Active threats
Organisations claimed as victims on ransomware groups' leak sites, classified by country and sector, and cross-checked with press coverage.
Claimed victims14
In United States14
Confirmed by press0
Most active groups
Most affected countries
Most affected sectors
Recent victims
| Organisation | Group | Country | Sector | Claimed | Status |
|---|---|---|---|---|---|
| Aware Inc | The Gentlemen | United States | Technology | 9/30/2026 | ◌ Claimed (unverified) |
| Midwest Business Technology | 3am | United States | Technology | 9/28/2026 | ◌ Claimed (unverified) |
| Cipher Systems | M3rx | United States | Technology | 9/26/2026 | ◌ Claimed (unverified) |
| Visual Intelligence Inc | Metaencryptor | United States | Technology | 9/26/2026 | ◌ Claimed (unverified) |
| Flex Ltd | Metaencryptor | United States | Technology | 9/26/2026 | ◌ Claimed (unverified) |
| Bruker Corporation | Metaencryptor | United States | Technology | 9/26/2026 | ◌ Claimed (unverified) |
| ANYTHINGIT | Spirals | United States | Technology | 9/18/2026 | ◌ Claimed (unverified) |
| Accela | Endzone | United States | Technology | 9/18/2026 | ◌ Claimed (unverified) |
| INDiC Electronic Solutions | The Gentlemen | United States | Technology | 9/14/2026 | ◌ Claimed (unverified) |
| CreateASoft | Akira | United States | Technology | 9/8/2026 | ◌ Claimed (unverified) |
| Benshaw, Inc. | Aurora | United States | Technology | 9/7/2026 | ◌ Claimed (unverified) |
| Metrea LLC | Aurora | United States | Technology | 9/5/2026 | ◌ Claimed (unverified) |
| Wolfram Research | Direwolf | United States | Technology | 9/4/2026 | ◌ Claimed (unverified) |
| NeoGen Corporation | ShinyHunters | United States | Technology | 9/3/2026 | ◌ Claimed (unverified) |
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.