Ransomware dossier

BlackCat / ALPHV

Rust-based RaaS behind the Change Healthcare attack. “Exit-scammed” its own affiliates in 2024, scattering talent across RansomHub and others. Lineage traces to DarkSide/BlackMatter.

Claimed victims

756

Top region

—

Top sector

—

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2024-03-03ipmaltamira——
2024-03-03Ewig Usa——
2024-03-02Petrus Resources Ltd.——
2024-03-02SBM & Co [You have 48 hours. Check your e-mail]——
2024-03-01Kumagai Gumi Group——
2024-02-29Allan Berger & Associates——
2024-02-28Change Healthcare - Optum - UnitedHealth——
2024-02-27verbraucherzentrale hessen——
2024-02-27Electro Marteix——
2024-02-26Angeles Medical Centers——

Suspected origin

Russia — Russian-speaking RaaS. Attribution reflects open-source consensus, not certainty.

Suspected affiliates & lineage

Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups