BreachCensus

darkside

First seen August 1, 2020Active10 claimed victims

The claims below are reproduced as posted by darkside on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
One Call (insurance)May 13, 2021ransomware_live
Colonial PipelineMay 7, 2021ransomware_live
Toshiba Tec GroupMay 1, 2021ransomware_live
Compucom (MSP)February 27, 2021ransomware_live
Companhia Paranaense de Energia (Copel)February 1, 2021ransomware_live
Home Hardware Stores LtdFebruary 1, 2021ransomware_live
Discount Car and Truck RentalsFebruary 1, 2021ransomware_live
Segafredo ZanettiFebruary 1, 2021ransomware_live
GuessFebruary 1, 2021ransomware_live
Brookfield Residential (land developer and home builder)August 1, 2020ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).