ZeroHour

Incidents

Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups

Ransomware & extortion groups · activity

#Group7dtrend30d90dall-time*Last postStatusEstimated earnings (public reporting)
1the gentlemen30▲8152400400activeno public figure
2qilin29▲16113364364activeno public figure
3storm9▼31496161activeno public figure
4krybit15▲15449595activeno public figure
5akira10▲3438787activeApproximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since.
6direwolf2▼9376262activeno public figure
7coinbase cartel0=355656activeno public figure
8inc ransom10▲634113113activeno public figure
9lockbit55=275454activeOver US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…
10audit team10▲1242626activeno public figure
11safepay10=226767activeno public figure
12leakeddata1▲1203939activeno public figure
13orova0=194444activeno public figure
14zawoo0=191919activeno public figure
15emperador4▼1182222activeno public figure
16kazu0▼17171717activeno public figure
17vexy3▼4151515activeno public figure
18shinyhunters2=143232activeno public figure
19panzer7▲5142525activeno public figure
20black nevas1▼12141414activeno public figure
21play3▼1134747activeno public figure
22chaos3▼1133535activeno public figure
23rhysida2▼2131515activeno public figure
24everest0▼3123434activeno public figure
25pear0▼1122323activeno public figure

*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.

Leak-site victims3 records · full details

VictimGroup / typeDiscoveredDetails
Bosch
tracker page ↗
d1rfilter this group · Jul 12, 2026Again, thanks to database Synopsys provided us with After analyzing technical leaks by other groups and cross-referencing targets from TARGETLIST.txt A company access was found and in the archives, a $10,000 gem: Bosch CAN module implementation Now it is going for free for every engineer and car enthusiast, thanks to Synopsys providing us with neat roadmap to tech sector Sorry, Bosch, you got third-partied! Call the Synopsys CEO and thank them for letting us all know where the valuable data is!
ARM
tracker page ↗
d1rfilter this group · Jul 12, 2026Thanks to leaked database by Synopsys, a roadmap was provided Many other group leaks were cross-referenced and thoroughly analyzed One of the leaked companies gave our team access to ARM center Severely incapacitated by 2FA email/sms-code required by ARM on every step, we were still able to download an interesting tool: Athena Download Manager That requires an SSL certificate of a company that owns ARM products, and downloading by means of Athena allows to bypass multiple 2FA checks that are required when downloading same files from www.arm.com This is now free for download to any reverse engineer on Earth and beyond, thanks to Synopsys company data negligence:
Synopsys
tracker page ↗
d1rfilter this group · Jul 12, 2026No details on the leak post beyond the victim name.

Breach & ransomware newsAll →

Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.