BreachCensus

blackshadow

First seen December 18, 2021Active3 claimed victims

The claims below are reproduced as posted by blackshadow on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
CyberServe CompanyDecember 18, 2021ransomware_live
K.L.S CapitalDecember 18, 2021ransomware_live
Shirbit Insurance CompanyDecember 18, 2021ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).