Incidents
Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups
Leak-site victims · 7d
183
Leak-site victims · 30d
1K
Active groups · 30d
778 new
Most active · 7d
the gentlemen
Breaches added · 30d
7
Accounts exposed · 30d
34.6MHIBP
Ransomware & extortion groups · activityleak-site posts · 90-day window · click a group for its profile
| # | Group | 7d | trend | 30d | 90d | all-time* | Last post | Status | Estimated earnings (public reporting) |
|---|---|---|---|---|---|---|---|---|---|
| 1 | the gentlemen | 30 | ▲6 | 152 | 400 | 400 | active | no public figure | |
| 2 | qilin | 25 | ▲11 | 119 | 360 | 360 | active | no public figure | |
| 3 | krybit | 15 | ▲15 | 49 | 95 | 95 | active | no public figure | |
| 4 | storm | 9 | ▼31 | 49 | 61 | 61 | active | no public figure | |
| 5 | akira | 9 | = | 43 | 86 | 86 | active | Approximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since. | |
| 6 | direwolf | 3 | ▼8 | 37 | 62 | 62 | active | no public figure | |
| 7 | coinbase cartel | 0 | = | 37 | 56 | 56 | active | no public figure | |
| 8 | inc ransom | 8 | ▲4 | 36 | 112 | 112 | active | no public figure | |
| 9 | lockbit5 | 4 | ▼4 | 27 | 53 | 53 | active | Over US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit… | |
| 10 | audit team | 9 | = | 23 | 25 | 25 | active | no public figure | |
| 11 | safepay | 10 | = | 22 | 67 | 67 | active | no public figure | |
| 12 | leakeddata | 1 | ▲1 | 20 | 39 | 39 | active | no public figure | |
| 13 | orova | 0 | = | 19 | 44 | 44 | active | no public figure | |
| 14 | zawoo | 0 | = | 19 | 19 | 19 | active | no public figure | |
| 15 | emperador | 5 | = | 18 | 22 | 22 | active | no public figure | |
| 16 | kazu | 0 | ▼17 | 17 | 17 | 17 | active | no public figure | |
| 17 | vexy | 3 | ▼7 | 15 | 15 | 15 | active | no public figure | |
| 18 | shinyhunters | 2 | ▼1 | 14 | 32 | 32 | active | no public figure | |
| 19 | panzer | 7 | ▲5 | 14 | 25 | 25 | active | no public figure | |
| 20 | black nevas | 1 | ▼12 | 14 | 14 | 14 | active | no public figure | |
| 21 | chaos | 3 | ▼1 | 13 | 35 | 35 | active | no public figure | |
| 22 | everest | 0 | ▼4 | 12 | 34 | 34 | active | no public figure | |
| 23 | pear | 1 | = | 12 | 23 | 23 | active | no public figure | |
| 24 | rhysida | 1 | ▼3 | 12 | 14 | 14 | active | no public figure | |
| 25 | cyberleek | 0 | = | 12 | 12 | 12 | active | no public figure |
*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.
Incidents5 records · full details
| Victim | Group / type | Discovered | Details |
|---|---|---|---|
Venture Logistics tracker page ↗ | helixfilter this group | · Aug 6, 2026 | SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. |
Uber tracker page ↗ | helixfilter this group | · Aug 6, 2026 | SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. |
Highwoods Properties tracker page ↗ | helixfilter this group | · Aug 6, 2026 | SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. |
Morguard tracker page ↗ | helixfilter this group | · Aug 6, 2026 | Morguard reached out, took extensions, then ignored the negotiation with no real offer. Contacting us and stalling is not a strategy. Deadlines stand. Silence after outreach gets a private board and a countdown then publication. |
Westland Insurance tracker page ↗ | helixfilter this group | · Aug 6, 2026 | Westland reached out, got the full demand, then stalled with no serious number. Contacting us and dragging process is not negotiation. |
Breach & ransomware newsAll →
Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.