madliberator
First seen July 17, 2024Active16 claimed victims
The claims below are reproduced as posted by madliberator on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
MadLiberator is a ransomware group that emerged in mid-2024, known for erratic behavior including randomized ransom demands and unpredictable encryption patterns, targeting government entities including the Italian Ministry of Culture and using a data leak site to post exfiltrated files.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| marthamedeiros.com.br | October 1, 2024 | ransomware_live | — |
| ctelift.com | September 6, 2024 | ransomware_live | — |
| ych.com | September 4, 2024 | ransomware_live | — |
| awsag.com | August 17, 2024 | ransomware_live | — |
| suandco.com | August 7, 2024 | ransomware_live | — |
| msprocuradores.es | August 6, 2024 | ransomware_live | — |
| coinbv.nl | August 2, 2024 | ransomware_live | — |
| orbinox.com | July 25, 2024 | ransomware_live | — |
| vrd.be | July 24, 2024 | ransomware_live | — |
| ORBINOX | July 24, 2024 | ransomware_live | — |
| zb.co.zw | July 13, 2024 | ransomware_live | — |
| sacities.net | July 12, 2024 | ransomware_live | — |
| MONTERO & SEGURA | July 12, 2024 | ransomware_live | — |
| crosswear.co.uk | June 19, 2024 | ransomware_live | — |
| VITALDENT | June 13, 2024 | ransomware_live | — |
| BENICULTURALI.IT | May 27, 2024 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).