Ransomware dossier

Royal

A direct Conti successor that later rebranded as BlackSuit. Big-game hunting across critical sectors.

Claimed victims

192

Top region

—

Top sector

—

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2023-07-19http://www.braintreema.gov——
2023-06-11http://www.tachi-s.com——
2023-06-09http://www.penncrest.org——
2023-05-26http://www.colrich.com——
2023-05-26http://www.haworthtompkins.com——
2023-05-26http://www.co-pack.co.uk——
2023-05-26http://www.sovitrat.fr——
2023-05-26http://www.bmprecision.com——
2023-05-26http://www.directviz.com——
2023-05-26http://www.thebestconnection.co.uk——

Suspected origin

Russia — Conti successor; Russian-speaking. Attribution reflects open-source consensus, not certainty.

Suspected affiliates & lineage

Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups