Ransomware Group intelligence
Ransomexx
ActiveTrack Ransomexx with 85 published victims and 1 known leak locations in a single intelligence view.
Overview
Ransomexx is tracked by Breach House as a ransomware group with 85 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Unknown | rnsm777cdsjrsdlbs4v5qoeppu3px6sb2igmh53jzrx7ipcrbjz5b2ad.onion |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (85)
Search, filter and paginate the victim timeline for Ransomexx.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | SOGO Auction id28281 View details | Retail / E-commerce | |||
|
SOGO Auction - 951MB leaked. SOGO Auction is a prominent Japan-based, specialized auctioneer with over 30 years of experience in trading used construction machinery and heavy equipment. Operating since the 1990s, they provide both on-site and online, high-volume auctions for items like excavators and bulldozers. It is operated by SOGO Corporation. |
|||||
| Ransomware | GoTip id28266 View details | Hospitality / Food & Beverage / Tourism | |||
|
GoTip - 1.13GB leaked. Gotip.jp is a Japanese live-streaming enhancement tool that connects digital tips (donations) to physical Bluetooth-enabled devices. It allows viewers to support creators by sending tips, which in turn trigger actions on devices owned by the creator, aimed at making live streams more interactive and engaging. |
|||||
| Ransomware | ADDA (adda.io) id18245 View details | India | Services | ||
|
ADDA is SaaS for Residential Community Management. 12 millions residents, visitors and stuff records leaked. |
|||||
| Ransomware | Grupo Vargas id18173 View details | Venezuela, Bolivarian Republic of | Healthcare / Pharma | ||
|
Laboratorios Vargas stands out in the pharmaceutical sector, not just for its longevity but also through continuous innovation and dedication toward creating high-quality medications tailored to meet diverse healthcare needs. Leak size: 37.6GB. |
|||||
| Ransomware | Lakeshore Title Agency id18172 View details | United States | Communication / Marketing | ||
|
Lakeshore Title Agency has closed over $100 million in commercial transactions and over $700 million in residential refinances and purchases. Leak size: 341GB. |
|||||
| Ransomware | Makesworth Accountants id18171 View details | United Kingdom | Communication / Marketing | ||
|
Makesworth Accountants is multi-award-winning accountancy practice of a chartered accountant, tax and business advisers. Leak size: 176.4GB. |
|||||
| Ransomware | Retemex id14289 View details | Mexico | Telecommunications | ||
|
Retemex is a virtual mobile operator in Mexico, operating on the country’s 4.5G LTE network. 24883 clients data even with PLAINTEXT PASSWORDS! |
|||||
| Ransomware | Brontoo Technology Solutions id13760 View details | India | IT | ||
|
OstaApp, developed by Brontoo Technology Solutions India Private Limited, is a digital payment platform designed to offer a secure, fast, and convenient way to make transactions without relying on traditional cards, wallets, or point-of-sale (POS) systems. The platform generates a unique, one-time-use digital number or QR code, which users can utilize for payments at registered merchants, partner ATMs, and more. Database with 146123 users leaked. Proof of PCI DSS compliance is not a guaranteed solution. |
|||||
| Ransomware | nursing.com id13682 View details | Healthcare / Pharma | |||
|
NURSING.com is an all-in-one online platform designed to help nursing students succeed in their studies and pass the NCLEX® exam with confidence. It provides a variety of resources, including video lessons, practice questions, cheat sheets, and custom study plans tailored to individual learning needs. The platform is particularly beneficial for visual learners, students with ADHD, dyslexia, and those who experience anxiety. Database dump, 568221 users. |
|||||
| Ransomware | Planet Group International id13573 View details | United States | Services | ||
|
Planet Group International is a multinational corporation specializing in innovative technology solutions and consulting services. With a presence in numerous countries, the company focuses on digital transformation, IT infrastructure, software development, and data analytics. They cater to a diverse range of industries, providing tailored solutions to enhance operational efficiency and drive business growth. Planet Group International is known for its commitment to excellence, leveraging cutting-edge technologies to deliver high-quality services and support to its global clientele. Leaked data size: 4.9GB. |
|||||
| Ransomware | LITEON id13572 View details | Taiwan, Province of China | IT | ||
|
LITEON Technology Corporation, based in Taiwan, is a leading company in the electronics industry known for its diverse range of products. Founded in 1975, LITEON specializes in the development and manufacturing of optoelectronics, storage devices, and other electronic components. Its products include LED lighting solutions, semiconductors, automotive electronics, and smart healthcare devices. LITEON is recognized for its innovation and commitment to sustainability, providing high-quality technology solutions to global customers while emphasizing environmental responsibility. Leaked data size: 142GB. |
|||||
