Maritime is an independent shipping company that manages and operate...2
cdc-biodiversite.fr · Sep 29, 2024CDC Biodiversité is a French environmental protection company making tens...11
antaeustravel.com · Aug 22, 2024Antaeus Travel is a travel agency specializing in corporate and sea trave...6
luzan5.com · Jul 14, 2024luzan5.com is a small company in the healthcare consulting field, perhaps...20
badel1862.hr · Jul 3, 2024Badel 1862 is an alcoholic beverage manufacturer from Croatia and at the ...29
mcmtelecom.com · May 29, 2024We carried out an attack on mcmtelecom.com, a b2b telecommunications prov...5
ht-hospitaltechnik.de · Apr 18, 2024Why don't medical companies pay us? As usual we got into the network ht-h...
ch-armentieres.fr · Feb 27, 2024First post on our new blog ! We encrypted 100+ servers and workstations ...
metal7.com · Feb 27, 2024This time we dug into the network of metal7.com, a company that manufactu...

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .