Active threats

Organisations claimed as victims on ransomware groups' leak sites, classified by country and sector, and cross-checked with press coverage.

Claimed victims14
In United States14
Confirmed by press0

Most active groups

  1. Metaencryptor3
  2. The Gentlemen2
  3. Aurora2
  4. 3am1
  5. Spirals1
  6. Endzone1
  7. Akira1
  8. Direwolf1
  9. ShinyHunters1
  10. M3rx1

Most affected countries

  1. United States14
  2. Germany5
  3. Brazil5
  4. Canada4
  5. Japan4
  6. India4
  7. Portugal2
  8. Switzerland2
  9. Ireland2
  10. China1

Most affected sectors

  1. Healthcare38
  2. Manufacturing28
  3. Construction21
  4. Legal20
  5. Professional services20
  6. Finance & insurance18
  7. Technology14
  8. Retail11
  9. Government9
  10. Education9

Recent victims

OrganisationGroupCountrySectorClaimedStatus
Aware IncThe GentlemenUnited StatesTechnology9/30/2026◌ Claimed (unverified)
Midwest Business Technology3amUnited StatesTechnology9/28/2026◌ Claimed (unverified)
Cipher SystemsM3rxUnited StatesTechnology9/26/2026◌ Claimed (unverified)
Visual Intelligence IncMetaencryptorUnited StatesTechnology9/26/2026◌ Claimed (unverified)
Flex LtdMetaencryptorUnited StatesTechnology9/26/2026◌ Claimed (unverified)
Bruker CorporationMetaencryptorUnited StatesTechnology9/26/2026◌ Claimed (unverified)
ANYTHINGITSpiralsUnited StatesTechnology9/18/2026◌ Claimed (unverified)
AccelaEndzoneUnited StatesTechnology9/18/2026◌ Claimed (unverified)
INDiC Electronic SolutionsThe GentlemenUnited StatesTechnology9/14/2026◌ Claimed (unverified)
CreateASoftAkiraUnited StatesTechnology9/8/2026◌ Claimed (unverified)
Benshaw, Inc.AuroraUnited StatesTechnology9/7/2026◌ Claimed (unverified)
Metrea LLCAuroraUnited StatesTechnology9/5/2026◌ Claimed (unverified)
Wolfram ResearchDirewolfUnited StatesTechnology9/4/2026◌ Claimed (unverified)
NeoGen CorporationShinyHuntersUnited StatesTechnology9/3/2026◌ Claimed (unverified)

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.