orca
First seen September 16, 2024Active5 claimed victims
The claims below are reproduced as posted by orca on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targeting organizations in manufacturing and logistics across Taiwan, Tunisia, Austria, and France, claiming to avoid hospitals, government institutions, and non-profits.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Casale Del Giglio | April 27, 2026 | ransomware_live | — |
| Transport Lutztulln | May 7, 2025 | ransomware_live | — |
| Transtec SAS | October 4, 2024 | ransomware_live | — |
| Chernan Technology | September 18, 2024 | ransomware_live | — |
| ExcelPlast Tunisie | September 16, 2024 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).