helldown
First seen August 13, 2024Active36 claimed victims
The claims below are reproduced as posted by helldown on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Helldown is an aggressive ransomware group first documented in August 2024, known for exploiting Zyxel firewall vulnerabilities to gain initial access and conducting large-scale data exfiltration averaging 70 GB per victim, targeting IT services, telecommunications, manufacturing, and healthcare primarily in the US.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| CSIKBS | November 6, 2024 | ransomware_live | — |
| AMERICANVENTURE | November 6, 2024 | ransomware_live | — |
| klinkamkurpark | November 6, 2024 | ransomware_live | — |
| SMARTS-ENGINEER | October 28, 2024 | ransomware_live | — |
| lacliniqueducoureur | October 25, 2024 | ransomware_live | — |
| TIVOLI-33 | October 23, 2024 | ransomware_live | — |
| qualiform.cz | October 22, 2024 | ransomware_live | — |
| children | October 12, 2024 | ransomware_live | — |
| compassfs | October 11, 2024 | ransomware_live | — |
| SANJACINTOCOUNY | October 11, 2024 | ransomware_live | — |
| VALLEYFIRM | October 11, 2024 | ransomware_live | — |
| knoxlawcenter | October 10, 2024 | ransomware_live | — |
| hausdesstiftens.org | October 8, 2024 | ransomware_live | — |
| fuelco | October 1, 2024 | ransomware_live | — |
| nightnurse.ch | September 13, 2024 | ransomware_live | — |
| HBGJEWISHCOMMUN | August 24, 2024 | ransomware_live | — |
| barryavenueplating | August 23, 2024 | ransomware_live | — |
| khonaysser.com | August 22, 2024 | ransomware_live | — |
| kbosecurity.co.uk | August 22, 2024 | ransomware_live | — |
| RSK-IMMOBILIEN | August 21, 2024 | ransomware_live | — |
| BARRYAVEPLATING | August 21, 2024 | ransomware_live | — |
| cincinnatipainphysicians | August 21, 2024 | ransomware_live | — |
| ATP | August 20, 2024 | ransomware_live | — |
| Khonaysser | August 19, 2024 | ransomware_live | — |
| kbo | August 18, 2024 | ransomware_live | — |
| zyxel | August 17, 2024 | ransomware_live | — |
| deganis | August 13, 2024 | ransomware_live | — |
| SCHLATTNER | August 13, 2024 | ransomware_live | — |
| hugwi | August 13, 2024 | ransomware_live | — |
| Albatros | August 11, 2024 | ransomware_live | — |
| vindix | August 11, 2024 | ransomware_live | — |
| briju | August 11, 2024 | ransomware_live | — |
| AZIENDA TRASPORTI PUBBLICI S.P.A. | August 10, 2024 | ransomware_live | — |
| cbmm | August 9, 2024 | ransomware_live | — |
| MyFreightWorld | August 5, 2024 | ransomware_live | — |
| XPERT Business Solutions GmbH | August 5, 2024 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).