BreachCensus

bert

First seen April 6, 2025Active7 claimed victims

The claims below are reproduced as posted by bert on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and event services sectors in Asia, Europe, and the US, with ransomware derived from a Linux variant of REvil using AES encryption and multi-threaded file locking.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
S5 Agency WorldJune 10, 2025ransomware_live
Columbia TIJune 5, 2025ransomware_live
Wawasan Dengkil Sdn BhdMay 22, 2025ransomware_live
ALL RING TECH CO., LTD.May 16, 2025ransomware_live
SIMCO ElectronicsApril 30, 2025ransomware_live
Yozgat City HospitalApril 9, 2025ransomware_live
National Ticket CompanyApril 4, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).