ZeroHour

dysphor1a

ransomware group · aka dysphor1a · unknown · active since 2026-09-04 (first leak-site post tracked by this dashboard; earlier activity unknown)

Victims · 7d
0▼3
Victims · 30d
10active targets
Victims · 90d
10
All-time (tracked)
10since 2026-08-29
Last post
09-06 20:42UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

dysphor1a is a ransomware/data-extortion group tracked by this dashboard through its leak-site activity, with the first observed listing posted on 2026-09-04 and the most recent on 2026-09-06. Three victims have been listed in total across the 7-, 30-, and 90-day windows, indicating a newly observed or very low-volume operation. The listed victims span the public sector, payments/financial services, and telecommunications, including a government entity associated with Myanmar (RTAD GOV MM). The leak-site model is consistent with the data-theft and double-extortion practices common among current ransomware groups. Detailed public reporting on the group's origins, affiliate relationships, malware tooling, and revenue remains limited; these elements are treated as unknown.

Tactics & tooling
  • Publishes victims and stolen-data claims on a dedicated leak/extortion site
  • Data-theft extortion consistent with the double-extortion model common to modern ransomware operations
  • Low publication cadence observed (three listings since the first tracked post on 2026-09-04)
  • Multi-sector targeting observed: government, financial services/payments, and telecommunications
  • At least one Myanmar government entity listed (RTAD GOV MM)
  • Initial access, delivery, and encryption tooling: unknown (no widely reported public analysis to date)
Targeted sectors
Government/public sectorFinancial services (payments)Telecommunications
Notable public victims

