kawa4096
Also known as: KaWaLockerFirst seen June 27, 2025Active17 claimed victims
The claims below are reproduced as posted by kawa4096 on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| ********.org | July 28, 2025 | ransomware_live | — |
| **********.com | July 27, 2025 | ransomware_live | — |
| **********.net | July 27, 2025 | ransomware_live | — |
| sbamh.org | July 20, 2025 | ransomware_live | — |
| *************.org | June 28, 2025 | ransomware_live | — |
| www.ogr-jp.com | June 28, 2025 | ransomware_live | — |
| carestlhealth.org | June 28, 2025 | ransomware_live | — |
| **********-*******.co.jp | June 26, 2025 | ransomware_live | — |
| tokiomarine-nichido.co.jp | June 26, 2025 | ransomware_live | — |
| ******.org | June 25, 2025 | ransomware_live | — |
| gatewaycsb.org | June 25, 2025 | ransomware_live | — |
| ******.com | June 24, 2025 | ransomware_live | — |
| www.malonebailey.com | June 24, 2025 | ransomware_live | — |
| ******.de | June 22, 2025 | ransomware_live | — |
| heimhaus.de | June 22, 2025 | ransomware_live | — |
| Morningsideservices | June 20, 2025 | ransomware_live | — |
| icmconv.com | June 19, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).