VanHelsing
Also known as: vanhelsingFirst seen March 17, 2025Active8 claimed victims
The claims below are reproduced as posted by VanHelsing on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and splitting ransoms 80/20, supporting Windows, Linux, BSD, ARM, and ESXi targets, reaching at least five victims across the US, France, Italy, and Australia within its first two months.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| caschile.cl | April 5, 2025 | ransomware_live | — |
| alertenterprise.com | March 31, 2025 | ransomware_live | — |
| attorneykohm.com | March 31, 2025 | ransomware_live | — |
| compumedics.com.au AND neuromedicalsupplies.com | March 26, 2025 | ransomware_live | — |
| studiocdlvallone.it | March 24, 2025 | ransomware_live | — |
| www.medsrx.com | March 19, 2025 | ransomware_live | — |
| Atos-racks.com | March 18, 2025 | ransomware_live | — |
| www.cityofbellville.com | March 12, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).