trinity
First seen June 11, 2024Active18 claimed victims
The claims below are reproduced as posted by trinity on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaCha20 encryption and double-extortion via a Tor leak site; the US HHS flagged it as a specific threat to the healthcare sector after confirmed attacks on healthcare organizations.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| la-z-boy | March 16, 2025 | ransomware_live | — |
| CNS | March 16, 2025 | ransomware_live | — |
| CANAM Realty Group | March 16, 2025 | ransomware_live | — |
| Lake Psychological Services | March 16, 2025 | ransomware_live | — |
| ROBONG-WINMINI | March 16, 2025 | ransomware_live | — |
| consultoria-consultores.es | March 16, 2025 | ransomware_live | — |
| Kairav Chemofarbe Industries | March 16, 2025 | ransomware_live | — |
| Agencia Tributaria AEAT | November 30, 2024 | ransomware_live | — |
| Barnes & Cohen | October 3, 2024 | ransomware_live | — |
| FoccoERP | October 2, 2024 | ransomware_live | — |
| Fabrica Industrial Machinery & Equipment | September 23, 2024 | ransomware_live | — |
| INTERNAL.ROCKYMOUNTAINGASTRO.COM | September 15, 2024 | ransomware_live | — |
| welland | September 1, 2024 | ransomware_live | — |
| Cosmetic Dental Group | August 18, 2024 | ransomware_live | — |
| Banner and Associates | August 13, 2024 | ransomware_live | — |
| CBSTRAINING | June 12, 2024 | ransomware_live | — |
| sgvfr.com | June 12, 2024 | ransomware_live | — |
| filmetrics corporation | June 6, 2024 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).