« All news

New threat group

Zawoo: newly emerged ransomware group with victims heavily concentrated in Germany

A previously unknown actor calling itself Zawoo began publishing victims on 29 August 2026 and has now listed 26 posts on its leak site. Most of the named organisations are European SMEs, with a clear German majority.

What happened

On 29 August 2026 a group operating under the name Zawoo appeared for the first time on the digital extortion scene. According to RansomLook tracking, the actor has accumulated 26 posts on its leak site since that date, representing just over a month of known activity.

It is important to stress that these posts are claims made by the group itself, not independently verified facts. Based on the available information, none of the listed organisations has publicly confirmed the real scope of an incident or the authenticity of the data the group says it holds.

Who the group is

Zawoo does not appear in reference repositories such as MISP Galaxy or MITRE ATT&CK, and no links to known ransomware families or evidence of earlier activity under a different name have been identified. In practice, this is an actor with no public track record: its initial access vectors, tooling and whether it encrypts systems or relies purely on data-theft extortion remain unknown.

The victim profile does offer clues. Germany dominates, followed to a lesser extent by Austria, the Czech Republic, Canada, Brazil and the United States. By sector, industrial manufacturing, technology, construction, professional services, real estate, hospitality and non-profit entities stand out. These are mostly small and medium-sized organisations, a typical target set for new groups seeking volume and victims with less mature defences.

What organisations can do

Faced with an actor whose tactics are undocumented, the sensible response is to reinforce the fundamentals that work against most extortion campaigns:

Our recommendation

If your organisation operates in Germany or within the European industrial supply chain, now is a good moment to review remote access and the state of your backups. We will continue monitoring Zawoo and will update this advisory if incidents are confirmed or its techniques become documented.

About the group: Zawoo

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.