blackout
First seen February 26, 2024Active12 claimed victims
The claims below are reproduced as posted by blackout on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| bluebellgroup.com | July 19, 2026 | ransomware_live | — |
| www.miatech.net | July 19, 2026 | ransomware_live | — |
| yano.tokyo | July 19, 2026 | ransomware_live | — |
| nedamaritime.gr | December 10, 2024 | ransomware_live | — |
| cdc-biodiversite.fr | September 26, 2024 | ransomware_live | — |
| antaeustravel.com | August 22, 2024 | ransomware_live | — |
| luzan5.com | July 14, 2024 | ransomware_live | — |
| badel1862.hr | July 3, 2024 | ransomware_live | — |
| mcmtelecom.com | May 29, 2024 | ransomware_live | — |
| ht-hospitaltechnik.de | April 18, 2024 | ransomware_live | — |
| metal7.com | February 26, 2024 | ransomware_live | — |
| ch-armentieres.fr | February 26, 2024 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).