ZeroHour

ransomhouse

ransomware group · aka Ransom House, White Rose (affiliate/related group per some public trackers, 2023; not confirmed) · Exact origin unknown. 2022 vendor reporting (e.g., Advanced Intel) described likely Russian-speaking, experienced operators, possibly veterans of established ransomware crews; attribution unconfirmed. · active since March 2022 (first leak-site listings; vendor reporting from April 2022 with the AMD incident)

Victims · 7d
2▲2 vs prev. week
Victims · 30d
5active targets
Victims · 90d
24
All-time (tracked)
253since 2022-08-18
Last post
09-15 17:38UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

RansomHouse is a data-extortion operation first reported in spring 2022, best known for claiming large-scale data thefts such as the AMD and Seiko Epson breaches; in most incidents it extorts via threatened publication of stolen data, and researchers have noted limited evidence of actual file encryption. The group has been described as likely Russian-speaking with experienced operators and openly recruits affiliates and partners on criminal forums. Recent dashboard-tracked activity shows steady output: 24 victims posted since 2026-06-16 (6 in the last 30 days, 0 in the last 7), with the latest post on 2026-09-02. Recent listings span Japan (REXT Holdings, Nichirei), Brazil (Alya Construtora), Cyprus (TECHVENTURES BANK), and US municipalities (City of Beacon, City of McMinnville), indicating global, sector-agnostic targeting. No reliable public aggregate of illicit earnings exists.

Tactics & tooling
  • Data-theft extortion; threatens to publish stolen data without demonstrated file encryption in most cases
  • Claims large-volume exfiltration (e.g., ~70 GB claimed in the April 2022 AMD incident)
  • Tor-based leak site with countdown timers before data release
  • Openly recruits affiliates/partners on criminal forums for access and exfiltration
  • 2022 vendor reporting indicated use of purchased initial access from access brokers
  • Posts taunting statements blaming victims' security failures to pressure payment
Targeted sectors
Technology/semiconductorsManufacturing (electronics, food)Banking/financial servicesConstructionGovernment (municipal/local)
Notable public victims

AMD - April 2022; ~70 GB of data claimed stolen; AMD confirmed the breach (widely reported), Seiko Epson - May 2022; customer and employee data exposed; company confirmed (widely reported), REXT Holdings Co., Ltd. (Japan) - dashboard-tracked leak-site listing, 2026, Nichirei (Japan) - dashboard-tracked leak-site listing, 2026, TECHVENTURES BANK S.A. - dashboard-tracked leak-site listing, 2026, Alya Construtora (Brazil) - dashboard-tracked leak-site listing, 2026, PCL Holding - dashboard-tracked leak-site listing, 2026, City of Beacon (NY, USA) - dashboard-tracked leak-site listing, 2026, City of McMinnville (OR, USA) - dashboard-tracked leak-site listing, 2026

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Summit Care · Aug 18, 2022
Fairfax - Crum & Forster · Aug 18, 2022
8 Italy Districts · Aug 18, 2022

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .