BlackCat / ALPHV
Rust-based RaaS behind the Change Healthcare attack. “Exit-scammed” its own affiliates in 2024, scattering talent across RansomHub and others. Lineage traces to DarkSide/BlackMatter.
Claimed victims
756
Top region
—
Top sector
—
Suspected origin
Russia
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2024-03-03 | ipmaltamira | — | — |
| 2024-03-03 | Ewig Usa | — | — |
| 2024-03-02 | Petrus Resources Ltd. | — | — |
| 2024-03-02 | SBM & Co [You have 48 hours. Check your e-mail] | — | — |
| 2024-03-01 | Kumagai Gumi Group | — | — |
| 2024-02-29 | Allan Berger & Associates | — | — |
| 2024-02-28 | Change Healthcare - Optum - UnitedHealth | — | — |
| 2024-02-27 | verbraucherzentrale hessen | — | — |
| 2024-02-27 | Electro Marteix | — | — |
| 2024-02-26 | Angeles Medical Centers | — | — |
Suspected origin
Russia — Russian-speaking RaaS. Attribution reflects open-source consensus, not certainty.
Suspected affiliates & lineage
Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.