arcusmedia
First seen May 15, 2024Active109 claimed victims
The claims below are reproduced as posted by arcusmedia on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA-2048 encryption and recruiting affiliates via a referral-based vetting process, claiming 50+ victims across manufacturing, healthcare, retail, and business services globally.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| RIO TECHNOLOGY | May 16, 2024 | ransomware_live | — |
| Grupo SASMET | May 11, 2024 | ransomware_live | — |
| GOLD RH S.A.S | May 11, 2024 | ransomware_live | — |
| Frigrífico Boa Carne | May 11, 2024 | ransomware_live | — |
| Cusat | May 11, 2024 | ransomware_live | — |
| FILSCAP | May 11, 2024 | ransomware_live | — |
| Thibabem Atacadista | May 11, 2024 | ransomware_live | — |
| Braz Assessoria Contábil | May 11, 2024 | ransomware_live | — |
| BRAZIL GOV | May 8, 2024 | ransomware_live | — |
← NewerPage 2 of 2
Claim data from ransomware.live and RansomLook (CC BY 4.0).