BreachCensus

sabbath

First seen November 22, 2021Active17 claimed victims

The claims below are reproduced as posted by sabbath on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
aria-label=Google>February 28, 2022ransomware_live
JALEEL TRADERS LLCJanuary 15, 2022ransomware_live
ASL Napoli 3 Sud Network SeizedJanuary 14, 2022ransomware_live
Protected: PRIVATE POST ITALYJanuary 12, 2022ransomware_live
Close search modalJanuary 4, 2022ransomware_live
Close drawerJanuary 4, 2022ransomware_live
Summit CollegeJanuary 4, 2022ransomware_live
TRIGYN 2 0 | Data LeakDecember 28, 2021ransomware_live
PrenaxDecember 20, 2021ransomware_live
Social Enterprise (SEC)December 12, 2021ransomware_live
Trigyn Technologies LtdDecember 10, 2021ransomware_live
MCP Services LLCNovember 22, 2021ransomware_live
RocTechnologiesNovember 22, 2021ransomware_live
StarlineNovember 22, 2021ransomware_live
AISDNovember 22, 2021ransomware_live
StoningtonschoolsNovember 22, 2021ransomware_live
FlagshipNovember 22, 2021ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).