ZeroHour

lapsus$

Ransomware / extortion group tracked from leak-site posts

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
0
All-time (tracked)
14since 2026-03-04
Last post
04-08 15:11UTC
Estimated earnings
public reporting
Profile not written yet: the pipeline profiles the most active groups first, a few per run.

Leak-site victims

VictimDiscoveredDetails
ASTRAZENECA CORP · Apr 8, 20262026-03-25 | Source Code, Employee DB, API Keys, MongoDB/MySQL Creds
VirtaHealth.com · Apr 8, 20262026-03-29 | Healthcare research
FR MINISTRY AGRICULTURE · Apr 8, 20262025-12-28 | Government Infrastructure
AXCERA.IO · Apr 8, 20262026-03-22 | Source Code + Infrastructure Configs
OSAC AERO · Mar 4, 2026
FR MINISTRY AGRI · Mar 4, 2026
LOOZAP · Mar 4, 2026
DREAMUP · Mar 4, 2026
SALESFLOOR · Mar 4, 2026
EIFFAGE · Mar 4, 2026
ADIDAS EXTRANET · Mar 4, 2026
LACOSTE · Mar 4, 2026
UNIV LILLE · Mar 4, 2026
ENI ENERGY · Mar 4, 2026

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .