BreachCensus

VanHelsing

Also known as: vanhelsingFirst seen March 17, 2025Active8 claimed victims

The claims below are reproduced as posted by VanHelsing on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and splitting ransoms 80/20, supporting Windows, Linux, BSD, ARM, and ESXi targets, reaching at least five victims across the US, France, Italy, and Australia within its first two months.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
caschile.clApril 5, 2025ransomware_live
alertenterprise.comMarch 31, 2025ransomware_live
attorneykohm.comMarch 31, 2025ransomware_live
compumedics.com.au AND neuromedicalsupplies.comMarch 26, 2025ransomware_live
studiocdlvallone.itMarch 24, 2025ransomware_live
www.medsrx.comMarch 19, 2025ransomware_live
Atos-racks.comMarch 18, 2025ransomware_live
www.cityofbellville.comMarch 12, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).