Ransomware Group intelligence
Donutleaks
InactiveTrack Donutleaks with 42 published victims and 4 known leak locations in a single intelligence view.
Overview
Donutleaks is tracked by Breach House as a ransomware group with 42 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | qkbbaxiuqqcqb5nox4np4qjcniy2q6m7yeluvj7n5i5dn7pgpcwxwfid.onion |
| Leak location 2 | Onion service | Unknown | sbc2zv2qnz5vubwtx3aobfpkeao6l4igjegm3xx7tk5suqhjkp5jxtqd.onion |
| Leak location 3 | Onion service | Unknown | doq32rjiuomfghm5a4lyf3lwwakt2774tkv4ppsos6ueo5mhx7662gid.onion |
| Leak location 4 | Onion service | Unknown | dk4mkfzqai6ure62oukzgtypedmwlfq57yj2fube7j5wsoi6tuia7nyd.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (42)
Search, filter and paginate the victim timeline for Donutleaks.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Jack "Designer" Sparrow. id13504 View details | Other | |||
|
http://1-sourcedesign.com/ ...and this Canadian company has distinguished itself by its reluctance to share with anyone, including the authors of the tools they use. In the depths of the date, a huge number of all kinds of cracks, serial numbers, Warez, etc. were discovered. It’s like I’ve… |
|||||
| Ransomware | Industrial Bolsera id13496 View details | Spain | Manufacturing / Engineering | ||
|
https://www.industrialbolsera.com/ca/index.htm A dubious company for sure. But which one is).Our design and R & D departments look for the most suitable solution. Subsequently, the product is manufactured according to a rigorous quality policy guaranteeing an excellent final product.At Industrial Bolsera, we apply… |
|||||
| Ransomware | KickDown ESET company. No overpayments at 0% (renamed and update) id13459 View details | Communication / Marketing | |||
|
This is what this note is now called. It's not about us "making" ESET. It's about the fact that: AT THE MOMENT I FUCKED THEIR NEW VERSION OF PREMIUM HOME SECURITY EDITION BEFORE THE PENTEST. == NO MORE == ....as the ever-condolent and praying “journalists” from... And now there will be a… |
|||||
| Ransomware | ESET. PREMIUM. id13454 View details | Communication / Marketing | |||
|
in preparation for the next goal, eset smart security premium was tested today. He fought epically, heroically and bravely with everything, with anything (mostly rubbish in C#), but, as befits a real AB, he chose not to notice the host of the party. It's something like drinking: once you fuck… |
|||||
| Ransomware | all-mode.com id13419 View details | Construction / Real Estate | |||
|
A Legacy Of Excellence Founded in 1972 All-Mode Communications inc. has always been dedicated to giving our customers a world class experience whether it is running, testing and certifying new cable infrastructure; installing a new phone system; or helping with a move to a cloud hosted phone service. From the… |
|||||
| Ransomware | labline.it id13406 View details | Italy | Communication / Marketing | ||
|
Scientific research comes first Diatech Lab Line is not simply the name of a new company that joins a group of distributors of products for biomedical research, it is much more. Our range of products arises from the continuous search for cutting-edge and high-quality solutions that can make an active… |
|||||
| Ransomware | valleylandtitleco.com - UPD id13346 View details | Public Sector | |||
|
I-❤️-TEXAS... there could be your advertisement here, but I posted the (official) statements of this company for the month. You can easily make sure that they are a bit of a pussy. It happens in a day that they "close" 10 times larger sums... I always thought that Texas… |
|||||
| Ransomware | valleylandtitleco.com id13242 View details | Public Sector | |||
|
I-❤️-TEXAS... there could be your advertisement here, but I posted the (official) statements of this company for the month. You can easily make sure that they are a bit of a pussy. It happens in a day that they "close" 10 times larger sums... I always thought that Texas… |
|||||
| Ransomware | Patriot Machine id12619 View details | United States | Services | ||
|
Today we consider make public any related data about Patriot Machine operations and business. The defense contractors which cant defense his docs. Updated version of that will be on our file server. Stay tuned. Guys was so skill-able and professional what mr.Mask and his SpaceX working with them. Its… |
|||||
| Ransomware | Pittsburgh’s Trusted Orthopaedic Surgeons id12604 View details | United States | Communication / Marketing | ||
|
Hello everyone! We got some not very smart people who was compromise and do not want to protect their clients data. Today here medical company from Pittsburgh(USA):"Pittsburgh’s Trusted Orthopaedic Surgeons" [must be not so trusted as you thought, but okay] Web site: https://www.gpoa.com/ "Pittsburgh’… |
|||||
| Ransomware | Good Morning id11525 View details | United States | Communication / Marketing | ||
|
