BreachCensus

vect

First seen January 6, 2026Active25 claimed victims

The claims below are reproduced as posted by vect on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

VECT is a RaaS group that launched its affiliate program in December 2025 with a five-tier revenue-sharing model and a formal partnership with BreachForums; its VECT 2.0 payload contains a critical encryption flaw that irreversibly destroys files larger than 128 KB rather than encrypting them.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
guesty, LITELLM/TRIVY CAMPAIGN (TEAMPCP)April 15, 2026ransomware_live
Verlat EnergyMarch 2, 2026ransomware_live
keliwebFebruary 28, 2026ransomware_live
Casas del MediterraneoFebruary 28, 2026ransomware_live
jdaasFebruary 28, 2026ransomware_live
USHA International LimitedFebruary 28, 2026ransomware_live
Del ReyFebruary 25, 2026ransomware_live
Sus Insumos S.A.SFebruary 25, 2026ransomware_live
PappytechFebruary 24, 2026ransomware_live
pay***February 24, 2026ransomware_live
for******a****ngFebruary 24, 2026ransomware_live
***wireFebruary 24, 2026ransomware_live
****360.comFebruary 24, 2026ransomware_live
a*f***aFebruary 24, 2026ransomware_live
s***om****xFebruary 24, 2026ransomware_live
MB ContabilidadeFebruary 24, 2026ransomware_live
ApexHospitalsFebruary 19, 2026ransomware_live
EnerTecFebruary 13, 2026ransomware_live
Mutualista ImbaburaFebruary 13, 2026ransomware_live
Was MadeirasFebruary 13, 2026ransomware_live
Grupo VerdeAzulFebruary 13, 2026ransomware_live
AuvoFebruary 13, 2026ransomware_live
Hytec South AfricaJanuary 5, 2026ransomware_live
Federal University of SergipeJanuary 5, 2026ransomware_live
S&PGLOBAL, LiteLLM/Trivy campaign (TeamPCP)October 5, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).