Incidents
Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups
Leak-site victims · 7d
205
Leak-site victims · 30d
1K
Active groups · 30d
8011 new
Most active · 7d
the gentlemen
Breaches added · 30d
7
Accounts exposed · 30d
34.6MHIBP
Ransomware & extortion groups · activityleak-site posts · 90-day window · click a group for its profile
| # | Group | 7d | trend | 30d | 90d | all-time* | Last post | Status | Estimated earnings (public reporting) |
|---|---|---|---|---|---|---|---|---|---|
| 1 | the gentlemen | 30 | ▲8 | 152 | 400 | 400 | active | no public figure | |
| 2 | qilin | 29 | ▲16 | 113 | 364 | 364 | active | no public figure | |
| 3 | storm | 9 | ▼31 | 49 | 61 | 61 | active | no public figure | |
| 4 | krybit | 15 | ▲15 | 44 | 95 | 95 | active | no public figure | |
| 5 | akira | 10 | ▲3 | 43 | 87 | 87 | active | Approximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since. | |
| 6 | direwolf | 2 | ▼9 | 37 | 62 | 62 | active | no public figure | |
| 7 | coinbase cartel | 0 | = | 35 | 56 | 56 | active | no public figure | |
| 8 | inc ransom | 10 | ▲6 | 34 | 113 | 113 | active | no public figure | |
| 9 | lockbit5 | 5 | = | 27 | 54 | 54 | active | Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit… | |
| 10 | audit team | 10 | ▲1 | 24 | 26 | 26 | active | no public figure | |
| 11 | safepay | 10 | = | 22 | 67 | 67 | active | no public figure | |
| 12 | leakeddata | 1 | ▲1 | 20 | 39 | 39 | active | no public figure | |
| 13 | orova | 0 | = | 19 | 44 | 44 | active | no public figure | |
| 14 | zawoo | 0 | = | 19 | 19 | 19 | active | no public figure | |
| 15 | emperador | 4 | ▼1 | 18 | 22 | 22 | active | no public figure | |
| 16 | kazu | 0 | ▼17 | 17 | 17 | 17 | active | no public figure | |
| 17 | vexy | 3 | ▼4 | 15 | 15 | 15 | active | no public figure | |
| 18 | shinyhunters | 2 | = | 14 | 32 | 32 | active | no public figure | |
| 19 | panzer | 7 | ▲5 | 14 | 25 | 25 | active | no public figure | |
| 20 | black nevas | 1 | ▼12 | 14 | 14 | 14 | active | no public figure | |
| 21 | play | 3 | ▼1 | 13 | 47 | 47 | active | no public figure | |
| 22 | chaos | 3 | ▼1 | 13 | 35 | 35 | active | no public figure | |
| 23 | rhysida | 2 | ▼2 | 13 | 15 | 15 | active | no public figure | |
| 24 | everest | 0 | ▼3 | 12 | 34 | 34 | active | no public figure | |
| 25 | pear | 0 | ▼1 | 12 | 23 | 23 | active | no public figure |
*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.
Incidents3 records · full details
| Victim | Group / type | Discovered | Details |
|---|---|---|---|
Bosch tracker page ↗ | d1rfilter this group | · Jul 12, 2026 | Again, thanks to database Synopsys provided us with After analyzing technical leaks by other groups and cross-referencing targets from TARGETLIST.txt A company access was found and in the archives, a $10,000 gem: Bosch CAN module implementation Now it is going for free for every engineer and car enthusiast, thanks to Synopsys providing us with neat roadmap to tech sector Sorry, Bosch, you got third-partied! Call the Synopsys CEO and thank them for letting us all know where the valuable data is! |
ARM tracker page ↗ | d1rfilter this group | · Jul 12, 2026 | Thanks to leaked database by Synopsys, a roadmap was provided Many other group leaks were cross-referenced and thoroughly analyzed One of the leaked companies gave our team access to ARM center Severely incapacitated by 2FA email/sms-code required by ARM on every step, we were still able to download an interesting tool: Athena Download Manager That requires an SSL certificate of a company that owns ARM products, and downloading by means of Athena allows to bypass multiple 2FA checks that are required when downloading same files from www.arm.com This is now free for download to any reverse engineer on Earth and beyond, thanks to Synopsys company data negligence: |
Synopsys tracker page ↗ | d1rfilter this group | · Jul 12, 2026 | No details on the leak post beyond the victim name. |
Breach & ransomware newsAll →
Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.