We live in an age of digital waste. We are constantly being sold something and pushed to believe in something. Personally, I don't watch TV or read news - it's all the same everywhere. The Good American soldiers are selling weapons, killing defenseless "protectors" in third-world countries, and the pathetic… |
|||||
| Ransomware | voidinteractive.net you are welcome in our chat id11224 View details | Iran, Islamic Republic of | Communication / Marketing | ||
|
https://imgur.com/a/aN5al4A You has been pwned. All data related Ready Or Not will be posted here if u will keep silent. We got 4Tb of source code and game related data. Send us a message via for on that blog as soon as possible. We will provide… |
|||||
| Ransomware | Watsonclinic.com id11145 View details | United States | Healthcare / Pharma | ||
|
We starting publishing data related medical company from U.S. they was silent almost a month. Soon here will be posted first pack of data. They was pen-tested by some another us-based company and they found a lot of vulnerability in Watsonclinic active directory network - and 90% of them… |
|||||
| Ransomware | DOD contractors you are welcome in our chat. id10662 View details | United States | Construction / Real Estate | ||
|
Hello [visitor_name]! We got some contractors of US Department of Defense here. They said SpaceX, Locheed Martin and Boing documents which is their legal property cost 20k usd. So we dont think like that and there our last warning. 500k usd at least: you will pay or all data… |
|||||
| Ransomware | carriereindustrial.com id9703 View details | Manufacturing / Engineering | |||
|
Full data leakage will be spreaded via bittorret. Here will be posted magnet link and torrent file soon. Full amount of docs More then 3Tb. Listing will be placed here also.… |
|||||
| Ransomware | Albert, Righter & Tittmann architechts, inc. id9702 View details | IT | |||
|
Full amount of his data will upload to our torrent server. Here will be placed magnet url and torrent file and full listing also. Update coming soon https://www.artarchitects.com/… |
|||||
| Ransomware | Who Is MONTY? ;) id9483 View details | Other | |||
|
https://www.databreaches.net/monti-ransomware-gang-leaks-donut-leaksHello. Today we received news that a little-known (or rather unknown) group with the telling name MONTI published a post saying that we owe them 100K USD. MONTI also allegedly posted "login details" for the admin panel(of course, for some unknown reason, either our site… |
|||||
| Ransomware | Sidockgroup. Published id9482 View details | Finance / Legal / Insurance | |||
|
Established in 1974, we are a full-service firm with offices throughout Michigan and have completed projects in most market sectors (website: sidockgroup.com) First sample of the data which will be posted.. There a lot of credit card information, bills and SSNs, carders will be very happy to use it.… |
|||||
| Ransomware | Sidockgroup. id9168 View details | Finance / Legal / Insurance | |||
|
Established in 1974, we are a full-service firm with offices throughout Michigan and have completed projects in most market sectors (website: sidockgroup.com) First sample of the data which will be posted.. There a lot of credit card information, bills and SSNs, carders will be very happy to use it.… |
|||||
| Ransomware | UPDATED: INC RANSOMWARE... id8967 View details | Communication / Marketing | |||
|
...and other... Appeal to the blog owners: if you work honestly and do not want to stain yourself with dirt and theft, do not post anything that the thief and scammer known as hulk, boss, MoonPrism asks you to post. His tox id: 0421BD35FA5A5849FB9BEB1595DBBE239DDE19B46B0B8BD73EDD1107C245B46C. All the data was stolen from… |
|||||
| Ransomware | RAT. id8935 View details | Retail / E-commerce | |||
|
The contacts of fucker which thought - he can steal from us: ToxID: 0421BD35FA5A5849FB9BEB1595DBBE239DDE19B46B0B8BD73EDD1107C245B46C Possible nickname: hulk That son of the bitch, stealed target and fucked up the operation. If someone with contacts like mentioned above will contact you - know that useless peace of shit, which acting as a… |
|||||
| Ransomware | INC RANSOMWARE... id8907 View details | Communication / Marketing | |||
|
...and other... Appeal to the blog owners: if you work honestly and do not want to stain yourself with dirt and theft, do not post anything that the thief and scammer known as hulk, boss, MoonPrism asks you to post. All the data was stolen from us, and one of… |
|||||
| Ransomware | Gossler, Gobert & Wolters Group. id8691 View details | Telecommunications | |||
|
[ 2,6Tb data-leakage coming soon ] We have a lot of information about your clients. We extract all your SQL databases from yourcomputers network and all your important data from your file servers - the file listing of the first pack of data which will leak if you do not contact… |
|||||
| Ransomware | Agilitas IT Solutions Limited id8690 View details | Services | |||
|
We can say for sure - you seen our meassage which was placed on yours website. If u will keep silent we gonna start posting the source code and SQL databases which we exfiltrated from yours computers network. First pack of data will contine 30Gb of source code and 450… |
