Ransomware dossier

BlackSuit

The rebrand of Royal; same operators, same Conti lineage.

Claimed victims

176

Top region

—

Top sector

—

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2025-06-02http://www.kcac.com——
2025-05-29http://www.innsofaurora.com——
2025-05-29http://metromont.com——
2025-05-15http://www.gloucesterva.gov——
2025-04-24https://www.pacmet.com——
2025-04-24https://fortunesociety.org/——
2025-04-05https://www.mmwec.org——
2025-03-21https://www.orangeville.ca——
2025-02-17https://www.dapope.com/——
2024-12-11http://midwest.com——

Suspected origin

Russia — Royal/Conti lineage; Russian-speaking. Attribution reflects open-source consensus, not certainty.

Suspected affiliates & lineage

Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups