Ransomware dossier

Conti / Wizard Spider

The crew behind Conti, Ryuk and the Trickbot botnet. Formally disbanded in 2022 but seeded Black Basta, Royal/BlackSuit and Akira. Operators were sanctioned via the Trickbot designations.

⚠ Sanctioned. OFAC / UK 2023 — Conti operators linked to designated Trickbot members. Paying this group may breach sanctions law — check with legal counsel and law enforcement before any payment is discussed.

Claimed victims

333

Top region

—

Top sector

—

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2022-06-07Alliance Steel——
2022-05-25LCRD——
2022-05-25The Contact Company——
2022-05-24Central Restaurant Products——
2022-05-24Schaumburg Park District——
2022-05-24RateGain——
2022-05-23Imenco AS——
2022-05-23Concepts in Millwork——
2022-05-23Eurofred——
2022-05-23Agile Sourcing Partners——

Suspected origin

Russia — Russian-speaking; leaked internal chats. Attribution reflects open-source consensus, not certainty.

Suspected affiliates & lineage

Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups