BreachCensus

cephalus

First seen August 26, 2025Active19 claimed victims

The claims below are reproduced as posted by cephalus on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
Delta Information SystemsAugust 29, 2025ransomware_live
Shelbourne AccountantsAugust 29, 2025ransomware_live
ShropdocAugust 29, 2025ransomware_live
One-LUXAugust 29, 2025ransomware_live
CoCo YachtsAugust 28, 2025ransomware_live
wilderlawfirmAugust 28, 2025ransomware_live
Texas Pregnancy Care NetworkAugust 28, 2025ransomware_live
Colorado Health Network IncAugust 28, 2025ransomware_live
SystemExec Co., Ltd.August 26, 2025ransomware_live
BAR Architects & InteriorsAugust 26, 2025ransomware_live
K Strategies Marketing and Public RelationsAugust 26, 2025ransomware_live
LPL FinancialAugust 26, 2025ransomware_live
Guerrero Mears LLPAugust 26, 2025ransomware_live
Sherman, Silverstein, Kohl, Rose & Podolsky, P.A.August 26, 2025ransomware_live
Lewis Baach Kaufmann Middlemiss PLLCAugust 26, 2025ransomware_live
Town of Vienna, VAAugust 26, 2025ransomware_live
txpregnancy.org - Fake Abortion Clinics ExposedAugust 26, 2025ransomware_live
Lee & AssociatesAugust 20, 2025ransomware_live
CareSTL HealthJune 28, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).