Ransomware dossier

Hive

A major RaaS taken down by the FBI/Europol in January 2023 after the Bureau infiltrated it and handed out decryptors. Its operators are assessed to have reconstituted as Hunters International.

Claimed victims

206

Top region

—

Top sector

—

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2023-01-16R C Stevens Construction——
2023-01-11G.W. Becker——
2023-01-06Consulate Health Care——
2022-12-31Centro Médico Virgen De La Caridad——
2022-12-30Camst Group——
2022-12-22MHMR Authority Of Brazos Valley——
2022-12-21Alvaria——
2022-12-21Interface——
2022-12-20Innovative Education Management——
2022-12-20Dixons Allerton Academy——

Suspected origin

Russia — Russian-speaking RaaS. Attribution reflects open-source consensus, not certainty.

Suspected affiliates & lineage

Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups