ZeroHour

Incidents

Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups

Ransomware & extortion groups · activity

#Group7dtrend30d90dall-time*Last postStatusEstimated earnings (public reporting)
1the gentlemen30▲6156401401activeno public figure
2qilin21▲6116359359activeno public figure
3krybit13▲11479696activeno public figure
4storm4▼36445656activeno public figure
5akira9▲3418383activeApproximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since.
6direwolf3▼8416262activeno public figure
7inc ransom6▲239109109activeno public figure
8coinbase cartel0=375656activeno public figure
9lockbit55▼2275353activeOver US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…
10audit team11▲2232525activeno public figure
11safepay10=226767activeno public figure
12leakeddata0▼4203838activeno public figure
13orova0=194444activeno public figure
14zawoo0=191919activeno public figure
15emperador4▼1172121activeno public figure
16kazu0▼17171717activeno public figure
17vexy4▼7151515activeno public figure
18shinyhunters1▼2143131activeno public figure
19panzer7▲4142525activeno public figure
20black nevas1▼12141414activeno public figure
21dragonforce3▲1127171activeno public figure
22chaos4▲2123434activeno public figure
23everest0▼4123434activeno public figure
24pear1▼1122424activeno public figure
25rhysida3▲1121414activeno public figure

*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.

Leak-site victims11 records · full details

VictimGroup / typeDiscoveredDetails
Cumar Marble & Granite
tracker page ↗
dark projectfilter this group · 1d agoCumar Marble & Granite, a company specializing in luxury kitchens, bathrooms, and custom projects, has been the target of a massive cyberattack. Hackers stole 489 gigabytes of data from the company’s servers, including personal information, technical drawings, and financial documents. This incident raises serious concerns regarding the theft of intellectual property and potential breaches of employee and customer privacy.
Specchem LLC
tracker page ↗
dark projectfilter this group · 7d agoA cyberattack on Specchem LLC resulted in a massive data breach. As a result of the incident, approximately 500 GB of data—containing roughly 700,000 files, including confidential personal and financial information—was stolen.
MEI Architects
tracker page ↗
dark projectfilter this group · 9d agoAs a result of the attack, 340 GB of data (approximately 130,000 files) was stolen: including Social Security numbers, passports, green cards, invoices, HR documents, and a vast number of architectural drawings—including those from past and current projects, as well as those currently under construction.
Alurwalls
tracker page ↗
dark projectfilter this group · 9d agoAlurwalls was attacked, resulting in the theft of approximately 17 GB of confidential data. The stolen information includes banking and other financial documents, client building plans, and other personal data belonging to the company and its partners. Currently, more than 16,000 files are no longer protected by Alurwalls.
Master Manufacturing Co., Inc.
tracker page ↗
dark projectfilter this group · 9d agoMaster Manufacturing Co specializing in custom metal stamping and production services has fallen victim to a significant cyberattack. Hackers reportedly exfiltrated 36 gigabytes of sensitive data from the company’s servers. The stolen information includes SQL databases containing personal data, as well as technical plans and schematics for custom metal parts. The breach raises serious concerns regarding intellectual property theft and potential privacy violations for employees and clients.
Dentist in New Britain, CT
tracker page ↗
dark projectfilter this group · 22d agoAs a result of the attack, the following were compromised: the entire customer database, consisting of just over 8,000 files, as well as a small number of records containing Social Security numbers
Pump Engineering Company
tracker page ↗
dark projectfilter this group · 22d agoDuring the cyberattack, 120,000 files (115 GB) were stolen, including an extensive customer database, insurance documents, confidential financial documents, and a vast number of project drawings.
Furnished Quarters
tracker page ↗
dark projectfilter this group · 23d agoThe company "Furnished Quarters" was the victim of a successful cyberattack, as a result of which the company’s confidential data was stolen. The volume of data stolen amounts to 155 GB. The data stolen included the company’s customer details, as well as documents containing banking and financial information. Currently, around 198,000 files are no longer under the control of "Furnished Quarters".
Design-Aire Engineering, INC
tracker page ↗
dark projectfilter this group · 23d agoDesign-Aire Engineering, INC has suffered a cyberattack on its service systems, resulting in the theft of approximately 377GB of sensitive data. The breached information includes employees' personal data and detailed architectural plans of clients' buildings.
Jones, Little & Co., CPAs, LLP
tracker page ↗
dark projectfilter this group · 23d agoAt least 100 gigabytes of company data—including financial records, internal files, and employee personal information—were stolen in a cyberattack. Hackers encrypted the firm's systems after exfiltrating the documents, leaving operations paralyzed.
The Liberty Group
tracker page ↗
dark projectfilter this group · 23d agoA company has suffered a major cyberattack resulting in the theft of approximately 27,000 internal files. The leaked documents include financial records, internal working materials, and personal data of employees. Attackers encrypted the company's systems following the breach, severely disrupting operations

Breach & ransomware newsAll →

Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.