Active threats

Organisations claimed as victims on ransomware groups' leak sites, classified by country and sector, and cross-checked with press coverage.

Claimed victims7
In United States20
Confirmed by press0

Most active groups

  1. Zawoo2
  2. Rhysida1
  3. The Gentlemen1
  4. Qilin1
  5. Lamashtu1
  6. 3am1

Most affected countries

  1. United States20
  2. France7
  3. Germany4
  4. Spain3
  5. Netherlands2
  6. Italy2
  7. China1
  8. Australia1
  9. Finland1
  10. Brazil1

Most affected sectors

  1. Professional services7
  2. Other3
  3. Manufacturing3
  4. Finance & insurance1
  5. Government1
  6. Healthcare1
  7. Media & entertainment1
  8. Non-profit1
  9. Pharma & chemicals1
  10. Real estate1

Recent victims

OrganisationGroupCountrySectorClaimedStatus
FIDUCIALLamashtuFranceProfessional services9/30/2026◌ Claimed (unverified)
EuroprimThe GentlemenFranceProfessional services9/29/2026◌ Claimed (unverified)
BHN Expertise3amFranceProfessional services9/28/2026◌ Claimed (unverified)
AgilianceZawooFranceProfessional services9/24/2026◌ Claimed (unverified)
FRANCARE IndustriesZawooFranceProfessional services9/24/2026◌ Claimed (unverified)
CARIDRO Val de LoireQilinFranceProfessional services9/13/2026◌ Claimed (unverified)
SAD'S InterimRhysidaFranceProfessional services9/8/2026◌ Claimed (unverified)

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.