ZeroHour

Incidents

Ransomware leak-site victims (RansomLook), confirmed breaches (Have I Been Pwned) and AI-written profiles of the most active groups

Ransomware & extortion groups · activity

#Group7dtrend30d90dall-time*Last postStatusEstimated earnings (public reporting)
1the gentlemen30▲6156401401activeno public figure
2qilin21▲7115359359activeno public figure
3krybit13▲12479696activeno public figure
4storm4▼36445656activeno public figure
5akira9▲3418383activeApproximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since.
6direwolf3▼8416262activeno public figure
7inc ransom6▲239109109activeno public figure
8coinbase cartel0=375656activeno public figure
9lockbit55▼2275353activeOver US$120 million in ransom payments received, per U.S. DOJ and UK NCA Operation Cronos announcement (February 2024). Earnings attributable to the LockBit…
10audit team11▲2232525activeno public figure
11safepay10=226767activeno public figure
12leakeddata0▼4203838activeno public figure
13orova0=194444activeno public figure
14zawoo0=191919activeno public figure
15emperador4▼1172121activeno public figure
16kazu0▼17171717activeno public figure
17vexy4▼5151515activeno public figure
18shinyhunters1▼2143131activeno public figure
19panzer7▲4142525activeno public figure
20black nevas1▼12141414activeno public figure
21dragonforce3▲1127171activeno public figure
22chaos4▲2123434activeno public figure
23everest0▼4123434activeno public figure
24pear1=122323activeno public figure
25rhysida3▲1121414activeno public figure

*all-time = since this tracker started collecting leak-site posts. Earnings are estimates from public reporting (law enforcement, blockchain analytics), compiled by the model; treat as indicative.

Incidents6 records · full details

VictimGroup / typeDiscoveredDetails
Partners Financial Services, a.s.
tracker page ↗
inc ransomfilter this group · 21h agoDate: September 2026 Target: Partners Financial Services, a.s. (IČO: 27699781) Location: Prague, Czech Republic Industry: Financial Services / Banking / Insurance
aidon.com
tracker page ↗
inc ransomfilter this group · 21h agoAidon Oy / Gridspertise (Enel Group) — Smart Meter Operations Platform Breach Date: September 2026 Sector: Critical Infrastructure — Energy / Smart Grid Country: Finland Parent Company: Gridspertise S.r.l. (joint venture: Enel Group + CVC Capital Partners)
Zito Marketi
tracker page ↗
inc ransomfilter this group · 21h agoIn the retail industry, there is a persistent myth that to scale nationally, a brand must inevitably shed its local soul. The prevailing logic dictates that as a chain expands, the neighborhood warmth of its origins is replaced by sterile corporate efficiency, and the familiar faces behind the counter are swapped for standardized kiosks. But in North Macedonia, a retail network that now spans dozens of towns and employs over 850 people is quietly dismantling that assumption. They are proving that the secret to dominating a national market might just be remembering exactly what it feels like to run a single corner store.
City of Princeton
tracker page ↗
inc ransomfilter this group · 21h agoDate added: September 2026 Website: princetontx.us Sector: Government / Municipal Administration Location: Collin County, Texas, USA (Dallas-Fort Worth Metroplex) Employees: ~150+ Annual Budget: $30–50M
Chicago History Museum
tracker page ↗
inc ransomfilter this group · 21h agoOrganization: Chicago History Museum (formerly Chicago Historical Society) Location: 1601 N Clark Street, Chicago, IL 60614 Website: chicagohistory.org CEO: Michael J. Anderson, President & CEO Industry: Non-profit / Cultural Institution Breach Date: September 2026 Data Volume: 4 departments + AWS cloud infrastructure, 15+ years of records Individuals Affected: 20,000+
jms building corporation
tracker page ↗
inc ransomfilter this group · 6d agoNo details on the leak post beyond the victim name.

Breach & ransomware newsAll →

Leak-site posts are claims by criminals and can be false or duplicated; victim names are shown as posted. HIBP entries are verified breaches with the affected account count. Dates are when the post or breach was first observed, not when the intrusion happened.