| Ransomware | Wagner-Meinert id13331 View details | Manufacturing / Engineering | |||
|
Wagner-Meinert is a company that specializes in industrial refrigeration, food process systems, and mechanical contracting. They provide services such as design, installation, maintenance, and compliance support for industrial and commercial refrigeration systems. Their expertise often spans areas including ammonia refrigeration systems, food processing equipment, HVAC systems, and related industrial solutions. Leaked data size: 685.3GB. |
|||||
| Ransomware | United Carton Industries Company id12099 View details | Saudi Arabia | Communication / Marketing | ||
|
United Carton Industries Company (UCIC) is a leading packaging solutions provider based in Saudi Arabia Leaked data size: 26.37GB. |
|||||
| Ransomware | Ruwac Industrial Vacuums id12098 View details | United States | Manufacturing / Engineering | ||
|
Ruwac Industrial Vacuums is a leading manufacturer of industrial vacuum cleaners and vacuum systems designed for specialized cleaning applications in various industries. Leaked data size: 7.79GB. |
|||||
| Ransomware | Diagnostica Stago id12097 View details | France | Other | ||
|
Diagnostica Stago is a global leader in the field of in-vitro diagnostics, specializing in hemostasis and thrombosis.Leaked data size: 423MB. |
|||||
| Ransomware | Bombardier Recreational Products id12096 View details | Canada | Hospitality / Food & Beverage / Tourism | ||
|
Bombardier Recreational Products (BRP) is a Canadian company that designs, manufactures, distributes, and markets motorized recreational vehicles and powersports engines. Leaked data size: 32.5GB. |
|||||
| Ransomware | Consorci Sanitari Integral id12095 View details | Spain | Healthcare / Pharma | ||
|
Consorci Sanitari Integral (CSI) is a healthcare consortium based in Catalonia, Spain Leaked data size: 52.47GB. |
|||||
| Ransomware | Badan Urusan Logistik id12094 View details | Indonesia | Transportation / Travel / Logistics | ||
|
BULOG, or Badan Urusan Logistik, is the state-owned logistics agency of Indonesia Leaked data size: 12.77GB. |
|||||
| Ransomware | Jacobs Farm / Del Cabo id12093 View details | United States | Agriculture / Food | ||
|
Jacobs Farm / Del Cabo is an organic farming company known for its commitment to sustainable agriculture and ethical business practices. Leaked data size: 399GB. |
|||||
| Ransomware | DVision Architecture id12092 View details | Italy | Construction / Real Estate | ||
|
Dvision Architecture is a global architecture and design firm known for its innovative approach to architectural projects. Leaked data size: 110GB. |
|||||
| Ransomware | Telecommunications Services of Trinidad and Tobago id12091 View details | Trinidad and Tobago | Telecommunications | ||
|
Telecommunications Services of Trinidad and Tobago (TSTT) is the primary telecommunications provider in the twin-island nation of Trinidad and Tobago. Leaked data size: 6GB. |
|||||
| Ransomware | Ministry of Defense of Peru id12090 View details | Peru | Public Sector | ||
|
The Peruvian Ministry of Defense (Ministerio de Defensa del Perú) is the government agency responsible for overseeing the defense and security affairs of Peru. Leaked data size: 763.8GB. |
|||||
| Ransomware | Asteco id12089 View details | United Arab Emirates | Construction / Real Estate | ||
|
Asteco is a real estate services firm based in the United Arab Emirates (UAE), with its headquarters in Dubai. It offers a wide range of real estate services including property management, valuation, research, investment consultancy, and sales and leasing brokerage. Asteco has been a prominent player in the UAE’s real estate market for several years, providing services to both individual clients and corporate entities Leaked data size: 11.4GB. |
|||||
| Ransomware | Kenya Airways id10337 View details | Kenya | Transportation / Travel | ||
|
Kenya Airways Ltd., more commonly known as Kenya Airways, is the flag carrier airline of Kenya. The company was founded in 1977, after the dissolution of East African Airways. Its head office is located in Embakasi, Nairobi, with its hub at Jomo Kenyatta International Airport. Accidents, IDs, cases, passports, staff death, etc. |
|||||
| Ransomware | AlJaber Engineering id9714 View details | Qatar | Manufacturing / Engineering | ||
|
AlJaber Engineering (JEC) is a leading general contractor based in the State of Qatar. |
|||||
| Ransomware | Admilla ELAP id9601 View details | Finance / Legal / Insurance | |||
|
Elap (formerly Admilia) offers its expertise and support throughout the implementation of your budget and accounting solution. Huge clients, financial documents, contracts, personal data and a lot of confidential things belongs to their customers. If you wanna be one someday your data will be here. |
|||||
| Ransomware | Telecommunications Services of Trinidad and Tobago (tstt.co.tt) id9244 View details | Trinidad and Tobago | Telecommunications | ||
|
tstt.co.tt and bmobile.co.tt. 4293368 customer's lines, ID scans, gitlab projects, db dumps. |
|||||
| Ransomware | DVA - DVision Architecture id7093 View details | Communication / Marketing | |||
|
