TiMc
Also known as: timcFirst seen April 9, 2026Active3 claimed victims
The claims below are reproduced as posted by TiMc on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader Seidor (1 TB+ data) and oncology organization Oncologica (100 GB+), targeting Business Services, Healthcare, and IT sectors with a focus on Spanish-speaking and European targets.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Debene S.A. | Página Principal | April 9, 2026 | ransomware_live | — |
| Seidor | April 9, 2026 | ransomware_live | — |
| oncologica | April 9, 2026 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).