blackwater
First seen April 12, 2026Active11 claimed victims
The claims below are reproduced as posted by blackwater on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Blackwater is a ransomware group that first surfaced in early 2026, combining file encryption with data theft and targeting healthcare organizations, with known victims including Minidoka Memorial Hospital in Idaho.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| www.ptesm.com | August 24, 2026 | ransomware_live | — |
| www.shalina.com | August 15, 2026 | ransomware_live | — |
| www.amca.org.ar | August 15, 2026 | ransomware_live | — |
| msgas.com.br | July 25, 2026 | ransomware_live | — |
| txdkj.com | July 10, 2026 | ransomware_live | — |
| www.utourworld.com | June 6, 2026 | ransomware_live | — |
| Tuopu | May 2, 2026 | ransomware_live | — |
| Compass Housing Alliance | April 30, 2026 | ransomware_live | — |
| Shenzhen Gongjin Electronics | April 29, 2026 | ransomware_live | — |
| Grupo EBD | April 17, 2026 | ransomware_live | — |
| Minidoka Memorial Hospital | April 17, 2026 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).