BreachCensus

kawa4096

Also known as: KaWaLockerFirst seen June 27, 2025Active17 claimed victims

The claims below are reproduced as posted by kawa4096 on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Kawa4096 is a ransomware group that emerged in June 2025, targeting multinational corporations across finance, education, and services sectors primarily in the US and Japan, using partial-encryption (25% of each file chunk) with Salsa20 and a leak site styled after Akira's retro terminal aesthetic, claiming at least 11 victims.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
********.orgJuly 28, 2025ransomware_live
**********.comJuly 27, 2025ransomware_live
**********.netJuly 27, 2025ransomware_live
sbamh.orgJuly 20, 2025ransomware_live
*************.orgJune 28, 2025ransomware_live
www.ogr-jp.comJune 28, 2025ransomware_live
carestlhealth.orgJune 28, 2025ransomware_live
**********-*******.co.jpJune 26, 2025ransomware_live
tokiomarine-nichido.co.jpJune 26, 2025ransomware_live
******.orgJune 25, 2025ransomware_live
gatewaycsb.orgJune 25, 2025ransomware_live
******.comJune 24, 2025ransomware_live
www.malonebailey.comJune 24, 2025ransomware_live
******.deJune 22, 2025ransomware_live
heimhaus.deJune 22, 2025ransomware_live
MorningsideservicesJune 20, 2025ransomware_live
icmconv.comJune 19, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).