sabbath
First seen November 22, 2021Active17 claimed victims
The claims below are reproduced as posted by sabbath on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| aria-label=Google> | February 28, 2022 | ransomware_live | — |
| JALEEL TRADERS LLC | January 15, 2022 | ransomware_live | — |
| ASL Napoli 3 Sud Network Seized | January 14, 2022 | ransomware_live | — |
| Protected: PRIVATE POST ITALY | January 12, 2022 | ransomware_live | — |
| Close search modal | January 4, 2022 | ransomware_live | — |
| Close drawer | January 4, 2022 | ransomware_live | — |
| Summit College | January 4, 2022 | ransomware_live | — |
| TRIGYN 2 0 | Data Leak | December 28, 2021 | ransomware_live | — |
| Prenax | December 20, 2021 | ransomware_live | — |
| Social Enterprise (SEC) | December 12, 2021 | ransomware_live | — |
| Trigyn Technologies Ltd | December 10, 2021 | ransomware_live | — |
| MCP Services LLC | November 22, 2021 | ransomware_live | — |
| RocTechnologies | November 22, 2021 | ransomware_live | — |
| Starline | November 22, 2021 | ransomware_live | — |
| AISD | November 22, 2021 | ransomware_live | — |
| Stoningtonschools | November 22, 2021 | ransomware_live | — |
| Flagship | November 22, 2021 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).