Ransomware Group intelligence
Toufan
InactiveTrack Toufan with 117 published victims and 6 known leak locations in a single intelligence view.
Overview
Toufan is tracked by Breach House as a ransomware group with 117 published victims.
Israel is currently the most targeted country in this dataset.
6 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (6)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Web location | Unknown | t.me/s/CyberToufanBackup |
| Leak location 2 | Web location | Unknown | t.me/s/CyberToufan |
| Leak location 3 | Web location | Unknown | t.me/CyberToufan |
| Leak location 4 | Web location | Unknown | t.me/CyberToufan02 |
| Leak location 5 | Web location | Unknown | t.me/CyberToufanBackup |
| Leak location 6 | Web location | Unknown | toufanleaks.org |
Top Activity Sectors
No sector intelligence available.
Ransom Notes (0)
▼No ransom notes available for this group.
Tools Used
▼No tools used available.
YARA Rules (0)
▼No YARA rules available.
Indicators of Compromise (0)
▼No IoCs available for this group.
Negotiation Chats (0)
▼No negotiation chats available.
Research Sources
No external research sources linked yet.
Victims (117)
Search, filter and paginate the victim timeline for Toufan.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ecom.gov.il id10307 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | maytronics.com id10306 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | carolinalemke.com id10301 View details | Germany | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | ari.co.il id10300 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | allot.com id10279 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | bconnect.co.il id10273 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | super-pharm.co.il id10272 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | teldor.com id10261 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | erco.co.il id10260 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | tefentech.com id10230 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | zoko.co.il id10229 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | strauss-group.com id10188 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.pts-tools.com id10184 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.plasson-pead.com.br id10183 View details | Brazil | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | www.nistx.com id10182 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.ktstooling.com id10181 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.herrickindustrial.com id10180 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.drillmex.com id10179 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.dixie-tool.com id10178 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.copreinternacional.com id10177 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.butlerbros.com id10176 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.atwoodindustries.com id10175 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | wsies.com id10174 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | vehicle.touch-ins.co.il id10173 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | tryhardindustrial.ca id10172 View details | Canada | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||
| Ransomware | sys.udidagan.co.il id10171 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | sys.touch-ins.co.il id10170 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | sys-cspartnershq1.caesarstone.com id10169 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | sys-cspartners.caesarstoneus.com id10168 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | sys-cspartners.caesarstone.sg id10167 View details | Singapore | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | sys-cspartners.caesarstone.co.uk id10166 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | sys-cspartners.caesarstone.com.au id10165 View details | Australia | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | sys-cspartners.caesarstone.ca id10164 View details | Canada | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | sys.biopet.co.il id10163 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | store.toolneeds.com id10162 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | store.brunswickindustrial.com id10161 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | stage.kravitz.co.il id10160 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | shop.smithindustrialsupply.com id10159 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | shop.shopsupply.net id10158 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | shop.reggiemckenzieindustrial.com id10157 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | shop.qct.tools id10156 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | shop.lgindustrial.com id10155 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | shop.emprecise.com id10154 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | shop.clador.com id10153 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | shop.britecon.com id10152 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | shefa-online.co.il id10151 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | selwayindustrialsupply.com id10150 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | rocket-supply.com id10149 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | rmpis.com id10148 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | reserved-il.com id10147 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | pts-tools.com id10146 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | product.touch-ins.co.il id10145 View details | Israel | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | pmt-usa.com id10144 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | phoenix.touch-ins.co.il id10143 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | pet.touch-ins.co.il id10142 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | pet.biopet.co.il id10141 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | paragon-supply.com id10140 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | old.shefa-online.co.il id10139 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | norviktools.com id10138 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | northernprecisionsales.com id10137 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | newstore.johnstoncompanies.com id10136 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | mortgage.touch-ins.co.il id10135 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | morsecuttingtools.com id10134 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | mitchellmckinney.com id10133 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | mgisales.com id10132 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | m.biopet.co.il id10131 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | libertytool.com id10130 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ktstooling.com id10129 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | knightesupply.com id10128 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | keter.com id10127 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | keter.co.il id10126 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | its-supply.com id10125 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | h-o.co.il id10124 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | goronco.com id10123 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | gordonindustrial.com id10122 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | global.keter.com id10121 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | giddirect.com id10120 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | gfwdsupply.com id10119 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | fugatesales.com id10118 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | drillmex.com id10117 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | dixie-tool.com id10116 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | dctsupply.com id10115 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | cspartnershq1.caesarstone.com id10114 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | cspartners.caesarstoneus.com id10113 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | cspartners.caesarstone.sg id10112 View details | Singapore | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | cspartners.caesarstone.co.uk id10111 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | cspartners.caesarstone.com.au id10110 View details | Australia | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | cspartners.caesarstone.ca id10109 View details | Canada | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | core.touch-ins.co.il id10108 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | copreinternacional.com id10107 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | colmarindustrial.com id10106 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | cmtindustrial.com id10105 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | cdt1.com id10104 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | catalog.ustg.net id10103 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | catalog.toolkrib.com id10102 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | catalog.fotcnc.com id10101 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | cartersoshkosh.co.il id10100 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | butlerbros.com id10099 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | blueashsupply.com id10098 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | berkshireesupply.com id10097 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | barindustrial.com id10096 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | badgermill.com id10095 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | atwoodindustries.com id10094 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | arieladar.com id10093 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | api.touch-ins.co.il id10092 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | apisinc.com id10091 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | amtektool.com id10090 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | alleghenytool.net id10089 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | alcornindustrial.com id10088 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ustg.net id10087 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | naandanjain.com id10072 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ta-Supply.com id10070 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | techno-rezef.com id10065 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | curver.com id10064 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | dorot.com id10063 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | graf.co.il id10062 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | brother.co.il id10061 View details | Israel | Other | — | |
|
No additional victim description available. |
|||||