RTAD GOV MM, CitizensPay, MBT Telecom

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
RTAD GOV MM · 9d agoLeaked: New | Sector: Government / Transport | Country: 🇲🇲 Myanmar | Records: 1.08 GB — full databases dump | Road Transport Administration Department (RTAD) — official government portal providing public transport services, driving license issuance, vehicle registration, and safety regulations. Full databases dump total 1.08 GB. Victim domain https://rtad.gov.mm. | Leaked | RTAD GOV MM Leaked New Critical 🇲🇲 Myanmar ID_RTAD-GOV-MM | Detected 2026 | Target // Government / Transport Description Road Transport Administration Department (RTAD) — official government portal providing public transport services, driving license issuance, vehicle registration, and safety regulations. Full databases dump total 1.08 GB. Victim domain https://rtad.gov.mm. Infection Mechanism Compromised RTAD government databases exposing vehicle registration records, owner PII, NRC numbers, addresses, vehicle details, and insurance premium data via internal API responses. Notable Attack Full databases dump — 1.08 GB from the Road Transport Administration Department (RTAD) of Myanmar, including owner names, NRC numbers, addresses, vehicle registration, branch, and premium payment records. Example Compromised {"code": 0, "status": "OK", "message": "Success", "data": {"owner_name": "U SOE MYINT", "nrc_no": "8/KHAMANA(N)073033", "address": ",,HTEIN SAN YWAR,CHAUK", "types": "T", "vehicle_no": "1A/1230", "book_no": "", "vehicle_name": "HINO TE11", "vehicle_type": "TRUCK_COMMERCIAL", "productType": "COMMERCIAL", "motorType": "TRUCK", "premiumYear": 2, "seating": 0, "weight": 7, "capacity": "7.0", "period_to": "2025-02-28", "premium_amount": "15000.0", "receipt_no": "", "receipt_date": "", "version": 1, "premiumTotalAmount": 30000, "total_month": 24, "rta_branch": "Regional Office(Magway)", "nextPremiumBuyDate": "2027-02-28", "isConvert": false, "penaltyFees": 0, "isDataValid": true}, "api_statuses": {"api_1": "false", "api_2": "success"}, "timestamp": "2026-01-24T18:19:18.162Z"} Download Source…
CitizensPay · 10d agoSector: Digital Wallet / Payment Platform | Country: 🇲🇲 Myanmar | Records: 30 GB | Countdown: 2d 12h 37m 53s | Citizens Pay (also known as CTZPay) is a mobile digital wallet and payment platform in Myanmar powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited. Compromised agent user information — total data size 30 GB. Price range $7,000 to $25,000. Victim domain https://ctzpay.com. | CITIZENSPAY | CitizensPay Upcoming Critical 🇲🇲 Myanmar ID_CITIZENSPAY | Detected 2026 | Target // Digital Wallet / Payment Platform Description Citizens Pay (also known as CTZPay) is a mobile digital wallet and payment platform in Myanmar powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited. Compromised agent user information — total data size 30 GB. Price range $7,000 to $25,000. Victim domain https://ctzpay.com. Infection Mechanism Exposed agent user info including business license, NRC pictures (front/back), selfie, shop pictures, and phone numbers from the CTZPay agent verification pipeline. Notable Attack Full agent user info dump from Citizens Pay (CTZPay) — 30 GB including KYC documents (NRC front/back), selfies, business license, shop pictures, and phone numbers. Example Compromised Example Data Include - business_picture - nrc_picture_front - nrc_picture_back - selfie_picture - shop_picture - Ph Number Evidence Images business_license_picture.jpg nrc_picture_front.jpg nrc_picture_back.jpg selfie_picture.jpg shop_picture.jpg Download Sample Contact Us On Session Close
MBT Telecom · 11d agoFor Sale: New | Sector: Telecommunications / ISP | Country: 🇲🇲 Myanmar | Records: 209,970 user records — full dump | Myanmar Broadband Telecom Co., Ltd. (MBT) is a leading fiber internet service provider and telecommunications network solutions company established in Myanmar in 2013. Full database compromise exposing 209,970 user records including PII, passwords, and device information. | For Sale | MBT Telecom For Sale Critical 🇲🇲 Myanmar ID_MBT-TELECOM | Detected 2026 | Target // Telecommunications / ISP Description Myanmar Broadband Telecom Co., Ltd. (MBT) is a leading fiber internet service provider and telecommunications network solutions company established in Myanmar in 2013. Full database compromise exposing 209,970 user records including PII, passwords, and device information. Infection Mechanism Compromised MBT customer database exposing user PII, passwords, device types, and account metadata from their FTTH, DIA, and enterprise VPN services. Notable Attack Full user dump of 209,970 MBT Telecom customer records including names, phone numbers, passwords, and device information. Example Compromised Full DB Access — 209,970 User Records id,name,phone,created_at,user_status,uniq_id,address,new_pass,device_type 225425,Phyo Wai Hein,09975578724,2026-09-04T09:03:45.000000Z,Normal,937064,,25809672, 225424,Ma Zar Zar,09776411439,2026-09-04T08:54:23.000000Z,Normal,386819,,444555, 225423,Arr Li,09973900796,2026-09-04T08:48:46.000000Z,Normal,4973,,mml19894, 225422,umyintthein,0943051152,2026-09-04T08:37:52.000000Z,Normal,856710,,123456, 225421,Ma Ei Thandarbo,09773450715,2026-09-04T08:33:53.000000Z,Normal,582959,,064071, 225420,Daw Aye Kyi Kyi Myint,09952295522,2026-09-04T08:32:43.000000Z,Normal,771678,,123456, 225419,Nan Phawy,09772111156,2026-09-04T08:31:36.000000Z,Normal,352373,,123456, 225418,U Soe Lwin,09941258904,2026-09-04T08:30:57.000000Z,Normal,101282,,12345678, 225417,Aung Kyaw Htun,09402695665,2026-09-04T08:28:35.000000Z,Normal,151460,,ak025846…
Yoma Fleet · 17d agoSector: Business / Vehicle Leasing | Country: 🇲🇲 Myanmar | Records: Orders, users, repayments, employees — full admin export | Yoma Fleet is a leading vehicle operating lease, rental, and financing company based in Yangon, Myanmar. The platform provides centralized administration and management for vehicle orders, employee financing, repayments, users, and employee records. Admin account access — need to contact on Telegram. | Leaked
AYUDHYA TH Insurance · 17d agoSector: Financial / Insurance | Country: Thailand | Records: Internal batch-control system + admin credentials | Leaked data from AYUDHYA (TH Insurance / Allianz Thailand). Internal batch-control system used within the financial/transaction batch-processing ecosystem behind the Allianz customer-facing web platform. Includes admin credentials (TBH2CASH:AAbb1234). | Leaked
GUSTO College GLMS · 17d agoSector: Education Sector | Country: 🇲🇲 Myanmar | Records: User account credentials | Compromised user accounts from GUSTO College's GLMS (Global Learning Management System). Exposed user credentials from the Moodle platform at gusto-education.com. | Leaked
Job Net .COM.MM · 17d agoSector: Business | Country: Myanmar | Records: ~500++ user accounts and cv information | Normal Hunters operation compromising Job Net .COM.MM business data, exposing corporate information, user accounts, and business operations data. | Leaked
The University of Delhi (DU) · 17d agoSector: Education Sector | Country: 🇮🇳 India | Records: Student records with PII, academic data, and identification documents | The University of Delhi (DU) is a major public university in New Delhi, India, founded in 1922. It is one of India's most well-known universities, offering undergraduate, postgraduate, and doctoral programs across subjects like science, arts, commerce, law, and technology. | For Sale
Indonesian Police Database · 17d agoSector: Government / Law Enforcement | Country: Indonesia | Records: 52,000 officer records + 4,000 facial photos | Database containing records of 52,000 Indonesian police officers including email addresses, phone numbers, first and last names, passwords, location details, and 4,000 facial photographs. | For Sale
Netim Company · 17d agoSector: Business / Domain Registrar | Country: 🇫🇷 France | Records: Source code, IPs, payment databases, customer PII — full infrastructure | Netim is a French domain name registrar and web hosting provider. Full compromise of internal systems — source code, infrastructure IPs, payment processing databases, customer PII, and internal business data. | For Sale

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .