BreachCensus

datacarry

First seen May 26, 2025Active16 claimed victims

The claims below are reproduced as posted by datacarry on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
CamomillaDecember 6, 2025ransomware_live
UAMNovember 21, 2025ransomware_live
MiljödataSeptember 13, 2025ransomware_live
Miljödata (1 day left)September 13, 2025ransomware_live
Peggy SageAugust 15, 2025ransomware_live
Món Sant BenetJune 7, 2025ransomware_live
Alliance Healthcare ITMay 29, 2025ransomware_live
V² DevelopmentMay 28, 2025ransomware_live
alles LægehusMay 26, 2025ransomware_live
La Maison LiégeoiseMay 26, 2025ransomware_live
Executive Jet SupportJanuary 30, 2025ransomware_live
Étude BordetJanuary 12, 2025ransomware_live
FrontierCoNovember 12, 2024ransomware_live
ALB ForexOctober 25, 2024ransomware_live
Mammut Sports GroupSeptember 27, 2024ransomware_live
Balcia InsuranceJune 26, 2024ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).