Cactus
Exploits VPN appliances for initial access and self-encrypts its own payload to evade detection.
Claimed victims
373
Top region
—
Top sector
—
Suspected origin
Unattributed
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2025-03-17 | urban1.com\$460.3M\USA\2.5TB\100% DISCLOSED | — | — |
| 2025-03-17 | rocketstores.com\$738.9M\USA\3.2TB\100% DISCLOSED | — | — |
| 2025-03-17 | tempel.com\$628.7M\USA\111GB\100% DISCLOSED | — | — |
| 2025-03-17 | thermoid.com\$183.2M\USA\199GB\100% DISCLOSED | — | — |
| 2025-03-17 | baillie.com\$130.5M\USA\52GB\100% DISCLOSED | — | — |
| 2025-03-17 | assaabloy.com\$14.4B\Sweden\229GB\<1% DISCLOSED | — | — |
| 2025-03-17 | kyb.com\$600.5M\USA\1.8TB\<1% DISCLOSED | — | — |
| 2025-03-17 | bluedge.com\$104.5M\USA\994GB\100% DISCLOSED | — | — |
| 2025-03-13 | chfindustries.com\$253.8M\USA\2.5TB\100% DISCLOSED | — | — |
| 2025-03-12 | tempel.com\$628.7M\USA\111GB\<1% DISCLOSED | — | — |
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.