Dalla digitalizzazione del progetto alla realizzazione di prototipi costruttivi: l’attività di DVA spazia dal concept di un intervento, all’organizzazione logistica di cantiere. Un approccio declinato secondo il connubio tra digitalizzazione e sostenibilità, orientamento cardine di tutte le scelte della società e rintracciabile in ognuna delle commesse prese in carico. |
|||||
| Ransomware | Jacobs Farm id7014 View details | Agriculture / Food | |||
|
Jacobs Farm was founded in 1980 as a small organic family farm dedicated to growing fresh, high quality, delicious food without damaging the environment. |
|||||
| Ransomware | Bettuzzi And Partners id5562 View details | Communication / Marketing | |||
|
Lo Studio BETTUZZI & PARTNERS - Dottori Commercialisti è stato fondato dal dott. Alvaro Bettuzzi, nell'anno 2005, dopo aver maturato significative esperienze nello svolgimento della professione di dottore commercialista. Oltre al contributo del fondatore, lo Studio si avvale della collaborazione di altri dottori commercialisti, di esperti professionisti in altre discipline, di docenti universitari e di specialisti in varie aree della consulenza, soprattutto in materia legale e fiscale, in ambito sia nazionale che internazionale. |
|||||
| Ransomware | BULOG id5511 View details | Indonesia | Other | ||
|
BULOG adalah perusahaan umum milik negara yang bergerak di bidang logistik pangan. |
|||||
| Ransomware | REC Silicon id4820 View details | Other | |||
|
REC Silicon is a global leader in silane-based, high-purity silicon materials. |
|||||
| Ransomware | Unimed Belem id4363 View details | Communication / Marketing | |||
|
A Unimed é a maior realidade cooperativista na área da saúde em todo o mundo e também a maior rede de assistência médica do Brasil, presente em 83% do território nacional. O Sistema nasceu com a fundação da Unimed Santos (SP) pelo Dr. Edmundo Castilho, em 1967, e hoje é composto por 368 cooperativas médicas, que prestam assistência para mais de 19 milhões de clientes e 73 mil empresas em todo País. Clientes Unimed contam com mais de 110 mil médicos, 3.244 hospitais credenciados, além de pronto-atendimentos, laboratórios, ambulâncias e hospitais próprios e credenciados para garantir qualidade na assistência médica, hospitalar e de diagnóstico complementar oferecidos. |
|||||
| Ransomware | Consorci Sanitari Integral & Geseme id4321 View details | Healthcare / Pharma | |||
|
El Consorci Sanitari Integral (CSI) és un ens públic de serveis sanitaris i socials que neix l'any 2000 assumint els antics hospitals de la Creu Roja en la província de Barcelona. Actualment, el CSI està participat pel Servei Català de la Salut, l'Institut Català de la Salut, l'Ajuntament de l'Hospitalet de Llobregat, l'Ajuntament de Sant Joan Despí, el Consell Comarcal del Baix Llobregat i la Creu Roja. En 2016 en fou nomenat director general Carles Constante i Beitia. |
|||||
| Ransomware | Ferrari id4274 View details | Other | |||
|
Some internal documents, datasheets, repair manuals, etc. |
|||||
| Ransomware | Bombardier Recreational Products (BRP) - SOURCE CODES id4269 View details | Communication / Marketing | |||
|
Here are some codes from BRP's repos. atgk.brp.ApprenticeShopAPI, atgk.brp.ApprenticeShopMobileAppBackend, atgk.brp.Tools.RemoteConnectionManager, BRP - Usine 9 - Tracking, BRP-PP-ALM, EPC, RIM, SAP-BenchStatusMobileApp. |
|||||
| Ransomware | Fundo Nacional de Desenvolvimento da Educação id4075 View details | Brazil | Education | ||
|
The National Fund for Educational Development (FNDE) is a federal agency under the Ministry of Education, responsible for implementing programs nationwide, including the National School Nutrition Program – PNAE, which serves 47 million students throughout the country, offering adequate and safe food in schools. Since its establishment, the FNDE has undergone several changes, which became more intense when the Brazilian government laid the groundwork for the formation of a substantive conception of education that pervades all levels of education and procedures. Thus, the agency was strengthened, especially with regard to the ongoing management of activities, projects and educational programs as a strategy to support the promotion of educational quality. Nowadays, besides the National School Nutrition Program - PNAE, the FNDE is responsible for implementing the Programs of School Transportation, National Textbook, School Direct Money, Brazil Literate, Pro-Youth, Joint Action Plan, Pro-Child, Decentralization and the Open University Credits. |
|||||
| Ransomware | Bombardier Recreational Products (BRP) - BONUS CONTENT (!!!) id4005 View details | Communication / Marketing | |||
|
In addition to previous leak: employees credentials, if you need netflix, battle.net, paypal or pornhub account feel free to use it; employees personal photos/videos; confidential BRP documents from several employees desktops/laptops. Why it's posted separately? They forces us to increase damage of the attack due to their negotiations team. |
|||||
| Ransomware | Bombardier Recreational Products (BRP) id3993 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
