arkana
First seen March 25, 2025Active6 claimed victims
The claims below are reproduced as posted by arkana on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband provider WideOpenWest (WOW!), operating a three-phase ransom/sale/leak extortion model primarily focused on telecom and internet service providers.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Ticketmaster | June 6, 2025 | ransomware_live | — |
| Synopsys | June 4, 2025 | ransomware_live | — |
| Infinox | May 28, 2025 | ransomware_live | — |
| Anglo American plc | May 21, 2025 | ransomware_live | — |
| Oregon Surveillance Network - OSN! | March 26, 2025 | ransomware_live | — |
| Wide Open West - WOW! | March 24, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).