benzona
First seen November 26, 2025Active14 claimed victims
The claims below are reproduced as posted by benzona on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| casamedica.com.gt | January 30, 2026 | ransomware_live | — |
| *a*ame*i*a.com.g* | January 22, 2026 | ransomware_live | — |
| empreinte-hotel.com | January 22, 2026 | ransomware_live | — |
| em***int*-ho***.com | January 17, 2026 | ransomware_live | — |
| ccbrt.org | January 17, 2026 | ransomware_live | — |
| cc***.or.*z | January 12, 2026 | ransomware_live | — |
| taminsho.com | December 22, 2025 | ransomware_live | — |
| platinumone.in | December 6, 2025 | ransomware_live | — |
| SUNNYGO.COM.TW | December 3, 2025 | ransomware_live | — |
| sevci.org | November 26, 2025 | ransomware_live | — |
| dacia-ploiesti.ro | November 26, 2025 | ransomware_live | — |
| mazda-ploiesti.ro | November 26, 2025 | ransomware_live | — |
| poliserv.ro | November 26, 2025 | ransomware_live | — |
| suzuki-ploiesti.ro | November 26, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).