BreachCensus

cactus

First seen July 20, 2023Active248 claimed victims

The claims below are reproduced as posted by cactus on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure. There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
Specialised Management ServicesSeptember 7, 2023ransomware_live
Trimaran Capital PartnersSeptember 7, 2023ransomware_live
West Craft ManufacturingSeptember 7, 2023ransomware_live
TORMAX USASeptember 7, 2023ransomware_live
reawire.comSeptember 6, 2023ransomware_live
Lagarde MeregnaniSeptember 5, 2023ransomware_live
Hornsyld KøbmandsgaardSeptember 5, 2023ransomware_live
Foroni SPASeptember 5, 2023ransomware_live
BarscoSeptember 5, 2023ransomware_live
Marfrig Global FoodsSeptember 5, 2023ransomware_live
SeymoursSeptember 5, 2023ransomware_live
PromotransSeptember 5, 2023ransomware_live
MINEMAN SystemsSeptember 5, 2023ransomware_live
Maxxd TrailersSeptember 5, 2023ransomware_live
Barco UniformsSeptember 4, 2023ransomware_live
BalcanSeptember 4, 2023ransomware_live
SpuncastSeptember 2, 2023ransomware_live
Astro LightingSeptember 2, 2023ransomware_live
Peacock BrosSeptember 1, 2023ransomware_live
ghimli.comAugust 26, 2023ransomware_live
Bacon UniversalAugust 22, 2023ransomware_live
BRiC PartnershipAugust 17, 2023ransomware_live
atWork Office FurnitureAugust 11, 2023ransomware_live
Custom Powder SystemsAugust 11, 2023ransomware_live
LeekesAugust 9, 2023ransomware_live
DM CivilAugust 8, 2023ransomware_live
UnimarketingAugust 3, 2023ransomware_live
My Insurance BrokerAugust 2, 2023ransomware_live
AmericoldJuly 20, 2023ransomware_live
WasserstromJuly 20, 2023ransomware_live
Phoenix TaxisJuly 20, 2023ransomware_live
Rotomail Italia SpAJuly 20, 2023ransomware_live
Reyes Automotive GroupJuly 20, 2023ransomware_live
ArtemideJuly 20, 2023ransomware_live
NovobitJuly 20, 2023ransomware_live
Michigan Production MachiningJuly 20, 2023ransomware_live
ItalkraftJuly 20, 2023ransomware_live
ImaginationJuly 20, 2023ransomware_live
Hawa Sliding SolutionsJuly 20, 2023ransomware_live
CWSJuly 20, 2023ransomware_live
ScanSourceJuly 20, 2023ransomware_live
Confartigianato Federimpresa FCJuly 20, 2023ransomware_live
Biocair InternationalJuly 20, 2023ransomware_live
American Meteorological SocietyJuly 20, 2023ransomware_live
AgoravitaJuly 20, 2023ransomware_live
Alberto Couto AlvesJuly 20, 2023ransomware_live
ebir.comJuly 19, 2023ransomware_live
millimages.comJuly 3, 2023ransomware_live
← NewerPage 3 of 3

Claim data from ransomware.live and RansomLook (CC BY 4.0).