BreachCensus

orca

First seen September 16, 2024Active5 claimed victims

The claims below are reproduced as posted by orca on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targeting organizations in manufacturing and logistics across Taiwan, Tunisia, Austria, and France, claiming to avoid hospitals, government institutions, and non-profits.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
Casale Del GiglioApril 27, 2026ransomware_live
Transport LutztullnMay 7, 2025ransomware_live
Transtec SASOctober 4, 2024ransomware_live
Chernan TechnologySeptember 18, 2024ransomware_live
ExcelPlast TunisieSeptember 16, 2024ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).