arvinclub
First seen September 9, 2021Active35 claimed victims
The claims below are reproduced as posted by arvinclub on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Arvin Club is a threat actor with hacktivist leanings that first appeared in May 2021, primarily publishing stolen data via a TOR site and Telegram rather than deploying file-encrypting ransomware, targeting government, education, and banking sectors globally including Iranian government entities.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Islamic Azad University Electronic Campus | October 15, 2023 | ransomware_live | — |
| Jahesh Innovation | October 14, 2023 | ransomware_live | — |
| Kimia Tadbir Kiyan | October 13, 2023 | ransomware_live | — |
| Islamic Azad University of Shiraz | October 8, 2023 | ransomware_live | — |
| Pasouk biological company | October 2, 2023 | ransomware_live | — |
| Shirin Travel Agency | October 1, 2023 | ransomware_live | — |
| Aban Tether & OK exchange | September 2, 2023 | ransomware_live | — |
| sti company | August 23, 2023 | ransomware_live | — |
| Sabalan Azmayesh | August 8, 2023 | ransomware_live | — |
| Parsian Bitumen | August 7, 2023 | ransomware_live | — |
| Draje food industrial group | August 5, 2023 | ransomware_live | — |
| seaside-kish co | August 4, 2023 | ransomware_live | — |
| Padena Factory | July 29, 2023 | ransomware_live | — |
| 150k sib360 Database | July 27, 2023 | ransomware_live | — |
| Haraz dairy | July 22, 2023 | ransomware_live | — |
| hamyari Shahrdari golestan | July 20, 2023 | ransomware_live | — |
| AFTA Isfahan | July 18, 2023 | ransomware_live | — |
| Bitimen | July 9, 2023 | ransomware_live | — |
| Al Bijjar | April 21, 2022 | ransomware_live | — |
| AM International | April 20, 2022 | ransomware_live | — |
| stormous | March 20, 2022 | ransomware_live | — |
| bedfordshire.police.uk | March 12, 2022 | ransomware_live | — |
| afcx.co | November 28, 2021 | ransomware_live | — |
| vidisha.kvs.ac.in | October 24, 2021 | ransomware_live | — |
| Revil | October 22, 2021 | ransomware_live | — |
| Bureau van Dijk(bvdinfo.com) | September 20, 2021 | ransomware_live | — |
| Compilation of Many Breaches (COMB) | September 10, 2021 | ransomware_live | — |
| elitemate.com | September 9, 2021 | ransomware_live | — |
| T-Mobile | September 9, 2021 | ransomware_live | — |
| Leiden University Hacked | September 9, 2021 | ransomware_live | — |
| UtAir | September 9, 2021 | ransomware_live | — |
| Beh Pardakht Mellat Cards | September 9, 2021 | ransomware_live | — |
| Etoudplus.ir | September 9, 2021 | ransomware_live | — |
| 33M Bank Mellat – Iran | September 9, 2021 | ransomware_live | — |
| CardPayPortal | September 9, 2021 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).