IMNCrew
First seen May 5, 2025Active12 claimed victims
The claims below are reproduced as posted by IMNCrew on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial services organizations in the US, Croatia, and Indonesia by exploiting exposed perimeter services such as firewalls and VPNs, claiming at least five victims.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Jansenfurniture.com | September 16, 2025 | ransomware_live | — |
| Onegolditalia.it | August 2, 2025 | ransomware_live | — |
| Apntelecom.com | July 4, 2025 | ransomware_live | — |
| Repremundo.com.co | June 14, 2025 | ransomware_live | — |
| Stiga.com | May 20, 2025 | ransomware_live | — |
| Goodson.com | May 5, 2025 | ransomware_live | — |
| Vnakc.org | May 5, 2025 | ransomware_live | — |
| Abdainsurance.co.id | May 5, 2025 | ransomware_live | — |
| Derp.org | May 5, 2025 | ransomware_live | — |
| Croatianmint.hr | May 5, 2025 | ransomware_live | — |
| Grupo Herradura Occidente | May 5, 2025 | ransomware_live | — |
| Synthesia.com | May 5, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).