Ransomware dossier

BianLian

Shifted to pure data-extortion — steal and threaten to leak, no encryption — which removes the backup defence. Subject of a joint CISA/FBI advisory.

Claimed victims

604

Top region

—

Top sector

—

Suspected origin

Unattributed

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2025-03-31CMC Technology Group——
2025-03-31Meridian Senior——
2025-03-31Saunders and Saunders——
2025-03-31Sonrisas Dental Health——
2025-03-23Goshen Medical Center——
2025-03-07Allworx——
2025-03-07Island Realty——
2025-03-07Minnesota Orthodontics——
2025-03-04Keystone Pacific Property Management LLC——
2025-03-04Layfield and Borel CPA's L.L.C——

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups