« All threats

Ransomware group

Brain Cipher

Brain Cipher ransomware surfaced in mid-2024, rapidly gaining notoriety after a high-impact attack on Indonesia’s National Data Center, which disrupted over 160 government services including immigration systems. The group operates with a double-extortion model, encrypting data using a LockBit 3.0-based payload (Salsa20/RSA hybrid) and threatening leaks via a Tor-hosted portal. Distinct behaviors include encrypting both file contents and filenames, and customizing encrypted file names with appended random extensions. Initial access methods include phishing and purchases from initial-access brokers. Ransom demands have ranged from tens of thousands up to $8 million USD, though victims have sometimes been offered decryption keys without payment. Victims span sectors such as government, healthcare, education, media, and manufacturing across Southeast Asia, Europe, and the Americas.

Victims in the last 90 days23

Most affected countries

  1. United States3
  2. Spain2
  3. Canada1
  4. Netherlands1

Most affected sectors

  1. Other7
  2. Professional services5
  3. Finance & insurance3
  4. Transport & logistics2
  5. Healthcare2
  6. Technology2
  7. Construction1
  8. Education1

Recent victims

OrganisationCountrySectorClaimedStatus
TrailerbridgeUnited StatesTransport & logistics9/29/2026◌ Claimed (unverified)
McCord ClaimsUnited StatesProfessional services9/29/2026◌ Claimed (unverified)
Goriteway—Education9/29/2026◌ Claimed (unverified)
Northeast Rehab—Healthcare9/29/2026◌ Claimed (unverified)
Mulholland—Transport & logistics9/29/2026◌ Claimed (unverified)
Wildman—Other9/29/2026◌ Claimed (unverified)
Maxwell Group—Finance & insurance9/29/2026◌ Claimed (unverified)
Latitude Subroación—Finance & insurance9/29/2026◌ Claimed (unverified)
Gold Star FinancialUnited StatesFinance & insurance9/23/2026◌ Claimed (unverified)
Hoyle Tanner—Professional services9/17/2026◌ Claimed (unverified)
AECOM—Construction9/17/2026◌ Claimed (unverified)
XperaCanadaTechnology9/17/2026◌ Claimed (unverified)
Ahadandco—Other8/31/2026◌ Claimed (unverified)
Sago—Other8/31/2026◌ Claimed (unverified)
CR Meyer—Other8/31/2026◌ Claimed (unverified)
CCS Perfusion—Healthcare8/31/2026◌ Claimed (unverified)
ICOTSpainTechnology8/31/2026◌ Claimed (unverified)
AEI Consultants—Professional services8/31/2026◌ Claimed (unverified)
SYCSpainProfessional services8/31/2026◌ Claimed (unverified)
Adviesbureau De Beuckelaer BVNetherlandsProfessional services8/31/2026◌ Claimed (unverified)
Windiam—Other7/22/2026◌ Claimed (unverified)
robroy—Other7/9/2026◌ Claimed (unverified)
IAC International—Other7/9/2026◌ Claimed (unverified)

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.