BreachCensus

weyhro

First seen March 6, 2025Active14 claimed victims

The claims below are reproduced as posted by weyhro on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
Chemtron RiverBendAugust 10, 2025ransomware_live
Community Services of MissouriAugust 10, 2025ransomware_live
Adriatic Glass & MirrorsMay 31, 2025ransomware_live
Terra CaribbeanMay 30, 2025ransomware_live
Synergy InvestmentsMay 26, 2025ransomware_live
101 Arch StreetMay 8, 2025ransomware_live
Valens Bank/Pay/ExchangeMarch 31, 2025ransomware_live
Montgomery Little & Soran, PCMarch 21, 2025ransomware_live
McMillan James Equipment Company (MJEC)March 19, 2025ransomware_live
Fragola S.p.AFebruary 26, 2025ransomware_live
Avantune CorporationFebruary 22, 2025ransomware_live
Central Electropolishing Company, Inc.February 8, 2025ransomware_live
MBI International, Inc.January 15, 2025ransomware_live
Resnick & Caffrey, PCDecember 12, 2024ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).