ZeroHour

Incidents

Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups

Ransomware & extortion groups · activity

#Group7dtrend30d90dall-time*Last postStatusEstimated earnings (public reporting)
1the gentlemen30▲6155401401activeno public figure
2qilin23▲9117361361activeno public figure
3krybit13▲13479696activeno public figure
4akira9=448686activeApproximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since.
5storm4▼36445656activeno public figure
6direwolf3▼8416262activeno public figure
7coinbase cartel0=375656activeno public figure
8inc ransom9▲536112112activeno public figure
9lockbit54▼4275353activeOver US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…
10audit team11▲2232525activeno public figure
11safepay10=226767activeno public figure
12leakeddata0▼4203838activeno public figure
13orova0=194444activeno public figure
14zawoo0=191919activeno public figure
15emperador5=182222activeno public figure
16kazu0▼17171717activeno public figure
17shinyhunters2▼1153232activeno public figure
18vexy4▼5151515activeno public figure
19panzer7▲5142525activeno public figure
20black nevas1▼12141414activeno public figure
21dragonforce3▲1127171activeno public figure
22chaos4▲2123434activeno public figure
23everest0▼4123434activeno public figure
24pear1=122323activeno public figure
25rhysida3▲1121414activeno public figure

*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.

Incidents10 records · full details

VictimGroup / typeDiscoveredDetails
RTAD GOV MM
tracker page ↗
dysphor1afilter this group · 10d agoLeaked: New | Sector: Government / Transport | Country: 🇲🇲 Myanmar | Records: 1.08 GB — full databases dump | Road Transport Administration Department (RTAD) — official government portal providing public transport services, driving license issuance, vehicle registration, and safety regulations. Full databases dump total 1.08 GB. Victim domain https://rtad.gov.mm. | Leaked | RTAD GOV MM Leaked New Critical 🇲🇲 Myanmar ID_RTAD-GOV-MM | Detected 2026 | Target // Government / Transport Description Road Transport Administration Department (RTAD) — official government portal providing public transport services, driving license issuance, vehicle registration, and safety regulations. Full databases dump total 1.08 GB. Victim domain https://rtad.gov.mm. Infection Mechanism Compromised RTAD government databases exposing vehicle registration records, owner PII, NRC numbers, addresses, vehicle details, and insurance premium data via internal API responses. Notable Attack Full databases dump — 1.08 GB from the Road Transport Administration Department (RTAD) of Myanmar, including owner names, NRC numbers, addresses, vehicle registration, branch, and premium payment records. Example Compromised {"code": 0, "status": "OK", "message": "Success", "data": {"owner_name": "U SOE MYINT", "nrc_no": "8/KHAMANA(N)073033", "address": ",,HTEIN SAN YWAR,CHAUK", "types": "T", "vehicle_no": "1A/1230", "book_no": "", "vehicle_name": "HINO TE11", "vehicle_type": "TRUCK_COMMERCIAL", "productType": "COMMERCIAL", "motorType": "TRUCK", "premiumYear": 2, "seating": 0, "weight": 7, "capacity": "7.0", "period_to": "2025-02-28", "premium_amount": "15000.0", "receipt_no": "", "receipt_date": "", "version": 1, "premiumTotalAmount": 30000, "total_month": 24, "rta_branch": "Regional Office(Magway)", "nextPremiumBuyDate": "2027-02-28", "isConvert": false, "penaltyFees": 0, "isDataValid": true}, "api_statuses": {"api_1": "false", "api_2": "success"}, "timestamp": "2026-01-24T18:19:18.162Z"} Download Source…
CitizensPay
tracker page ↗
dysphor1afilter this group · 11d agoSector: Digital Wallet / Payment Platform | Country: 🇲🇲 Myanmar | Records: 30 GB | Countdown: 2d 12h 37m 53s | Citizens Pay (also known as CTZPay) is a mobile digital wallet and payment platform in Myanmar powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited. Compromised agent user information — total data size 30 GB. Price range $7,000 to $25,000. Victim domain https://ctzpay.com. | CITIZENSPAY | CitizensPay Upcoming Critical 🇲🇲 Myanmar ID_CITIZENSPAY | Detected 2026 | Target // Digital Wallet / Payment Platform Description Citizens Pay (also known as CTZPay) is a mobile digital wallet and payment platform in Myanmar powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited. Compromised agent user information — total data size 30 GB. Price range $7,000 to $25,000. Victim domain https://ctzpay.com. Infection Mechanism Exposed agent user info including business license, NRC pictures (front/back), selfie, shop pictures, and phone numbers from the CTZPay agent verification pipeline. Notable Attack Full agent user info dump from Citizens Pay (CTZPay) — 30 GB including KYC documents (NRC front/back), selfies, business license, shop pictures, and phone numbers. Example Compromised Example Data Include - business_picture - nrc_picture_front - nrc_picture_back - selfie_picture - shop_picture - Ph Number Evidence Images business_license_picture.jpg nrc_picture_front.jpg nrc_picture_back.jpg selfie_picture.jpg shop_picture.jpg Download Sample Contact Us On Session Close
