Blacklocks, a newly emerged ransomware group with three claimed victims
A previously undocumented actor known as Blacklocks opened its leak site on 6 September 2026 and has since posted three claimed victims in South Korea and South Africa. Its lack of known history calls for caution and for tightening basic security controls.
What happened
On 6 September 2026, the leak site of a group calling itself Blacklocks (also referred to as blacklocks) appeared online for the first time. Since then, according to the tracking platform RansomLook, the group has made three posts naming alleged victims.
The organisations named by the group itself are an automotive company in South Korea (posted on 6 September 2026) and two South African firms: one in transportation and logistics (23 September) and one in construction (26 September).
It is worth stressing that a leak-site post is a claim made by the attacker, not a verified fact. None of the three entries currently has independent confirmation regarding the scope of the incident, the volume of information involved or any financial demands.
Who the group is
As of today, Blacklocks is an almost unknown actor. It does not appear in the main public threat databases, such as MISP Galaxy or MITRE ATT&CK, and no identifiable relationship has been established with already documented ransomware families. There is also no reliable public information about its initial access vectors, tooling or operating model.
With only 24 days of visible activity and three claims, it is too early to tell whether this is a new brand run by experienced operators, an offshoot of another affiliate programme, or a short-lived outfit. The geographic and sector spread of the claimed victims suggests, tentatively, opportunistic targeting rather than a campaign aimed at one specific industry.
What organisations can do
Since no techniques specific to this actor are known, the sensible response is to strengthen the controls that block the usual ransomware entry points.
These measures are not specific to Blacklocks: they reduce the impact of any encryption-and-extortion operation, including those run by groups that have yet to be catalogued.
- Enforce multi-factor authentication on VPNs, remote access, email and administration portals.
- Prioritise patching of internet-facing systems and decommission services that are not needed.
- Keep isolated or immutable backups and regularly test that restoration actually works.
- Segment the network and limit the number of accounts with domain administration privileges.
- Monitor for unusual data exfiltration and maintain endpoint detection with 24/7 response.
- Prepare and rehearse an incident response plan covering communications, legal matters and notification to the data protection authority.
About the group: Blacklocks
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.