Skip to content
Leak site of auditteam, captured by ThreatCluster

auditteam

Active

25 tracked victims · First seen Feb 21, 2026 · Last seen Aug 27, 2026

About

Summarised by ThreatCluster from the group's own leak site

Leak site homepage shows a list of audit records with IDs, discovery dates, and status labels such as public transparency, remediation, cooperation, and paid, along with a few company names visible in the list.

Sectors: Technology, Manufacturing, Consumer Services · Countries: RU, KR, CO

Recent victims

View all →
VictimSectorCountryDataPostedStatus
TE***PBNot FoundRUSep 12, 2026
ki***jpNot FoundJPSep 9, 2026listed
my***ruTechnologyRUSep 9, 2026listed
mo***alNot FoundDESep 10, 2026listed
dg***krNot FoundKRSep 8, 2026listed
go***etTechnologyKRSep 9, 2026listed
kr***rgNot FoundARSep 9, 2026listed
bu***enNot FoundRUSep 8, 2026listed
Wi***ITTechnologyUASep 8, 2026listed
pa***opNot FoundRUSep 8, 2026listed
mansurovogroupAgricultureRussiaAug 26, 2026published
PIT.localNot FoundCOAug 27, 2026published
PI***alFinancial ServicesCOAug 27, 2026listed
Demidov Steel GroupManufacturingRUAug 18, 2026published
ma***upNot FoundRUAug 25, 2026listed
De***upNot FoundRUAug 18, 2026
I-SYSBusiness automationRUJun 15, 2026published
I-***YSNot FoundRUJun 15, 2026
Paid Victim 111CEAA5AD9DA2F1Not FoundRUJun 4, 2026
ca***lmNot FoundRUJun 2, 2026
Paid Victim B35411691DDC2265Not FoundRUMay 28, 2026
On***deNot FoundRUMay 28, 2026
Mopas Online SupermarketConsumer ServicesTRMay 15, 2026listed
Trésor PublicPublic SectorSN70 GBMay 10, 2026
Mo***etE-commerceMay 15, 2026

All ransomware groups · Dark web intelligence