ZeroHour

ransomhouse

ransomware group · aka Ransom House, White Rose (affiliate/related group per some public trackers, 2023; not confirmed) · Exact origin unknown. 2022 vendor reporting (e.g., Advanced Intel) described likely Russian-speaking, experienced operators, possibly veterans of established ransomware crews; attribution unconfirmed. · active since March 2022 (first leak-site listings; vendor reporting from April 2022 with the AMD incident)

Victims · 7d
2▲1 vs prev. week
Victims · 30d
5active targets
Victims · 90d
24
All-time (tracked)
253since 2022-08-18
Last post
09-15 17:38UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

RansomHouse is a data-extortion operation first reported in spring 2022, best known for claiming large-scale data thefts such as the AMD and Seiko Epson breaches; in most incidents it extorts via threatened publication of stolen data, and researchers have noted limited evidence of actual file encryption. The group has been described as likely Russian-speaking with experienced operators and openly recruits affiliates and partners on criminal forums. Recent dashboard-tracked activity shows steady output: 24 victims posted since 2026-06-16 (6 in the last 30 days, 0 in the last 7), with the latest post on 2026-09-02. Recent listings span Japan (REXT Holdings, Nichirei), Brazil (Alya Construtora), Cyprus (TECHVENTURES BANK), and US municipalities (City of Beacon, City of McMinnville), indicating global, sector-agnostic targeting. No reliable public aggregate of illicit earnings exists.

Tactics & tooling
  • Data-theft extortion; threatens to publish stolen data without demonstrated file encryption in most cases
  • Claims large-volume exfiltration (e.g., ~70 GB claimed in the April 2022 AMD incident)
  • Tor-based leak site with countdown timers before data release
  • Openly recruits affiliates/partners on criminal forums for access and exfiltration
  • 2022 vendor reporting indicated use of purchased initial access from access brokers
  • Posts taunting statements blaming victims' security failures to pressure payment
Targeted sectors
Technology/semiconductorsManufacturing (electronics, food)Banking/financial servicesConstructionGovernment (municipal/local)
Notable public victims

AMD - April 2022; ~70 GB of data claimed stolen; AMD confirmed the breach (widely reported), Seiko Epson - May 2022; customer and employee data exposed; company confirmed (widely reported), REXT Holdings Co., Ltd. (Japan) - dashboard-tracked leak-site listing, 2026, Nichirei (Japan) - dashboard-tracked leak-site listing, 2026, TECHVENTURES BANK S.A. - dashboard-tracked leak-site listing, 2026, Alya Construtora (Brazil) - dashboard-tracked leak-site listing, 2026, PCL Holding - dashboard-tracked leak-site listing, 2026, City of Beacon (NY, USA) - dashboard-tracked leak-site listing, 2026, City of McMinnville (OR, USA) - dashboard-tracked leak-site listing, 2026

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Tri State Electric · May 20, 2025
Triple Jump · May 16, 2025
[DISCLOSED]OeTTINGER Brauerei · May 15, 2025
Commune de Jemeppe-sur-Sambre · May 6, 2025
OeTTINGER Brauerei · May 5, 2025
[DISCLOSED]Imedexsa · May 2, 2025
Bacton Transport Services · Apr 22, 2025
C-Mec · Apr 21, 2025
[EVIDENCE PACK 2] Telecontrol · Apr 18, 2025
Telecontrol · Apr 7, 2025
[DISCLOSED]Cell C · Apr 7, 2025
NEW JERSEY CPA · Mar 27, 2025
TUV India Pvt. Ltd. · Mar 12, 2025
[DISCLOSED]Nationz Technologies Inc. · Mar 10, 2025
The Loretto Hospital · Mar 10, 2025
Nationz Technologies Inc. · Feb 26, 2025
[DISCLOSED] Aishu, Eshoo · Feb 24, 2025
[EVIDENCE] Aishu, Eshoo · Feb 24, 2025
Supreme Administrative Court of Bulgaria · Feb 19, 2025
[EVIDANCE] AIshu, Eshoo · Feb 4, 2025
AIshu, Eshoo · Jan 26, 2025
Cell C · Dec 28, 2024
[DISCLOSED] Lago Group Spa · Dec 27, 2024
[DISCLOSED] KuiperCompagnons · Dec 27, 2024
[DISCLOSED] INFiLED · Dec 27, 2024
[DISCLOSED]Interior Metals · Dec 5, 2024
[DISCLOSED]GuangDong South Land pharmaceutical · Dec 5, 2024
[DISCLOSED]Sabesp · Dec 5, 2024
Interior Metals · Nov 27, 2024
INFiLED · Nov 25, 2024
GuangDong South Land pharmaceutical · Nov 25, 2024
Hellmich · Nov 13, 2024
Sabesp · Nov 1, 2024
[DISCLOSED]Fursan Travel · Oct 29, 2024
[DISCLOSED]Universite Paris Sud · Oct 29, 2024
[File Tree and Full Data Dump]VOP CZ · Oct 28, 2024
[File Tree Full Data Dump, Evidance Pack 2]VOP CZ · Oct 21, 2024
[DISCLOSED][i2p-torrent]Jangho Group · Oct 11, 2024
[DISCLOSED][i2p-torrent] Roberto Verino Difusion · Oct 11, 2024
Universite Paris Sud · Oct 9, 2024
Fursan Travel · Oct 4, 2024
VOP CZ · Sep 3, 2024
[DISCLOSED][TORRENT] Roberto Verino Difusion · Sep 3, 2024
[DISCLOSED] Lake Washington Institute of Technology · Aug 26, 2024
Jangho Group · Aug 19, 2024
[DISCLOSED] Valisana · Aug 16, 2024
[DISCLOSED]Sibanye-Stillwater · Aug 15, 2024
[DISCLOSED] Ronglian Group [Source code of RONGLIAN GROUP company developments] · Aug 12, 2024
[DISCLOSED] Al-Karam Textile Mills Pvt · Aug 8, 2024
Veren Inc and Crescent Point Energy · Aug 2, 2024

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .