Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us
Search v2
before

Prefix a filter with + to require it, or - to exclude it — e.g. +country:us only shows US victims, -country:us hides them. Mix several with free-text words; everything is combined with AND (so hospital +country:us -group:lockbit3 means: text "hospital", country is US, group is not lockbit3). Repeating + on the same field is OR'd together (+country:us +country:ca → US or Canada); repeating - excludes all of them. Wrap multi-word values in quotes, e.g. +sector:"public sector". infostealer and press take a bare +/- with no value: +infostealer / -infostealer filter on infostealer data, while +press searches press articles only and -press hides press coverage; +campaign:fortibleed / -campaign:fortibleed filter on domains found in the FortiBleed leaked-credential dataset; before:/after: take a date directly with no +/- prefix, as shown below.

+country:only this country — opens a picker
-country:exclude this country — opens a picker
+group:only this group — opens a picker
-group:exclude this group — opens a picker
+website:example.comonly this website
+sector:only this sector — opens a picker
-sector:exclude this sector — opens a picker
+infostealerhas infostealer data
-infostealerno infostealer data
+presssearch press articles only
-presshide press coverage
+campaign:fortibleeddomain found in the FortiBleed dataset
-campaign:fortibleeddomain not in the FortiBleed dataset
after:2025-01-01discovered/attacked on or after
before:2026-01-01discovered/attacked on or before
1 victim matched
Logo
Discovered: 2026-07-25 (9d ago)
customers' personal data, contract information, internal company data: http://[REDACTED].onion/s/7f…
Press Coverage 1
MSGás
2026-07-05

La MSGás, compagnie de gaz de l'État de Mato Grosso do Sul, a notifié ses clients d'un incident de cybersécurité. Un attaque par ransomware a potentiellement exposé des données personnelles telles que le nom, le CPF et l'adresse. La compagnie a pris des mesures pour isoler les systèmes, révoquer les accès et a notifié l'ANPD (Autorité Nationale de Protection des Données). Elle recommande aux clients de rester vigilants face aux fraudes et aux tentatives d'ingénierie sociale. L'attaque a été revendiquée le 25 juillet par Blackwater.

Read article