MBT Telecom
tracker page ↗
dysphor1afilter this group · 12d agoFor Sale: New | Sector: Telecommunications / ISP | Country: 🇲🇲 Myanmar | Records: 209,970 user records — full dump | Myanmar Broadband Telecom Co., Ltd. (MBT) is a leading fiber internet service provider and telecommunications network solutions company established in Myanmar in 2013. Full database compromise exposing 209,970 user records including PII, passwords, and device information. | For Sale | MBT Telecom For Sale Critical 🇲🇲 Myanmar ID_MBT-TELECOM | Detected 2026 | Target // Telecommunications / ISP Description Myanmar Broadband Telecom Co., Ltd. (MBT) is a leading fiber internet service provider and telecommunications network solutions company established in Myanmar in 2013. Full database compromise exposing 209,970 user records including PII, passwords, and device information. Infection Mechanism Compromised MBT customer database exposing user PII, passwords, device types, and account metadata from their FTTH, DIA, and enterprise VPN services. Notable Attack Full user dump of 209,970 MBT Telecom customer records including names, phone numbers, passwords, and device information. Example Compromised Full DB Access — 209,970 User Records id,name,phone,created_at,user_status,uniq_id,address,new_pass,device_type 225425,Phyo Wai Hein,09975578724,2026-09-04T09:03:45.000000Z,Normal,937064,,25809672, 225424,Ma Zar Zar,09776411439,2026-09-04T08:54:23.000000Z,Normal,386819,,444555, 225423,Arr Li,09973900796,2026-09-04T08:48:46.000000Z,Normal,4973,,mml19894, 225422,umyintthein,0943051152,2026-09-04T08:37:52.000000Z,Normal,856710,,123456, 225421,Ma Ei Thandarbo,09773450715,2026-09-04T08:33:53.000000Z,Normal,582959,,064071, 225420,Daw Aye Kyi Kyi Myint,09952295522,2026-09-04T08:32:43.000000Z,Normal,771678,,123456, 225419,Nan Phawy,09772111156,2026-09-04T08:31:36.000000Z,Normal,352373,,123456, 225418,U Soe Lwin,09941258904,2026-09-04T08:30:57.000000Z,Normal,101282,,12345678, 225417,Aung Kyaw Htun,09402695665,2026-09-04T08:28:35.000000Z,Normal,151460,,ak025846…
Yoma Fleet
tracker page ↗
dysphor1afilter this group · 18d agoSector: Business / Vehicle Leasing | Country: 🇲🇲 Myanmar | Records: Orders, users, repayments, employees — full admin export | Yoma Fleet is a leading vehicle operating lease, rental, and financing company based in Yangon, Myanmar. The platform provides centralized administration and management for vehicle orders, employee financing, repayments, users, and employee records. Admin account access — need to contact on Telegram. | Leaked
AYUDHYA TH Insurance
tracker page ↗
dysphor1afilter this group · 18d agoSector: Financial / Insurance | Country: Thailand | Records: Internal batch-control system + admin credentials | Leaked data from AYUDHYA (TH Insurance / Allianz Thailand). Internal batch-control system used within the financial/transaction batch-processing ecosystem behind the Allianz customer-facing web platform. Includes admin credentials (TBH2CASH:AAbb1234). | Leaked
GUSTO College GLMS
tracker page ↗
dysphor1afilter this group · 18d agoSector: Education Sector | Country: 🇲🇲 Myanmar | Records: User account credentials | Compromised user accounts from GUSTO College's GLMS (Global Learning Management System). Exposed user credentials from the Moodle platform at gusto-education.com. | Leaked
Job Net .COM.MM
tracker page ↗
dysphor1afilter this group · 18d agoSector: Business | Country: Myanmar | Records: ~500++ user accounts and cv information | Normal Hunters operation compromising Job Net .COM.MM business data, exposing corporate information, user accounts, and business operations data. | Leaked
The University of Delhi (DU)
tracker page ↗
dysphor1afilter this group · 18d agoSector: Education Sector | Country: 🇮🇳 India | Records: Student records with PII, academic data, and identification documents | The University of Delhi (DU) is a major public university in New Delhi, India, founded in 1922. It is one of India's most well-known universities, offering undergraduate, postgraduate, and doctoral programs across subjects like science, arts, commerce, law, and technology. | For Sale
Indonesian Police Database
tracker page ↗
dysphor1afilter this group · 18d agoSector: Government / Law Enforcement | Country: Indonesia | Records: 52,000 officer records + 4,000 facial photos | Database containing records of 52,000 Indonesian police officers including email addresses, phone numbers, first and last names, passwords, location details, and 4,000 facial photographs. | For Sale
Netim Company
tracker page ↗
dysphor1afilter this group · 18d agoSector: Business / Domain Registrar | Country: 🇫🇷 France | Records: Source code, IPs, payment databases, customer PII — full infrastructure | Netim is a French domain name registrar and web hosting provider. Full compromise of internal systems — source code, infrastructure IPs, payment processing databases, customer PII, and internal business data. | For Sale

Breach & ransomware newsAll →

Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.