BlackSuit
The rebrand of Royal; same operators, same Conti lineage.
Claimed victims
176
Top region
—
Top sector
—
Suspected origin
Russia
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2025-06-02 | http://www.kcac.com | — | — |
| 2025-05-29 | http://www.innsofaurora.com | — | — |
| 2025-05-29 | http://metromont.com | — | — |
| 2025-05-15 | http://www.gloucesterva.gov | — | — |
| 2025-04-24 | https://www.pacmet.com | — | — |
| 2025-04-24 | https://fortunesociety.org/ | — | — |
| 2025-04-05 | https://www.mmwec.org | — | — |
| 2025-03-21 | https://www.orangeville.ca | — | — |
| 2025-02-17 | https://www.dapope.com/ | — | — |
| 2024-12-11 | http://midwest.com | — | — |
Suspected origin
Russia — Royal/Conti lineage; Russian-speaking. Attribution reflects open-source consensus, not certainty.
Suspected affiliates & lineage
Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.