BRP Inc. is the holding company for Bombardier Recreational Products Inc., operating as BRP, a Canadian manufacturer of snowmobiles, all-terrain vehicles, side by sides, motorcycles, and personal watercraft. It was founded in 2003, when the Recreational Products Division of Bombardier Inc. was spun-off and sold to a group of investors consisting of Bain Capital, the Bombardier-Beaudoin family and the Caisse de dépôt et placement du Québec. Bombardier Inc., was founded in 1942 as L'Auto-Neige Bombardier Limitée (Bombardier Snowmobile Limited) by Joseph-Armand Bombardier at Valcourt in the Eastern Townships, Quebec. As of October 6, 2009, BRP had about 5,500 employees; its revenues in 2007 were above US$2.5 billion. BRP has manufacturing facilities in five countries: Canada, the United States (Wisconsin, Illinois, North Carolina, Arkansas, Michigan and Minnesota), Mexico, Finland, and Austria. The company's products are sold in more than 100 countries, some of which have their own direct-sales network. BRP's products include the Ski-Doo and Lynx snowmobiles, Can-Am ATVs and Can-Am motorcycles, Sea-Doo personal watercraft, and Rotax engines. The Ski-Doo was ranked 17th place on CBC Television's The Greatest Canadian Invention in 2007. Confidential agreements, NDA's, personal data, passports, etc. |
|||||
| Ransomware | Sonae id3092 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Stago id3009 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Scottish Association for Mental Health id2898 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Viva Air id2831 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | POP TV id2646 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KCA Deutag id2530 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hellmann Worldwide Logistics id2184 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | UMW Group id2158 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ruwac id2070 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Unione dei Comuni Terre di Pianura id1927 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Digicel Group id1704 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Unione Reno Galliera id1466 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | United Carton Industries Company Ltd id1413 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ultrapar Participações S.A. id1150 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Vistra id1149 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Indura SA id1148 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Soluzioni Infrastrutturali Telefoniche ed Elettriche S.p.A. id1147 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CalAmp (NASDAQ: CAMP) id1146 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pertamina EP id1145 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Consiglio Nazionale del Notariato id1144 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ajuntament de Castelló id1143 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Nobiskrug id1142 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Samvardhana Motherson Peguform id1141 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Wallace & Carey id1140 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | STEMCOR id1139 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Universal Assistance S.A. id1138 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | WT Microelectronics id1137 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Walsin id1136 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Corporación Nacional de Telecomunicación id1135 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Liberty Group & ForHousing id1134 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ermenegildo Zegna Holding id1133 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gigabyte Technology id1132 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | American Megatrends International id1131 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gigabyte id670 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Lazio Region in Italy id669 View details | Italy | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Corporación Nacional de Telecomunicación (CNT) id664 View details | Ecuador | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | Mutuelle Nationale des Hospitaliers (MNH) id576 View details | France | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Inchcape id549 View details | Australia | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Brazil’s Superior Tribunal de Justiça (Court System) id518 View details | Brazil | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Société de transport de Montréal (STM) (public transport agency) id500 View details | Canada | Transportation / Travel / Logistics | — | |
|
No additional victim description available. |
|||||
| Ransomware | Tyler Technologies id482 View details | United States | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | IPG Photonics id481 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | SoftServe id471 View details | Ukraine | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | R1 RCM (medical debt collection firm) id452 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Konica Minolta id447 View details | Japan | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Texas Department of Transportation id374 View details | United States | Transportation / Travel / Logistics | — | |
|
No additional victim description available. |
|||||