BreachCensus

IMNCrew

First seen May 5, 2025Active12 claimed victims

The claims below are reproduced as posted by IMNCrew on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial services organizations in the US, Croatia, and Indonesia by exploiting exposed perimeter services such as firewalls and VPNs, claiming at least five victims.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
Jansenfurniture.comSeptember 16, 2025ransomware_live
Onegolditalia.itAugust 2, 2025ransomware_live
Apntelecom.comJuly 4, 2025ransomware_live
Repremundo.com.coJune 14, 2025ransomware_live
Stiga.comMay 20, 2025ransomware_live
Goodson.comMay 5, 2025ransomware_live
Vnakc.orgMay 5, 2025ransomware_live
Abdainsurance.co.idMay 5, 2025ransomware_live
Derp.orgMay 5, 2025ransomware_live
Croatianmint.hrMay 5, 2025ransomware_live
Grupo Herradura OccidenteMay 5, 2025ransomware_live
Synthesia.comMay 5, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).