Black Basta
Conti-linked, Russian-speaking. Internal chat logs leaked in 2026, exposing its targeting, tooling and affiliate structure.
Claimed victims
449
Top region
—
Top sector
—
Suspected origin
Russia
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2025-01-11 | Schuff Steel Company | — | — |
| 2025-01-11 | Granby Industries | — | — |
| 2025-01-11 | Plasma-Therm | — | — |
| 2025-01-11 | Arun Estates | — | — |
| 2025-01-11 | Brachot | — | — |
| 2025-01-11 | Avril Supermarché Santé | — | — |
| 2025-01-11 | Mortgage Investors Group (MIG) | — | — |
| 2025-01-11 | Bnext.nl | — | — |
| 2024-12-18 | Furmano’s | — | — |
| 2024-12-18 | Fruit of the Earth | — | — |
Suspected origin
Russia — Conti successor; Russian-speaking; leaked chats. Attribution reflects open-source consensus, not certainty.
Suspected affiliates & lineage
Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.