ShadowByt3$
Also known as: shadowbyt3$First seen February 25, 2026Active18 claimed victims
The claims below are reproduced as posted by ShadowByt3$ on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| BayView Real Estate | August 29, 2026 | ransomware_live | — |
| Bayview Real Estate WARNING | August 28, 2026 | ransomware_live | — |
| Knottingham Trent University | August 25, 2026 | ransomware_live | — |
| A-Plus Software Limited | August 25, 2026 | ransomware_live | — |
| Nintendo Corporation | August 25, 2026 | ransomware_live | — |
| Sinar Mas Agribusiness and Food Golden Agri-Resources) | August 25, 2026 | ransomware_live | — |
| TINYpulse NINTENDO BREACH | June 16, 2026 | ransomware_live | — |
| Nintendo Company | June 12, 2026 | ransomware_live | — |
| Lead Company (Leadership Boulevard) | June 3, 2026 | ransomware_live | — |
| Cropwise (Syngenta Group) | June 2, 2026 | ransomware_live | — |
| Hotelogix Company | May 21, 2026 | ransomware_live | — |
| Hotelogix | May 14, 2026 | ransomware_live | — |
| University Of Georgia | May 14, 2026 | ransomware_live | — |
| Amplify Technology | May 14, 2026 | ransomware_live | — |
| Stride Learning | May 14, 2026 | ransomware_live | — |
| PowerCampus | May 14, 2026 | ransomware_live | — |
| StarBucks Company | April 1, 2026 | ransomware_live | — |
| UMSA | February 17, 2026 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).