pysa
First seen July 1, 2020Active309 claimed victims
The claims below are reproduced as posted by pysa on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Fincamex | September 9, 2021 | ransomware_live | — |
| Allard | September 9, 2021 | ransomware_live | — |
| Diamond Box | September 9, 2021 | ransomware_live | — |
| Faic | September 9, 2021 | ransomware_live | — |
| Liberty Linehaul | September 9, 2021 | ransomware_live | — |
| Sacschool | September 9, 2021 | ransomware_live | — |
| Hackney Council | October 1, 2020 | ransomware_live | — |
| Nonin Medical | September 1, 2020 | ransomware_live | — |
| Durham Radio | July 1, 2020 | ransomware_live | — |
← NewerPage 4 of 4
Claim data from ransomware.live and RansomLook (CC BY 4.0).