|||||
| Ransomware | Jackson Township Police Department and Administration. id7419 View details | Public Sector | |||
|
We are prepare some announce. The data of Police Department and FBI Supervisor will be released if you will keep acting in the same way as you did early. First data package will containe 500gb dumps which was taken by Cellebrite - there the data from phones of suspects and… |
|||||
| Ransomware | Southwest Healthcare Services id7330 View details | Healthcare / Pharma | |||
|
Southwest Healthcare Services is a non-profit organization dedicated to providing quality healthcare in southwest North Dakota and northwest South Dakota. https://swhealthcare.net/ Full Data Download… |
|||||
| Ransomware | JANUS Research Group id7190 View details | IT | |||
|
https://www.janusresearch.com JANUS is a technology innovator and engineering and technical services large business. Founded in 1997 as a virtual training and mission support services company, we have grown over time by forging a reputation for technical excellence, innovation, cost-schedule performance, and customer service. Today, JANUS’ centers of… |
|||||
| Ransomware | Garden Hotel NARITA id7189 View details | Hospitality / Food & Beverage / Tourism | |||
|
【公式】インターナショナルガーデンホテル成田- 成田市 成田空港近くの快適で利便性の高いホテルを予約する【公式】インターナショナルガーデンホテル成田へようこそ, 成田空港近くの快適で利便性の高いホテル. インターネット上で最良の価格で成田市の快適で利便性の高いホテルを予約する【公式】インターナショナルガーデンホテル成田- 成田市 成田空港近くの快適で利便性の高いホテルを予約するhttps://gardennarita.com/Narita is a comfortable and tranquil city with a interesting history. Conveniently located for sightseeing spots such as Naritasan Shinshoji temple and close to Narita International Airport. This is an ideal location for business meetings and… |
|||||
| Ransomware | Montgomery General Hospital id7188 View details | Healthcare / Pharma | |||
|
Montgomery General HospitalIt provides the patient the opportunity to access their health information securely, confidentially and at their convenience.Montgomery General HospitalMontgomery General Hospitalhttps://mghwv.com/Here at Montgomery General Hospital, we understand that healthcare is evolving. The advances in medicine and strides in technology are providing local communities access… |
|||||
| Ransomware | Nabtesco Motion Control id7187 View details | Communication / Marketing | |||
|
High Precision Cycloidal Gear Manufacturer - NabtescoNabtesco manufactures cycloidal gearboxs and provides high performance reduction gears, hollow shaft gear heads and single axis servo-actuators and controllers.Nabtescohttps://www.nabtescomotioncontrol.com/ Nabtesco is the largest precision Cycloidal gearbox manufacturer in the world and leads the precision gear industry by providing High… |
|||||
| Ransomware | UnitedLex.com id7186 View details | Services | |||
|
Moving legal to the future. From routine litigation and IP matters to operational redesign, our modern solutions are built to scale, remove friction, and create competitive advantage. Get in Touch Litigation & Investigations Multi-platform by design, our comprehensive litigation support and investigations services are designed to take on the most… |
|||||
| Ransomware | The Travel Network Group id7185 View details | Telecommunications | |||
|
The Travel Network Group is the largest in Europe network of commercial businesses that operate in the independent travel market. This network has been hacked and over 1500GB of sensitive data were stolen from company's file servers, including: financial data (budgets, payments, taxes, etc)membership's data (personal details, address, contacts,… |
|||||
| Ransomware | Jacklyn Dawson Solicitors id7184 View details | Finance / Legal / Insurance | |||
|
Jacklyn Dawson Solicitors is a UK based solicitors and lawyers company which is providing legal services for business and individuals. This network has been hacked and over 400GB of sensitive data were stolen from company's file servers, including: financial data (budgets, bank accounts, taxes, etc)client's data (personal details, address,… |
|||||
| Ransomware | Peroni Pompe id7183 View details | Communication / Marketing | |||
|
Since the 1950s, Peroni has focused its activities on the design and production of oscillating process pumps, meeting the application needs of its customers with tailor-made solutions. The full package of yours data will be uploaded within 30 day. You must contacts us as soon as possible for preventing the… |
|||||
| Ransomware | Health Care Solutions Group id4268 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Evo exhibits id4256 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Monarchnc id4067 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Enso Detego id4010 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sando id4009 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CMZ UK id4008 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | PlanET Biogas Solutions id4007 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sheppard Robson id4006 View details | Other | — | ||
|
No additional victim description available. |
|||||