ZeroHour

secp0

Ransomware / extortion group tracked from leak-site posts

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
0
All-time (tracked)
13since 2025-03-05
Last post
04-30 10:55UTC
Estimated earnings
public reporting
Profile not written yet: the pipeline profiles the most active groups first, a few per run.

Leak-site victims

VictimDiscoveredDetails
Leak: Color Communications LLC · Apr 30, 2026The exposed dataset includes over 200,000 unique files containing sensitive information on more than 4,500 individuals and over 5,500 organizations... Open post
Color Communications LLC · Apr 29, 2026The exposed dataset includes over 200,000 unique files containing sensitive information on more than 4,500 individuals and over 5,500 organizations... Open post
/files/12b3429e1124122e/ · Mar 9, 2026
Leak: Mike Brandner Law · Mar 9, 2026The total volume of extracted data amounts to approximately 489 GB (459,391 files total). The files contain references to more than 4,000 unique individuals... Open post
Leak: Richmond Plywood Corporation Limited · Mar 9, 2026The total volume of extracted data amounts to approximately 1.09TB (522,925 files total), with a filtered size of 230GB (161,200 files). The files contain references to more than 2,500 unique individuals and 4,000 organizations... Open post
Important Announcement · Mar 9, 2026Our colleagues in offensive security at lexfo.fr published a review of one of our tools that we used in the Group Indigo network... Open post
Leak: Indigo Group · Mar 9, 2026The exposed dataset includes over 897,000 unique files (1,707,433 with duplicates) containing sensitive information on more than 27,000 individuals and over 27,000 organizations Open post
Leak: JM Bozeman Enterprises · Mar 9, 2026The exposed dataset includes over 100,000 unique files (192,993 with duplicates) containing sensitive information on more than 4,000 individuals and over 4,500 organizations Open post
Publication hold announcement · Jul 21, 2025Hello everyone! We have a substantial queue of companies waiting for their data to be published, but nothing has been released yet. The reason is simple: the datasets we process often exceed tens of terabytes. We know publishing this kind of raw, chaotic "data mush" makes no sense — it's impossible to download or use effectively. While we acknowledge that some groups opt to publish raw data volumes as a standard practice, we've chosen to aim higher. Our team is actively testing a software solution designed to streamline the publication of large datasets. We're not ready to share details yet, but the new format will make the data easy to access and use for everyone involved. To companies in our publication queue: don't assume you have time to fix problems later. For some of you, the window to address critical issues in your data may already be closed. Stay tuned for updates.
Announcement for the Terralogic and its clients · Apr 28, 2025Due to Terralogic's unwillingness to cooperate, we are publishing evidence of the breach of their network. This proof pack is partial and only hints at the impending disaster for Terralogic and its clients, which include, for example, an investment fund acting as a market maker on NASDAQ and a software developer for laboratories. In addition to these clients, there are also government networks and numerous other corporations.
Response to PRODAFT journalists · Mar 6, 2025Hello, PRODAFT! Could you clarify where exactly you saw information about a new approach? We had a good laugh, but we decided to set the record straight. We have no issues with Passwordstate (clickstudios.com.au), only recommendations for improving their software, which, to put it mildly, leaves much to be desired. Our post is purely informational. It is intended to help hackers understand the encryption routine in Passwordstate and to warn system administrators about the dangers of using this product.
Passwordstate weak encryption article · Mar 5, 2025Some time ago I came across a server running Passwordstate software, which is designed for password storage — something like KeePass, but as a web service for corporations. After examining the database, specifically the "Passwords" table, I became curious about the bytes stored in the "Password" field and how they were encrypted. I proceeded to download all the program files, took a dump of the database, and began analyzing it.
Welcome · Mar 5, 2025We are pleased to welcome you to our blog, a dedicated space designed to deliver confidential data leaked due to the dismissive attitude of the companies. Companies that do not wish to cooperate with us will be published here, and as a result, we are forced to ruin their reputation and demonstrate what happens when CEOs and company founders neglect their clients data, disrespect their business, and their employees. All these companies had to do was either invest in data security from the very beginning to prevent our attack or pay us afterward to avoid negative consequences. However, they are so stingy that they prefer to pay twice — through monetary losses from legal battles and, more importantly, through a ruined reputation and a destroyed business. Thank you for joining us on this journey. We look forward to sharing valuable and hidden knowledge with you. Sincerely, SECP0 Team.

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .