BreachCensus

cuba

Also known as: ColddrawFirst seen February 3, 2021Active103 claimed victims

The claims below are reproduced as posted by cuba on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted. Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
First Coast Logistics Services, Inc. was founded in 1999. The Company's line of business iSeptember 9, 2021ransomware_live
The Squamish Nation is comprised of descendants of the Coast Salish Aboriginal peoples whoSeptember 9, 2021ransomware_live
Automatic Funds Transfer Services Inc. (vendor to city of Bainbridge Island)February 3, 2021ransomware_live
← NewerPage 2 of 2

Claim data from ransomware.live and RansomLook (CC BY 4.0).