BreachCensus

ms13089

Also known as: ms13-089First seen December 18, 2025Active5 claimed victims

The claims below are reproduced as posted by ms13089 on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
servmarmg.clAugust 15, 2026ransomware_live
brittanyresidential.comMay 5, 2026ransomware_live
sjl-legal.comJanuary 15, 2026ransomware_live
uro.comDecember 18, 2025ransomware_live
dgpcommercialisti.itDecember 18, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).