ยซ All threats

Ransomware group

Rhysida

Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads. The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development. The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin. After encryption, the ransomware appends the extension ".ryshida" to encrypted files. For encryption purposes, Trend Micro published an analysis stating that the ransomware uses a 4096-bit RSA key and AES-CTR for encryption. In addition to the encryption method, Trend Micro published an analysis of the Ryshida Ransomware attack chain. Finally, the group has a website on the Tor network hosting the companies that have been breached.

Victims in the last 90 days20

Most affected countries

  1. Germany6
  2. United States4
  3. France1
  4. Australia1
  5. Italy1
  6. Philippines1
  7. Hungary1
  8. Colombia1

Most affected sectors

  1. Healthcare4
  2. Government4
  3. Professional services2
  4. Retail2
  5. Technology2
  6. Legal2
  7. Media & entertainment1
  8. Education1

Recent victims

OrganisationCountrySectorClaimedStatus
clicks digital GmbHGermanyTechnology9/30/2026โ—Œ Claimed (unverified)
๐Ÿ”’ Despacho de abogadosโ€”Legal9/30/2026โ—Œ Claimed (unverified)
NEAD ProItalyLegal9/24/2026โ—Œ Claimed (unverified)
LegisColombiaMedia & entertainment9/23/2026โ—Œ Claimed (unverified)
Kreishandwerkerschaft BorkenGermanyProfessional services9/19/2026โ—Œ Claimed (unverified)
MPA Pharma GmbHGermanyPharma & chemicals9/18/2026โ—Œ Claimed (unverified)
Axdia InternationalGermanyTechnology9/12/2026โ—Œ Claimed (unverified)
General Santos Doctors HospitalPhilippinesHealthcare9/10/2026โ—Œ Claimed (unverified)
๐Ÿ”’ Empresa de servicios retailโ€”Retail9/10/2026โ—Œ Claimed (unverified)
SAD'S InterimFranceProfessional services9/8/2026โ—Œ Claimed (unverified)
Rug & HomeUnited StatesRetail9/7/2026โ—Œ Claimed (unverified)
Szechenyi Programiroda Nonprofit KfHungaryGovernment9/1/2026โ—Œ Claimed (unverified)
Berlin, GermanyGermanyGovernment8/28/2026โ—Œ Claimed (unverified)
Valley Health Teamโ€”Healthcare8/28/2026โ—Œ Claimed (unverified)
CRI ElectricUnited StatesConstruction8/22/2026โ—Œ Claimed (unverified)
Fairview Dental Groupโ€”Healthcare8/21/2026โ—Œ Claimed (unverified)
Organismo gubernamental alemรกnGermanyGovernment8/21/2026โ—Œ Claimed (unverified)
Battle Creek Public SchoolsUnited StatesEducation8/21/2026โ—Œ Claimed (unverified)
Pierce TownshipUnited StatesGovernment8/14/2026โ—Œ Claimed (unverified)
SIA Medical CentreAustraliaHealthcare8/13/2026โ—Œ Claimed (unverified)

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CKยฎ, MISP Galaxy, GDELT.