bert
First seen April 6, 2025Active7 claimed victims
The claims below are reproduced as posted by bert on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and event services sectors in Asia, Europe, and the US, with ransomware derived from a Linux variant of REvil using AES encryption and multi-threaded file locking.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| S5 Agency World | June 10, 2025 | ransomware_live | — |
| Columbia TI | June 5, 2025 | ransomware_live | — |
| Wawasan Dengkil Sdn Bhd | May 22, 2025 | ransomware_live | — |
| ALL RING TECH CO., LTD. | May 16, 2025 | ransomware_live | — |
| SIMCO Electronics | April 30, 2025 | ransomware_live | — |
| Yozgat City Hospital | April 9, 2025 | ransomware_live | — |
| National Ticket Company | April 4, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).