BreachCensus

benzona

First seen November 26, 2025Active14 claimed victims

The claims below are reproduced as posted by benzona on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
casamedica.com.gtJanuary 30, 2026ransomware_live
*a*ame*i*a.com.g*January 22, 2026ransomware_live
empreinte-hotel.comJanuary 22, 2026ransomware_live
em***int*-ho***.comJanuary 17, 2026ransomware_live
ccbrt.orgJanuary 17, 2026ransomware_live
cc***.or.*zJanuary 12, 2026ransomware_live
taminsho.comDecember 22, 2025ransomware_live
platinumone.inDecember 6, 2025ransomware_live
SUNNYGO.COM.TWDecember 3, 2025ransomware_live
sevci.orgNovember 26, 2025ransomware_live
dacia-ploiesti.roNovember 26, 2025ransomware_live
mazda-ploiesti.roNovember 26, 2025ransomware_live
poliserv.roNovember 26, 2025ransomware_live
suzuki-ploiesti.roNovember 26, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).