darkside
First seen August 1, 2020Active10 claimed victims
The claims below are reproduced as posted by darkside on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| One Call (insurance) | May 13, 2021 | ransomware_live | — |
| Colonial Pipeline | May 7, 2021 | ransomware_live | — |
| Toshiba Tec Group | May 1, 2021 | ransomware_live | — |
| Compucom (MSP) | February 27, 2021 | ransomware_live | — |
| Companhia Paranaense de Energia (Copel) | February 1, 2021 | ransomware_live | — |
| Home Hardware Stores Ltd | February 1, 2021 | ransomware_live | — |
| Discount Car and Truck Rentals | February 1, 2021 | ransomware_live | — |
| Segafredo Zanetti | February 1, 2021 | ransomware_live | — |
| Guess | February 1, 2021 | ransomware_live | — |
| Brookfield Residential (land developer and home builder) | August 1, 2020 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).