datacarry
First seen May 26, 2025Active16 claimed victims
The claims below are reproduced as posted by datacarry on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Camomilla | December 6, 2025 | ransomware_live | — |
| UAM | November 21, 2025 | ransomware_live | — |
| Miljödata | September 13, 2025 | ransomware_live | — |
| Miljödata (1 day left) | September 13, 2025 | ransomware_live | — |
| Peggy Sage | August 15, 2025 | ransomware_live | — |
| Món Sant Benet | June 7, 2025 | ransomware_live | — |
| Alliance Healthcare IT | May 29, 2025 | ransomware_live | — |
| V² Development | May 28, 2025 | ransomware_live | — |
| alles Lægehus | May 26, 2025 | ransomware_live | — |
| La Maison Liégeoise | May 26, 2025 | ransomware_live | — |
| Executive Jet Support | January 30, 2025 | ransomware_live | — |
| Étude Bordet | January 12, 2025 | ransomware_live | — |
| FrontierCo | November 12, 2024 | ransomware_live | — |
| ALB Forex | October 25, 2024 | ransomware_live | — |
| Mammut Sports Group | September 27, 2024 | ransomware_live | — |
| Balcia Insurance | June 26, 2024 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).