ms13089
Also known as: ms13-089First seen December 18, 2025Active5 claimed victims
The claims below are reproduced as posted by ms13089 on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| servmarmg.cl | August 15, 2026 | ransomware_live | — |
| brittanyresidential.com | May 5, 2026 | ransomware_live | — |
| sjl-legal.com | January 15, 2026 | ransomware_live | — |
| uro.com | December 18, 2025 | ransomware_live | — |
| dgpcommercialisti.it | December 18, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).