Threat-actor trackers
The ransomware and extortion crews behind the breaches we cover — who they are, how active they've been, and every incident we've attributed to them. Each tracker grows automatically as our daily breach ingest picks up new claims.
Most active crews
Also tracking
Chaos
Latest: Wikoff Color Corporation Listed by Chaos Ransomware
Doommageddon
Latest: Reni Farmácias Associadas Listed by Doommageddon Ransomware Group
Project
Latest: Pelli Clarke Pelli Architects Listed by Booba Project Ransomware Group
Qilin
Latest: Ahorramas Supermarket Chain — May 2026
BrainCipher
Latest: windiam.com Listed by BrainCipher Ransomware Group
Collective
Latest: Brightspeed Fiber Broadband Incident — January 2026
Engineering
Latest: Atencio Engineering Ransomware Claim — May 2026
Everest
Latest: Everest ransomware claims breach of Liberty Mutual insurance data
Gentlemen
Latest: Aveiro Constructors Listed by The Gentlemen Ransomware
GodDamn
Latest: GodDamn Ransomware Uses PoisonX BYOVD Driver in Attacks
LockBit
Latest: Bancroft Engineering Listed by LockBit
MoneyMessage
Latest: MoneyMessage Ransomware Hits Nonprofit Envision Unlimited
Residential
Latest: Brittany Residential Ransomware Claim — May 2026
Services
Latest: Bay State Land Services Ransomware Claim — May 2026
Supermercados
Latest: Bandeirante Supermercados Ransomware Claim — May 2026
How these trackers work
Our breach ingest monitors public reporting and ransomware leak sites daily. When an incident is claimed by or attributed to a named group, it's added to that group's tracker automatically. "Claimed by" is not proof — extortion crews sometimes exaggerate or recycle old data — so every entry links to the full write-up with sources.
If an organization you use appears here
Treat your data as circulating. Stolen records get scraped into the same broker-and-dump ecosystem that doxxers and identity thieves search. The fastest way to know your real exposure is a free breach scan — it checks your email against 15.4B+ leaked records in about 15 seconds, including data tied to the groups above.
Both halves of the chain, cleaned once.
A breach put your credentials in 15.4B+ leaked records. Hackers chain that data to your address on 800+ broker sites. GalaxyWarden closes both halves — see what’s exposed first, then pick the protection that fits.