BreachCensus

pysa

First seen July 1, 2020Active309 claimed victims

The claims below are reproduced as posted by pysa on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
FincamexSeptember 9, 2021ransomware_live
AllardSeptember 9, 2021ransomware_live
Diamond BoxSeptember 9, 2021ransomware_live
FaicSeptember 9, 2021ransomware_live
Liberty LinehaulSeptember 9, 2021ransomware_live
SacschoolSeptember 9, 2021ransomware_live
Hackney CouncilOctober 1, 2020ransomware_live
Nonin MedicalSeptember 1, 2020ransomware_live
Durham RadioJuly 1, 2020ransomware_live
← NewerPage 4 of 4

Claim data from ransomware.live and RansomLook (CC BY 4.0).