ZeroHour

linkc

Ransomware / extortion group tracked from leak-site posts

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
0
All-time (tracked)
7since 2025-02-18
Last post
04-07 04:50UTC
Estimated earnings
public reporting
Profile not written yet: the pipeline profiles the most active groups first, a few per run.

Leak-site victims

VictimDiscoveredDetails
Sajet Products · Apr 7, 2026700mb of blueprints including Amazon LEO (satellite) Project Kuiper scheme, Airbus, Boeing engines and metal alloy technologies. Enjoy. https://amber-wooden-prawn-35.mypinata.cloud/ipfs/bafybeic5m7e3dvlunitnv6vxzbcvqqgm4pybgc3ykn3jo62jipshf6bjve
Sajet Products [SAMPLE PUBLUSHED] · Mar 10, 2026700mb of blueprints including Amazon LEO (satellite) Project Kuiper scheme, Airbus, Boeing engines and metal alloy technologies. Enjoy. https://amber-wooden-prawn-35.mypinata.cloud/ipfs/bafybeic5m7e3dvlunitnv6vxzbcvqqgm4pybgc3ykn3jo62jipshf6bjve
StrongLink [SAMPLE PUBLISHED] · Mar 2, 2026DOWNLOAD SAMPLE: https://amber-wooden-prawn-35.mypinata.cloud/ipfs/bafybeian2lxaye6gwvi2kztzfpyr2lokzfngai3d4zjmtgqhhv74ixsvi4
Network Technology Services of New Jersey · Feb 27, 2026Whole datacenter is encrypted. Waiting for you in chat.
Sajet Products (Senior Aerospace) · Feb 3, 2026We have confirmed that due to ransomware attack in early december, your confidential files were accessed and leaked from your network.
StrongLink · Feb 3, 2026All repositories with Strong Link source code were successfully exfiltrated.
h2o.ai · Feb 18, 2025As a result of our operation, we have discovered the following concerning data: 1. Unanonymized customer datasets intended for AI training. 2. Full source code of programs from the Git repository, including code for driverless systems, GPT models, and others. 3. A substantial amount of internal information, including contracts, customer personal data, project costs, and project documentation. 4. Backup copies of employee email accounts containing customer correspondence.

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .