Incidents
Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups
Leak-site victims · 7d
189
Leak-site victims · 30d
1K
Active groups · 30d
778 new
Most active · 7d
the gentlemen
Breaches added · 30d
9
Accounts exposed · 30d
36.8MHIBP
Ransomware & extortion groups · activityleak-site posts · 90-day window · click a group for its profile
| # | Group | 7d | trend | 30d | 90d | all-time* | Last post | Status | Estimated earnings (public reporting) |
|---|---|---|---|---|---|---|---|---|---|
| 1 | the gentlemen | 30 | ▲6 | 155 | 401 | 401 | active | no public figure | |
| 2 | qilin | 23 | ▲9 | 117 | 361 | 361 | active | no public figure | |
| 3 | krybit | 13 | ▲13 | 47 | 96 | 96 | active | no public figure | |
| 4 | akira | 12 | ▲6 | 44 | 86 | 86 | active | Approximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since. | |
| 5 | storm | 4 | ▼36 | 44 | 56 | 56 | active | no public figure | |
| 6 | direwolf | 3 | ▼8 | 41 | 62 | 62 | active | no public figure | |
| 7 | coinbase cartel | 0 | = | 37 | 56 | 56 | active | no public figure | |
| 8 | inc ransom | 9 | ▲5 | 36 | 112 | 112 | active | no public figure | |
| 9 | lockbit5 | 5 | ▼2 | 27 | 53 | 53 | active | Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit… | |
| 10 | audit team | 11 | ▲2 | 23 | 25 | 25 | active | no public figure | |
| 11 | safepay | 10 | = | 22 | 67 | 67 | active | no public figure | |
| 12 | leakeddata | 0 | ▼4 | 20 | 38 | 38 | active | no public figure | |
| 13 | orova | 0 | = | 19 | 44 | 44 | active | no public figure | |
| 14 | zawoo | 0 | = | 19 | 19 | 19 | active | no public figure | |
| 15 | emperador | 5 | = | 18 | 22 | 22 | active | no public figure | |
| 16 | kazu | 0 | ▼17 | 17 | 17 | 17 | active | no public figure | |
| 17 | shinyhunters | 2 | ▼1 | 15 | 32 | 32 | active | no public figure | |
| 18 | vexy | 4 | ▼5 | 15 | 15 | 15 | active | no public figure | |
| 19 | panzer | 7 | ▲5 | 14 | 25 | 25 | active | no public figure | |
| 20 | black nevas | 1 | ▼12 | 14 | 14 | 14 | active | no public figure | |
| 21 | dragonforce | 3 | ▲1 | 12 | 71 | 71 | active | no public figure | |
| 22 | chaos | 4 | ▲2 | 12 | 34 | 34 | active | no public figure | |
| 23 | everest | 0 | ▼4 | 12 | 34 | 34 | active | no public figure | |
| 24 | pear | 1 | = | 12 | 23 | 23 | active | no public figure | |
| 25 | rhysida | 3 | ▲1 | 12 | 14 | 14 | active | no public figure |
*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.
Incidents12 records · full details
| Victim | Group / type | Discovered | Details |
|---|---|---|---|
GGS tracker page ↗ | everestfilter this group | · 9d ago | 2 posts - 1h |
KÖRBER tracker page ↗ | everestfilter this group | · 9d ago | 2 posts - 1h |
GENESILICO tracker page ↗ | everestfilter this group | · 9d ago | 2 posts - 1h |
Negotiation Rules tracker page ↗ | everestfilter this group | · 12d ago | 1 posts - 1h |
Rise UP tracker page ↗ | everestfilter this group | · 16d ago | 2 posts - 1h |
VIVOTEK tracker page ↗ | everestfilter this group | · 16d ago | 2 posts - 1h |
Italtel Peru tracker page ↗ | everestfilter this group | · 16d ago | 2 posts - 1h |
CCA Bank tracker page ↗ | everestfilter this group | · 28d ago | 2 posts - 1h |
Capgemini Engineering tracker page ↗ | everestfilter this group | · 28d ago | 2 posts - 1h |
Grupo DT tracker page ↗ | everestfilter this group | · 28d ago | 2 posts - 1h |
Kingston Technology tracker page ↗ | everestfilter this group | · 28d ago | 2 posts - 1h |
Experts Entreprendre tracker page ↗ | everestfilter this group | · 28d ago | 2 posts - 1h |
Breach & ransomware newsAll →
Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.