BreachCensus

trinity

First seen June 11, 2024Active18 claimed victims

The claims below are reproduced as posted by trinity on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaCha20 encryption and double-extortion via a Tor leak site; the US HHS flagged it as a specific threat to the healthcare sector after confirmed attacks on healthcare organizations.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
la-z-boyMarch 16, 2025ransomware_live
CNSMarch 16, 2025ransomware_live
CANAM Realty GroupMarch 16, 2025ransomware_live
Lake Psychological ServicesMarch 16, 2025ransomware_live
ROBONG-WINMINIMarch 16, 2025ransomware_live
consultoria-consultores.esMarch 16, 2025ransomware_live
Kairav Chemofarbe IndustriesMarch 16, 2025ransomware_live
Agencia Tributaria AEATNovember 30, 2024ransomware_live
Barnes & CohenOctober 3, 2024ransomware_live
FoccoERPOctober 2, 2024ransomware_live
Fabrica Industrial Machinery & EquipmentSeptember 23, 2024ransomware_live
INTERNAL.ROCKYMOUNTAINGASTRO.COMSeptember 15, 2024ransomware_live
wellandSeptember 1, 2024ransomware_live
Cosmetic Dental GroupAugust 18, 2024ransomware_live
Banner and AssociatesAugust 13, 2024ransomware_live
CBSTRAININGJune 12, 2024ransomware_live
sgvfr.comJune 12, 2024ransomware_live
filmetrics corporationJune 6, 2024ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).