Royal
A direct Conti successor that later rebranded as BlackSuit. Big-game hunting across critical sectors.
Claimed victims
192
Top region
—
Top sector
—
Suspected origin
Russia
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2023-07-19 | http://www.braintreema.gov | — | — |
| 2023-06-11 | http://www.tachi-s.com | — | — |
| 2023-06-09 | http://www.penncrest.org | — | — |
| 2023-05-26 | http://www.colrich.com | — | — |
| 2023-05-26 | http://www.haworthtompkins.com | — | — |
| 2023-05-26 | http://www.co-pack.co.uk | — | — |
| 2023-05-26 | http://www.sovitrat.fr | — | — |
| 2023-05-26 | http://www.bmprecision.com | — | — |
| 2023-05-26 | http://www.directviz.com | — | — |
| 2023-05-26 | http://www.thebestconnection.co.uk | — | — |
Suspected origin
Russia — Conti successor; Russian-speaking. Attribution reflects open-source consensus, not certainty.
Suspected affiliates & lineage
Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.