rancoz
First seen May 5, 2023Active6 claimed victims
The claims below are reproduced as posted by rancoz on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Rancoz is a Windows-targeting ransomware strain first observed in November 2022 that appends the ".rec_rans" extension to encrypted files, considered a Vice Society copycat, deployed against a small number of organizations using double extortion and linked to the same developer as the "Buddy" ransomware.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Rick Ramos Law (rickramoslaw.com) | September 3, 2023 | ransomware_live | — |
| DDB Unlimited (ddbunlimited.com) | September 3, 2023 | ransomware_live | — |
| Industrial Heat Transfer (iht-inc.com) | July 7, 2023 | ransomware_live | — |
| Air Comfort (aircomfort.ac) | June 14, 2023 | ransomware_live | — |
| TrueLogic (truelogiccompany.com) | May 5, 2023 | ransomware_live | — |
| RIC Electronics (ricelectronics.com) | May 5, 2023 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).