BreachCensus

underground

First seen May 1, 2024Active26 claimed victims

The claims below are reproduced as posted by underground on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023 by exploiting CVE-2023-36884, encrypting files without changing extensions and deleting Volume Shadow Copies and Windows event logs in double-extortion campaigns.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
SFA EngineeringAugust 15, 2025ransomware_live
GMORS Co., LtdJune 25, 2025ransomware_live
semex.comApril 15, 2025ransomware_live
shengyusteel.comApril 8, 2025ransomware_live
Afa Systems Ltd.February 13, 2025ransomware_live
Simmtech Co., Ltd.December 16, 2024ransomware_live
hcsgcorp.comOctober 25, 2024ransomware_live
Casio Computer Co., LtdOctober 9, 2024ransomware_live
ramservices.comJuly 3, 2024ransomware_live
EthypharmJune 20, 2024ransomware_live
A-Line Staffing SolutionsMay 24, 2024ransomware_live
CentralSecurities.comMay 15, 2024ransomware_live
www.belcherpharma.comMay 4, 2024ransomware_live
belcherpharma.comMay 4, 2024ransomware_live
cochraneglobal.comApril 15, 2024ransomware_live
Skender ConstructionMarch 21, 2024ransomware_live
Creative Business InteriorsMarch 17, 2024ransomware_live
Y. Hata & Co., Ltd.March 14, 2024ransomware_live
KyungChangMarch 6, 2024ransomware_live
kc.co.krFebruary 23, 2024ransomware_live
Triathlon.groupJanuary 26, 2024ransomware_live
awwg.comJanuary 25, 2024ransomware_live
frenckengroup.comJuly 18, 2023ransomware_live
bulldogbag.comJuly 14, 2023ransomware_live
tpa-group.skJuly 4, 2023ransomware_live
synology.comMay 30, 2023ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).