BreachCensus

rancoz

First seen May 5, 2023Active6 claimed victims

The claims below are reproduced as posted by rancoz on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Rancoz is a Windows-targeting ransomware strain first observed in November 2022 that appends the ".rec_rans" extension to encrypted files, considered a Vice Society copycat, deployed against a small number of organizations using double extortion and linked to the same developer as the "Buddy" ransomware.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
Rick Ramos Law (rickramoslaw.com)September 3, 2023ransomware_live
DDB Unlimited (ddbunlimited.com)September 3, 2023ransomware_live
Industrial Heat Transfer (iht-inc.com)July 7, 2023ransomware_live
Air Comfort (aircomfort.ac)June 14, 2023ransomware_live
TrueLogic (truelogiccompany.com)May 5, 2023ransomware_live
RIC Electronics (ricelectronics.com)May 5, 2023ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).