Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Due to abuse of the free use of Ransomware.live, we have updated our Terms & Conditions. Please review them before continuing to use the Data.
Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us
Search v2
before

Prefix a filter with + to require it, or - to exclude it — e.g. +country:us only shows US victims, -country:us hides them. Mix several with free-text words; everything is combined with AND (so hospital +country:us -group:lockbit3 means: text "hospital", country is US, group is not lockbit3). Repeating + on the same field is OR'd together (+country:us +country:ca → US or Canada); repeating - excludes all of them. Wrap multi-word values in quotes, e.g. +sector:"public sector". infostealer, press and multipleclaims take a bare +/- with no value: +infostealer / -infostealer filter on infostealer data, while +press searches press articles only and -press hides press coverage; +multipleclaims restricts to victims claimed by more than one group (cross-referenced) and -multipleclaims keeps only single-claim victims; +campaign:fortibleed / -campaign:fortibleed filter on domains found in the FortiBleed leaked-credential dataset; before:/after: take a date directly with no +/- prefix, as shown below.

+country:only this country — opens a picker
-country:exclude this country — opens a picker
+group:only this group — opens a picker
-group:exclude this group — opens a picker
+website:example.comonly this website
+sector:only this sector — opens a picker
-sector:exclude this sector — opens a picker
+infostealerhas infostealer data
-infostealerno infostealer data
+presssearch press articles only
-presshide press coverage
+multipleclaimsclaimed by more than one group (cross-ref only)
-multipleclaimsclaimed by a single group only
+campaign:fortibleeddomain found in the FortiBleed dataset
-campaign:fortibleeddomain not in the FortiBleed dataset
after:2025-01-01discovered/attacked on or after
before:2026-01-01discovered/attacked on or before
1 victim matched
Logo
Discovered: 2024-02-09 (2y ago)  ·  Attack est.: 2024-02-02
Willis Lease Finance Corporation has been a pioneer and provider of aviation services for over 45 ye…
Press Coverage 1
Willis Lease Finance Corporation (WLFC)
2024-01-31

La Willis Lease Finance Corporation, une entreprise spécialisée dans la location de pièces d'avions, a signalé à la SEC avoir été victime d'une cyberattaque détectée le 31 janvier, dont l'activité non autorisée a été complètement contenue le 2 février, sans que l'entreprise ne puisse encore déterminer l'étendue des données affectées. Le groupe de ransomware Black Basta a revendiqué l'attaque, affirmant avoir dérobé plus de 900 Go de données sensibles et menaçant de les divulguer publiquement. Black Basta est actif depuis avril 2022 et a été lié à plus de 300 infections, avec des demandes de rançon estimées à environ 100 millions de dollars en novembre 2023.

Read article