ZeroHour

Incidents

Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups

Ransomware & extortion groups · activity

#Group7dtrend30d90dall-time*Last postStatusEstimated earnings (public reporting)
1the gentlemen32▲9157413413activeno public figure
2qilin18▲2117359359activeno public figure
3krybit13▲11479696activeno public figure
4direwolf5▼6456262activeno public figure
5storm44▲44445656activeno public figure
6akira7▼1388282activeApproximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since.
7coinbase cartel0=375656activeno public figure
8inc ransom3▼636106106activeno public figure
9lockbit55▼1278686activeOver US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…
10shinyhunters1▼2243434activeno public figure
11safepay20▲20227272activeno public figure
12leakeddata0▼8203838activeno public figure
13orova0=194444activeno public figure
14zawoo0=191919activeno public figure
15audit team10▲6181919activeno public figure
16emperador6▲5181919activeno public figure
17panzer6▲3172424activeno public figure
18kazu0▼17171717activeno public figure
19play4▲4144444activeno public figure
20vexy4▼6141414activeno public figure
21black nevas13▲13131313activeno public figure
22chaos5▲4123434activeno public figure
23everest0▼4123434activeno public figure
24pear1▼1122727activeno public figure
25rhysida3▲1121515activeno public figure

*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.

Incidents11 records · full details

VictimGroup / typeDiscoveredDetails
Cumar Marble & Granite
tracker page ↗
dark projectfilter this group · 3h agoCumar Marble & Granite, a company specializing in luxury kitchens, bathrooms, and custom projects, has been the target of a massive cyberattack. Hackers stole 489 gigabytes of data from the company’s servers, including personal information, technical drawings, and financial documents. This incident raises serious concerns regarding the theft of intellectual property and potential breaches of employee and customer privacy.
Specchem LLC
tracker page ↗
dark projectfilter this group · 6d agoA cyberattack on Specchem LLC resulted in a massive data breach. As a result of the incident, approximately 500 GB of data—containing roughly 700,000 files, including confidential personal and financial information—was stolen.
MEI Architects
tracker page ↗
dark projectfilter this group · 7d agoAs a result of the attack, 340 GB of data (approximately 130,000 files) was stolen: including Social Security numbers, passports, green cards, invoices, HR documents, and a vast number of architectural drawings—including those from past and current projects, as well as those currently under construction.
Alurwalls
tracker page ↗
dark projectfilter this group · 8d agoAlurwalls was attacked, resulting in the theft of approximately 17 GB of confidential data. The stolen information includes banking and other financial documents, client building plans, and other personal data belonging to the company and its partners. Currently, more than 16,000 files are no longer protected by Alurwalls.
Master Manufacturing Co., Inc.
tracker page ↗
dark projectfilter this group · 8d agoMaster Manufacturing Co specializing in custom metal stamping and production services has fallen victim to a significant cyberattack. Hackers reportedly exfiltrated 36 gigabytes of sensitive data from the company’s servers. The stolen information includes SQL databases containing personal data, as well as technical plans and schematics for custom metal parts. The breach raises serious concerns regarding intellectual property theft and potential privacy violations for employees and clients.
Dentist in New Britain, CT
tracker page ↗
dark projectfilter this group · 21d agoAs a result of the attack, the following were compromised: the entire customer database, consisting of just over 8,000 files, as well as a small number of records containing Social Security numbers
Pump Engineering Company
tracker page ↗
dark projectfilter this group · 21d agoDuring the cyberattack, 120,000 files (115 GB) were stolen, including an extensive customer database, insurance documents, confidential financial documents, and a vast number of project drawings.
Furnished Quarters
tracker page ↗
dark projectfilter this group · 22d agoThe company "Furnished Quarters" was the victim of a successful cyberattack, as a result of which the company’s confidential data was stolen. The volume of data stolen amounts to 155 GB. The data stolen included the company’s customer details, as well as documents containing banking and financial information. Currently, around 198,000 files are no longer under the control of "Furnished Quarters".
Design-Aire Engineering, INC
tracker page ↗
dark projectfilter this group · 22d agoDesign-Aire Engineering, INC has suffered a cyberattack on its service systems, resulting in the theft of approximately 377GB of sensitive data. The breached information includes employees' personal data and detailed architectural plans of clients' buildings.
Jones, Little & Co., CPAs, LLP
tracker page ↗
dark projectfilter this group · 22d agoAt least 100 gigabytes of company data—including financial records, internal files, and employee personal information—were stolen in a cyberattack. Hackers encrypted the firm's systems after exfiltrating the documents, leaving operations paralyzed.
The Liberty Group
tracker page ↗
dark projectfilter this group · 22d agoA company has suffered a major cyberattack resulting in the theft of approximately 27,000 internal files. The leaked documents include financial records, internal working materials, and personal data of employees. Attackers encrypted the company's systems following the breach, severely disrupting operations

Breach & ransomware newsAll →

Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.