brotherhood
First seen November 15, 2025Active18 claimed victims
The claims below are reproduced as posted by brotherhood on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia across manufacturing, communications, and construction sectors, operating a Tor-based double-extortion leak site.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Italgrafica Sistemi | January 6, 2026 | ransomware_live | — |
| häussermann stauden gehölze gmbh | December 10, 2025 | ransomware_live | — |
| Ingenieurbüro Laudi | November 28, 2025 | ransomware_live | — |
| Ninas Jewellery | November 15, 2025 | ransomware_live | — |
| Kaener Personal | November 15, 2025 | ransomware_live | — |
| Cera Stribley | November 15, 2025 | ransomware_live | — |
| Spoleta Construction | November 15, 2025 | ransomware_live | — |
| Horst Realty | November 15, 2025 | ransomware_live | — |
| Citizens' Committee for Children of New York | October 11, 2025 | ransomware_live | — |
| Integlia | October 11, 2025 | ransomware_live | — |
| Coal Industry Social Welfare Organisation | October 10, 2025 | ransomware_live | — |
| Orion Communications and Public Relations | October 10, 2025 | ransomware_live | — |
| Motility Software | October 10, 2025 | ransomware_live | — |
| UVJ Technologies | October 10, 2025 | ransomware_live | — |
| Kevmor | October 10, 2025 | ransomware_live | — |
| Sternthal Montigny Greenberg St-Germain | October 10, 2025 | ransomware_live | — |
| Momentum Logistics | October 10, 2025 | ransomware_live | — |
| Woodmen Valley Chapel | April 4, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).