RansomHub
A RaaS that exploded in 2024–25 by recruiting affiliates left stranded when ALPHV/BlackCat and LockBit were disrupted. Aggressive affiliate revenue split and fast victim turnover.
Claimed victims
963
Top region
—
Top sector
—
Suspected origin
Unattributed
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2025-04-01 | europtec.com | — | — |
| 2025-04-01 | delta-life.com | — | — |
| 2025-04-01 | intellioan.com | — | — |
| 2025-04-01 | jackpotjunction.com | — | — |
| 2025-03-30 | www.assisi.nl | — | — |
| 2025-03-28 | www.bassi.it | — | — |
| 2025-03-28 | phaus.us&phakr.com&phabodysystems.com | — | — |
| 2025-03-28 | www.solventacentroamerica.com | — | — |
| 2025-03-27 | www.allmilmoe.com | — | — |
| 2025-03-27 | www.solidworld.it | — | — |
Suspected affiliates & lineage
Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.